Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-34840 |
|
Vulnerability in hackerbay (CVE-2026-34840)
vulnerability in hackerbay (CVE-2026-34840). Confidential information can be exposed externally.
|
| CVE-2024-14034 |
|
Authentication Bypass in CVE-2024-14034 (CVE-2024-14034)
authentication bypass in CVE-2024-14034 (CVE-2024-14034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34121 |
|
Authentication Bypass in tp-link (CVE-2026-34121)
authentication bypass in tp-link (CVE-2026-34121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34072 |
|
Authentication Bypass in fccview (CVE-2026-34072)
authentication bypass in fccview (CVE-2026-34072). Confidential information can be exposed externally.
|
| CVE-2026-3356 |
|
Vulnerability in CVE-2026-3356 (CVE-2026-3356)
vulnerability in CVE-2026-3356 (CVE-2026-3356). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71257 |
|
Vulnerability in bmc (CVE-2025-71257)
vulnerability in bmc (CVE-2025-71257). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14716 |
|
Authentication Bypass in CVE-2025-14716 (CVE-2025-14716)
authentication bypass in CVE-2025-14716 (CVE-2025-14716). Confidential information can be exposed externally.
|
| CVE-2026-32841 |
|
Vulnerability in edimax (CVE-2026-32841)
vulnerability in edimax (CVE-2026-32841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29515 |
|
Vulnerability in xiaomi (CVE-2026-29515)
vulnerability in xiaomi (CVE-2026-29515). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29000 |
|
Vulnerability in CVE-2026-29000 (CVE-2026-29000)
vulnerability in CVE-2026-29000 (CVE-2026-29000). Confidential information can be exposed externally.
|
| CVE-2026-23600 |
|
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
|
| CVE-2026-26227 |
|
Vulnerability in CVE-2026-26227 (CVE-2026-26227)
vulnerability in CVE-2026-26227 (CVE-2026-26227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2624 |
|
Vulnerability in epati (CVE-2026-2624)
vulnerability in epati (CVE-2026-2624). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2635 |
|
Vulnerability in mlflow (CVE-2026-2635)
vulnerability in mlflow (CVE-2026-2635). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.8.0rc0` or later.
|
| CVE-2025-8350 |
|
Vulnerability in CVE-2025-8350 (CVE-2025-8350)
vulnerability in CVE-2025-8350 (CVE-2025-8350). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1618 |
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc....
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc....
|
| CVE-2025-6967 |
|
Vulnerability in CVE-2025-6967 (CVE-2025-6967)
vulnerability in CVE-2025-6967 (CVE-2025-6967). Confidential information can be exposed externally.
|
| CVE-2026-23903 |
|
Vulnerability in spring (CVE-2026-23903)
vulnerability in spring (CVE-2026-23903). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1709 |
|
Vulnerability in keylime (CVE-2026-1709)
vulnerability in keylime (CVE-2026-1709). Data can be tampered with by attackers. Mitigation: upgrade to `7.12.0` or later.
|
| CVE-2020-37002 |
|
OS Command Injection in CVE-2020-37002 (CVE-2020-37002)
OS command injection in CVE-2020-37002 (CVE-2020-37002). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24858 KEV |
|
[KEV] Vulnerability in Fortinet multiple-products (CVE-2026-24858)
vulnerability in Fortinet multiple-products (CVE-2026-24858). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-23760 KEV |
|
[KEV] Vulnerability in Smartertools smartermail (CVE-2026-23760)
vulnerability in Smartertools smartermail (CVE-2026-23760). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-4320 |
|
Vulnerability in CVE-2025-4320 (CVE-2025-4320)
vulnerability in CVE-2025-4320 (CVE-2025-4320). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0650 |
|
Vulnerability in CVE-2026-0650 (CVE-2026-0650)
vulnerability in CVE-2026-0650 (CVE-2026-0650). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-60534 |
|
Authentication Bypass in blueaccesstech (CVE-2025-60534)
authentication bypass in blueaccesstech (CVE-2025-60534). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0625 |
|
Vulnerability in CVE-2026-0625 (CVE-2026-0625)
vulnerability in CVE-2026-0625 (CVE-2026-0625). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15115 |
|
Vulnerability in petlibro (CVE-2025-15115)
vulnerability in petlibro (CVE-2025-15115). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67158 |
|
Authentication Bypass in revotech (CVE-2025-67158)
authentication bypass in revotech (CVE-2025-67158). Confidential information can be exposed externally.
|
| CVE-2025-64055 |
|
Authentication Bypass in fanvil (CVE-2025-64055)
authentication bypass in fanvil (CVE-2025-64055). Successful exploitation can lead to full system takeover.
|
| CVE-2025-8855 |
|
Vulnerability in CVE-2025-8855 (CVE-2025-8855)
vulnerability in CVE-2025-8855 (CVE-2025-8855). Confidential information can be exposed externally.
|
| CVE-2025-56385 |
|
SQL Injection in sqli (CVE-2025-56385)
SQL injection in sqli (CVE-2025-56385). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10161 |
|
Vulnerability in CVE-2025-10161 (CVE-2025-10161)
vulnerability in CVE-2025-10161 (CVE-2025-10161). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56447 |
|
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
|
| CVE-2025-48044 |
|
Authorization Flaw in ash (CVE-2025-48044)
vulnerability in ash (CVE-2025-48044). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.1` or later.
|
| CVE-2025-59249 |
|
Vulnerability in microsoft (CVE-2025-59249)
vulnerability in microsoft (CVE-2025-59249). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59248 |
|
Vulnerability in microsoft (CVE-2025-59248)
vulnerability in microsoft (CVE-2025-59248). Confidential information can be exposed externally.
|
| CVE-2025-48043 |
|
Authorization Flaw in ash (CVE-2025-48043)
vulnerability in ash (CVE-2025-48043). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2025-8886 |
|
Information Disclosure in CVE-2025-8886 (CVE-2025-8886)
vulnerability in CVE-2025-8886 (CVE-2025-8886). Confidential information can be exposed externally.
|
| CVE-2025-22862 |
|
Vulnerability in fortinet (CVE-2025-22862)
vulnerability in fortinet (CVE-2025-22862). Successful exploitation can lead to full system takeover.
|
| CVE-2025-0642 |
|
Vulnerability in CVE-2025-0642 (CVE-2025-0642)
vulnerability in CVE-2025-0642 (CVE-2025-0642). Confidential information can be exposed externally.
|
| CVE-2025-2417 |
|
Vulnerability in CVE-2025-2417 (CVE-2025-2417)
vulnerability in CVE-2025-2417 (CVE-2025-2417). Confidential information can be exposed externally.
|
| CVE-2025-2411 |
|
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano...
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano...
|
| CVE-2025-2416 |
|
Vulnerability in CVE-2025-2416 (CVE-2025-2416)
vulnerability in CVE-2025-2416 (CVE-2025-2416). Confidential information can be exposed externally.
|
| CVE-2025-1740 |
|
Vulnerability in CVE-2025-1740 (CVE-2025-1740)
vulnerability in CVE-2025-1740 (CVE-2025-1740). Successful exploitation can lead to full system takeover.
|
| CVE-2025-2413 |
|
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor...
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor...
|
| CVE-2025-2412 |
|
Vulnerability in CVE-2025-2412 (CVE-2025-2412)
vulnerability in CVE-2025-2412 (CVE-2025-2412). Confidential information can be exposed externally.
|
| CVE-2025-34162 |
|
SQL Injection in sqli (CVE-2025-34162)
SQL injection in sqli (CVE-2025-34162). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-53786 |
|
Authentication Bypass in microsoft (CVE-2025-53786)
authentication bypass in microsoft (CVE-2025-53786). Successful exploitation can lead to full system takeover.
|
| CVE-2025-4378 |
|
Vulnerability in CVE-2025-4378 (CVE-2025-4378)
vulnerability in CVE-2025-4378 (CVE-2025-4378). Confidential information can be exposed externally.
|
| CVE-2025-4383 |
|
Vulnerability in CVE-2025-4383 (CVE-2025-4383)
vulnerability in CVE-2025-4383 (CVE-2025-4383). Risk of unauthorized operations or information disclosure.
|