Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39343 |
|
SQL Injection in sqli (CVE-2026-39343)
SQL injection in sqli (CVE-2026-39343). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-39344 |
|
Cross-Site Scripting (XSS) in churchcrm (CVE-2026-39344)
cross-site scripting in churchcrm (CVE-2026-39344). Confidential information can be exposed externally. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-24156 |
|
Unsafe Deserialization in deserialization (CVE-2026-24156)
vulnerability in deserialization (CVE-2026-24156). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22682 |
|
Authorization Flaw in CVE-2026-22682 (CVE-2026-22682)
vulnerability in CVE-2026-22682 (CVE-2026-22682). Confidential information can be exposed externally.
|
| CVE-2025-14821 |
|
Vulnerability in c (CVE-2025-14821)
vulnerability in c (CVE-2025-14821). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30460 |
|
Code Injection in thedaylightstudio (CVE-2026-30460)
code injection in thedaylightstudio (CVE-2026-30460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24660 |
|
Vulnerability in libraw (CVE-2026-24660)
vulnerability in libraw (CVE-2026-24660). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5733 |
|
Buffer Overflow in mozilla (CVE-2026-5733)
vulnerability in mozilla (CVE-2026-5733). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5732 |
|
Vulnerability in mozilla (CVE-2026-5732)
vulnerability in mozilla (CVE-2026-5732). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4740 |
|
Vulnerability in open-cluster-management.io/ocm (CVE-2026-4740)
vulnerability in open-cluster-management.io/ocm (CVE-2026-4740). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.2.1` or later.
|
| CVE-2026-35554 |
|
Vulnerability in apache (CVE-2026-35554)
vulnerability in apache (CVE-2026-35554). Confidential information can be exposed externally.
|
| CVE-2026-22666 |
|
Vulnerability in dolibarr (CVE-2026-22666)
vulnerability in dolibarr (CVE-2026-22666). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32144 |
|
Vulnerability in erlang (CVE-2026-32144)
vulnerability in erlang (CVE-2026-32144). Confidential information can be exposed externally.
|
| CVE-2026-31842 |
|
Vulnerability in c (CVE-2026-31842)
vulnerability in c (CVE-2026-31842). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20432 |
|
Out-of-Bounds Write in mediatek (CVE-2026-20432)
out-of-bounds write in mediatek (CVE-2026-20432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5692 |
|
Command Injection in CVE-2026-5692 (CVE-2026-5692)
command injection in CVE-2026-5692 (CVE-2026-5692). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5691 |
|
Command Injection in CVE-2026-5691 (CVE-2026-5691)
command injection in CVE-2026-5691 (CVE-2026-5691). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5690 |
|
Command Injection in CVE-2026-5690 (CVE-2026-5690)
command injection in CVE-2026-5690 (CVE-2026-5690). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5689 |
|
Command Injection in CVE-2026-5689 (CVE-2026-5689)
command injection in CVE-2026-5689 (CVE-2026-5689). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5688 |
|
Command Injection in CVE-2026-5688 (CVE-2026-5688)
command injection in CVE-2026-5688 (CVE-2026-5688). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5687 |
|
Buffer Overflow in tenda (CVE-2026-5687)
vulnerability in tenda (CVE-2026-5687). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5708 |
|
Vulnerability in amazon (CVE-2026-5708)
vulnerability in amazon (CVE-2026-5708). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5709 |
|
OS Command Injection in c (CVE-2026-5709)
OS command injection in c (CVE-2026-5709). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5684 |
|
Buffer Overflow in tenda (CVE-2026-5684)
vulnerability in tenda (CVE-2026-5684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5685 |
|
Buffer Overflow in tenda (CVE-2026-5685)
vulnerability in tenda (CVE-2026-5685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5686 |
|
Buffer Overflow in tenda (CVE-2026-5686)
vulnerability in tenda (CVE-2026-5686). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35444 |
|
Out-of-Bounds Read in c (CVE-2026-35444)
vulnerability in c (CVE-2026-35444). Confidential information can be exposed externally.
|
| CVE-2026-35412 |
|
Authorization Flaw in monospace (CVE-2026-35412)
vulnerability in monospace (CVE-2026-35412). Data can be tampered with by attackers. Mitigation: upgrade to `11.16.1` or later.
|
| CVE-2026-35442 |
|
Information Disclosure in monospace (CVE-2026-35442)
vulnerability in monospace (CVE-2026-35442). Confidential information can be exposed externally. Mitigation: upgrade to `11.17.0` or later.
|
| CVE-2026-35408 |
|
Vulnerability in monospace (CVE-2026-35408)
vulnerability in monospace (CVE-2026-35408). Confidential information can be exposed externally. Mitigation: upgrade to `11.17.0` or later.
|
| CVE-2026-35409 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-35409)
SSRF in ssrf (CVE-2026-35409). Confidential information can be exposed externally. Mitigation: upgrade to `11.16.0` or later.
|
| CVE-2026-35394 |
|
Vulnerability in mobilenexthq (CVE-2026-35394)
vulnerability in mobilenexthq (CVE-2026-35394). Data can be tampered with by attackers. Mitigation: upgrade to `0.0.50` or later.
|
| CVE-2026-35395 |
|
SQL Injection in sqli (CVE-2026-35395)
SQL injection in sqli (CVE-2026-35395). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2026-35213 |
|
Vulnerability in dos (CVE-2026-35213)
vulnerability in dos (CVE-2026-35213). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.1` or later.
|
| CVE-2026-35389 |
|
Vulnerability in bulwarkmail (CVE-2026-35389)
vulnerability in bulwarkmail (CVE-2026-35389). Data can be tampered with by attackers. Mitigation: upgrade to `1.4.11` or later.
|
| CVE-2026-35391 |
|
Vulnerability in bulwarkmail (CVE-2026-35391)
vulnerability in bulwarkmail (CVE-2026-35391). Data can be tampered with by attackers. Mitigation: upgrade to `1.4.11` or later.
|
| CVE-2025-54601 |
|
Vulnerability in samsung (CVE-2025-54601)
vulnerability in samsung (CVE-2025-54601). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35203 |
|
Out-of-Bounds Read in cpp (CVE-2026-35203)
vulnerability in cpp (CVE-2026-35203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35185 |
|
Vulnerability in psu (CVE-2026-35185)
vulnerability in psu (CVE-2026-35185). Confidential information can be exposed externally. Mitigation: upgrade to `25.0.0` or later.
|
| CVE-2026-35187 |
|
SSRF (Server-Side Request Forgery) in pyload-ng-project (CVE-2026-35187)
SSRF in pyload-ng-project (CVE-2026-35187). Confidential information can be exposed externally.
|
| CVE-2026-35182 |
|
Vulnerability in ajax30 (CVE-2026-35182)
vulnerability in ajax30 (CVE-2026-35182). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-35183 |
|
Vulnerability in ajax30 (CVE-2026-35183)
vulnerability in ajax30 (CVE-2026-35183). Data can be tampered with by attackers. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-35172 |
|
Vulnerability in distribution (CVE-2026-35172)
vulnerability in distribution (CVE-2026-35172). Confidential information can be exposed externally. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-35170 |
|
Out-of-Bounds Read in trabucayre (CVE-2026-35170)
vulnerability in trabucayre (CVE-2026-35170). Confidential information can be exposed externally.
|
| CVE-2026-35176 |
|
Out-of-Bounds Read in trabucayre (CVE-2026-35176)
vulnerability in trabucayre (CVE-2026-35176). Confidential information can be exposed externally.
|
| CVE-2025-57834 |
|
Vulnerability in dos (CVE-2025-57834)
vulnerability in dos (CVE-2025-57834). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54602 |
|
Vulnerability in samsung (CVE-2025-54602)
vulnerability in samsung (CVE-2025-54602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5677 |
|
Command Injection in CVE-2026-5677 (CVE-2026-5677)
command injection in CVE-2026-5677 (CVE-2026-5677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5676 |
|
Authentication Bypass in CVE-2026-5676 (CVE-2026-5676)
authentication bypass in CVE-2026-5676 (CVE-2026-5676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5678 |
|
Command Injection in CVE-2026-5678 (CVE-2026-5678)
command injection in CVE-2026-5678 (CVE-2026-5678). Risk of unauthorized operations or information disclosure.
|