Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5873 |
|
Out-of-Bounds Read in google (CVE-2026-5873)
vulnerability in google (CVE-2026-5873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5858 |
|
Vulnerability in google (CVE-2026-5858)
vulnerability in google (CVE-2026-5858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5859 |
|
Vulnerability in google (CVE-2026-5859)
vulnerability in google (CVE-2026-5859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5861 |
|
Use-After-Free in google (CVE-2026-5861)
vulnerability in google (CVE-2026-5861). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5862 |
|
Vulnerability in google (CVE-2026-5862)
vulnerability in google (CVE-2026-5862). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5860 |
|
Use-After-Free in google (CVE-2026-5860)
vulnerability in google (CVE-2026-5860). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40036 |
|
Vulnerability in dfir-unfurl (CVE-2026-40036)
vulnerability in dfir-unfurl (CVE-2026-40036). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20260405` or later.
|
| CVE-2026-40029 |
|
OS Command Injection in khyrenz (CVE-2026-40029)
OS command injection in khyrenz (CVE-2026-40029). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40030 |
|
OS Command Injection in khyrenz (CVE-2026-40030)
OS command injection in khyrenz (CVE-2026-40030). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40031 |
|
Vulnerability in ufrisk (CVE-2026-40031)
vulnerability in ufrisk (CVE-2026-40031). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40032 |
|
OS Command Injection in CVE-2026-40032 (CVE-2026-40032)
OS command injection in CVE-2026-40032 (CVE-2026-40032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40027 |
|
Path Traversal in path-traversal (CVE-2026-40027)
path traversal in path-traversal (CVE-2026-40027). Confidential information can be exposed externally.
|
| CVE-2026-40024 |
|
Path Traversal in path-traversal (CVE-2026-40024)
path traversal in path-traversal (CVE-2026-40024). Confidential information can be exposed externally.
|
| CVE-2026-5805 |
|
Vulnerability in c (CVE-2026-5805)
vulnerability in c (CVE-2026-5805). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5436 |
|
Path Traversal in wordpress (CVE-2026-5436)
path traversal in wordpress (CVE-2026-5436). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39889 |
|
Information Disclosure in praison (CVE-2026-39889)
vulnerability in praison (CVE-2026-39889). Confidential information can be exposed externally. Mitigation: upgrade to `4.5.115` or later.
|
| CVE-2026-39891 |
|
Code Injection in praison (CVE-2026-39891)
code injection in praison (CVE-2026-39891). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.115` or later.
|
| CVE-2026-39883 |
|
Vulnerability in opentelemetry (CVE-2026-39883)
vulnerability in opentelemetry (CVE-2026-39883). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.43.0` or later.
|
| CVE-2026-39885 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39885)
SSRF in ssrf (CVE-2026-39885). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-39429 |
|
Vulnerability in github.com/kcp-dev/kcp (CVE-2026-39429)
vulnerability in github.com/kcp-dev/kcp (CVE-2026-39429). Confidential information can be exposed externally. Mitigation: upgrade to `0.29.3` or later.
|
| CVE-2026-5802 |
|
Command Injection in CVE-2026-5802 (CVE-2026-5802)
command injection in CVE-2026-5802 (CVE-2026-5802). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39859 |
|
Path Traversal in liquidjs (CVE-2026-39859)
path traversal in liquidjs (CVE-2026-39859). Confidential information can be exposed externally. Mitigation: upgrade to `10.25.3` or later.
|
| CVE-2026-39862 |
|
OS Command Injection in c (CVE-2026-39862)
OS command injection in c (CVE-2026-39862). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.5.1` or later.
|
| CVE-2026-39863 |
|
Buffer Overflow in dos (CVE-2026-39863)
vulnerability in dos (CVE-2026-39863). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.1` or later.
|
| CVE-2026-39362 |
|
SSRF (Server-Side Request Forgery) in django (CVE-2026-39362)
SSRF in django (CVE-2026-39362). Data can be tampered with by attackers. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-35476 |
|
Vulnerability in inventree-project (CVE-2026-35476)
vulnerability in inventree-project (CVE-2026-35476). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-35478 |
|
Vulnerability in inventree-project (CVE-2026-35478)
vulnerability in inventree-project (CVE-2026-35478). Confidential information can be exposed externally. Exploitable via `POST /api/user/tokens/`. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-35525 |
|
Vulnerability in liquidjs (CVE-2026-35525)
vulnerability in liquidjs (CVE-2026-35525). Confidential information can be exposed externally. Mitigation: upgrade to `10.25.3` or later.
|
| CVE-2026-23869 |
|
Vulnerability in react (CVE-2026-23869)
vulnerability in react (CVE-2026-23869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35446 |
|
Vulnerability in mcgill (CVE-2026-35446)
vulnerability in mcgill (CVE-2026-35446). Confidential information can be exposed externally. Mitigation: upgrade to `27.0.3` or later.
|
| CVE-2026-35455 |
|
Cross-Site Scripting (XSS) in futo (CVE-2026-35455)
cross-site scripting in futo (CVE-2026-35455). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.7.0` or later.
|
| CVE-2026-35169 |
|
Cross-Site Scripting (XSS) in mcgill (CVE-2026-35169)
cross-site scripting in mcgill (CVE-2026-35169). Confidential information can be exposed externally. Mitigation: upgrade to `27.0.3` or later.
|
| CVE-2026-35401 |
|
Vulnerability in c (CVE-2026-35401)
vulnerability in c (CVE-2026-35401). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.23.0a3` or later.
|
| CVE-2026-34723 |
|
Vulnerability in zammad (CVE-2026-34723)
vulnerability in zammad (CVE-2026-34723). Confidential information can be exposed externally. Mitigation: upgrade to `7.0.1` or later.
|
| CVE-2026-34724 |
|
Code Injection in zammad (CVE-2026-34724)
code injection in zammad (CVE-2026-34724). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.1` or later.
|
| CVE-2026-33350 |
|
SQL Injection in sqli (CVE-2026-33350)
SQL injection in sqli (CVE-2026-33350). Confidential information can be exposed externally. Mitigation: upgrade to `27.0.3` or later.
|
| CVE-2026-34392 |
|
Vulnerability in mcgill (CVE-2026-34392)
vulnerability in mcgill (CVE-2026-34392). Confidential information can be exposed externally. Mitigation: upgrade to `27.0.3` or later.
|
| CVE-2026-30814 |
|
Vulnerability in tp-link (CVE-2026-30814)
vulnerability in tp-link (CVE-2026-30814). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30815 |
|
OS Command Injection in tp-link (CVE-2026-30815)
OS command injection in tp-link (CVE-2026-30815). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30818 |
|
OS Command Injection in tp-link (CVE-2026-30818)
OS command injection in tp-link (CVE-2026-30818). Successful exploitation can lead to full system takeover.
|
| CVE-2025-50673 |
|
Vulnerability in dlink (CVE-2025-50673)
vulnerability in dlink (CVE-2025-50673). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50664 |
|
Vulnerability in dlink (CVE-2025-50664)
vulnerability in dlink (CVE-2025-50664). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50665 |
|
Vulnerability in dlink (CVE-2025-50665)
vulnerability in dlink (CVE-2025-50665). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50666 |
|
Vulnerability in dlink (CVE-2025-50666)
vulnerability in dlink (CVE-2025-50666). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50667 |
|
Vulnerability in dlink (CVE-2025-50667)
vulnerability in dlink (CVE-2025-50667). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50668 |
|
Vulnerability in dlink (CVE-2025-50668)
vulnerability in dlink (CVE-2025-50668). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50669 |
|
Vulnerability in dlink (CVE-2025-50669)
vulnerability in dlink (CVE-2025-50669). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50670 |
|
Vulnerability in dlink (CVE-2025-50670)
vulnerability in dlink (CVE-2025-50670). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50671 |
|
Vulnerability in dlink (CVE-2025-50671)
vulnerability in dlink (CVE-2025-50671). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50672 |
|
Vulnerability in dlink (CVE-2025-50672)
vulnerability in dlink (CVE-2025-50672). Risk of unauthorized operations or information disclosure.
|