Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-32829 |
|
Vulnerability in pseitz (CVE-2026-32829)
vulnerability in pseitz (CVE-2026-32829). Confidential information can be exposed externally. Exploitable via ``decompress_into``.
|
| CVE-2025-31277 KEV |
|
[KEV] Buffer Overflow in Apple multiple-products (CVE-2025-31277)
vulnerability in Apple multiple-products (CVE-2025-31277). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-32843 |
|
Cross-Site Scripting (XSS) in CVE-2026-32843 (CVE-2026-32843)
cross-site scripting in CVE-2026-32843 (CVE-2026-32843). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69720 |
|
Vulnerability in c (CVE-2025-69720)
vulnerability in c (CVE-2025-69720). Confidential information can be exposed externally.
|
| CVE-2025-71260 |
|
Unsafe Deserialization in csharp (CVE-2025-71260)
vulnerability in csharp (CVE-2025-71260). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27135 |
|
Vulnerability in c (CVE-2026-27135)
vulnerability in c (CVE-2026-27135). Risk of unauthorized operations or information disclosure. Exploitable via ``nghttp2_session_terminate_session``.
|
| CVE-2026-23265 |
|
Vulnerability in c (CVE-2026-23265)
vulnerability in c (CVE-2026-23265). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23266 |
|
Vulnerability in Kernel (CVE-2026-23266)
vulnerability in Kernel (CVE-2026-23266). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251, 5.15.201, 6.1.164, 6.6.127, 6.12.74, 6.18.13, 6.19.3` or later.
|
| CVE-2026-23244 |
|
Out-of-Bounds Read in c (CVE-2026-23244)
vulnerability in c (CVE-2026-23244). Confidential information can be exposed externally.
|
| CVE-2026-31938 |
|
Cross-Site Scripting (XSS) in parall (CVE-2026-31938)
cross-site scripting in parall (CVE-2026-31938). Confidential information can be exposed externally. Exploitable via ``options``.
|
| CVE-2026-31898 |
|
Vulnerability in parall (CVE-2026-31898)
vulnerability in parall (CVE-2026-31898). Confidential information can be exposed externally. Exploitable via ``createAnnotation``.
|
| CVE-2026-30922 |
|
Vulnerability in pyasn1 (CVE-2026-30922)
vulnerability in pyasn1 (CVE-2026-30922). Risk of unauthorized operations or information disclosure. Exploitable via ``pyasn1``. Mitigation: upgrade to `0.6.3` or later.
|
| CVE-2026-27459 |
|
Vulnerability in pyopenssl (CVE-2026-27459)
vulnerability in pyopenssl (CVE-2026-27459). Successful exploitation can lead to full system takeover. Exploitable via ``set_cookie_generate_callback``. Mitigation: upgrade to `26.0.0` or later.
|
| CVE-2026-30707 |
|
Vulnerability in csharp (CVE-2026-30707)
vulnerability in csharp (CVE-2026-30707). Confidential information can be exposed externally.
|
| CVE-2025-50881 |
|
Code Injection in CVE-2025-50881 (CVE-2025-50881)
code injection in CVE-2025-50881 (CVE-2025-50881). Successful exploitation can lead to full system takeover. Exploitable via ``action``.
|
| CVE-2026-29516 |
|
Vulnerability in buffaloamericas (CVE-2026-29516)
vulnerability in buffaloamericas (CVE-2026-29516). Confidential information can be exposed externally.
|
| CVE-2026-3644 |
|
Vulnerability in CVE-2026-3644 (CVE-2026-3644)
vulnerability in CVE-2026-3644 (CVE-2026-3644). Data can be tampered with by attackers.
|
| CVE-2026-27962 |
|
Vulnerability in authlib (CVE-2026-27962)
vulnerability in authlib (CVE-2026-27962). Confidential information can be exposed externally. Exploitable via ``authlib``. Mitigation: upgrade to `1.6.9` or later.
|
| CVE-2026-28498 |
|
Vulnerability in authlib (CVE-2026-28498)
vulnerability in authlib (CVE-2026-28498). Data can be tampered with by attackers. Exploitable via ``_verify_hash``. Mitigation: upgrade to `1.6.9` or later.
|
| CVE-2016-20031 |
|
Vulnerability in c (CVE-2016-20031)
vulnerability in c (CVE-2016-20031). Confidential information can be exposed externally.
|
| CVE-2016-20024 |
|
Vulnerability in csharp (CVE-2016-20024)
vulnerability in csharp (CVE-2016-20024). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32640 |
|
Code Injection in simpleeval (CVE-2026-32640)
code injection in simpleeval (CVE-2026-32640). Successful exploitation can lead to full system takeover. Exploitable via ``names``. Mitigation: upgrade to `1.0.5` or later.
|
| CVE-2026-32304 |
|
Code Injection in locutus (CVE-2026-32304)
code injection in locutus (CVE-2026-32304). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.0.14` or later.
|
| CVE-2025-13702 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2025-13702)
cross-site scripting in ibm (CVE-2025-13702). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32597 |
|
Vulnerability in pyjwt (CVE-2026-32597)
vulnerability in pyjwt (CVE-2026-32597). Data can be tampered with by attackers. Exploitable via ``crit``. Mitigation: upgrade to `2.12.0` or later.
|
| CVE-2026-2229 |
|
Vulnerability in c (CVE-2026-2229)
vulnerability in c (CVE-2026-2229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1526 |
|
Vulnerability in nodejs (CVE-2026-1526)
vulnerability in nodejs (CVE-2026-1526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32274 |
|
Path Traversal in black (CVE-2026-32274)
path traversal in black (CVE-2026-32274). Data can be tampered with by attackers. Mitigation: upgrade to `26.3.1` or later.
|
| CVE-2025-61154 |
|
Vulnerability in c (CVE-2025-61154)
vulnerability in c (CVE-2025-61154). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13462 |
|
Vulnerability in CVE-2025-13462 (CVE-2025-13462)
vulnerability in CVE-2025-13462 (CVE-2025-13462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32141 |
|
Vulnerability in webreflection (CVE-2026-32141)
vulnerability in webreflection (CVE-2026-32141). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.0` or later.
|
| CVE-2026-73426 |
|
Cross-Site Scripting (XSS) in action_text-trix (CVE-2026-73426)
cross-site scripting in action_text-trix (CVE-2026-73426). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.1.17` or later.
|
| CVE-2026-28356 |
|
Vulnerability in multipart (CVE-2026-28356)
vulnerability in multipart (CVE-2026-28356). Risk of unauthorized operations or information disclosure. Exploitable via ``multipart.py``. Mitigation: upgrade to `1.2.2` or later.
|
| CVE-2026-3904 |
|
Vulnerability in c (CVE-2026-3904)
vulnerability in c (CVE-2026-3904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21361 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-21361)
cross-site scripting in adobe (CVE-2026-21361). Confidential information can be exposed externally.
|
| CVE-2026-21311 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-21311)
cross-site scripting in adobe (CVE-2026-21311). Confidential information can be exposed externally.
|
| CVE-2026-21295 |
|
Open Redirect in c (CVE-2026-21295)
vulnerability in c (CVE-2026-21295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21284 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-21284)
cross-site scripting in adobe (CVE-2026-21284). Confidential information can be exposed externally.
|
| CVE-2026-21290 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-21290)
cross-site scripting in adobe (CVE-2026-21290). Confidential information can be exposed externally.
|
| CVE-2026-27262 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27262)
cross-site scripting in adobe (CVE-2026-27262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27265 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27265)
cross-site scripting in adobe (CVE-2026-27265). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27266 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27266)
cross-site scripting in adobe (CVE-2026-27266). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27255 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27255)
cross-site scripting in adobe (CVE-2026-27255). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27256 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27256)
cross-site scripting in adobe (CVE-2026-27256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27257 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27257)
cross-site scripting in adobe (CVE-2026-27257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27249 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27249)
cross-site scripting in adobe (CVE-2026-27249). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27250 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27250)
cross-site scripting in adobe (CVE-2026-27250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27251 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27251)
cross-site scripting in adobe (CVE-2026-27251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27252 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27252)
cross-site scripting in adobe (CVE-2026-27252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27253 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-27253)
cross-site scripting in adobe (CVE-2026-27253). Risk of unauthorized operations or information disclosure.
|