Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-32213 |
|
Vulnerability in microsoft (CVE-2026-32213)
vulnerability in microsoft (CVE-2026-32213). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35053 |
|
Vulnerability in hackerbay (CVE-2026-35053)
vulnerability in hackerbay (CVE-2026-35053). Successful exploitation can lead to full system takeover. Exploitable via `GET /workflow/manual/run/`.
|
| CVE-2026-34838 |
|
Unsafe Deserialization in deserialization (CVE-2026-34838)
vulnerability in deserialization (CVE-2026-34838). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34931 |
|
Open Redirect in hoppscotch (CVE-2026-34931)
vulnerability in hoppscotch (CVE-2026-34931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34932 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-34932)
cross-site scripting in csrf (CVE-2026-34932). Confidential information can be exposed externally.
|
| CVE-2024-14034 |
|
Authentication Bypass in CVE-2024-14034 (CVE-2024-14034)
authentication bypass in CVE-2024-14034 (CVE-2024-14034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34745 |
|
Path Traversal in shaneisrael (CVE-2026-34745)
path traversal in shaneisrael (CVE-2026-34745). Data can be tampered with by attackers.
|
| CVE-2026-34758 |
|
Vulnerability in hackerbay (CVE-2026-34758)
vulnerability in hackerbay (CVE-2026-34758). Confidential information can be exposed externally.
|
| CVE-2026-34717 |
|
SQL Injection in openproject (CVE-2026-34717)
SQL injection in openproject (CVE-2026-34717). Data can be tampered with by attackers.
|
| CVE-2026-34877 |
|
Vulnerability in arm (CVE-2026-34877)
vulnerability in arm (CVE-2026-34877). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33950 |
|
Vulnerability in privilege-escalation (CVE-2026-33950)
vulnerability in privilege-escalation (CVE-2026-33950). Confidential information can be exposed externally.
|
| CVE-2026-25212 |
|
Vulnerability in percona (CVE-2026-25212)
vulnerability in percona (CVE-2026-25212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33746 |
|
Authentication Bypass in convoypanel (CVE-2026-33746)
authentication bypass in convoypanel (CVE-2026-33746). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35002 |
|
Vulnerability in agno (CVE-2026-35002)
vulnerability in agno (CVE-2026-35002). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.3.24` or later.
|
| CVE-2026-32871 |
|
SSRF (Server-Side Request Forgery) in fastmcp (CVE-2026-32871)
SSRF in fastmcp (CVE-2026-32871). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-34873 |
|
Authentication Bypass in trustedfirmware (CVE-2026-34873)
authentication bypass in trustedfirmware (CVE-2026-34873). Confidential information can be exposed externally.
|
| CVE-2026-34875 |
|
Vulnerability in trustedfirmware (CVE-2026-34875)
vulnerability in trustedfirmware (CVE-2026-34875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4374 |
|
XXE (XML External Entity) in rti (CVE-2026-4374)
vulnerability in rti (CVE-2026-4374). Confidential information can be exposed externally.
|
| CVE-2026-34448 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448). Successful exploitation can lead to full system takeover. Exploitable via ``mAsse``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34449 |
|
Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449). Successful exploitation can lead to full system takeover. Exploitable via ``Origin``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34400 |
|
SQL Injection in sqli (CVE-2026-34400)
SQL injection in sqli (CVE-2026-34400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1579 |
|
Vulnerability in px4 (CVE-2026-1579)
vulnerability in px4 (CVE-2026-1579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30285 |
|
Path Traversal in zora (CVE-2026-30285)
path traversal in zora (CVE-2026-30285). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30282 |
|
Path Traversal in uxgroupllc (CVE-2026-30282)
path traversal in uxgroupllc (CVE-2026-30282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30283 |
|
Path Traversal in peaksel (CVE-2026-30283)
path traversal in peaksel (CVE-2026-30283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30286 |
|
Path Traversal in funambol (CVE-2026-30286)
path traversal in funambol (CVE-2026-30286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30278 |
|
Path Traversal in funair (CVE-2026-30278)
path traversal in funair (CVE-2026-30278). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34361 |
|
Vulnerability in hapifhir (CVE-2026-34361)
vulnerability in hapifhir (CVE-2026-34361). Confidential information can be exposed externally.
|
| CVE-2026-34243 |
|
Command Injection in njzjz (CVE-2026-34243)
command injection in njzjz (CVE-2026-34243). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34220 |
|
SQL Injection in sqli (CVE-2026-34220)
SQL injection in sqli (CVE-2026-34220). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34221 |
|
Vulnerability in mikro-orm (CVE-2026-34221)
vulnerability in mikro-orm (CVE-2026-34221). Data can be tampered with by attackers.
|
| CVE-2026-34235 |
|
Out-of-Bounds Read in c (CVE-2026-34235)
vulnerability in c (CVE-2026-34235). Confidential information can be exposed externally.
|
| CVE-2026-30276 |
|
Vulnerability in deftpdf (CVE-2026-30276)
vulnerability in deftpdf (CVE-2026-30276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30281 |
|
Vulnerability in maru (CVE-2026-30281)
vulnerability in maru (CVE-2026-30281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34532 |
|
Authorization Flaw in parseplatform (CVE-2026-34532)
vulnerability in parseplatform (CVE-2026-34532). Confidential information can be exposed externally.
|
| CVE-2026-34162 |
|
Vulnerability in fastgpt (CVE-2026-34162)
vulnerability in fastgpt (CVE-2026-34162). Confidential information can be exposed externally.
|
| CVE-2026-33579 |
|
Authorization Flaw in privilege-escalation (CVE-2026-33579)
vulnerability in privilege-escalation (CVE-2026-33579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30312 |
|
OS Command Injection in CVE-2026-30312 (CVE-2026-30312)
OS command injection in CVE-2026-30312 (CVE-2026-30312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30314 |
|
OS Command Injection in ridvay (CVE-2026-30314)
OS command injection in ridvay (CVE-2026-30314). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30311 |
|
OS Command Injection in ridvay (CVE-2026-30311)
OS command injection in ridvay (CVE-2026-30311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34156 |
|
Vulnerability in nocobase (CVE-2026-34156)
vulnerability in nocobase (CVE-2026-34156). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30310 |
|
Command Injection in CVE-2026-30310 (CVE-2026-30310)
command injection in CVE-2026-30310 (CVE-2026-30310). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32916 |
|
Vulnerability in openclaw (CVE-2026-32916)
vulnerability in openclaw (CVE-2026-32916). Confidential information can be exposed externally.
|
| CVE-2026-32917 |
|
OS Command Injection in openclaw (CVE-2026-32917)
OS command injection in openclaw (CVE-2026-32917). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34060 |
|
Code Injection in shopify (CVE-2026-34060)
code injection in shopify (CVE-2026-34060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34714 |
|
OS Command Injection in vim (CVE-2026-34714)
OS command injection in vim (CVE-2026-34714). Confidential information can be exposed externally.
|
| CVE-2025-15379 |
|
Command Injection in mlflow (CVE-2025-15379)
command injection in mlflow (CVE-2025-15379). Successful exploitation can lead to full system takeover. Exploitable via ``python_env.yaml``. Mitigation: upgrade to `3.8.1` or later.
|
| CVE-2025-15036 |
|
Vulnerability in mlflow (CVE-2025-15036)
vulnerability in mlflow (CVE-2025-15036). Successful exploitation can lead to full system takeover. Exploitable via ``extract_archive_to_dir``. Mitigation: upgrade to `3.9.0rc0` or later.
|
| CVE-2026-3256 |
|
Vulnerability in ktat (CVE-2026-3256)
vulnerability in ktat (CVE-2026-3256). Successful exploitation can lead to full system takeover.
|
| CVE-2025-9497 |
|
Vulnerability in microchip (CVE-2025-9497)
vulnerability in microchip (CVE-2025-9497). Successful exploitation can lead to full system takeover.
|