Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73226 |
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions t...
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handle...
|
| CVE-2026-73224 |
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user do...
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties and Calculate Size because calcLocal in src/client/c...
|
| CVE-2026-73222 |
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
| CVE-2026-72742 |
|
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field...
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field...
|
| CVE-2026-15426 |
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
| CVE-2026-58641 |
|
Vulnerability in csharp (CVE-2026-58641)
vulnerability in csharp (CVE-2026-58641). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59119 |
|
Vulnerability in microsoft (CVE-2026-59119)
vulnerability in microsoft (CVE-2026-59119). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58612 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-58612)
SSRF in ssrf (CVE-2026-58612). Confidential information can be exposed externally.
|
| CVE-2026-54981 |
|
Vulnerability in microsoft (CVE-2026-54981)
vulnerability in microsoft (CVE-2026-54981). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48414 |
|
Cross-Site Scripting (XSS) in CVE-2026-48414 (CVE-2026-48414)
cross-site scripting in CVE-2026-48414 (CVE-2026-48414). Confidential information can be exposed externally.
|
| CVE-2026-48413 |
|
Cross-Site Scripting (XSS) in CVE-2026-48413 (CVE-2026-48413)
cross-site scripting in CVE-2026-48413 (CVE-2026-48413). Confidential information can be exposed externally.
|
| CVE-2026-73089 |
|
Vulnerability in CVE-2026-73089 (CVE-2026-73089)
vulnerability in CVE-2026-73089 (CVE-2026-73089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73088 |
|
Vulnerability in CVE-2026-73088 (CVE-2026-73088)
vulnerability in CVE-2026-73088 (CVE-2026-73088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73086 |
|
Vulnerability in csrf (CVE-2026-73086)
vulnerability in csrf (CVE-2026-73086). Confidential information can be exposed externally.
|
| CVE-2026-70354 |
|
Out-of-Bounds Write in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-70354)
out-of-bounds write in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-70354). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-70338 |
|
Code Injection in microsoft (CVE-2026-70338)
code injection in microsoft (CVE-2026-70338). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70337 |
|
Vulnerability in path-traversal (CVE-2026-70337)
vulnerability in path-traversal (CVE-2026-70337). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65810 |
|
Vulnerability in csharp (CVE-2026-65810)
vulnerability in csharp (CVE-2026-65810). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62909 |
|
Vulnerability in Microsoft.NETCore.App.Runtime.linux-arm (CVE-2026-62909)
vulnerability in Microsoft.NETCore.App.Runtime.linux-arm (CVE-2026-62909). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-62901 |
|
Vulnerability in Microsoft.NETCore.App.Runtime.win-arm64 (CVE-2026-62901)
vulnerability in Microsoft.NETCore.App.Runtime.win-arm64 (CVE-2026-62901). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-62897 |
|
Vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62897)
vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62897). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-62886 |
|
Vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62886)
vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62886). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-62871 |
|
Vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62871)
vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-62871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-62872 |
|
Authorization Flaw in csharp (CVE-2026-62872)
vulnerability in csharp (CVE-2026-62872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72778 |
|
Vulnerability in csrf (CVE-2026-72778)
vulnerability in csrf (CVE-2026-72778). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72745 |
|
Vulnerability in c (CVE-2026-72745)
vulnerability in c (CVE-2026-72745). Confidential information can be exposed externally.
|
| CVE-2026-72747 |
|
Cross-Site Scripting (XSS) in CVE-2026-72747 (CVE-2026-72747)
cross-site scripting in CVE-2026-72747 (CVE-2026-72747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72556 |
|
OS Command Injection in CVE-2026-72556 (CVE-2026-72556)
OS command injection in CVE-2026-72556 (CVE-2026-72556). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72557 |
|
Unrestricted File Upload in CVE-2026-72557 (CVE-2026-72557)
vulnerability in CVE-2026-72557 (CVE-2026-72557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72551 |
|
OS Command Injection in CVE-2026-72551 (CVE-2026-72551)
OS command injection in CVE-2026-72551 (CVE-2026-72551). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8718 |
|
Out-of-Bounds Write in c (CVE-2026-8718)
out-of-bounds write in c (CVE-2026-8718). Data can be tampered with by attackers.
|
| CVE-2026-11810 |
|
Vulnerability in c (CVE-2026-11810)
vulnerability in c (CVE-2026-11810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71966 |
|
OS Command Injection in c (CVE-2026-71966)
OS command injection in c (CVE-2026-71966). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69118 |
|
Authorization Flaw in CVE-2026-69118 (CVE-2026-69118)
vulnerability in CVE-2026-69118 (CVE-2026-69118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66738 |
|
Code Injection in CVE-2026-66738 (CVE-2026-66738)
code injection in CVE-2026-66738 (CVE-2026-66738). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68414 |
|
Vulnerability in c (CVE-2026-68414)
vulnerability in c (CVE-2026-68414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68420 |
|
Vulnerability in c (CVE-2026-68420)
vulnerability in c (CVE-2026-68420). Confidential information can be exposed externally.
|
| CVE-2026-68402 |
|
Vulnerability in c (CVE-2026-68402)
vulnerability in c (CVE-2026-68402). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68387 |
|
Vulnerability in c (CVE-2026-68387)
vulnerability in c (CVE-2026-68387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68377 |
|
Vulnerability in c (CVE-2026-68377)
vulnerability in c (CVE-2026-68377). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68323 |
|
Vulnerability in c (CVE-2026-68323)
vulnerability in c (CVE-2026-68323). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68320 |
|
Vulnerability in c (CVE-2026-68320)
vulnerability in c (CVE-2026-68320). Data can be tampered with by attackers.
|
| CVE-2026-68293 |
|
Vulnerability in c (CVE-2026-68293)
vulnerability in c (CVE-2026-68293). Confidential information can be exposed externally.
|
| CVE-2026-68315 |
|
Vulnerability in c (CVE-2026-68315)
vulnerability in c (CVE-2026-68315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68297 |
|
Vulnerability in c (CVE-2026-68297)
vulnerability in c (CVE-2026-68297). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68290 |
|
Vulnerability in c (CVE-2026-68290)
vulnerability in c (CVE-2026-68290). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68263 |
|
Vulnerability in c (CVE-2026-68263)
vulnerability in c (CVE-2026-68263). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68245 |
|
Vulnerability in c (CVE-2026-68245)
vulnerability in c (CVE-2026-68245). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68230 |
|
Vulnerability in c (CVE-2026-68230)
vulnerability in c (CVE-2026-68230). Confidential information can be exposed externally.
|
| CVE-2026-68219 |
|
Vulnerability in c (CVE-2026-68219)
vulnerability in c (CVE-2026-68219). Successful exploitation can lead to full system takeover.
|