Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-27490 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
|
| CVE-2026-4937 |
|
Vulnerability in ibm (CVE-2026-4937)
vulnerability in ibm (CVE-2026-4937). Confidential information can be exposed externally.
|
| CVE-2026-4936 |
|
Vulnerability in ibm (CVE-2026-4936)
vulnerability in ibm (CVE-2026-4936). Confidential information can be exposed externally.
|
| CVE-2026-19906 |
|
Vulnerability in CVE-2026-19906 (CVE-2026-19906)
vulnerability in CVE-2026-19906 (CVE-2026-19906). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19748 |
|
Vulnerability in CVE-2026-19748 (CVE-2026-19748)
vulnerability in CVE-2026-19748 (CVE-2026-19748). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71851 |
|
Vulnerability in crypto-js (CVE-2026-71851)
vulnerability in crypto-js (CVE-2026-71851). Successful exploitation can lead to full system takeover. Exploitable via ``crypto``. Mitigation: upgrade to `4.0.0` or later.
|
| CVE-2026-38447 |
|
Vulnerability in CVE-2026-38447 (CVE-2026-38447)
vulnerability in CVE-2026-38447 (CVE-2026-38447). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15629 |
|
Vulnerability in tp-link (CVE-2025-15629)
vulnerability in tp-link (CVE-2025-15629). Confidential information can be exposed externally.
|
| CVE-2026-4932 |
|
Vulnerability in CVE-2026-4932 (CVE-2026-4932)
vulnerability in CVE-2026-4932 (CVE-2026-4932). Confidential information can be exposed externally.
|
| CVE-2026-11403 |
|
Vulnerability in CVE-2026-11403 (CVE-2026-11403)
vulnerability in CVE-2026-11403 (CVE-2026-11403). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13199 |
|
Vulnerability in CVE-2026-13199 (CVE-2026-13199)
vulnerability in CVE-2026-13199 (CVE-2026-13199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4930 |
|
Vulnerability in CVE-2026-4930 (CVE-2026-4930)
vulnerability in CVE-2026-4930 (CVE-2026-4930). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46473 |
|
Vulnerability in CVE-2026-46473 (CVE-2026-46473)
vulnerability in CVE-2026-46473 (CVE-2026-46473). Confidential information can be exposed externally.
|
| CVE-2026-8700 |
|
Vulnerability in CVE-2026-8700 (CVE-2026-8700)
vulnerability in CVE-2026-8700 (CVE-2026-8700). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46474 |
|
Vulnerability in CVE-2026-46474 (CVE-2026-46474)
vulnerability in CVE-2026-46474 (CVE-2026-46474). Confidential information can be exposed externally.
|
| CVE-2026-42155 |
|
Vulnerability in openmage/magento-lts (CVE-2026-42155)
vulnerability in openmage/magento-lts (CVE-2026-42155). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/xmlrpc/`. Mitigation: upgrade to `20.18.0` or later.
|
| CVE-2025-14972 |
|
Vulnerability in CVE-2025-14972 (CVE-2025-14972)
vulnerability in CVE-2025-14972 (CVE-2025-14972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4827 |
|
Vulnerability in CVE-2026-4827 (CVE-2026-4827)
vulnerability in CVE-2026-4827 (CVE-2026-4827). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7210 |
|
Vulnerability in libpython (CVE-2026-7210)
vulnerability in libpython (CVE-2026-7210). Risk of unauthorized operations or information disclosure. Exploitable via ``xml.parsers.expat``.
|
| CVE-2026-2336 |
|
Vulnerability in privilege-escalation (CVE-2026-2336)
vulnerability in privilege-escalation (CVE-2026-2336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41080 |
|
Vulnerability in libexpat-project (CVE-2026-41080)
vulnerability in libexpat-project (CVE-2026-41080). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-53522 |
|
Vulnerability in CVE-2024-53522 (CVE-2024-53522)
vulnerability in CVE-2024-53522 (CVE-2024-53522). Confidential information can be exposed externally.
|
| CVE-2024-20331 |
|
Vulnerability in c (CVE-2024-20331)
vulnerability in c (CVE-2024-20331). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-37822 |
|
Vulnerability in eufy (CVE-2023-37822)
vulnerability in eufy (CVE-2023-37822). Confidential information can be exposed externally.
|
| CVE-2024-6508 |
|
Vulnerability in csrf (CVE-2024-6508)
vulnerability in csrf (CVE-2024-6508). Successful exploitation can lead to full system takeover.
|
| CVE-2023-20107 |
|
Vulnerability in cisco (CVE-2023-20107)
vulnerability in cisco (CVE-2023-20107). Confidential information can be exposed externally.
|
| CVE-2014-0691 |
|
Vulnerability in cisco (CVE-2014-0691)
vulnerability in cisco (CVE-2014-0691). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-13992 |
|
Vulnerability in loytec (CVE-2017-13992)
vulnerability in loytec (CVE-2017-13992). Successful exploitation can lead to full system takeover.
|
| CVE-2015-7764 |
|
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
|
| CVE-2015-3405 |
|
Vulnerability in ntp (CVE-2015-3405)
vulnerability in ntp (CVE-2015-3405). Confidential information can be exposed externally.
|
| CVE-2017-6030 |
|
Vulnerability in schneider-electric (CVE-2017-6030)
vulnerability in schneider-electric (CVE-2017-6030). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-0897 |
|
Vulnerability in expressionengine (CVE-2017-0897)
vulnerability in expressionengine (CVE-2017-0897). Confidential information can be exposed externally.
|
| CVE-2016-2564 |
|
Vulnerability in invisioncommunity (CVE-2016-2564)
vulnerability in invisioncommunity (CVE-2016-2564). Confidential information can be exposed externally.
|