Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-3987 |
|
Path Traversal in path-traversal (CVE-2026-3987)
path traversal in path-traversal (CVE-2026-3987). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34545 |
|
Vulnerability in openexr (CVE-2026-34545)
vulnerability in openexr (CVE-2026-34545). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34874 |
|
Vulnerability in trustedfirmware (CVE-2026-34874)
vulnerability in trustedfirmware (CVE-2026-34874). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25835 |
|
Vulnerability in arm (CVE-2026-25835)
vulnerability in arm (CVE-2026-25835). Confidential information can be exposed externally.
|
| CVE-2026-25833 |
|
Vulnerability in trustedfirmware (CVE-2026-25833)
vulnerability in trustedfirmware (CVE-2026-25833). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.6` or later.
|
| CVE-2026-34072 |
|
Authentication Bypass in fccview (CVE-2026-34072)
authentication bypass in fccview (CVE-2026-34072). Confidential information can be exposed externally.
|
| CVE-2026-27489 |
|
Vulnerability in path-traversal (CVE-2026-27489)
vulnerability in path-traversal (CVE-2026-27489). Confidential information can be exposed externally.
|
| CVE-2026-35093 |
|
Code Injection in freedesktop (CVE-2026-35093)
code injection in freedesktop (CVE-2026-35093). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35091 |
|
Vulnerability in dos (CVE-2026-35091)
vulnerability in dos (CVE-2026-35091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35092 |
|
Vulnerability in dos (CVE-2026-35092)
vulnerability in dos (CVE-2026-35092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34430 |
|
Vulnerability in deerflow (CVE-2026-34430)
vulnerability in deerflow (CVE-2026-34430). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5272 |
|
Vulnerability in google (CVE-2026-5272)
vulnerability in google (CVE-2026-5272). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5281 KEV |
|
[KEV] Use-After-Free in Google dawn (CVE-2026-5281)
vulnerability in Google dawn (CVE-2026-5281). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34453 |
|
Authorization Flaw in github.com/siyuan-note/siyuan/kernel (CVE-2026-34453)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34453). Confidential information can be exposed externally. Exploitable via `POST /api/bookmark/getBookmark`. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34404 |
|
Vulnerability in vue (CVE-2026-34404)
vulnerability in vue (CVE-2026-34404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34406 |
|
Vulnerability in django (CVE-2026-34406)
vulnerability in django (CVE-2026-34406). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/auth/edituser/`.
|
| CVE-2026-5213 |
|
Buffer Overflow in dlink (CVE-2026-5213)
vulnerability in dlink (CVE-2026-5213). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5212 |
|
Buffer Overflow in dlink (CVE-2026-5212)
vulnerability in dlink (CVE-2026-5212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34731 |
|
Vulnerability in wwbn (CVE-2026-34731)
vulnerability in wwbn (CVE-2026-34731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34381 |
|
Vulnerability in apache (CVE-2026-34381)
vulnerability in apache (CVE-2026-34381). Confidential information can be exposed externally.
|
| CVE-2026-34394 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34394)
vulnerability in csrf (CVE-2026-34394). Confidential information can be exposed externally.
|
| CVE-2026-34366 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34366)
SSRF in ssrf (CVE-2026-34366). Confidential information can be exposed externally.
|
| CVE-2026-34367 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34367)
SSRF in ssrf (CVE-2026-34367). Confidential information can be exposed externally.
|
| CVE-2026-4800 |
|
Code Injection in lodash (CVE-2026-4800)
code injection in lodash (CVE-2026-4800). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34365 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34365)
SSRF in ssrf (CVE-2026-34365). Confidential information can be exposed externally.
|
| CVE-2026-34784 |
|
Vulnerability in parseplatform (CVE-2026-34784)
vulnerability in parseplatform (CVE-2026-34784). Confidential information can be exposed externally.
|
| CVE-2026-5211 |
|
Buffer Overflow in dlink (CVE-2026-5211)
vulnerability in dlink (CVE-2026-5211). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34204 |
|
Authentication Bypass in minio (CVE-2026-34204)
authentication bypass in minio (CVE-2026-34204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30290 |
|
Path Traversal in intouchapp (CVE-2026-30290)
path traversal in intouchapp (CVE-2026-30290). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5210 |
|
Vulnerability in CVE-2026-5210 (CVE-2026-5210)
vulnerability in CVE-2026-5210 (CVE-2026-5210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32725 |
|
Vulnerability in c (CVE-2026-32725)
vulnerability in c (CVE-2026-32725). Confidential information can be exposed externally.
|
| CVE-2026-32726 |
|
Authorization Flaw in c (CVE-2026-32726)
vulnerability in c (CVE-2026-32726). Confidential information can be exposed externally.
|
| CVE-2026-30279 |
|
Path Traversal in c (CVE-2026-30279)
path traversal in c (CVE-2026-30279). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30277 |
|
Path Traversal in triumph-adler (CVE-2026-30277)
path traversal in triumph-adler (CVE-2026-30277). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2123 |
|
Vulnerability in privilege-escalation (CVE-2026-2123)
vulnerability in privilege-escalation (CVE-2026-2123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24165 |
|
Unsafe Deserialization in dos (CVE-2026-24165)
vulnerability in dos (CVE-2026-24165). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34359 |
|
Vulnerability in hapifhir (CVE-2026-34359)
vulnerability in hapifhir (CVE-2026-34359). Confidential information can be exposed externally.
|
| CVE-2026-24154 |
|
OS Command Injection in dos (CVE-2026-24154)
OS command injection in dos (CVE-2026-24154). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24164 |
|
Unsafe Deserialization in dos (CVE-2026-24164)
vulnerability in dos (CVE-2026-24164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24148 |
|
Vulnerability in dos (CVE-2026-24148)
vulnerability in dos (CVE-2026-24148). Confidential information can be exposed externally.
|
| CVE-2026-5087 |
|
Vulnerability in jjnapiork (CVE-2026-5087)
vulnerability in jjnapiork (CVE-2026-5087). Confidential information can be exposed externally.
|
| CVE-2026-5204 |
|
Buffer Overflow in tenda (CVE-2026-5204)
vulnerability in tenda (CVE-2026-5204). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34240 |
|
Vulnerability in appsup-dart (CVE-2026-34240)
vulnerability in appsup-dart (CVE-2026-34240). Data can be tampered with by attackers.
|
| CVE-2026-34573 |
|
Vulnerability in parseplatform (CVE-2026-34573)
vulnerability in parseplatform (CVE-2026-34573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34227 |
|
Vulnerability in github.com/bishopfox/sliver (CVE-2026-34227)
vulnerability in github.com/bishopfox/sliver (CVE-2026-34227). Successful exploitation can lead to full system takeover. Exploitable via ``ntds.dit``. Mitigation: upgrade to `1.7.4` or later.
|
| CVE-2026-30284 |
|
Vulnerability in uxgroupllc (CVE-2026-30284)
vulnerability in uxgroupllc (CVE-2026-30284). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22561 |
|
Vulnerability in privilege-escalation (CVE-2026-22561)
vulnerability in privilege-escalation (CVE-2026-22561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0596 |
|
OS Command Injection in mlflow (CVE-2026-0596)
OS command injection in mlflow (CVE-2026-0596). Successful exploitation can lead to full system takeover. Exploitable via ``model_uri``. Mitigation: upgrade to `3.9.0` or later.
|
| CVE-2026-34373 |
|
Vulnerability in parseplatform (CVE-2026-34373)
vulnerability in parseplatform (CVE-2026-34373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34377 |
|
Vulnerability in zfnd (CVE-2026-34377)
vulnerability in zfnd (CVE-2026-34377). Data can be tampered with by attackers.
|