Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-26601 |
|
Use-After-Free in tigervnc (CVE-2025-26601)
vulnerability in tigervnc (CVE-2025-26601). Successful exploitation can lead to full system takeover.
|
| CVE-2025-26597 |
|
Buffer Overflow in tigervnc (CVE-2025-26597)
vulnerability in tigervnc (CVE-2025-26597). Successful exploitation can lead to full system takeover.
|
| CVE-2025-26594 |
|
Use-After-Free in tigervnc (CVE-2025-26594)
vulnerability in tigervnc (CVE-2025-26594). Successful exploitation can lead to full system takeover.
|
| CVE-2025-26595 |
|
Vulnerability in tigervnc (CVE-2025-26595)
vulnerability in tigervnc (CVE-2025-26595). Successful exploitation can lead to full system takeover.
|
| CVE-2025-26596 |
|
Out-of-Bounds Write in tigervnc (CVE-2025-26596)
out-of-bounds write in tigervnc (CVE-2025-26596). Successful exploitation can lead to full system takeover.
|
| CVE-2025-26598 |
|
Out-of-Bounds Write in tigervnc (CVE-2025-26598)
out-of-bounds write in tigervnc (CVE-2025-26598). Successful exploitation can lead to full system takeover.
|
| CVE-2023-34192 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Synacor zimbra-collaboration-suite-zcs (CVE-2023-34192)
cross-site scripting in Synacor zimbra-collaboration-suite-zcs (CVE-2023-34192). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-49035 KEV |
|
[KEV] Privilege Escalation in Microsoft partner-center (CVE-2024-49035)
vulnerability in Microsoft partner-center (CVE-2024-49035). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-12916 |
|
SQL Injection in sqli (CVE-2024-12916)
SQL injection in sqli (CVE-2024-12916). Successful exploitation can lead to full system takeover.
|
| CVE-2024-12917 |
|
Vulnerability in CVE-2024-12917 (CVE-2024-12917)
vulnerability in CVE-2024-12917 (CVE-2024-12917). Confidential information can be exposed externally.
|
| CVE-2024-12918 |
|
SQL Injection in sqli (CVE-2024-12918)
SQL injection in sqli (CVE-2024-12918). Successful exploitation can lead to full system takeover.
|
| CVE-2024-20953 KEV |
|
[KEV] Unsafe Deserialization in Oracle agile-product-lifecycle-management-plm (CVE-2024-20953)
vulnerability in Oracle agile-product-lifecycle-management-plm (CVE-2024-20953). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-3066 KEV |
|
[KEV] Unsafe Deserialization in Adobe coldfusion (CVE-2017-3066)
vulnerability in Adobe coldfusion (CVE-2017-3066). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21704 |
|
Out-of-Bounds Write in linux (CVE-2025-21704)
out-of-bounds write in linux (CVE-2025-21704). Successful exploitation can lead to full system takeover.
|
| CVE-2025-24989 KEV |
|
[KEV] Vulnerability in Microsoft power-pages (CVE-2025-24989)
vulnerability in Microsoft power-pages (CVE-2025-24989). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-0111 KEV |
|
[KEV] Vulnerability in Palo alto networks palo-alto-networks (CVE-2025-0111)
vulnerability in Palo alto networks palo-alto-networks (CVE-2025-0111). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-23209 KEV |
|
[KEV] Code Injection in Craft cms craft-cms (CVE-2025-23209)
code injection in Craft cms craft-cms (CVE-2025-23209). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-0624 |
|
Out-of-Bounds Write in CVE-2025-0624 (CVE-2025-0624)
out-of-bounds write in CVE-2025-0624 (CVE-2025-0624). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57256 |
|
Vulnerability in denx (CVE-2024-57256)
vulnerability in denx (CVE-2024-57256). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57258 |
|
Vulnerability in denx (CVE-2024-57258)
vulnerability in denx (CVE-2024-57258). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21702 |
|
Vulnerability in privilege-escalation (CVE-2025-21702)
vulnerability in privilege-escalation (CVE-2025-21702). Successful exploitation can lead to full system takeover. Exploitable via ``NET_XMIT_CN``.
|
| CVE-2025-0108 KEV |
|
[KEV] Vulnerability in Palo alto networks palo-alto-networks (CVE-2025-0108)
vulnerability in Palo alto networks palo-alto-networks (CVE-2025-0108). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-12651 |
|
Vulnerability in CVE-2024-12651 (CVE-2024-12651)
vulnerability in CVE-2024-12651 (CVE-2024-12651). Confidential information can be exposed externally.
|
| CVE-2025-21701 |
|
Vulnerability in c (CVE-2025-21701)
vulnerability in c (CVE-2025-21701). Successful exploitation can lead to full system takeover.
|
| CVE-2025-26569 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-26569)
vulnerability in csrf (CVE-2025-26569). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-26570 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-26570)
vulnerability in csrf (CVE-2025-26570). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-1247 |
|
Vulnerability in CVE-2025-1247 (CVE-2025-1247)
vulnerability in CVE-2025-1247 (CVE-2025-1247). Confidential information can be exposed externally.
|
| CVE-2024-57727 KEV |
|
[KEV] Path Traversal in Simplehelp path-traversal (CVE-2024-57727)
path traversal in Simplehelp path-traversal (CVE-2024-57727). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2025-1244 |
|
OS Command Injection in CVE-2025-1244 (CVE-2025-1244)
OS command injection in CVE-2025-1244 (CVE-2025-1244). Successful exploitation can lead to full system takeover.
|
| CVE-2024-12251 |
|
Command Injection in telerik (CVE-2024-12251)
command injection in telerik (CVE-2024-12251). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21699 |
|
Vulnerability in linux (CVE-2025-21699)
vulnerability in linux (CVE-2025-21699). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21697 |
|
Vulnerability in linux (CVE-2025-21697)
vulnerability in linux (CVE-2025-21697). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57951 |
|
Use-After-Free in linux (CVE-2024-57951)
vulnerability in linux (CVE-2024-57951). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57952 |
|
Vulnerability in linux (CVE-2024-57952)
vulnerability in linux (CVE-2024-57952). Data can be tampered with by attackers.
|
| CVE-2025-24200 KEV |
|
[KEV] Authorization Flaw in Apple ios-and-ipados (CVE-2025-24200)
vulnerability in Apple ios-and-ipados (CVE-2025-24200). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-41710 KEV |
|
[KEV] Vulnerability in Mitel sip-phones (CVE-2024-41710)
vulnerability in Mitel sip-phones (CVE-2024-41710). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-40891 KEV |
|
[KEV] OS Command Injection in Zyxel dsl-cpe-devices (CVE-2024-40891)
OS command injection in Zyxel dsl-cpe-devices (CVE-2024-40891). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-40890 KEV |
|
[KEV] OS Command Injection in Zyxel dsl-cpe-devices (CVE-2024-40890)
OS command injection in Zyxel dsl-cpe-devices (CVE-2024-40890). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21418 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-21418)
vulnerability in Microsoft windows (CVE-2025-21418). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21391 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-21391)
vulnerability in Microsoft windows (CVE-2025-21391). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21692 |
|
Vulnerability in c (CVE-2025-21692)
vulnerability in c (CVE-2025-21692). Successful exploitation can lead to full system takeover.
|
| CVE-2025-21687 |
|
Out-of-Bounds Read in linux (CVE-2025-21687)
vulnerability in linux (CVE-2025-21687). Successful exploitation can lead to full system takeover.
|
| CVE-2025-0994 KEV |
|
[KEV] Unsafe Deserialization in Trimble cityworks (CVE-2025-0994)
vulnerability in Trimble cityworks (CVE-2025-0994). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-15069 KEV |
|
[KEV] Vulnerability in Sophos xg-firewall (CVE-2020-15069)
vulnerability in Sophos xg-firewall (CVE-2020-15069). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-23748 KEV |
|
[KEV] Vulnerability in Audinate dante-discovery (CVE-2022-23748)
vulnerability in Audinate dante-discovery (CVE-2022-23748). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-0411 KEV |
|
[KEV] Vulnerability in 7-zip (CVE-2025-0411)
vulnerability in 7-zip (CVE-2025-0411). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-1022 |
|
Vulnerability in CVE-2025-1022 (CVE-2025-1022)
vulnerability in CVE-2025-1022 (CVE-2025-1022). Confidential information can be exposed externally.
|
| CVE-2024-53104 KEV |
|
[KEV] Out-of-Bounds Write in Linux kernel (CVE-2024-53104)
out-of-bounds write in Linux kernel (CVE-2024-53104). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-22205 |
|
Path Traversal in path-traversal (CVE-2025-22205)
path traversal in path-traversal (CVE-2025-22205). Confidential information can be exposed externally.
|
| CVE-2018-19410 KEV |
|
[KEV] Vulnerability in Paessler prtg-network-monitor (CVE-2018-19410)
vulnerability in Paessler prtg-network-monitor (CVE-2018-19410). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|