Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-24717 |
|
Path Traversal in path-traversal (CVE-2026-24717)
path traversal in path-traversal (CVE-2026-24717). Confidential information can be exposed externally.
|
| CVE-2026-22899 |
|
Vulnerability in dos (CVE-2026-22899)
vulnerability in dos (CVE-2026-22899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24716 |
|
Vulnerability in dos (CVE-2026-24716)
vulnerability in dos (CVE-2026-24716). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66281 |
|
Vulnerability in dos (CVE-2025-66281)
vulnerability in dos (CVE-2025-66281). Successful exploitation can lead to full system takeover.
|
| CVE-2025-62851 |
|
Path Traversal in path-traversal (CVE-2025-62851)
path traversal in path-traversal (CVE-2025-62851). Confidential information can be exposed externally.
|
| CVE-2025-62850 |
|
Vulnerability in dos (CVE-2025-62850)
vulnerability in dos (CVE-2025-62850). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58468 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-58468)
vulnerability in csrf (CVE-2025-58468). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45541 |
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation pat...
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the esp_http_server component. While parsing the client-supplied Sec-WebSocket-Protocol request...
|
| CVE-2026-53674 |
|
Vulnerability in dos (CVE-2026-53674)
vulnerability in dos (CVE-2026-53674). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41721 |
|
Vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41721)
vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41721). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41731 |
|
Unsafe Deserialization in org.springframework.kafka:spring-kafka (CVE-2026-41731)
vulnerability in org.springframework.kafka:spring-kafka (CVE-2026-41731). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40988 |
|
Vulnerability in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-40988)
vulnerability in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-40988). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41711 |
|
Vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41711)
vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9743 |
|
Vulnerability in mongodb (CVE-2026-9743)
vulnerability in mongodb (CVE-2026-9743). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.24` or later.
|
| CVE-2026-44963 |
|
Unsafe Deserialization in CVE-2026-44963 (CVE-2026-44963)
vulnerability in CVE-2026-44963 (CVE-2026-44963). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46518 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-46518)
cross-site scripting in csrf (CVE-2026-46518). Confidential information can be exposed externally.
|
| CVE-2026-41695 |
|
Vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41695)
vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41695). Risk of unauthorized operations or information disclosure. Exploitable via `GET /things`.
|
| CVE-2026-25860 |
|
Cross-Site Scripting (XSS) in CVE-2026-25860 (CVE-2026-25860)
cross-site scripting in CVE-2026-25860 (CVE-2026-25860). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34417 |
|
Cross-Site Scripting (XSS) in CVE-2026-34417 (CVE-2026-34417)
cross-site scripting in CVE-2026-34417 (CVE-2026-34417). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34657 |
|
Path Traversal in path-traversal (CVE-2026-34657)
path traversal in path-traversal (CVE-2026-34657). Data can be tampered with by attackers.
|
| CVE-2026-48030 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-48030)
OS command injection in pheditor/pheditor (CVE-2026-48030). Successful exploitation can lead to full system takeover. Exploitable via ``command``. Mitigation: upgrade to `2.0.4` or later.
|
| CVE-2026-47933 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-47933)
cross-site scripting in adobe (CVE-2026-47933). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47938 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-47938)
SSRF in ssrf (CVE-2026-47938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47932 |
|
Path Traversal in path-traversal (CVE-2026-47932)
path traversal in path-traversal (CVE-2026-47932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25557 |
|
Cross-Site Scripting (XSS) in CVE-2026-25557 (CVE-2026-25557)
cross-site scripting in CVE-2026-25557 (CVE-2026-25557). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34416 |
|
Cross-Site Scripting (XSS) in CVE-2026-34416 (CVE-2026-34416)
cross-site scripting in CVE-2026-34416 (CVE-2026-34416). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48306 |
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
|
| CVE-2026-48305 |
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
|
| CVE-2026-47906 |
|
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
|
| CVE-2026-47907 |
|
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control...
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control...
|
| CVE-2026-47908 |
|
Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer...
Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer...
|
| CVE-2026-47106 |
|
Cross-Site Scripting (XSS) in CVE-2026-47106 (CVE-2026-47106)
cross-site scripting in CVE-2026-47106 (CVE-2026-47106). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34709 |
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
|
| CVE-2026-34710 |
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write...
|
| CVE-2026-32856 |
|
Cross-Site Scripting (XSS) in CVE-2026-32856 (CVE-2026-32856)
cross-site scripting in CVE-2026-32856 (CVE-2026-32856). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11822 |
|
SQLite before 3.53.2 Memory Corruption in FTS5 Extension
SQLite before 3.53.2 Memory Corruption in FTS5 Extension
|
| CVE-2026-11824 |
|
SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate
|
| CVE-2026-36823 |
|
Vulnerability in dos (CVE-2026-36823)
vulnerability in dos (CVE-2026-36823). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39170 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39170)
vulnerability in csrf (CVE-2026-39170). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36815 |
|
Vulnerability in dos (CVE-2026-36815)
vulnerability in dos (CVE-2026-36815). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36816 |
|
Vulnerability in dos (CVE-2026-36816)
vulnerability in dos (CVE-2026-36816). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36817 |
|
Vulnerability in dos (CVE-2026-36817)
vulnerability in dos (CVE-2026-36817). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36818 |
|
Vulnerability in dos (CVE-2026-36818)
vulnerability in dos (CVE-2026-36818). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36819 |
|
Vulnerability in dos (CVE-2026-36819)
vulnerability in dos (CVE-2026-36819). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36820 |
|
Vulnerability in dos (CVE-2026-36820)
vulnerability in dos (CVE-2026-36820). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36821 |
|
Vulnerability in dos (CVE-2026-36821)
vulnerability in dos (CVE-2026-36821). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36822 |
|
Vulnerability in dos (CVE-2026-36822)
vulnerability in dos (CVE-2026-36822). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36803 |
|
Vulnerability in dos (CVE-2026-36803)
vulnerability in dos (CVE-2026-36803). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36805 |
|
Vulnerability in dos (CVE-2026-36805)
vulnerability in dos (CVE-2026-36805). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36806 |
|
Vulnerability in dos (CVE-2026-36806)
vulnerability in dos (CVE-2026-36806). Risk of unauthorized operations or information disclosure.
|