Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-53667 |
|
Cross-Site Scripting (XSS) in react-router (CVE-2026-53667)
cross-site scripting in react-router (CVE-2026-53667). Confidential information can be exposed externally. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2025-6947 |
|
Cross-Site Scripting (XSS) in jvn (CVE-2025-6947)
cross-site scripting in jvn (CVE-2025-6947). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-1071 |
|
Cross-Site Scripting (XSS) in jvn (CVE-2025-1071)
cross-site scripting in jvn (CVE-2025-1071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46590 |
|
Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-46590)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-46590). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-45367 |
|
Vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-45367)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-45367). Risk of unauthorized operations or information disclosure. Exploitable via ``funcMatches``. Mitigation: upgrade to `6.9.7` or later.
|
| CVE-2026-22007 |
|
Vulnerability in java (CVE-2026-22007)
vulnerability in java (CVE-2026-22007). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.0, 8.0.491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1` or later.
|
| CVE-2026-40048 |
|
Unsafe Deserialization in apache (CVE-2026-40048)
vulnerability in apache (CVE-2026-40048). Successful exploitation can lead to full system takeover. Exploitable via ``java.security.KeyPair``.
|
| CVE-2026-25580 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-25580)
SSRF in ssrf (CVE-2026-25580). Confidential information can be exposed externally. Mitigation: upgrade to `1.56.0` or later.
|
| CVE-2025-39860 |
|
Use-After-Free in c (CVE-2025-39860)
vulnerability in c (CVE-2025-39860). Successful exploitation can lead to full system takeover.
|
| CVE-2025-4318 |
|
Vulnerability in Amazon @aws-amplify/codegen-ui-react (CVE-2025-4318)
vulnerability in Amazon @aws-amplify/codegen-ui-react (CVE-2025-4318). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.20.3` or later.
|