Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2025-54324 Vulnerability in dos (CVE-2025-54324)
vulnerability in dos (CVE-2025-54324). Risk of unauthorized operations or information disclosure.
CVE-2026-5672 Vulnerability in sqli (CVE-2026-5672)
vulnerability in sqli (CVE-2026-5672). Risk of unauthorized operations or information disclosure.
CVE-2026-35209 defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or...
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype...
CVE-2026-35470 SQL Injection in sqli (CVE-2026-35470)
SQL injection in sqli (CVE-2026-35470). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.10.2` or later.
CVE-2026-35029 Authorization Flaw in litellm (CVE-2026-35029)
vulnerability in litellm (CVE-2026-35029). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.83.0` or later.
CVE-2026-34982 OS Command Injection in vim (CVE-2026-34982)
OS command injection in vim (CVE-2026-34982). Confidential information can be exposed externally. Exploitable via ``complete``.
CVE-2026-34379 Vulnerability in c (CVE-2026-34379)
vulnerability in c (CVE-2026-34379). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.7` or later.
CVE-2026-34588 Out-of-Bounds Read in openexr (CVE-2026-34588)
vulnerability in openexr (CVE-2026-34588). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.7` or later.
CVE-2026-3524 Vulnerability in mattermost (CVE-2026-3524)
vulnerability in mattermost (CVE-2026-3524). Successful exploitation can lead to full system takeover.
CVE-2026-5633 SSRF (Server-Side Request Forgery) in CVE-2026-5633 (CVE-2026-5633)
SSRF in CVE-2026-5633 (CVE-2026-5633). Risk of unauthorized operations or information disclosure.
CVE-2026-5634 Vulnerability in sqli (CVE-2026-5634)
vulnerability in sqli (CVE-2026-5634). Risk of unauthorized operations or information disclosure.
CVE-2026-31406 Vulnerability in linux (CVE-2026-31406)
vulnerability in linux (CVE-2026-31406). Successful exploitation can lead to full system takeover.
CVE-2026-31407 Out-of-Bounds Write in linux (CVE-2026-31407)
out-of-bounds write in linux (CVE-2026-31407). Confidential information can be exposed externally.
CVE-2026-31408 Use-After-Free in linux (CVE-2026-31408)
vulnerability in linux (CVE-2026-31408). Successful exploitation can lead to full system takeover.
CVE-2026-31409 Vulnerability in linux (CVE-2026-31409)
vulnerability in linux (CVE-2026-31409). Successful exploitation can lead to full system takeover.
CVE-2026-5632 Authentication Bypass in CVE-2026-5632 (CVE-2026-5632)
authentication bypass in CVE-2026-5632 (CVE-2026-5632). Risk of unauthorized operations or information disclosure.
CVE-2026-5631 Vulnerability in CVE-2026-5631 (CVE-2026-5631)
vulnerability in CVE-2026-5631 (CVE-2026-5631). Risk of unauthorized operations or information disclosure.
CVE-2026-5628 Buffer Overflow in belkin (CVE-2026-5628)
vulnerability in belkin (CVE-2026-5628). Successful exploitation can lead to full system takeover.
CVE-2026-5629 Buffer Overflow in belkin (CVE-2026-5629)
vulnerability in belkin (CVE-2026-5629). Successful exploitation can lead to full system takeover.
CVE-2026-5616 Authentication Bypass in CVE-2026-5616 (CVE-2026-5616)
authentication bypass in CVE-2026-5616 (CVE-2026-5616). Risk of unauthorized operations or information disclosure.
CVE-2026-5614 Buffer Overflow in belkin (CVE-2026-5614)
vulnerability in belkin (CVE-2026-5614). Successful exploitation can lead to full system takeover.
CVE-2026-5613 Buffer Overflow in belkin (CVE-2026-5613)
vulnerability in belkin (CVE-2026-5613). Successful exploitation can lead to full system takeover.
CVE-2026-5611 A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage results in...
A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public...
CVE-2026-5612 A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webpage can...
A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been publi...
CVE-2026-5609 Buffer Overflow in tenda (CVE-2026-5609)
vulnerability in tenda (CVE-2026-5609). Successful exploitation can lead to full system takeover.
CVE-2026-5610 Buffer Overflow in belkin (CVE-2026-5610)
vulnerability in belkin (CVE-2026-5610). Successful exploitation can lead to full system takeover.
CVE-2026-5608 Buffer Overflow in belkin (CVE-2026-5608)
vulnerability in belkin (CVE-2026-5608). Successful exploitation can lead to full system takeover.
CVE-2026-5605 Buffer Overflow in tenda (CVE-2026-5605)
vulnerability in tenda (CVE-2026-5605). Successful exploitation can lead to full system takeover.
CVE-2026-5604 A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Perfor...
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploita...
CVE-2026-4272 Vulnerability in CVE-2026-4272 (CVE-2026-4272)
vulnerability in CVE-2026-4272 (CVE-2026-4272). Confidential information can be exposed externally.
CVE-2019-25694 SQL Injection in sqli (CVE-2019-25694)
SQL injection in sqli (CVE-2019-25694). Confidential information can be exposed externally.
CVE-2019-25696 SQL Injection in sqli (CVE-2019-25696)
SQL injection in sqli (CVE-2019-25696). Confidential information can be exposed externally.
CVE-2019-25698 SQL Injection in sqli (CVE-2019-25698)
SQL injection in sqli (CVE-2019-25698). Confidential information can be exposed externally.
CVE-2019-25700 SQL Injection in sqli (CVE-2019-25700)
SQL injection in sqli (CVE-2019-25700). Confidential information can be exposed externally.
CVE-2019-25702 SQL Injection in sqli (CVE-2019-25702)
SQL injection in sqli (CVE-2019-25702). Confidential information can be exposed externally.
CVE-2019-25704 SQL Injection in sqli (CVE-2019-25704)
SQL injection in sqli (CVE-2019-25704). Confidential information can be exposed externally.
CVE-2019-25686 Vulnerability in dos (CVE-2019-25686)
vulnerability in dos (CVE-2019-25686). Risk of unauthorized operations or information disclosure.
CVE-2019-25688 SQL Injection in sqli (CVE-2019-25688)
SQL injection in sqli (CVE-2019-25688). Confidential information can be exposed externally.
CVE-2019-25690 SQL Injection in sqli (CVE-2019-25690)
SQL injection in sqli (CVE-2019-25690). Confidential information can be exposed externally.
CVE-2019-25692 SQL Injection in sqli (CVE-2019-25692)
SQL injection in sqli (CVE-2019-25692). Confidential information can be exposed externally.
CVE-2019-25679 Out-of-Bounds Write in crun (CVE-2019-25679)
out-of-bounds write in crun (CVE-2019-25679). Successful exploitation can lead to full system takeover.
CVE-2019-25680 SQL Injection in sqli (CVE-2019-25680)
SQL injection in sqli (CVE-2019-25680). Confidential information can be exposed externally.
CVE-2019-25681 Out-of-Bounds Write in xlightftpd (CVE-2019-25681)
out-of-bounds write in xlightftpd (CVE-2019-25681). Successful exploitation can lead to full system takeover.
CVE-2019-25684 SQL Injection in sqli (CVE-2019-25684)
SQL injection in sqli (CVE-2019-25684). Confidential information can be exposed externally.
CVE-2019-25673 Unrestricted File Upload in laravel (CVE-2019-25673)
vulnerability in laravel (CVE-2019-25673). Successful exploitation can lead to full system takeover.
CVE-2019-25674 SQL Injection in sqli (CVE-2019-25674)
SQL injection in sqli (CVE-2019-25674). Confidential information can be exposed externally.
CVE-2019-25675 SQL Injection in sqli (CVE-2019-25675)
SQL injection in sqli (CVE-2019-25675). Confidential information can be exposed externally.
CVE-2019-25676 Cross-Site Scripting (XSS) in sqli (CVE-2019-25676)
cross-site scripting in sqli (CVE-2019-25676). Confidential information can be exposed externally.
CVE-2019-25678 Vulnerability in sqli (CVE-2019-25678)
vulnerability in sqli (CVE-2019-25678). Confidential information can be exposed externally.
CVE-2019-25668 SQL Injection in sqli (CVE-2019-25668)
SQL injection in sqli (CVE-2019-25668). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →