Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-24051 |
|
Vulnerability in opentelemetry (CVE-2026-24051)
vulnerability in opentelemetry (CVE-2026-24051). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22226 |
|
OS Command Injection in tp-link (CVE-2026-22226)
OS command injection in tp-link (CVE-2026-22226). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0631 |
|
OS Command Injection in tp-link (CVE-2026-0631)
OS command injection in tp-link (CVE-2026-0631). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1761 |
|
Vulnerability in CVE-2026-1761 (CVE-2026-1761)
vulnerability in CVE-2026-1761 (CVE-2026-1761). Data can be tampered with by attackers.
|
| CVE-2025-8587 |
|
SQL Injection in sqli (CVE-2025-8587)
SQL injection in sqli (CVE-2025-8587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1530 |
|
Vulnerability in CVE-2026-1530 (CVE-2026-1530)
vulnerability in CVE-2026-1530 (CVE-2026-1530). Confidential information can be exposed externally.
|
| CVE-2026-1531 |
|
Vulnerability in CVE-2026-1531 (CVE-2026-1531)
vulnerability in CVE-2026-1531 (CVE-2026-1531). Confidential information can be exposed externally.
|
| CVE-2026-23025 |
|
Vulnerability in c (CVE-2026-23025)
vulnerability in c (CVE-2026-23025). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25153 |
|
Code Injection in linuxfoundation (CVE-2026-25153)
code injection in linuxfoundation (CVE-2026-25153). Confidential information can be exposed externally. Exploitable via ``hooks``.
|
| CVE-2025-24293 |
|
Command Injection in CVE-2025-24293 (CVE-2025-24293)
command injection in CVE-2025-24293 (CVE-2025-24293). Successful exploitation can lead to full system takeover.
|
| CVE-2025-4686 |
|
SQL Injection in sqli (CVE-2025-4686)
SQL injection in sqli (CVE-2025-4686). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-4027 |
|
Vulnerability in dos (CVE-2024-4027)
vulnerability in dos (CVE-2024-4027). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-1395 |
|
Vulnerability in CVE-2025-1395 (CVE-2025-1395)
vulnerability in CVE-2025-1395 (CVE-2025-1395). Confidential information can be exposed externally.
|
| CVE-2025-69604 |
|
Vulnerability in shirt-pocket (CVE-2025-69604)
vulnerability in shirt-pocket (CVE-2025-69604). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7713 |
|
Cross-Site Scripting (XSS) in globalmedya (CVE-2025-7713)
cross-site scripting in globalmedya (CVE-2025-7713). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7714 |
|
SQL Injection in sqli (CVE-2025-7714)
SQL injection in sqli (CVE-2025-7714). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-37011 |
|
Out-of-Bounds Write in CVE-2020-37011 (CVE-2020-37011)
out-of-bounds write in CVE-2020-37011 (CVE-2020-37011). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-37015 |
|
Path Traversal in path-traversal (CVE-2020-37015)
path traversal in path-traversal (CVE-2020-37015). Confidential information can be exposed externally.
|
| CVE-2020-37004 |
|
SQL Injection in sqli (CVE-2020-37004)
SQL injection in sqli (CVE-2020-37004). Confidential information can be exposed externally.
|
| CVE-2025-7016 |
|
Vulnerability in akinsoft (CVE-2025-7016)
vulnerability in akinsoft (CVE-2025-7016). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1281 KEV |
|
[KEV] Code Injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1281)
code injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1281). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-61726 |
|
Vulnerability in stdlib (CVE-2025-61726)
vulnerability in stdlib (CVE-2025-61726). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.24.12, 1.25.6` or later.
|
| CVE-2025-61731 |
|
Vulnerability in toolchain (CVE-2025-61731)
vulnerability in toolchain (CVE-2025-61731). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.24.12, 1.25.6` or later.
|
| CVE-2025-70999 |
|
Vulnerability in dos (CVE-2025-70999)
vulnerability in dos (CVE-2025-70999). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71000 |
|
Vulnerability in dos (CVE-2025-71000)
vulnerability in dos (CVE-2025-71000). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65891 |
|
Vulnerability in dos (CVE-2025-65891)
vulnerability in dos (CVE-2025-65891). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65886 |
|
Vulnerability in dos (CVE-2025-65886)
vulnerability in dos (CVE-2025-65886). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65888 |
|
Vulnerability in dos (CVE-2025-65888)
vulnerability in dos (CVE-2025-65888). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65889 |
|
Vulnerability in dos (CVE-2025-65889)
vulnerability in dos (CVE-2025-65889). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65890 |
|
Vulnerability in dos (CVE-2025-65890)
vulnerability in dos (CVE-2025-65890). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-57283 |
|
Code Injection in browserstack (CVE-2025-57283)
code injection in browserstack (CVE-2025-57283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24842 |
|
Path Traversal in path-traversal (CVE-2026-24842)
path traversal in path-traversal (CVE-2026-24842). Confidential information can be exposed externally.
|
| CVE-2026-24779 |
|
SSRF (Server-Side Request Forgery) in vllm (CVE-2026-24779)
SSRF in vllm (CVE-2026-24779). Confidential information can be exposed externally. Exploitable via ``MediaConnector``. Mitigation: upgrade to `0.14.1` or later.
|
| CVE-2026-24747 |
|
Code Injection in linuxfoundation (CVE-2026-24747)
code injection in linuxfoundation (CVE-2026-24747). Successful exploitation can lead to full system takeover. Exploitable via ``weights_only``.
|
| CVE-2026-24881 |
|
Vulnerability in dos (CVE-2026-24881)
vulnerability in dos (CVE-2026-24881). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24882 |
|
Vulnerability in gnupg (CVE-2026-24882)
vulnerability in gnupg (CVE-2026-24882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24869 |
|
Use-After-Free in mozilla (CVE-2026-24869)
vulnerability in mozilla (CVE-2026-24869). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69419 |
|
Out-of-Bounds Write in dos (CVE-2025-69419)
out-of-bounds write in dos (CVE-2025-69419). Confidential information can be exposed externally.
|
| CVE-2025-69420 |
|
Vulnerability in dos (CVE-2025-69420)
vulnerability in dos (CVE-2025-69420). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69421 |
|
Vulnerability in dos (CVE-2025-69421)
vulnerability in dos (CVE-2025-69421). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15467 |
|
Out-of-Bounds Write in cisa (CVE-2025-15467)
out-of-bounds write in cisa (CVE-2025-15467). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21721 |
|
Authorization Flaw in privilege-escalation (CVE-2026-21721)
vulnerability in privilege-escalation (CVE-2026-21721). Confidential information can be exposed externally.
|
| CVE-2026-21720 |
|
Vulnerability in grafana (CVE-2026-21720)
vulnerability in grafana (CVE-2026-21720). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.6.9, 12.0.8, 12.1.5, 12.2.3, 12.3.1` or later.
|
| CVE-2026-24486 |
|
Path Traversal in python-multipart (CVE-2026-24486)
path traversal in python-multipart (CVE-2026-24486). Data can be tampered with by attackers. Exploitable via ``UPLOAD_DIR``. Mitigation: upgrade to `0.0.22` or later.
|
| CVE-2025-14459 |
|
Vulnerability in CVE-2025-14459 (CVE-2025-14459)
vulnerability in CVE-2025-14459 (CVE-2025-14459). Confidential information can be exposed externally.
|
| CVE-2026-23864 |
|
Vulnerability in react (CVE-2026-23864)
vulnerability in react (CVE-2026-23864). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-14634 KEV |
|
[KEV] Vulnerability in Linux kernel (CVE-2018-14634)
vulnerability in Linux kernel (CVE-2018-14634). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-52691 KEV |
|
[KEV] Unrestricted File Upload in Smartertools smartermail (CVE-2025-52691)
vulnerability in Smartertools smartermail (CVE-2025-52691). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-24061 KEV |
|
[KEV] Vulnerability in Gnu inetutils (CVE-2026-24061)
vulnerability in Gnu inetutils (CVE-2026-24061). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21509 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2026-21509)
vulnerability in Microsoft office (CVE-2026-21509). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|