Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-47839 |
|
Cross-Site Scripting (XSS) in CVE-2021-47839 (CVE-2021-47839)
cross-site scripting in CVE-2021-47839 (CVE-2021-47839). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47836 |
|
Cross-Site Scripting (XSS) in CVE-2021-47836 (CVE-2021-47836)
cross-site scripting in CVE-2021-47836 (CVE-2021-47836). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47814 |
|
Vulnerability in dos (CVE-2021-47814)
vulnerability in dos (CVE-2021-47814). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22774 |
|
Vulnerability in dos (CVE-2026-22774)
vulnerability in dos (CVE-2026-22774). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.6.2` or later.
|
| CVE-2026-22775 |
|
Vulnerability in dos (CVE-2026-22775)
vulnerability in dos (CVE-2026-22775). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.6.2` or later.
|
| CVE-2025-67246 |
|
Privilege Escalation in privilege-escalation (CVE-2025-67246)
vulnerability in privilege-escalation (CVE-2025-67246). Confidential information can be exposed externally.
|
| CVE-2026-0990 |
|
Vulnerability in dos (CVE-2026-0990)
vulnerability in dos (CVE-2026-0990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0897 |
|
Vulnerability in keras (CVE-2026-0897)
vulnerability in keras (CVE-2026-0897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.1` or later.
|
| CVE-2025-71164 |
|
Cross-Site Scripting (XSS) in typesettercms (CVE-2025-71164)
cross-site scripting in typesettercms (CVE-2025-71164). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71165 |
|
Cross-Site Scripting (XSS) in typesettercms (CVE-2025-71165)
cross-site scripting in typesettercms (CVE-2025-71165). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71166 |
|
Cross-Site Scripting (XSS) in typesettercms (CVE-2025-71166)
cross-site scripting in typesettercms (CVE-2025-71166). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22211 |
|
Out-of-Bounds Write in dos (CVE-2026-22211)
out-of-bounds write in dos (CVE-2026-22211). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14242 |
|
Vulnerability in dos (CVE-2025-14242)
vulnerability in dos (CVE-2025-14242). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20834 |
|
Vulnerability in path-traversal (CVE-2026-20834)
vulnerability in path-traversal (CVE-2026-20834). Confidential information can be exposed externally.
|
| CVE-2025-13444 |
|
OS Command Injection in progress (CVE-2025-13444)
OS command injection in progress (CVE-2025-13444). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15514 |
|
Vulnerability in dos (CVE-2025-15514)
vulnerability in dos (CVE-2025-15514). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-14021 |
|
Unsafe Deserialization in llama-index (CVE-2024-14021)
vulnerability in llama-index (CVE-2024-14021). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.11.7` or later.
|
| CVE-2026-22610 |
|
Cross-Site Scripting (XSS) in @angular/compiler (CVE-2026-22610)
cross-site scripting in @angular/compiler (CVE-2026-22610). Risk of unauthorized operations or information disclosure. Exploitable via ``href``.
|
| CVE-2025-59057 |
|
Cross-Site Scripting (XSS) in react (CVE-2025-59057)
cross-site scripting in react (CVE-2025-59057). Confidential information can be exposed externally.
|
| CVE-2026-21884 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-21884)
cross-site scripting in react (CVE-2026-21884). Confidential information can be exposed externally.
|
| CVE-2025-9222 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2025-9222)
cross-site scripting in gitlab (CVE-2025-9222). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
|
| CVE-2025-65518 |
|
Vulnerability in dos (CVE-2025-65518)
vulnerability in dos (CVE-2025-65518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21639 |
|
Vulnerability in ui (CVE-2026-21639)
vulnerability in ui (CVE-2026-21639). Successful exploitation can lead to full system takeover.
|
| CVE-2025-50334 |
|
Vulnerability in dos (CVE-2025-50334)
vulnerability in dos (CVE-2025-50334). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69262 |
|
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings....
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code E...
|
| CVE-2025-69264 |
|
Vulnerability in pnpm (CVE-2025-69264)
vulnerability in pnpm (CVE-2025-69264). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69263 |
|
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve differe...
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package w...
|
| CVE-2026-22188 |
|
Vulnerability in dos (CVE-2026-22188)
vulnerability in dos (CVE-2026-22188). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0650 |
|
Vulnerability in CVE-2026-0650 (CVE-2026-0650)
vulnerability in CVE-2026-0650 (CVE-2026-0650). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-60534 |
|
Authentication Bypass in blueaccesstech (CVE-2025-60534)
authentication bypass in blueaccesstech (CVE-2025-60534). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0625 |
|
Vulnerability in CVE-2026-0625 (CVE-2026-0625)
vulnerability in CVE-2026-0625 (CVE-2026-0625). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69223 |
|
Vulnerability in aiohttp (CVE-2025-69223)
vulnerability in aiohttp (CVE-2025-69223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.3` or later.
|
| CVE-2025-68428 |
|
Vulnerability in path-traversal (CVE-2025-68428)
vulnerability in path-traversal (CVE-2025-68428). Confidential information can be exposed externally. Exploitable via ``addImage``.
|
| CVE-2026-0621 |
|
Vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621)
vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621). Risk of unauthorized operations or information disclosure. Exploitable via ``UriTemplate``. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2025-15115 |
|
Vulnerability in petlibro (CVE-2025-15115)
vulnerability in petlibro (CVE-2025-15115). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-63396 |
|
Vulnerability in pytorch (CVE-2025-63396)
vulnerability in pytorch (CVE-2025-63396). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.1, 2.8.0` or later.
|
| CVE-2025-67269 |
|
Vulnerability in c (CVE-2025-67269)
vulnerability in c (CVE-2025-67269). Risk of unauthorized operations or information disclosure. Exploitable via ``ffa1d6f40bca0b035fc7f5e563160ebb67199da7``.
|
| CVE-2025-67268 |
|
Vulnerability in c (CVE-2025-67268)
vulnerability in c (CVE-2025-67268). Successful exploitation can lead to full system takeover.
|
| CVE-2025-67158 |
|
Authentication Bypass in revotech (CVE-2025-67158)
authentication bypass in revotech (CVE-2025-67158). Confidential information can be exposed externally.
|
| CVE-2025-67160 |
|
Path Traversal in path-traversal (CVE-2025-67160)
path traversal in path-traversal (CVE-2025-67160). Confidential information can be exposed externally.
|
| CVE-2025-59381 |
|
Path Traversal in path-traversal (CVE-2025-59381)
path traversal in path-traversal (CVE-2025-59381). Confidential information can be exposed externally.
|
| CVE-2025-15437 |
|
Cross-Site Scripting (XSS) in ligerosmart (CVE-2025-15437)
cross-site scripting in ligerosmart (CVE-2025-15437). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-11157 |
|
Unsafe Deserialization in feast (CVE-2025-11157)
vulnerability in feast (CVE-2025-11157). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.54.0` or later.
|
| CVE-2023-7332 |
|
Vulnerability in dos (CVE-2023-7332)
vulnerability in dos (CVE-2023-7332). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-34468 |
|
Vulnerability in libcoap (CVE-2025-34468)
vulnerability in libcoap (CVE-2025-34468). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66824 |
|
Cross-Site Scripting (XSS) in trueconf (CVE-2025-66824)
cross-site scripting in trueconf (CVE-2025-66824). Confidential information can be exposed externally.
|
| CVE-2025-66737 |
|
Vulnerability in path-traversal (CVE-2025-66737)
vulnerability in path-traversal (CVE-2025-66737). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-2307 |
|
Cross-Site Scripting (XSS) in CVE-2025-2307 (CVE-2025-2307)
cross-site scripting in CVE-2025-2307 (CVE-2025-2307). Data can be tampered with by attackers.
|
| CVE-2025-2405 |
|
Cross-Site Scripting (XSS) in CVE-2025-2405 (CVE-2025-2405)
cross-site scripting in CVE-2025-2405 (CVE-2025-2405). Data can be tampered with by attackers.
|
| CVE-2025-2406 |
|
Cross-Site Scripting (XSS) in CVE-2025-2406 (CVE-2025-2406)
cross-site scripting in CVE-2025-2406 (CVE-2025-2406). Data can be tampered with by attackers.
|