Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-9222 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2025-9222)
cross-site scripting in gitlab (CVE-2025-9222). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
|
| CVE-2025-13761 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2025-13761)
cross-site scripting in gitlab (CVE-2025-13761). Confidential information can be exposed externally. Mitigation: upgrade to `18.6.3, 18.7.1` or later.
|
| CVE-2025-13772 |
|
Vulnerability in gitlab (CVE-2025-13772)
vulnerability in gitlab (CVE-2025-13772). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
|
| CVE-2025-65518 |
|
Vulnerability in dos (CVE-2025-65518)
vulnerability in dos (CVE-2025-65518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21639 |
|
Vulnerability in ui (CVE-2026-21639)
vulnerability in ui (CVE-2026-21639). Successful exploitation can lead to full system takeover.
|
| CVE-2025-50334 |
|
Vulnerability in dos (CVE-2025-50334)
vulnerability in dos (CVE-2025-50334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22244 |
|
Vulnerability in open-metadata (CVE-2026-22244)
vulnerability in open-metadata (CVE-2026-22244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0719 |
|
Vulnerability in CVE-2026-0719 (CVE-2026-0719)
vulnerability in CVE-2026-0719 (CVE-2026-0719). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69262 |
|
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings....
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code E...
|
| CVE-2026-21441 |
|
Vulnerability in urllib3 (CVE-2026-21441)
vulnerability in urllib3 (CVE-2026-21441). Risk of unauthorized operations or information disclosure. Exploitable via ``gzip``. Mitigation: upgrade to `2.6.3` or later.
|
| CVE-2025-69263 |
|
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve differe...
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package w...
|
| CVE-2025-69264 |
|
Vulnerability in pnpm (CVE-2025-69264)
vulnerability in pnpm (CVE-2025-69264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22184 |
|
Out-of-Bounds Write in zlib (CVE-2026-22184)
out-of-bounds write in zlib (CVE-2026-22184). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22190 |
|
Vulnerability in cmu (CVE-2026-22190)
vulnerability in cmu (CVE-2026-22190). Confidential information can be exposed externally.
|
| CVE-2009-0556 KEV |
|
[KEV] Code Injection in Microsoft office (CVE-2009-0556)
code injection in Microsoft office (CVE-2009-0556). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-37164 KEV |
|
[KEV] Code Injection in Hewlett packard enterprise (hpe) hewlett-packard-enterprise-hpe (CVE-2025-37164)
code injection in Hewlett packard enterprise (hpe) hewlett-packard-enterprise-hpe (CVE-2025-37164). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-69223 |
|
Vulnerability in aiohttp (CVE-2025-69223)
vulnerability in aiohttp (CVE-2025-69223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.3` or later.
|
| CVE-2025-68428 |
|
Vulnerability in path-traversal (CVE-2025-68428)
vulnerability in path-traversal (CVE-2025-68428). Confidential information can be exposed externally. Exploitable via ``addImage``.
|
| CVE-2026-0621 |
|
Vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621)
vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621). Risk of unauthorized operations or information disclosure. Exploitable via ``UriTemplate``. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2025-68761 |
|
Vulnerability in CVE-2025-68761 (CVE-2025-68761)
vulnerability in CVE-2025-68761 (CVE-2025-68761). Successful exploitation can lead to full system takeover.
|
| CVE-2025-68753 |
|
Vulnerability in CVE-2025-68753 (CVE-2025-68753)
vulnerability in CVE-2025-68753 (CVE-2025-68753). Data can be tampered with by attackers.
|
| CVE-2025-68764 |
|
Vulnerability in CVE-2025-68764 (CVE-2025-68764)
vulnerability in CVE-2025-68764 (CVE-2025-68764). Successful exploitation can lead to full system takeover.
|
| CVE-2025-3653 |
|
Vulnerability in petlibro (CVE-2025-3653)
vulnerability in petlibro (CVE-2025-3653). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-3646 |
|
Vulnerability in petlibro (CVE-2025-3646)
vulnerability in petlibro (CVE-2025-3646). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67269 |
|
Vulnerability in c (CVE-2025-67269)
vulnerability in c (CVE-2025-67269). Risk of unauthorized operations or information disclosure. Exploitable via ``ffa1d6f40bca0b035fc7f5e563160ebb67199da7``.
|
| CVE-2025-67158 |
|
Authentication Bypass in revotech (CVE-2025-67158)
authentication bypass in revotech (CVE-2025-67158). Confidential information can be exposed externally.
|
| CVE-2025-67159 |
|
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
|
| CVE-2025-67160 |
|
Path Traversal in path-traversal (CVE-2025-67160)
path traversal in path-traversal (CVE-2025-67160). Confidential information can be exposed externally.
|
| CVE-2025-62842 |
|
Vulnerability in qnap (CVE-2025-62842)
vulnerability in qnap (CVE-2025-62842). Successful exploitation can lead to full system takeover.
|
| CVE-2025-11157 |
|
Unsafe Deserialization in feast (CVE-2025-11157)
vulnerability in feast (CVE-2025-11157). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.54.0` or later.
|
| CVE-2024-58315 |
|
Vulnerability in tosi (CVE-2024-58315)
vulnerability in tosi (CVE-2024-58315). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66835 |
|
Vulnerability in trueconf (CVE-2025-66835)
vulnerability in trueconf (CVE-2025-66835). Confidential information can be exposed externally.
|
| CVE-2025-66824 |
|
Cross-Site Scripting (XSS) in trueconf (CVE-2025-66824)
cross-site scripting in trueconf (CVE-2025-66824). Confidential information can be exposed externally.
|
| CVE-2025-66834 |
|
Vulnerability in trueconf (CVE-2025-66834)
vulnerability in trueconf (CVE-2025-66834). Confidential information can be exposed externally.
|
| CVE-2023-54317 |
|
Vulnerability in CVE-2023-54317 (CVE-2023-54317)
vulnerability in CVE-2023-54317 (CVE-2023-54317). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54326 |
|
Vulnerability in CVE-2023-54326 (CVE-2023-54326)
vulnerability in CVE-2023-54326 (CVE-2023-54326). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54318 |
|
Vulnerability in CVE-2023-54318 (CVE-2023-54318)
vulnerability in CVE-2023-54318 (CVE-2023-54318). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54325 |
|
Vulnerability in CVE-2023-54325 (CVE-2023-54325)
vulnerability in CVE-2023-54325 (CVE-2023-54325). Confidential information can be exposed externally.
|
| CVE-2023-54306 |
|
Vulnerability in CVE-2023-54306 (CVE-2023-54306)
vulnerability in CVE-2023-54306 (CVE-2023-54306). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-54303 |
|
Vulnerability in CVE-2023-54303 (CVE-2023-54303)
vulnerability in CVE-2023-54303 (CVE-2023-54303). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54308 |
|
Vulnerability in CVE-2023-54308 (CVE-2023-54308)
vulnerability in CVE-2023-54308 (CVE-2023-54308). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54310 |
|
Vulnerability in CVE-2023-54310 (CVE-2023-54310)
vulnerability in CVE-2023-54310 (CVE-2023-54310). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54262 |
|
Vulnerability in c (CVE-2023-54262)
vulnerability in c (CVE-2023-54262). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54286 |
|
Vulnerability in c (CVE-2023-54286)
vulnerability in c (CVE-2023-54286). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-54284 |
|
Vulnerability in CVE-2023-54284 (CVE-2023-54284)
vulnerability in CVE-2023-54284 (CVE-2023-54284). Confidential information can be exposed externally.
|
| CVE-2023-54238 |
|
Vulnerability in c (CVE-2023-54238)
vulnerability in c (CVE-2023-54238). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54250 |
|
Vulnerability in CVE-2023-54250 (CVE-2023-54250)
vulnerability in CVE-2023-54250 (CVE-2023-54250). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-54254 |
|
Vulnerability in CVE-2023-54254 (CVE-2023-54254)
vulnerability in CVE-2023-54254 (CVE-2023-54254). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54219 |
|
Vulnerability in c (CVE-2023-54219)
vulnerability in c (CVE-2023-54219). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-54220 |
|
Vulnerability in CVE-2023-54220 (CVE-2023-54220)
vulnerability in CVE-2023-54220 (CVE-2023-54220). Successful exploitation can lead to full system takeover.
|