Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-24779 |
|
SSRF (Server-Side Request Forgery) in vllm (CVE-2026-24779)
SSRF in vllm (CVE-2026-24779). Confidential information can be exposed externally. Exploitable via ``MediaConnector``. Mitigation: upgrade to `0.14.1` or later.
|
| CVE-2026-24881 |
|
Vulnerability in dos (CVE-2026-24881)
vulnerability in dos (CVE-2026-24881). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22795 |
|
Vulnerability in dos (CVE-2026-22795)
vulnerability in dos (CVE-2026-22795). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69419 |
|
Out-of-Bounds Write in dos (CVE-2025-69419)
out-of-bounds write in dos (CVE-2025-69419). Confidential information can be exposed externally.
|
| CVE-2025-69420 |
|
Vulnerability in dos (CVE-2025-69420)
vulnerability in dos (CVE-2025-69420). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69421 |
|
Vulnerability in dos (CVE-2025-69421)
vulnerability in dos (CVE-2025-69421). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-68160 |
|
Out-of-Bounds Write in dos (CVE-2025-68160)
out-of-bounds write in dos (CVE-2025-68160). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15467 |
|
Out-of-Bounds Write in cisa (CVE-2025-15467)
out-of-bounds write in cisa (CVE-2025-15467). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21721 |
|
Authorization Flaw in privilege-escalation (CVE-2026-21721)
vulnerability in privilege-escalation (CVE-2026-21721). Confidential information can be exposed externally.
|
| CVE-2026-24486 |
|
Path Traversal in python-multipart (CVE-2026-24486)
path traversal in python-multipart (CVE-2026-24486). Data can be tampered with by attackers. Exploitable via ``UPLOAD_DIR``. Mitigation: upgrade to `0.0.22` or later.
|
| CVE-2026-24858 KEV |
|
[KEV] Vulnerability in Fortinet multiple-products (CVE-2026-24858)
vulnerability in Fortinet multiple-products (CVE-2026-24858). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-23864 |
|
Vulnerability in react (CVE-2026-23864)
vulnerability in react (CVE-2026-23864). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-9820 |
|
Vulnerability in privilege-escalation (CVE-2025-9820)
vulnerability in privilege-escalation (CVE-2025-9820). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23760 KEV |
|
[KEV] Vulnerability in Smartertools smartermail (CVE-2026-23760)
vulnerability in Smartertools smartermail (CVE-2026-23760). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-52025 |
|
SQL Injection in sqli (CVE-2025-52025)
SQL injection in sqli (CVE-2025-52025). Confidential information can be exposed externally.
|
| CVE-2025-71177 |
|
Cross-Site Scripting (XSS) in lavalite (CVE-2025-71177)
cross-site scripting in lavalite (CVE-2025-71177). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0994 |
|
Vulnerability in protobuf (CVE-2026-0994)
vulnerability in protobuf (CVE-2026-0994). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.29.6` or later.
|
| CVE-2025-4320 |
|
Vulnerability in CVE-2025-4320 (CVE-2025-4320)
vulnerability in CVE-2025-4320 (CVE-2025-4320). Successful exploitation can lead to full system takeover.
|
| CVE-2025-2204 |
|
Cross-Site Scripting (XSS) in CVE-2025-2204 (CVE-2025-2204)
cross-site scripting in CVE-2025-2204 (CVE-2025-2204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0603 |
|
SQL Injection in sqli (CVE-2026-0603)
SQL injection in sqli (CVE-2026-0603). Confidential information can be exposed externally.
|
| CVE-2025-15059 |
|
Vulnerability in gimp (CVE-2025-15059)
vulnerability in gimp (CVE-2025-15059). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0775 |
|
Vulnerability in privilege-escalation (CVE-2026-0775)
vulnerability in privilege-escalation (CVE-2026-0775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0535 |
|
Cross-Site Scripting (XSS) in autodesk (CVE-2026-0535)
cross-site scripting in autodesk (CVE-2026-0535). Confidential information can be exposed externally.
|
| CVE-2026-0534 |
|
Cross-Site Scripting (XSS) in autodesk (CVE-2026-0534)
cross-site scripting in autodesk (CVE-2026-0534). Confidential information can be exposed externally.
|
| CVE-2026-0533 |
|
Cross-Site Scripting (XSS) in autodesk (CVE-2026-0533)
cross-site scripting in autodesk (CVE-2026-0533). Confidential information can be exposed externally.
|
| CVE-2025-68900 |
|
Cross-Site Scripting (XSS) in CVE-2025-68900 (CVE-2025-68900)
cross-site scripting in CVE-2025-68900 (CVE-2025-68900). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56589 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-56589)
SSRF in ssrf (CVE-2025-56589). Confidential information can be exposed externally.
|
| CVE-2023-7335 |
|
Path Traversal in path-traversal (CVE-2023-7335)
path traversal in path-traversal (CVE-2023-7335). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69612 |
|
Path Traversal in path-traversal (CVE-2025-69612)
path traversal in path-traversal (CVE-2025-69612). Confidential information can be exposed externally.
|
| CVE-2025-4764 |
|
SQL Injection in sqli (CVE-2025-4764)
SQL injection in sqli (CVE-2025-4764). Successful exploitation can lead to full system takeover.
|
| CVE-2025-4763 |
|
Cross-Site Scripting (XSS) in aida (CVE-2025-4763)
cross-site scripting in aida (CVE-2025-4763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24049 |
|
Path Traversal in wheel (CVE-2026-24049)
path traversal in wheel (CVE-2026-24049). Data can be tampered with by attackers. Mitigation: upgrade to `0.46.2` or later.
|
| CVE-2025-71176 |
|
Vulnerability in pytest (CVE-2025-71176)
vulnerability in pytest (CVE-2025-71176). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.3` or later.
|
| CVE-2026-24046 |
|
Path Traversal in path-traversal (CVE-2026-24046)
path traversal in path-traversal (CVE-2026-24046). Confidential information can be exposed externally.
|
| CVE-2026-23960 |
|
Cross-Site Scripting (XSS) in argo-workflows (CVE-2026-23960)
cross-site scripting in argo-workflows (CVE-2026-23960). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.17, 3.7.8` or later.
|
| CVE-2021-47870 |
|
Cross-Site Scripting (XSS) in get-simple (CVE-2021-47870)
cross-site scripting in get-simple (CVE-2021-47870). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47817 |
|
Cross-Site Scripting (XSS) in open-emr (CVE-2021-47817)
cross-site scripting in open-emr (CVE-2021-47817). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23956 |
|
Vulnerability in seroval (CVE-2026-23956)
vulnerability in seroval (CVE-2026-23956). Risk of unauthorized operations or information disclosure. Exploitable via ``Seroval``. Mitigation: upgrade to `1.4.1` or later.
|
| CVE-2025-59465 |
|
Vulnerability in node (CVE-2025-59465)
vulnerability in node (CVE-2025-59465). Risk of unauthorized operations or information disclosure. Exploitable via ``HPACK``. Mitigation: upgrade to `20.20.0, 22.22.0, 24.13.0, 25.3.0` or later.
|
| CVE-2025-56005 |
|
Unsafe Deserialization in dabeaz (CVE-2025-56005)
vulnerability in dabeaz (CVE-2025-56005). Successful exploitation can lead to full system takeover. Exploitable via ``picklefile``.
|
| CVE-2026-22219 |
|
SSRF (Server-Side Request Forgery) in chainlit (CVE-2026-22219)
SSRF in chainlit (CVE-2026-22219). Confidential information can be exposed externally. Mitigation: upgrade to `2.9.4` or later.
|
| CVE-2026-23883 |
|
Use-After-Free in dos (CVE-2026-23883)
vulnerability in dos (CVE-2026-23883). Successful exploitation can lead to full system takeover. Exploitable via ``xf_Pointer_New``.
|
| CVE-2026-23884 |
|
Use-After-Free in dos (CVE-2026-23884)
vulnerability in dos (CVE-2026-23884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23533 |
|
Vulnerability in dos (CVE-2026-23533)
vulnerability in dos (CVE-2026-23533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23534 |
|
Vulnerability in dos (CVE-2026-23534)
vulnerability in dos (CVE-2026-23534). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23532 |
|
Vulnerability in dos (CVE-2026-23532)
vulnerability in dos (CVE-2026-23532). Successful exploitation can lead to full system takeover. Exploitable via ``gdi_SurfaceToSurface``.
|
| CVE-2026-23530 |
|
Vulnerability in dos (CVE-2026-23530)
vulnerability in dos (CVE-2026-23530). Successful exploitation can lead to full system takeover. Exploitable via ``freerdp_bitmap_decompress_planar``.
|
| CVE-2026-23531 |
|
Vulnerability in dos (CVE-2026-23531)
vulnerability in dos (CVE-2026-23531). Successful exploitation can lead to full system takeover. Exploitable via ``glyphData``.
|
| CVE-2025-68616 |
|
Open Redirect in weasyprint (CVE-2025-68616)
vulnerability in weasyprint (CVE-2025-68616). Confidential information can be exposed externally. Exploitable via ``default_url_fetcher``. Mitigation: upgrade to `68.0` or later.
|
| CVE-2026-21618 |
|
Cross-Site Scripting (XSS) in hex (CVE-2026-21618)
cross-site scripting in hex (CVE-2026-21618). Risk of unauthorized operations or information disclosure.
|