Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44244 |
|
Code Injection in GitPython (CVE-2026-44244)
code injection in GitPython (CVE-2026-44244). Successful exploitation can lead to full system takeover. Exploitable via ``configparser``. Mitigation: upgrade to `3.1.49` or later.
|
| CVE-2026-7841 |
|
Code Injection in CVE-2026-7841 (CVE-2026-7841)
code injection in CVE-2026-7841 (CVE-2026-7841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38431 |
|
Code Injection in frappe (CVE-2026-38431)
code injection in frappe (CVE-2026-38431). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42090 |
|
Cross-Site Scripting (XSS) in streetwriters (CVE-2026-42090)
cross-site scripting in streetwriters (CVE-2026-42090). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26332 |
|
Code Injection in vm2-project (CVE-2026-26332)
code injection in vm2-project (CVE-2026-26332). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24118 |
|
Code Injection in vm2-project (CVE-2026-24118)
code injection in vm2-project (CVE-2026-24118). Successful exploitation can lead to full system takeover. Exploitable via ``__lookupGetter__``.
|
| CVE-2026-24120 |
|
Code Injection in vm2-project (CVE-2026-24120)
code injection in vm2-project (CVE-2026-24120). Successful exploitation can lead to full system takeover. Exploitable via ``resetPromiseSpecies``.
|
| CVE-2026-24781 |
|
Code Injection in vm2-project (CVE-2026-24781)
code injection in vm2-project (CVE-2026-24781). Successful exploitation can lead to full system takeover. Exploitable via ``inspect``.
|
| CVE-2026-3120 |
|
Code Injection in CVE-2026-3120 (CVE-2026-3120)
code injection in CVE-2026-3120 (CVE-2026-3120). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6543 |
|
Code Injection in langflow (CVE-2026-6543)
code injection in langflow (CVE-2026-6543). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14576 |
|
Vulnerability in dos (CVE-2025-14576)
vulnerability in dos (CVE-2025-14576). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7296 |
|
Cross-Site Scripting (XSS) in CVE-2026-7296 (CVE-2026-7296)
cross-site scripting in CVE-2026-7296 (CVE-2026-7296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7297 |
|
Cross-Site Scripting (XSS) in CVE-2026-7297 (CVE-2026-7297)
cross-site scripting in CVE-2026-7297 (CVE-2026-7297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7295 |
|
Cross-Site Scripting (XSS) in CVE-2026-7295 (CVE-2026-7295)
cross-site scripting in CVE-2026-7295 (CVE-2026-7295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27760 |
|
Code Injection in CVE-2026-27760 (CVE-2026-27760)
code injection in CVE-2026-27760 (CVE-2026-27760). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7222 |
|
Cross-Site Scripting (XSS) in CVE-2026-7222 (CVE-2026-7222)
cross-site scripting in CVE-2026-7222 (CVE-2026-7222). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7200 |
|
Cross-Site Scripting (XSS) in CVE-2026-7200 (CVE-2026-7200)
cross-site scripting in CVE-2026-7200 (CVE-2026-7200). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6999 |
|
Cross-Site Scripting (XSS) in CVE-2026-6999 (CVE-2026-6999)
cross-site scripting in CVE-2026-6999 (CVE-2026-6999). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6951 |
|
Code Injection in simple-git (CVE-2026-6951)
code injection in simple-git (CVE-2026-6951). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.36.0` or later.
|
| CVE-2026-41246 |
|
Code Injection in github.com/projectcontour/contour (CVE-2026-41246)
code injection in github.com/projectcontour/contour (CVE-2026-41246). Confidential information can be exposed externally. Mitigation: upgrade to `1.33.4` or later.
|
| CVE-2026-40466 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-41044 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-39087 |
|
Code Injection in heckel.io/ntfy/v2 (CVE-2026-39087)
code injection in heckel.io/ntfy/v2 (CVE-2026-39087). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.22.0` or later.
|
| CVE-2026-3960 |
|
Code Injection in h2o (CVE-2026-3960)
code injection in h2o (CVE-2026-3960). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41196 |
|
Code Injection in minetest (CVE-2026-41196)
code injection in minetest (CVE-2026-41196). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41134 |
|
Code Injection in kiota (CVE-2026-41134)
code injection in kiota (CVE-2026-41134). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.31.1` or later.
|
| CVE-2026-41179 |
|
OS Command Injection in github.com/rclone/rclone (CVE-2026-41179)
OS command injection in github.com/rclone/rclone (CVE-2026-41179). Successful exploitation can lead to full system takeover. Exploitable via ``bearer_token_command``. Mitigation: upgrade to `1.73.5` or later.
|
| CVE-2026-31018 |
|
Code Injection in dolibarr (CVE-2026-31018)
code injection in dolibarr (CVE-2026-31018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39918 |
|
Code Injection in CVE-2026-39918 (CVE-2026-39918)
code injection in CVE-2026-39918 (CVE-2026-39918). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41242 |
|
Code Injection in protobufjs-project (CVE-2026-41242)
code injection in protobufjs-project (CVE-2026-41242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34197 KEV |
|
[KEV] Vulnerability in Apache activemq (CVE-2026-34197)
vulnerability in Apache activemq (CVE-2026-34197). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-40316 |
|
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflo...
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run with...
|
| CVE-2026-33414 |
|
OS Command Injection in github.com/containers/podman (CVE-2026-33414)
OS command injection in github.com/containers/podman (CVE-2026-33414). Successful exploitation can lead to full system takeover. Exploitable via ``fmt.Sprintf``. Mitigation: upgrade to `5.8.2` or later.
|
| CVE-2026-25125 |
|
Code Injection in october/rain (CVE-2026-25125)
code injection in october/rain (CVE-2026-25125). Confidential information can be exposed externally. Exploitable via ``cms.safe_mode``. Mitigation: upgrade to `3.7.14` or later.
|
| CVE-2025-61260 |
|
Code Injection in CVE-2025-61260 (CVE-2025-61260)
code injection in CVE-2025-61260 (CVE-2025-61260). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27674 |
|
Code Injection in sap (CVE-2026-27674)
code injection in sap (CVE-2026-27674). Risk of unauthorized operations or information disclosure.
|
| CVE-2009-0238 KEV |
|
[KEV] Code Injection in Microsoft office (CVE-2009-0238)
code injection in Microsoft office (CVE-2009-0238). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-70364 |
|
Code Injection in CVE-2025-70364 (CVE-2025-70364)
code injection in CVE-2025-70364 (CVE-2025-70364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5835 |
|
Cross-Site Scripting (XSS) in CVE-2026-5835 (CVE-2026-5835)
cross-site scripting in CVE-2026-5835 (CVE-2026-5835). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5836 |
|
Cross-Site Scripting (XSS) in CVE-2026-5836 (CVE-2026-5836)
cross-site scripting in CVE-2026-5836 (CVE-2026-5836). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5834 |
|
Cross-Site Scripting (XSS) in CVE-2026-5834 (CVE-2026-5834)
cross-site scripting in CVE-2026-5834 (CVE-2026-5834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5826 |
|
Cross-Site Scripting (XSS) in CVE-2026-5826 (CVE-2026-5826)
cross-site scripting in CVE-2026-5826 (CVE-2026-5826). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5825 |
|
Cross-Site Scripting (XSS) in CVE-2026-5825 (CVE-2026-5825)
cross-site scripting in CVE-2026-5825 (CVE-2026-5825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1516 |
|
Code Injection in gitlab (CVE-2026-1516)
code injection in gitlab (CVE-2026-1516). Confidential information can be exposed externally.
|
| CVE-2026-5810 |
|
Cross-Site Scripting (XSS) in CVE-2026-5810 (CVE-2026-5810)
cross-site scripting in CVE-2026-5810 (CVE-2026-5810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5806 |
|
Cross-Site Scripting (XSS) in CVE-2026-5806 (CVE-2026-5806)
cross-site scripting in CVE-2026-5806 (CVE-2026-5806). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5808 |
|
Cross-Site Scripting (XSS) in CVE-2026-5808 (CVE-2026-5808)
cross-site scripting in CVE-2026-5808 (CVE-2026-5808). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39891 |
|
Code Injection in praison (CVE-2026-39891)
code injection in praison (CVE-2026-39891). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.115` or later.
|
| CVE-2026-39881 |
|
Code Injection in vim (CVE-2026-39881)
code injection in vim (CVE-2026-39881). Data can be tampered with by attackers. Mitigation: upgrade to `9.2.0316` or later.
|
| CVE-2026-34724 |
|
Code Injection in zammad (CVE-2026-34724)
code injection in zammad (CVE-2026-34724). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.1` or later.
|