Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-3502 KEV |
|
[KEV] Vulnerability in Trueconf client (CVE-2026-3502)
vulnerability in Trueconf client (CVE-2026-3502). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-3987 |
|
Path Traversal in path-traversal (CVE-2026-3987)
path traversal in path-traversal (CVE-2026-3987). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34545 |
|
Vulnerability in openexr (CVE-2026-34545)
vulnerability in openexr (CVE-2026-34545). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34072 |
|
Authentication Bypass in fccview (CVE-2026-34072)
authentication bypass in fccview (CVE-2026-34072). Confidential information can be exposed externally.
|
| CVE-2026-27489 |
|
Vulnerability in onnx (CVE-2026-27489)
vulnerability in onnx (CVE-2026-27489). Confidential information can be exposed externally. Exploitable via ``model.data``. Mitigation: upgrade to `1.21.0` or later.
|
| CVE-2026-20090 |
|
Cross-Site Scripting (XSS) in cisco (CVE-2026-20090)
cross-site scripting in cisco (CVE-2026-20090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20088 |
|
Cross-Site Scripting (XSS) in cisco (CVE-2026-20088)
cross-site scripting in cisco (CVE-2026-20088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20089 |
|
Cross-Site Scripting (XSS) in cisco (CVE-2026-20089)
cross-site scripting in cisco (CVE-2026-20089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20087 |
|
Cross-Site Scripting (XSS) in cisco (CVE-2026-20087)
cross-site scripting in cisco (CVE-2026-20087). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30526 |
|
Cross-Site Scripting (XSS) in pushpam02 (CVE-2026-30526)
cross-site scripting in pushpam02 (CVE-2026-30526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29598 |
|
Cross-Site Scripting (XSS) in CVE-2026-29598 (CVE-2026-29598)
cross-site scripting in CVE-2026-29598 (CVE-2026-29598). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35091 |
|
Vulnerability in dos (CVE-2026-35091)
vulnerability in dos (CVE-2026-35091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35092 |
|
Vulnerability in dos (CVE-2026-35092)
vulnerability in dos (CVE-2026-35092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5281 KEV |
|
[KEV] Use-After-Free in Google dawn (CVE-2026-5281)
vulnerability in Google dawn (CVE-2026-5281). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-41363 |
|
Path Traversal in openclaw (CVE-2026-41363)
path traversal in openclaw (CVE-2026-41363). Confidential information can be exposed externally. Mitigation: upgrade to `>= 2026.3.28` or later.
|
| CVE-2026-34449 |
|
Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449). Successful exploitation can lead to full system takeover. Exploitable via ``Origin``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34448 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448). Successful exploitation can lead to full system takeover. Exploitable via ``mAsse``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34400 |
|
SQL Injection in alerta-server (CVE-2026-34400)
SQL injection in alerta-server (CVE-2026-34400). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.1.0` or later.
|
| CVE-2026-34404 |
|
Vulnerability in vue (CVE-2026-34404)
vulnerability in vue (CVE-2026-34404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3469 |
|
Vulnerability in dos (CVE-2026-3469)
vulnerability in dos (CVE-2026-3469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3468 |
|
Cross-Site Scripting (XSS) in sonicwall (CVE-2026-3468)
cross-site scripting in sonicwall (CVE-2026-3468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34740 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34740)
SSRF in ssrf (CVE-2026-34740). Confidential information can be exposed externally.
|
| CVE-2026-34716 |
|
Cross-Site Scripting (XSS) in wwbn (CVE-2026-34716)
cross-site scripting in wwbn (CVE-2026-34716). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34611 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34611)
vulnerability in csrf (CVE-2026-34611). Data can be tampered with by attackers.
|
| CVE-2026-34613 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34613)
vulnerability in csrf (CVE-2026-34613). Data can be tampered with by attackers.
|
| CVE-2026-34382 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34382)
vulnerability in csrf (CVE-2026-34382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34383 |
|
Vulnerability in csrf (CVE-2026-34383)
vulnerability in csrf (CVE-2026-34383). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34384 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34384)
vulnerability in csrf (CVE-2026-34384). Data can be tampered with by attackers.
|
| CVE-2026-34394 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34394)
vulnerability in csrf (CVE-2026-34394). Confidential information can be exposed externally.
|
| CVE-2026-34396 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-34396)
cross-site scripting in csrf (CVE-2026-34396). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34366 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34366)
SSRF in ssrf (CVE-2026-34366). Confidential information can be exposed externally.
|
| CVE-2026-34367 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34367)
SSRF in ssrf (CVE-2026-34367). Confidential information can be exposed externally.
|
| CVE-2026-34365 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34365)
SSRF in ssrf (CVE-2026-34365). Confidential information can be exposed externally.
|
| CVE-2026-34206 |
|
Cross-Site Scripting (XSS) in libops (CVE-2026-34206)
cross-site scripting in libops (CVE-2026-34206). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5209 |
|
Cross-Site Scripting (XSS) in CVE-2026-5209 (CVE-2026-5209)
cross-site scripting in CVE-2026-5209 (CVE-2026-5209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3356 |
|
Vulnerability in CVE-2026-3356 (CVE-2026-3356)
vulnerability in CVE-2026-3356 (CVE-2026-3356). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5206 |
|
Vulnerability in sqli (CVE-2026-5206)
vulnerability in sqli (CVE-2026-5206). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32725 |
|
Vulnerability in c (CVE-2026-32725)
vulnerability in c (CVE-2026-32725). Confidential information can be exposed externally.
|
| CVE-2026-32273 |
|
Cross-Site Scripting (XSS) in discourse (CVE-2026-32273)
cross-site scripting in discourse (CVE-2026-32273). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30520 |
|
SQL Injection in sqli (CVE-2026-30520)
SQL injection in sqli (CVE-2026-30520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2123 |
|
Vulnerability in privilege-escalation (CVE-2026-2123)
vulnerability in privilege-escalation (CVE-2026-2123). Successful exploitation can lead to full system takeover.
|
| CVE-2025-62184 |
|
Cross-Site Scripting (XSS) in pega (CVE-2025-62184)
cross-site scripting in pega (CVE-2025-62184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24165 |
|
Unsafe Deserialization in dos (CVE-2026-24165)
vulnerability in dos (CVE-2026-24165). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24154 |
|
OS Command Injection in dos (CVE-2026-24154)
OS command injection in dos (CVE-2026-24154). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24164 |
|
Unsafe Deserialization in dos (CVE-2026-24164)
vulnerability in dos (CVE-2026-24164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24148 |
|
Vulnerability in dos (CVE-2026-24148)
vulnerability in dos (CVE-2026-24148). Confidential information can be exposed externally.
|
| CVE-2026-5203 |
|
Path Traversal in path-traversal (CVE-2026-5203)
path traversal in path-traversal (CVE-2026-5203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34220 |
|
SQL Injection in sqli (CVE-2026-34220)
SQL injection in sqli (CVE-2026-34220). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34231 |
|
Cross-Site Scripting (XSS) in slippers (CVE-2026-34231)
cross-site scripting in slippers (CVE-2026-34231). Risk of unauthorized operations or information disclosure. Exploitable via ``slippers``. Mitigation: upgrade to `0.6.3` or later.
|
| CVE-2026-22561 |
|
Vulnerability in privilege-escalation (CVE-2026-22561)
vulnerability in privilege-escalation (CVE-2026-22561). Successful exploitation can lead to full system takeover.
|