Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5418 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-5418 (CVE-2026-5418)
SSRF in CVE-2026-5418 (CVE-2026-5418). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34752 |
|
Vulnerability in haraka-project (CVE-2026-34752)
vulnerability in haraka-project (CVE-2026-34752). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34759 |
|
Vulnerability in nginx (CVE-2026-34759)
vulnerability in nginx (CVE-2026-34759). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34742 |
|
Vulnerability in github.com/modelcontextprotocol/go-sdk (CVE-2026-34742)
vulnerability in github.com/modelcontextprotocol/go-sdk (CVE-2026-34742). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-34581 |
|
Vulnerability in github.com/patrickhener/goshs (CVE-2026-34581)
vulnerability in github.com/patrickhener/goshs (CVE-2026-34581). Confidential information can be exposed externally. Exploitable via ``BasicAuthMiddleware``.
|
| CVE-2026-34426 |
|
Vulnerability in openclaw (CVE-2026-34426)
vulnerability in openclaw (CVE-2026-34426). Data can be tampered with by attackers.
|
| CVE-2025-43264 |
|
Buffer Overflow in apple (CVE-2025-43264)
vulnerability in apple (CVE-2025-43264). Successful exploitation can lead to full system takeover.
|
| CVE-2025-43257 |
|
Vulnerability in apple (CVE-2025-43257)
vulnerability in apple (CVE-2025-43257). Confidential information can be exposed externally.
|
| CVE-2025-43219 |
|
Out-of-Bounds Write in apple (CVE-2025-43219)
out-of-bounds write in apple (CVE-2025-43219). Successful exploitation can lead to full system takeover.
|
| CVE-2025-43202 |
|
Out-of-Bounds Write in apple (CVE-2025-43202)
out-of-bounds write in apple (CVE-2025-43202). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44303 |
|
Vulnerability in apple (CVE-2024-44303)
vulnerability in apple (CVE-2024-44303). Confidential information can be exposed externally.
|
| CVE-2024-44286 |
|
Vulnerability in apple (CVE-2024-44286)
vulnerability in apple (CVE-2024-44286). Confidential information can be exposed externally.
|
| CVE-2024-44250 |
|
Privilege Escalation in apple (CVE-2024-44250)
vulnerability in apple (CVE-2024-44250). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44219 |
|
Vulnerability in apple (CVE-2024-44219)
vulnerability in apple (CVE-2024-44219). Confidential information can be exposed externally.
|
| CVE-2024-40858 |
|
Vulnerability in apple (CVE-2024-40858)
vulnerability in apple (CVE-2024-40858). Confidential information can be exposed externally.
|
| CVE-2024-40849 |
|
Vulnerability in apple (CVE-2024-40849)
vulnerability in apple (CVE-2024-40849). Confidential information can be exposed externally.
|
| CVE-2023-7342 |
|
Privilege Escalation in privilege-escalation (CVE-2023-7342)
vulnerability in privilege-escalation (CVE-2023-7342). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34785 |
|
Vulnerability in rack (CVE-2026-34785)
vulnerability in rack (CVE-2026-34785). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.6` or later.
|
| CVE-2026-35385 |
|
Vulnerability in openbsd (CVE-2026-35385)
vulnerability in openbsd (CVE-2026-35385). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5368 |
|
Vulnerability in sqli (CVE-2026-5368)
vulnerability in sqli (CVE-2026-5368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34828 |
|
Vulnerability in github.com/knadh/listmonk (CVE-2026-34828)
vulnerability in github.com/knadh/listmonk (CVE-2026-34828). Confidential information can be exposed externally. Exploitable via `GET /api/profile`. Mitigation: upgrade to `1.1.1-0.20260329113754-1b5e8d38c778` or later.
|
| CVE-2026-34725 |
|
Cross-Site Scripting (XSS) in CVE-2026-34725 (CVE-2026-34725)
cross-site scripting in CVE-2026-34725 (CVE-2026-34725). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34601 |
|
Vulnerability in CVE-2026-34601 (CVE-2026-34601)
vulnerability in CVE-2026-34601 (CVE-2026-34601). Data can be tampered with by attackers. Exploitable via ``DOMParser``.
|
| CVE-2026-34593 |
|
Vulnerability in ash-hq (CVE-2026-34593)
vulnerability in ash-hq (CVE-2026-34593). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34576 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34576)
SSRF in ssrf (CVE-2026-34576). Confidential information can be exposed externally. Exploitable via `POST /public/v1/upload-from-url`.
|
| CVE-2026-34577 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34577)
SSRF in ssrf (CVE-2026-34577). Confidential information can be exposed externally. Exploitable via `GET /public/stream`.
|
| CVE-2026-34522 |
|
Path Traversal in path-traversal (CVE-2026-34522)
path traversal in path-traversal (CVE-2026-34522). Data can be tampered with by attackers.
|
| CVE-2026-34524 |
|
Path Traversal in path-traversal (CVE-2026-34524)
path traversal in path-traversal (CVE-2026-34524). Confidential information can be exposed externally.
|
| CVE-2026-34121 |
|
Authentication Bypass in tp-link (CVE-2026-34121)
authentication bypass in tp-link (CVE-2026-34121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33951 |
|
Vulnerability in signalk (CVE-2026-33951)
vulnerability in signalk (CVE-2026-33951). Data can be tampered with by attackers. Exploitable via `PUT /signalk/v1/api/sourcePriorities`.
|
| CVE-2025-65114 |
|
Vulnerability in apache (CVE-2025-65114)
vulnerability in apache (CVE-2025-65114). Data can be tampered with by attackers.
|
| CVE-2025-58136 |
|
Vulnerability in apache (CVE-2025-58136)
vulnerability in apache (CVE-2025-58136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5350 |
|
Buffer Overflow in trendnet (CVE-2026-5350)
vulnerability in trendnet (CVE-2026-5350). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5349 |
|
Buffer Overflow in trendnet (CVE-2026-5349)
vulnerability in trendnet (CVE-2026-5349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34876 |
|
Out-of-Bounds Read in c (CVE-2026-34876)
vulnerability in c (CVE-2026-34876). Confidential information can be exposed externally.
|
| CVE-2026-30332 |
|
Vulnerability in CVE-2026-30332 (CVE-2026-30332)
vulnerability in CVE-2026-30332 (CVE-2026-30332). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5346 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-5346 (CVE-2026-5346)
SSRF in CVE-2026-5346 (CVE-2026-5346). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34796 |
|
OS Command Injection in endian (CVE-2026-34796)
OS command injection in endian (CVE-2026-34796). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34797 |
|
OS Command Injection in endian (CVE-2026-34797)
OS command injection in endian (CVE-2026-34797). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34794 |
|
OS Command Injection in endian (CVE-2026-34794)
OS command injection in endian (CVE-2026-34794). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34795 |
|
OS Command Injection in endian (CVE-2026-34795)
OS command injection in endian (CVE-2026-34795). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34792 |
|
OS Command Injection in endian (CVE-2026-34792)
OS command injection in endian (CVE-2026-34792). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34793 |
|
OS Command Injection in endian (CVE-2026-34793)
OS command injection in endian (CVE-2026-34793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3692 |
|
OS Command Injection in progress (CVE-2026-3692)
OS command injection in progress (CVE-2026-3692). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4634 |
|
Vulnerability in dos (CVE-2026-4634)
vulnerability in dos (CVE-2026-4634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4636 |
|
Vulnerability in redhat (CVE-2026-4636)
vulnerability in redhat (CVE-2026-4636). Confidential information can be exposed externally.
|
| CVE-2026-3872 |
|
Open Redirect in redhat (CVE-2026-3872)
vulnerability in redhat (CVE-2026-3872). Confidential information can be exposed externally.
|
| CVE-2026-4282 |
|
Vulnerability in privilege-escalation (CVE-2026-4282)
vulnerability in privilege-escalation (CVE-2026-4282). Confidential information can be exposed externally.
|
| CVE-2026-23414 |
|
Vulnerability in linux (CVE-2026-23414)
vulnerability in linux (CVE-2026-23414). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3502 KEV |
|
[KEV] Vulnerability in Trueconf client (CVE-2026-3502)
vulnerability in Trueconf client (CVE-2026-3502). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|