Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-21525 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-21525)
vulnerability in Microsoft windows (CVE-2026-21525). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21510 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-21510)
vulnerability in Microsoft windows (CVE-2026-21510). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21533 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2026-21533)
vulnerability in Microsoft windows (CVE-2026-21533). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21519 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-21519)
vulnerability in Microsoft windows (CVE-2026-21519). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21514 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2026-21514)
vulnerability in Microsoft office (CVE-2026-21514). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-1486 |
|
Vulnerability in CVE-2026-1486 (CVE-2026-1486)
vulnerability in CVE-2026-1486 (CVE-2026-1486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1529 |
|
Vulnerability in CVE-2026-1529 (CVE-2026-1529)
vulnerability in CVE-2026-1529 (CVE-2026-1529). Confidential information can be exposed externally.
|
| CVE-2026-24678 |
|
Use-After-Free in freerdp (CVE-2026-24678)
vulnerability in freerdp (CVE-2026-24678). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.22.0` or later.
|
| CVE-2026-25639 |
|
Vulnerability in axios (CVE-2026-25639)
vulnerability in axios (CVE-2026-25639). Risk of unauthorized operations or information disclosure. Exploitable via ``mergeConfig``. Mitigation: upgrade to `0.30.3` or later.
|
| CVE-2025-10465 |
|
Unrestricted File Upload in CVE-2025-10465 (CVE-2025-10465)
vulnerability in CVE-2025-10465 (CVE-2025-10465). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10463 |
|
Authentication Bypass in CVE-2025-10463 (CVE-2025-10463)
authentication bypass in CVE-2025-10463 (CVE-2025-10463). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7799 |
|
Cross-Site Scripting (XSS) in CVE-2025-7799 (CVE-2025-7799)
cross-site scripting in CVE-2025-7799 (CVE-2025-7799). Data can be tampered with by attackers.
|
| CVE-2026-25859 |
|
Authorization Flaw in wekan-project (CVE-2026-25859)
vulnerability in wekan-project (CVE-2026-25859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25561 |
|
Authorization Flaw in wekan-project (CVE-2026-25561)
vulnerability in wekan-project (CVE-2026-25561). Data can be tampered with by attackers.
|
| CVE-2026-25563 |
|
Vulnerability in wekan-project (CVE-2026-25563)
vulnerability in wekan-project (CVE-2026-25563). Data can be tampered with by attackers.
|
| CVE-2026-25564 |
|
Vulnerability in wekan-project (CVE-2026-25564)
vulnerability in wekan-project (CVE-2026-25564). Data can be tampered with by attackers.
|
| CVE-2026-25580 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-25580)
SSRF in ssrf (CVE-2026-25580). Confidential information can be exposed externally. Mitigation: upgrade to `1.56.0` or later.
|
| CVE-2026-25640 |
|
Path Traversal in path-traversal (CVE-2026-25640)
path traversal in path-traversal (CVE-2026-25640). Confidential information can be exposed externally. Mitigation: upgrade to `1.51.0` or later.
|
| CVE-2026-25556 |
|
Vulnerability in artifex (CVE-2026-25556)
vulnerability in artifex (CVE-2026-25556). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25293 |
|
Vulnerability in c (CVE-2019-25293)
vulnerability in c (CVE-2019-25293). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61732 |
|
Code Injection in toolchain (CVE-2025-61732)
code injection in toolchain (CVE-2025-61732). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.24.13, 1.25.7` or later.
|
| CVE-2025-11953 KEV |
|
[KEV] OS Command Injection in React native community react-native-community (CVE-2025-11953)
OS command injection in React native community react-native-community (CVE-2025-11953). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-25521 |
|
Vulnerability in locutus (CVE-2026-25521)
vulnerability in locutus (CVE-2026-25521). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25536 |
|
Vulnerability in lfprojects (CVE-2026-25536)
vulnerability in lfprojects (CVE-2026-25536). Confidential information can be exposed externally.
|
| CVE-2026-23074 |
|
Use-After-Free in linux (CVE-2026-23074)
vulnerability in linux (CVE-2026-23074). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23103 |
|
Vulnerability in linux (CVE-2026-23103)
vulnerability in linux (CVE-2026-23103). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23099 |
|
Out-of-Bounds Read in c (CVE-2026-23099)
vulnerability in c (CVE-2026-23099). Confidential information can be exposed externally.
|
| CVE-2026-23095 |
|
Vulnerability in c (CVE-2026-23095)
vulnerability in c (CVE-2026-23095). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23083 |
|
Vulnerability in linux (CVE-2026-23083)
vulnerability in linux (CVE-2026-23083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23066 |
|
Vulnerability in linux (CVE-2026-23066)
vulnerability in linux (CVE-2026-23066). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0537 |
|
Out-of-Bounds Write in autodesk (CVE-2026-0537)
out-of-bounds write in autodesk (CVE-2026-0537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0538 |
|
Out-of-Bounds Write in autodesk (CVE-2026-0538)
out-of-bounds write in autodesk (CVE-2026-0538). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0660 |
|
Vulnerability in autodesk (CVE-2026-0660)
vulnerability in autodesk (CVE-2026-0660). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0661 |
|
Out-of-Bounds Write in autodesk (CVE-2026-0661)
out-of-bounds write in autodesk (CVE-2026-0661). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71192 |
|
Vulnerability in CVE-2025-71192 (CVE-2025-71192)
vulnerability in CVE-2025-71192 (CVE-2025-71192). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1819 |
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
|
| CVE-2025-69621 |
|
Path Traversal in CVE-2025-69621 (CVE-2025-69621)
path traversal in CVE-2025-69621 (CVE-2025-69621). Confidential information can be exposed externally.
|
| CVE-2020-37094 |
|
Vulnerability in espocrm (CVE-2020-37094)
vulnerability in espocrm (CVE-2020-37094). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-25223 |
|
Vulnerability in fastify (CVE-2026-25223)
vulnerability in fastify (CVE-2026-25223). Data can be tampered with by attackers.
|
| CVE-2025-6397 |
|
Cross-Site Scripting (XSS) in CVE-2025-6397 (CVE-2025-6397)
cross-site scripting in CVE-2025-6397 (CVE-2025-6397). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7760 |
|
Cross-Site Scripting (XSS) in CVE-2025-7760 (CVE-2025-7760)
cross-site scripting in CVE-2025-7760 (CVE-2025-7760). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8456 |
|
Cross-Site Scripting (XSS) in CVE-2025-8456 (CVE-2025-8456)
cross-site scripting in CVE-2025-8456 (CVE-2025-8456). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8461 |
|
Cross-Site Scripting (XSS) in CVE-2025-8461 (CVE-2025-8461)
cross-site scripting in CVE-2025-8461 (CVE-2025-8461). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8589 |
|
Cross-Site Scripting (XSS) in CVE-2025-8589 (CVE-2025-8589)
cross-site scripting in CVE-2025-8589 (CVE-2025-8589). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8590 |
|
Information Disclosure in CVE-2025-8590 (CVE-2025-8590)
vulnerability in CVE-2025-8590 (CVE-2025-8590). Confidential information can be exposed externally.
|
| CVE-2026-22550 |
|
OS Command Injection in elecom (CVE-2026-22550)
OS command injection in elecom (CVE-2026-22550). Successful exploitation can lead to full system takeover.
|
| CVE-2021-39935 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Gitlab community-and-enterprise-editions (CVE-2021-39935)
SSRF in Gitlab community-and-enterprise-editions (CVE-2021-39935). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-64328 KEV |
|
[KEV] OS Command Injection in Sangoma freepbx (CVE-2025-64328)
OS command injection in Sangoma freepbx (CVE-2025-64328). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-40551 KEV |
|
[KEV] Unsafe Deserialization in Solarwinds web-help-desk (CVE-2025-40551)
vulnerability in Solarwinds web-help-desk (CVE-2025-40551). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-24737 |
|
Vulnerability in parall (CVE-2026-24737)
vulnerability in parall (CVE-2026-24737). Confidential information can be exposed externally.
|