Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2023-49105 KEV |
|
[KEV] Authentication Bypass in owncloud (CVE-2023-49105)
authentication bypass in owncloud (CVE-2023-49105). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-23758 KEV |
|
Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
|
| CVE-2015-5287 KEV |
|
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
|
| CVE-2015-3246 KEV |
|
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the...
|
| CVE-2022-0995 KEV |
|
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event...
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event...
|
| CVE-2026-60004 KEV |
|
[KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21962 KEV |
|
[KEV] Vulnerability in Oracle c (CVE-2026-21962)
vulnerability in Oracle c (CVE-2026-21962). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-69836 KEV |
|
[KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-69836)
vulnerability in Microsoft deserialization (CVE-2026-69836). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-72530 KEV |
|
[KEV] Code Injection in trueconf (CVE-2026-72530)
code injection in trueconf (CVE-2026-72530). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-72529 KEV |
|
[KEV] Vulnerability in trueconf (CVE-2026-72529)
vulnerability in trueconf (CVE-2026-72529). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-62593 KEV |
|
[KEV] Cross-Site Request Forgery (CSRF) in Ray-project ray (CVE-2025-62593)
vulnerability in Ray-project ray (CVE-2025-62593). Successful exploitation can lead to full system takeover. Exploitable via ``fetch``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2.52.0` or later.
|
| CVE-2026-64849 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-73570 KEV |
|
[KEV] OS Command Injection in Synacor zimbra-collaboration-suite (CVE-2026-73570)
OS command injection in Synacor zimbra-collaboration-suite (CVE-2026-73570). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-66384 KEV |
|
[KEV] Path Traversal in Jfrog artifactory (CVE-2026-66384)
path traversal in Jfrog artifactory (CVE-2026-66384). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2026-68820 KEV |
|
[KEV] Use-After-Free in Microsoft windows-10-1607 (CVE-2026-68820)
vulnerability in Microsoft windows-10-1607 (CVE-2026-68820). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-72898 KEV |
|
[KEV] SQL Injection in metabase (CVE-2026-72898)
SQL injection in metabase (CVE-2026-72898). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-65400 KEV |
|
[KEV] Authentication Bypass in Apple macos (CVE-2026-65400)
authentication bypass in Apple macos (CVE-2026-65400). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-18577 KEV |
|
[KEV] Vulnerability in N-able n-central (CVE-2026-18577)
vulnerability in N-able n-central (CVE-2026-18577). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-18556 KEV |
|
[KEV] Vulnerability in N-able n-central (CVE-2026-18556)
vulnerability in N-able n-central (CVE-2026-18556). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-59310 KEV |
|
[KEV] Path Traversal in Broadcom path-traversal (CVE-2026-59310)
path traversal in Broadcom path-traversal (CVE-2026-59310). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20316 KEV |
|
[KEV] Vulnerability in Cisco secure-firewall-management-center (CVE-2026-20316)
vulnerability in Cisco secure-firewall-management-center (CVE-2026-20316). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-63077 KEV |
|
[KEV] Unsafe Deserialization in Jetbrains teamcity (CVE-2026-63077)
vulnerability in Jetbrains teamcity (CVE-2026-63077). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-16812 KEV |
|
[KEV] OS Command Injection in Arista velocloud-orchestrator (CVE-2026-16812)
OS command injection in Arista velocloud-orchestrator (CVE-2026-16812). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-68686 KEV |
|
[KEV] Information Disclosure in Fortinet fortios (CVE-2025-68686)
vulnerability in Fortinet fortios (CVE-2025-68686). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-16232 KEV |
|
[KEV] Authentication Bypass in Check point checkpoint (CVE-2026-16232)
authentication bypass in Check point checkpoint (CVE-2026-16232). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-0770 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-0770)
vulnerability in langflow (CVE-2026-0770). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-63030 KEV |
|
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
|
| CVE-2026-60137 KEV |
|
[KEV] SQL Injection in Wordpress sqli (CVE-2026-60137)
SQL injection in Wordpress sqli (CVE-2026-60137). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-9198 KEV |
|
[KEV] Code Injection in Ibm langflow (CVE-2026-9198)
code injection in Ibm langflow (CVE-2026-9198). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-27137 KEV |
|
[KEV] Vulnerability in Dd-wrt c (CVE-2021-27137)
vulnerability in Dd-wrt c (CVE-2021-27137). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-39808 KEV |
|
[KEV] OS Command Injection in Fortinet fortisandbox (CVE-2026-39808)
OS command injection in Fortinet fortisandbox (CVE-2026-39808). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-55040 KEV |
|
[KEV] Vulnerability in Microsoft sharepoint-server (CVE-2026-55040)
vulnerability in Microsoft sharepoint-server (CVE-2026-55040). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-58644 KEV |
|
[KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-58644)
vulnerability in Microsoft deserialization (CVE-2026-58644). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-56155 KEV |
|
[KEV] Vulnerability in Microsoft windows-10-1607 (CVE-2026-56155)
vulnerability in Microsoft windows-10-1607 (CVE-2026-56155). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-56164 KEV |
|
[KEV] Vulnerability in Microsoft sharepoint-server (CVE-2026-56164)
vulnerability in Microsoft sharepoint-server (CVE-2026-56164). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-50522 KEV |
|
[KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-50522)
vulnerability in Microsoft deserialization (CVE-2026-50522). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-15409 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Sonicwall ssrf (CVE-2026-15409)
SSRF in Sonicwall ssrf (CVE-2026-15409). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-15410 KEV |
|
[KEV] Code Injection in Sonicwall sma6210-firmware (CVE-2026-15410)
code injection in Sonicwall sma6210-firmware (CVE-2026-15410). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-56291 KEV |
|
[KEV] Unrestricted File Upload in Balbooa forms (CVE-2026-56291)
vulnerability in Balbooa forms (CVE-2026-56291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-53362 KEV |
|
[KEV] Out-of-Bounds Write in linux (CVE-2026-53362)
out-of-bounds write in linux (CVE-2026-53362). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-48282 KEV |
|
[KEV] Path Traversal in Adobe path-traversal (CVE-2026-48282)
path traversal in Adobe path-traversal (CVE-2026-48282). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-8452 KEV |
|
[KEV] Buffer Overflow in Citrix dos (CVE-2026-8452)
vulnerability in Citrix dos (CVE-2026-8452). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-56290 KEV |
|
[KEV] Unrestricted File Upload in Joomlack page-builder-ck (CVE-2026-56290)
vulnerability in Joomlack page-builder-ck (CVE-2026-56290). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-67038 KEV |
|
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell...
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell...
|
| CVE-2026-48939 KEV |
|
[KEV] Unrestricted File Upload in Icagenda joomlic (CVE-2026-48939)
vulnerability in Icagenda joomlic (CVE-2026-48939). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-48908 KEV |
|
[KEV] Unrestricted File Upload in Joomshaper ollyo (CVE-2026-48908)
vulnerability in Joomshaper ollyo (CVE-2026-48908). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-12569 KEV |
|
[KEV] Vulnerability in Ptc deserialization (CVE-2026-12569)
vulnerability in Ptc deserialization (CVE-2026-12569). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20262 KEV |
|
[KEV] Path Traversal in Cisco catalyst-sd-wan-manager (CVE-2026-20262)
path traversal in Cisco catalyst-sd-wan-manager (CVE-2026-20262). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2026-48558 KEV |
|
[KEV] Vulnerability in Simplehelp simple-help (CVE-2026-48558)
vulnerability in Simplehelp simple-help (CVE-2026-48558). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-35273 KEV |
|
[KEV] Vulnerability in Oracle c (CVE-2026-35273)
vulnerability in Oracle c (CVE-2026-35273). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|