Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-28870 |
|
Vulnerability in apple (CVE-2026-28870)
vulnerability in apple (CVE-2026-28870). Confidential information can be exposed externally.
|
| CVE-2026-28877 |
|
Information Disclosure in apple (CVE-2026-28877)
vulnerability in apple (CVE-2026-28877). Confidential information can be exposed externally.
|
| CVE-2026-28878 |
|
Information Disclosure in apple (CVE-2026-28878)
vulnerability in apple (CVE-2026-28878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28882 |
|
Vulnerability in apple (CVE-2026-28882)
vulnerability in apple (CVE-2026-28882). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28857 |
|
Out-of-Bounds Read in apple (CVE-2026-28857)
vulnerability in apple (CVE-2026-28857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28859 |
|
Out-of-Bounds Read in apple (CVE-2026-28859)
vulnerability in apple (CVE-2026-28859). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28826 |
|
Vulnerability in apple (CVE-2026-28826)
vulnerability in apple (CVE-2026-28826). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20657 |
|
Buffer Overflow in apple (CVE-2026-20657)
vulnerability in apple (CVE-2026-20657). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20664 |
|
Out-of-Bounds Write in apple (CVE-2026-20664)
out-of-bounds write in apple (CVE-2026-20664). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28861 |
|
Cross-Site Scripting (XSS) in apple (CVE-2026-28861)
cross-site scripting in apple (CVE-2026-28861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28863 |
|
Vulnerability in apple (CVE-2026-28863)
vulnerability in apple (CVE-2026-28863). Confidential information can be exposed externally.
|
| CVE-2026-28833 |
|
Vulnerability in apple (CVE-2026-28833)
vulnerability in apple (CVE-2026-28833). Confidential information can be exposed externally.
|
| CVE-2026-28838 |
|
Vulnerability in apple (CVE-2026-28838)
vulnerability in apple (CVE-2026-28838). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20684 |
|
Vulnerability in apple (CVE-2026-20684)
vulnerability in apple (CVE-2026-20684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20670 |
|
Vulnerability in apple (CVE-2026-20670)
vulnerability in apple (CVE-2026-20670). Confidential information can be exposed externally.
|
| CVE-2026-20622 |
|
Vulnerability in apple (CVE-2026-20622)
vulnerability in apple (CVE-2026-20622). Confidential information can be exposed externally.
|
| CVE-2026-33017 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-33017)
vulnerability in langflow (CVE-2026-33017). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/build_public_tmp/{flow_id}/flow`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2026-1995 |
|
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded conte...
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any stand...
|
| CVE-2026-4729 |
|
Vulnerability in mozilla (CVE-2026-4729)
vulnerability in mozilla (CVE-2026-4729). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4720 |
|
Vulnerability in mozilla (CVE-2026-4720)
vulnerability in mozilla (CVE-2026-4720). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4721 |
|
Vulnerability in mozilla (CVE-2026-4721)
vulnerability in mozilla (CVE-2026-4721). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4697 |
|
Vulnerability in mozilla (CVE-2026-4697)
vulnerability in mozilla (CVE-2026-4697). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4699 |
|
Vulnerability in mozilla (CVE-2026-4699)
vulnerability in mozilla (CVE-2026-4699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4700 |
|
Vulnerability in mozilla (CVE-2026-4700)
vulnerability in mozilla (CVE-2026-4700). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4695 |
|
Vulnerability in mozilla (CVE-2026-4695)
vulnerability in mozilla (CVE-2026-4695). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4694 |
|
Vulnerability in mozilla (CVE-2026-4694)
vulnerability in mozilla (CVE-2026-4694). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4696 |
|
Use-After-Free in mozilla (CVE-2026-4696)
vulnerability in mozilla (CVE-2026-4696). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4688 |
|
Use-After-Free in mozilla (CVE-2026-4688)
vulnerability in mozilla (CVE-2026-4688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4684 |
|
Vulnerability in mozilla (CVE-2026-4684)
vulnerability in mozilla (CVE-2026-4684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4687 |
|
Vulnerability in mozilla (CVE-2026-4687)
vulnerability in mozilla (CVE-2026-4687). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4690 |
|
Vulnerability in mozilla (CVE-2026-4690)
vulnerability in mozilla (CVE-2026-4690). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4692 |
|
Vulnerability in mozilla (CVE-2026-4692)
vulnerability in mozilla (CVE-2026-4692). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4686 |
|
Vulnerability in mozilla (CVE-2026-4686)
vulnerability in mozilla (CVE-2026-4686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4685 |
|
Vulnerability in mozilla (CVE-2026-4685)
vulnerability in mozilla (CVE-2026-4685). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4693 |
|
Vulnerability in mozilla (CVE-2026-4693)
vulnerability in mozilla (CVE-2026-4693). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4689 |
|
Vulnerability in mozilla (CVE-2026-4689)
vulnerability in mozilla (CVE-2026-4689). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4691 |
|
Use-After-Free in mozilla (CVE-2026-4691)
vulnerability in mozilla (CVE-2026-4691). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4698 |
|
Vulnerability in mozilla (CVE-2026-4698)
vulnerability in mozilla (CVE-2026-4698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32642 |
|
Authorization Flaw in apache (CVE-2026-32642)
vulnerability in apache (CVE-2026-32642). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-41008 |
|
SQL Injection in sqli (CVE-2025-41008)
SQL injection in sqli (CVE-2025-41008). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-41007 |
|
SQL Injection in sqli (CVE-2025-41007)
SQL injection in sqli (CVE-2025-41007). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4447 |
|
Vulnerability in google (CVE-2026-4447)
vulnerability in google (CVE-2026-4447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32935 |
|
Vulnerability in phpseclib/phpseclib (CVE-2026-32935)
vulnerability in phpseclib/phpseclib (CVE-2026-32935). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.27` or later.
|
| CVE-2025-31277 KEV |
|
[KEV] Buffer Overflow in Apple multiple-products (CVE-2025-31277)
vulnerability in Apple multiple-products (CVE-2025-31277). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-32432 KEV |
|
[KEV] Code Injection in Craft cms craft-cms (CVE-2025-32432)
code injection in Craft cms craft-cms (CVE-2025-32432). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-54068 KEV |
|
[KEV] Code Injection in Laravel livewire (CVE-2025-54068)
code injection in Laravel livewire (CVE-2025-54068). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-43510 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2025-43510)
vulnerability in Apple multiple-products (CVE-2025-43510). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-43520 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2025-43520)
vulnerability in Apple multiple-products (CVE-2025-43520). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-32843 |
|
Cross-Site Scripting (XSS) in CVE-2026-32843 (CVE-2026-32843)
cross-site scripting in CVE-2026-32843 (CVE-2026-32843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20131 KEV |
|
[KEV] Unsafe Deserialization in Cisco secure-firewall-management-center-fmc (CVE-2026-20131)
vulnerability in Cisco secure-firewall-management-center-fmc (CVE-2026-20131). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|