Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-54324 |
|
Vulnerability in dos (CVE-2025-54324)
vulnerability in dos (CVE-2025-54324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5672 |
|
Vulnerability in sqli (CVE-2026-5672)
vulnerability in sqli (CVE-2026-5672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35209 |
|
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or...
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype...
|
| CVE-2026-35470 |
|
SQL Injection in sqli (CVE-2026-35470)
SQL injection in sqli (CVE-2026-35470). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.10.2` or later.
|
| CVE-2026-35029 |
|
Authorization Flaw in litellm (CVE-2026-35029)
vulnerability in litellm (CVE-2026-35029). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.83.0` or later.
|
| CVE-2026-34982 |
|
OS Command Injection in vim (CVE-2026-34982)
OS command injection in vim (CVE-2026-34982). Confidential information can be exposed externally. Exploitable via ``complete``.
|
| CVE-2026-34379 |
|
Vulnerability in c (CVE-2026-34379)
vulnerability in c (CVE-2026-34379). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.7` or later.
|
| CVE-2026-34588 |
|
Out-of-Bounds Read in openexr (CVE-2026-34588)
vulnerability in openexr (CVE-2026-34588). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.7` or later.
|
| CVE-2026-3524 |
|
Vulnerability in mattermost (CVE-2026-3524)
vulnerability in mattermost (CVE-2026-3524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5633 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-5633 (CVE-2026-5633)
SSRF in CVE-2026-5633 (CVE-2026-5633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5634 |
|
Vulnerability in sqli (CVE-2026-5634)
vulnerability in sqli (CVE-2026-5634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31406 |
|
Vulnerability in linux (CVE-2026-31406)
vulnerability in linux (CVE-2026-31406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31407 |
|
Out-of-Bounds Write in linux (CVE-2026-31407)
out-of-bounds write in linux (CVE-2026-31407). Confidential information can be exposed externally.
|
| CVE-2026-31408 |
|
Use-After-Free in linux (CVE-2026-31408)
vulnerability in linux (CVE-2026-31408). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31409 |
|
Vulnerability in linux (CVE-2026-31409)
vulnerability in linux (CVE-2026-31409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5632 |
|
Authentication Bypass in CVE-2026-5632 (CVE-2026-5632)
authentication bypass in CVE-2026-5632 (CVE-2026-5632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5631 |
|
Vulnerability in CVE-2026-5631 (CVE-2026-5631)
vulnerability in CVE-2026-5631 (CVE-2026-5631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5628 |
|
Buffer Overflow in belkin (CVE-2026-5628)
vulnerability in belkin (CVE-2026-5628). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5629 |
|
Buffer Overflow in belkin (CVE-2026-5629)
vulnerability in belkin (CVE-2026-5629). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5616 |
|
Authentication Bypass in CVE-2026-5616 (CVE-2026-5616)
authentication bypass in CVE-2026-5616 (CVE-2026-5616). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5614 |
|
Buffer Overflow in belkin (CVE-2026-5614)
vulnerability in belkin (CVE-2026-5614). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5613 |
|
Buffer Overflow in belkin (CVE-2026-5613)
vulnerability in belkin (CVE-2026-5613). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5611 |
|
A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage results in...
A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public...
|
| CVE-2026-5612 |
|
A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webpage can...
A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been publi...
|
| CVE-2026-5609 |
|
Buffer Overflow in tenda (CVE-2026-5609)
vulnerability in tenda (CVE-2026-5609). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5610 |
|
Buffer Overflow in belkin (CVE-2026-5610)
vulnerability in belkin (CVE-2026-5610). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5608 |
|
Buffer Overflow in belkin (CVE-2026-5608)
vulnerability in belkin (CVE-2026-5608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5605 |
|
Buffer Overflow in tenda (CVE-2026-5605)
vulnerability in tenda (CVE-2026-5605). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5604 |
|
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Perfor...
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploita...
|
| CVE-2026-4272 |
|
Vulnerability in CVE-2026-4272 (CVE-2026-4272)
vulnerability in CVE-2026-4272 (CVE-2026-4272). Confidential information can be exposed externally.
|
| CVE-2019-25694 |
|
SQL Injection in sqli (CVE-2019-25694)
SQL injection in sqli (CVE-2019-25694). Confidential information can be exposed externally.
|
| CVE-2019-25696 |
|
SQL Injection in sqli (CVE-2019-25696)
SQL injection in sqli (CVE-2019-25696). Confidential information can be exposed externally.
|
| CVE-2019-25698 |
|
SQL Injection in sqli (CVE-2019-25698)
SQL injection in sqli (CVE-2019-25698). Confidential information can be exposed externally.
|
| CVE-2019-25700 |
|
SQL Injection in sqli (CVE-2019-25700)
SQL injection in sqli (CVE-2019-25700). Confidential information can be exposed externally.
|
| CVE-2019-25702 |
|
SQL Injection in sqli (CVE-2019-25702)
SQL injection in sqli (CVE-2019-25702). Confidential information can be exposed externally.
|
| CVE-2019-25704 |
|
SQL Injection in sqli (CVE-2019-25704)
SQL injection in sqli (CVE-2019-25704). Confidential information can be exposed externally.
|
| CVE-2019-25686 |
|
Vulnerability in dos (CVE-2019-25686)
vulnerability in dos (CVE-2019-25686). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25688 |
|
SQL Injection in sqli (CVE-2019-25688)
SQL injection in sqli (CVE-2019-25688). Confidential information can be exposed externally.
|
| CVE-2019-25690 |
|
SQL Injection in sqli (CVE-2019-25690)
SQL injection in sqli (CVE-2019-25690). Confidential information can be exposed externally.
|
| CVE-2019-25692 |
|
SQL Injection in sqli (CVE-2019-25692)
SQL injection in sqli (CVE-2019-25692). Confidential information can be exposed externally.
|
| CVE-2019-25679 |
|
Out-of-Bounds Write in crun (CVE-2019-25679)
out-of-bounds write in crun (CVE-2019-25679). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25680 |
|
SQL Injection in sqli (CVE-2019-25680)
SQL injection in sqli (CVE-2019-25680). Confidential information can be exposed externally.
|
| CVE-2019-25681 |
|
Out-of-Bounds Write in xlightftpd (CVE-2019-25681)
out-of-bounds write in xlightftpd (CVE-2019-25681). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25684 |
|
SQL Injection in sqli (CVE-2019-25684)
SQL injection in sqli (CVE-2019-25684). Confidential information can be exposed externally.
|
| CVE-2019-25673 |
|
Unrestricted File Upload in laravel (CVE-2019-25673)
vulnerability in laravel (CVE-2019-25673). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25674 |
|
SQL Injection in sqli (CVE-2019-25674)
SQL injection in sqli (CVE-2019-25674). Confidential information can be exposed externally.
|
| CVE-2019-25675 |
|
SQL Injection in sqli (CVE-2019-25675)
SQL injection in sqli (CVE-2019-25675). Confidential information can be exposed externally.
|
| CVE-2019-25676 |
|
Cross-Site Scripting (XSS) in sqli (CVE-2019-25676)
cross-site scripting in sqli (CVE-2019-25676). Confidential information can be exposed externally.
|
| CVE-2019-25678 |
|
Vulnerability in sqli (CVE-2019-25678)
vulnerability in sqli (CVE-2019-25678). Confidential information can be exposed externally.
|
| CVE-2019-25668 |
|
SQL Injection in sqli (CVE-2019-25668)
SQL injection in sqli (CVE-2019-25668). Confidential information can be exposed externally.
|