Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-22175 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in gitlab (CVE-2021-22175)
SSRF in gitlab (CVE-2021-22175). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-22769 KEV |
|
[KEV] Vulnerability in Dell recoverpoint-for-virtual-machines-rp4vms (CVE-2026-22769)
vulnerability in Dell recoverpoint-for-virtual-machines-rp4vms (CVE-2026-22769). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-24734 |
|
Vulnerability in apache (CVE-2026-24734)
vulnerability in apache (CVE-2026-24734). Data can be tampered with by attackers.
|
| CVE-2025-70397 |
|
SQL Injection in sqli (CVE-2025-70397)
SQL injection in sqli (CVE-2025-70397). Successful exploitation can lead to full system takeover.
|
| CVE-2025-65753 |
|
Vulnerability in CVE-2025-65753 (CVE-2025-65753)
vulnerability in CVE-2025-65753 (CVE-2025-65753). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7631 |
|
SQL Injection in c (CVE-2025-7631)
SQL injection in c (CVE-2025-7631). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-7796 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Synacor zimbra-collaboration-suite (CVE-2020-7796)
SSRF in Synacor zimbra-collaboration-suite (CVE-2020-7796). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-7694 KEV |
|
[KEV] Unrestricted File Upload in Teamt5 threatsonar-anti-ransomware (CVE-2024-7694)
vulnerability in Teamt5 threatsonar-anti-ransomware (CVE-2024-7694). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2008-0015 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2008-0015)
vulnerability in Microsoft windows (CVE-2008-0015). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-2441 KEV |
|
[KEV] Use-After-Free in Google chromium (CVE-2026-2441)
vulnerability in Google chromium (CVE-2026-2441). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-2447 |
|
Vulnerability in mozilla (CVE-2026-2447)
vulnerability in mozilla (CVE-2026-2447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26369 |
|
Privilege Escalation in privilege-escalation (CVE-2026-26369)
vulnerability in privilege-escalation (CVE-2026-26369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23185 |
|
Use-After-Free in linux (CVE-2026-23185)
vulnerability in linux (CVE-2026-23185). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71221 |
|
Vulnerability in linux (CVE-2025-71221)
vulnerability in linux (CVE-2025-71221). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71204 |
|
Vulnerability in linux (CVE-2025-71204)
vulnerability in linux (CVE-2025-71204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23204 |
|
Out-of-Bounds Read in c (CVE-2026-23204)
vulnerability in c (CVE-2026-23204). Confidential information can be exposed externally.
|
| CVE-2026-23171 |
|
Use-After-Free in c (CVE-2026-23171)
vulnerability in c (CVE-2026-23171). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71201 |
|
Out-of-Bounds Read in c (CVE-2025-71201)
vulnerability in c (CVE-2025-71201). Confidential information can be exposed externally.
|
| CVE-2025-71202 |
|
Vulnerability in linux (CVE-2025-71202)
vulnerability in linux (CVE-2025-71202). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23111 |
|
Use-After-Free in privilege-escalation (CVE-2026-23111)
vulnerability in privilege-escalation (CVE-2026-23111). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1619 |
|
Vulnerability in uni-yaz (CVE-2026-1619)
vulnerability in uni-yaz (CVE-2026-1619). Confidential information can be exposed externally.
|
| CVE-2025-14349 |
|
Vulnerability in privilege-escalation (CVE-2025-14349)
vulnerability in privilege-escalation (CVE-2025-14349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1618 |
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc....
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc....
|
| CVE-2026-1731 KEV |
|
[KEV] OS Command Injection in Beyondtrust remote-support-rs-and-privileged-remote-access-pra (CVE-2026-1731)
OS command injection in Beyondtrust remote-support-rs-and-privileged-remote-access-pra (CVE-2026-1731). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-25949 |
|
Vulnerability in github.com/traefik/traefik/v3 (CVE-2026-25949)
vulnerability in github.com/traefik/traefik/v3 (CVE-2026-25949). Risk of unauthorized operations or information disclosure. Exploitable via ``respondingTimeouts.readTimeout``. Mitigation: upgrade to `3.6.8` or later.
|
| CVE-2026-26214 |
|
Vulnerability in apache (CVE-2026-26214)
vulnerability in apache (CVE-2026-26214). Confidential information can be exposed externally.
|
| CVE-2026-26217 |
|
Path Traversal in crawl4ai (CVE-2026-26217)
path traversal in crawl4ai (CVE-2026-26217). Confidential information can be exposed externally. Exploitable via `POST /execute_js`. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2025-13002 |
|
Cross-Site Scripting (XSS) in farktor (CVE-2025-13002)
cross-site scripting in farktor (CVE-2025-13002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2007 |
|
Vulnerability in postgresql (CVE-2026-2007)
vulnerability in postgresql (CVE-2026-2007). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.2.0` or later.
|
| CVE-2026-2005 |
|
Vulnerability in postgresql (CVE-2026-2005)
vulnerability in postgresql (CVE-2026-2005). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.21.0, 15.16.0, 16.12.0, 17.8.0, 18.2.0` or later.
|
| CVE-2026-2004 |
|
Vulnerability in postgresql (CVE-2026-2004)
vulnerability in postgresql (CVE-2026-2004). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.21.0, 15.16.0, 16.12.0, 17.8.0, 18.2.0` or later.
|
| CVE-2026-2006 |
|
Vulnerability in postgresql (CVE-2026-2006)
vulnerability in postgresql (CVE-2026-2006). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.21.0, 15.16.0, 16.12.0, 17.8.0, 18.2.0` or later.
|
| CVE-2026-20700 KEV |
|
[KEV] Buffer Overflow in Apple multiple-products (CVE-2026-20700)
vulnerability in Apple multiple-products (CVE-2026-20700). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-43468 KEV |
|
[KEV] SQL Injection in Microsoft configuration-manager (CVE-2024-43468)
SQL injection in Microsoft configuration-manager (CVE-2024-43468). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-15556 KEV |
|
[KEV] Vulnerability in Notepad++ notepad (CVE-2025-15556)
vulnerability in Notepad++ notepad (CVE-2025-15556). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-40536 KEV |
|
[KEV] Vulnerability in Solarwinds web-help-desk (CVE-2025-40536)
vulnerability in Solarwinds web-help-desk (CVE-2025-40536). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20615 |
|
Path Traversal in apple (CVE-2026-20615)
path traversal in apple (CVE-2026-20615). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20617 |
|
Vulnerability in apple (CVE-2026-20617)
vulnerability in apple (CVE-2026-20617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1669 |
|
Vulnerability in keras (CVE-2026-1669)
vulnerability in keras (CVE-2026-1669). Confidential information can be exposed externally.
|
| CVE-2026-26157 |
|
Vulnerability in CVE-2026-26157 (CVE-2026-26157)
vulnerability in CVE-2026-26157 (CVE-2026-26157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26158 |
|
Vulnerability in privilege-escalation (CVE-2026-26158)
vulnerability in privilege-escalation (CVE-2026-26158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25990 |
|
Out-of-Bounds Write in pillow (CVE-2026-25990)
out-of-bounds write in pillow (CVE-2026-25990). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.1.1` or later.
|
| CVE-2020-37208 |
|
SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste i...
SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.
|
| CVE-2020-37209 |
|
Vulnerability in dos (CVE-2020-37209)
vulnerability in dos (CVE-2020-37209). Confidential information can be exposed externally.
|
| CVE-2020-37210 |
|
SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste i...
SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.
|
| CVE-2020-37211 |
|
SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character...
SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.
|
| CVE-2020-37212 |
|
SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste...
SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.
|
| CVE-2020-37204 |
|
Vulnerability in dos (CVE-2020-37204)
vulnerability in dos (CVE-2020-37204). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-37205 |
|
Vulnerability in dos (CVE-2020-37205)
vulnerability in dos (CVE-2020-37205). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-37206 |
|
Vulnerability in dos (CVE-2020-37206)
vulnerability in dos (CVE-2020-37206). Risk of unauthorized operations or information disclosure.
|