Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-30707 |
|
Vulnerability in csharp (CVE-2026-30707)
vulnerability in csharp (CVE-2026-30707). Confidential information can be exposed externally.
|
| CVE-2026-21570 |
|
Code Injection in atlassian (CVE-2026-21570)
code injection in atlassian (CVE-2026-21570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3888 |
|
Vulnerability in privilege-escalation (CVE-2026-3888)
vulnerability in privilege-escalation (CVE-2026-3888). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4258 |
|
Vulnerability in bitwiseshiftleft (CVE-2026-4258)
vulnerability in bitwiseshiftleft (CVE-2026-4258). Confidential information can be exposed externally.
|
| CVE-2026-0708 |
|
Out-of-Bounds Read in dos (CVE-2026-0708)
vulnerability in dos (CVE-2026-0708). Confidential information can be exposed externally. Exploitable via ``ucl_object_emit``.
|
| CVE-2025-50881 |
|
Code Injection in CVE-2025-50881 (CVE-2025-50881)
code injection in CVE-2025-50881 (CVE-2025-50881). Successful exploitation can lead to full system takeover. Exploitable via ``action``.
|
| CVE-2026-32759 |
|
Vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-32759)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-32759). Data can be tampered with by attackers. Exploitable via ``enableExec``. Mitigation: upgrade to `2.33.8` or later.
|
| CVE-2026-3644 |
|
Vulnerability in CVE-2026-3644 (CVE-2026-3644)
vulnerability in CVE-2026-3644 (CVE-2026-3644). Data can be tampered with by attackers.
|
| CVE-2026-28498 |
|
Vulnerability in authlib (CVE-2026-28498)
vulnerability in authlib (CVE-2026-28498). Data can be tampered with by attackers.
|
| CVE-2026-23862 |
|
Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local...
Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
|
| CVE-2026-4276 |
|
Code Injection in librechat (CVE-2026-4276)
code injection in librechat (CVE-2026-4276). Data can be tampered with by attackers.
|
| CVE-2026-3084 |
|
Vulnerability in gstreamer (CVE-2026-3084)
vulnerability in gstreamer (CVE-2026-3084). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3086 |
|
Out-of-Bounds Write in gstreamer (CVE-2026-3086)
out-of-bounds write in gstreamer (CVE-2026-3086). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3081 |
|
Vulnerability in gstreamer (CVE-2026-3081)
vulnerability in gstreamer (CVE-2026-3081). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4255 |
|
Vulnerability in thermalright (CVE-2026-4255)
vulnerability in thermalright (CVE-2026-4255). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3476 |
|
Code Injection in 3ds (CVE-2026-3476)
code injection in 3ds (CVE-2026-3476). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3082 |
|
Vulnerability in gstreamer (CVE-2026-3082)
vulnerability in gstreamer (CVE-2026-3082). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3085 |
|
Vulnerability in gstreamer (CVE-2026-3085)
vulnerability in gstreamer (CVE-2026-3085). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3083 |
|
Vulnerability in gstreamer (CVE-2026-3083)
vulnerability in gstreamer (CVE-2026-3083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2923 |
|
Out-of-Bounds Write in gstreamer (CVE-2026-2923)
out-of-bounds write in gstreamer (CVE-2026-2923). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31386 |
|
OS Command Injection in litespeedtech (CVE-2026-31386)
OS command injection in litespeedtech (CVE-2026-31386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2921 |
|
Vulnerability in gstreamer (CVE-2026-2921)
vulnerability in gstreamer (CVE-2026-2921). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2922 |
|
Out-of-Bounds Write in gstreamer (CVE-2026-2922)
out-of-bounds write in gstreamer (CVE-2026-2922). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2920 |
|
Vulnerability in gstreamer (CVE-2026-2920)
vulnerability in gstreamer (CVE-2026-2920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25083 |
|
Vulnerability in CVE-2026-25083 (CVE-2026-25083)
vulnerability in CVE-2026-25083 (CVE-2026-25083). Confidential information can be exposed externally.
|
| CVE-2025-14287 |
|
Code Injection in lfprojects (CVE-2025-14287)
code injection in lfprojects (CVE-2025-14287). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20032 |
|
Cross-Site Scripting (XSS) in CVE-2016-20032 (CVE-2016-20032)
cross-site scripting in CVE-2016-20032 (CVE-2016-20032). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-20025 |
|
Vulnerability in privilege-escalation (CVE-2016-20025)
vulnerability in privilege-escalation (CVE-2016-20025). Successful exploitation can lead to full system takeover.
|
| CVE-2025-47813 KEV |
|
[KEV] Vulnerability in Wing ftp server wing-ftp-server (CVE-2025-47813)
vulnerability in Wing ftp server wing-ftp-server (CVE-2025-47813). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-3999 |
|
Vulnerability in privilege-escalation (CVE-2026-3999)
vulnerability in privilege-escalation (CVE-2026-3999). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4111 |
|
Vulnerability in CVE-2026-4111 (CVE-2026-4111)
vulnerability in CVE-2026-4111 (CVE-2026-4111). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3873 |
|
Vulnerability in CVE-2026-3873 (CVE-2026-3873)
vulnerability in CVE-2026-3873 (CVE-2026-3873). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71263 |
|
Vulnerability in opengroup (CVE-2025-71263)
vulnerability in opengroup (CVE-2025-71263). Successful exploitation can lead to full system takeover.
|
| CVE-2025-13779 |
|
Vulnerability in CVE-2025-13779 (CVE-2025-13779)
vulnerability in CVE-2025-13779 (CVE-2025-13779). Confidential information can be exposed externally.
|
| CVE-2026-3910 KEV |
|
[KEV] Buffer Overflow in Google chromium-v8 (CVE-2026-3910)
vulnerability in Google chromium-v8 (CVE-2026-3910). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-3909 KEV |
|
[KEV] Out-of-Bounds Write in Google skia (CVE-2026-3909)
out-of-bounds write in Google skia (CVE-2026-3909). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-32597 |
|
Vulnerability in pyjwt (CVE-2026-32597)
vulnerability in pyjwt (CVE-2026-32597). Data can be tampered with by attackers. Exploitable via ``crit``. Mitigation: upgrade to `2.12.0` or later.
|
| CVE-2026-1528 |
|
Vulnerability in nodejs (CVE-2026-1528)
vulnerability in nodejs (CVE-2026-1528). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2229 |
|
Vulnerability in c (CVE-2026-2229)
vulnerability in c (CVE-2026-2229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1526 |
|
Vulnerability in nodejs (CVE-2026-1526)
vulnerability in nodejs (CVE-2026-1526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32274 |
|
Path Traversal in black (CVE-2026-32274)
path traversal in black (CVE-2026-32274). Data can be tampered with by attackers. Mitigation: upgrade to `26.3.1` or later.
|
| CVE-2026-3497 |
|
Vulnerability in canonical (CVE-2026-3497)
vulnerability in canonical (CVE-2026-3497). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32141 |
|
Vulnerability in webreflection (CVE-2026-32141)
vulnerability in webreflection (CVE-2026-32141). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.0` or later.
|
| CVE-2026-28356 |
|
Vulnerability in dos (CVE-2026-28356)
vulnerability in dos (CVE-2026-28356). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.2` or later.
|
| CVE-2026-21672 |
|
Vulnerability in privilege-escalation (CVE-2026-21672)
vulnerability in privilege-escalation (CVE-2026-21672). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21670 |
|
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
|
| CVE-2026-21668 |
|
Vulnerability in veeam (CVE-2026-21668)
vulnerability in veeam (CVE-2026-21668). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3989 |
|
Unsafe Deserialization in deserialization (CVE-2026-3989)
vulnerability in deserialization (CVE-2026-3989). Successful exploitation can lead to full system takeover. Exploitable via ``replay_request_dump.py``.
|
| CVE-2023-43010 |
|
Out-of-Bounds Write in apple (CVE-2023-43010)
out-of-bounds write in apple (CVE-2023-43010). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2368 |
|
Vulnerability in lenovo (CVE-2026-2368)
vulnerability in lenovo (CVE-2026-2368). Successful exploitation can lead to full system takeover.
|