Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-74887 |
|
Vulnerability in CVE-2026-74887 (CVE-2026-74887)
vulnerability in CVE-2026-74887 (CVE-2026-74887). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74874 |
|
Vulnerability in CVE-2026-74874 (CVE-2026-74874)
vulnerability in CVE-2026-74874 (CVE-2026-74874). Confidential information can be exposed externally.
|
| CVE-2026-71851 |
|
Vulnerability in crypto-js (CVE-2026-71851)
vulnerability in crypto-js (CVE-2026-71851). Successful exploitation can lead to full system takeover. Exploitable via ``crypto``. Mitigation: upgrade to `4.0.0` or later.
|
| CVE-2026-73567 |
|
Vulnerability in sm-crypto (CVE-2026-73567)
vulnerability in sm-crypto (CVE-2026-73567). Confidential information can be exposed externally. Exploitable via ``SecureRandom``. Mitigation: upgrade to `0.5.0` or later.
|
| CVE-2026-8169 |
|
Vulnerability in CVE-2026-8169 (CVE-2026-8169)
vulnerability in CVE-2026-8169 (CVE-2026-8169). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9323 |
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
| CVE-2026-7830 |
|
Vulnerability in cpp (CVE-2026-7830)
vulnerability in cpp (CVE-2026-7830). Confidential information can be exposed externally.
|
| CVE-2026-44040 |
|
Vulnerability in c (CVE-2026-44040)
vulnerability in c (CVE-2026-44040). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46493 |
|
Vulnerability in CVE-2026-46493 (CVE-2026-46493)
vulnerability in CVE-2026-46493 (CVE-2026-46493). Confidential information can be exposed externally. Exploitable via ``uniqid``.
|
| CVE-2026-42155 |
|
Vulnerability in openmage/magento-lts (CVE-2026-42155)
vulnerability in openmage/magento-lts (CVE-2026-42155). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/xmlrpc/`. Mitigation: upgrade to `20.18.0` or later.
|
| CVE-2026-4599 |
|
Vulnerability in jsrsasign (CVE-2026-4599)
vulnerability in jsrsasign (CVE-2026-4599). Confidential information can be exposed externally. Mitigation: upgrade to `11.1.1` or later.
|
| CVE-2017-11671 |
|
Vulnerability in c (CVE-2017-11671)
vulnerability in c (CVE-2017-11671). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8081 |
|
Vulnerability in csrf (CVE-2017-8081)
vulnerability in csrf (CVE-2017-8081). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5493 |
|
Vulnerability in wordpress (CVE-2017-5493)
vulnerability in wordpress (CVE-2017-5493). Data can be tampered with by attackers.
|