Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-2770 |
|
Use-After-Free in mozilla (CVE-2026-2770)
vulnerability in mozilla (CVE-2026-2770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2776 |
|
Buffer Overflow in mozilla (CVE-2026-2776)
vulnerability in mozilla (CVE-2026-2776). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2775 |
|
Vulnerability in mozilla (CVE-2026-2775)
vulnerability in mozilla (CVE-2026-2775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2774 |
|
Vulnerability in mozilla (CVE-2026-2774)
vulnerability in mozilla (CVE-2026-2774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2758 |
|
Use-After-Free in mozilla (CVE-2026-2758)
vulnerability in mozilla (CVE-2026-2758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2761 |
|
Vulnerability in mozilla (CVE-2026-2761)
vulnerability in mozilla (CVE-2026-2761). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2759 |
|
Vulnerability in mozilla (CVE-2026-2759)
vulnerability in mozilla (CVE-2026-2759). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2786 |
|
Use-After-Free in mozilla (CVE-2026-2786)
vulnerability in mozilla (CVE-2026-2786). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25985 |
|
Vulnerability in imagemagick (CVE-2026-25985)
vulnerability in imagemagick (CVE-2026-25985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25968 |
|
Vulnerability in c (CVE-2026-25968)
vulnerability in c (CVE-2026-25968). Confidential information can be exposed externally.
|
| CVE-2026-25969 |
|
Vulnerability in c (CVE-2026-25969)
vulnerability in c (CVE-2026-25969). Risk of unauthorized operations or information disclosure. Exploitable via ``WriteASHLARImage``.
|
| CVE-2026-25965 |
|
Path Traversal in path-traversal (CVE-2026-25965)
path traversal in path-traversal (CVE-2026-25965). Confidential information can be exposed externally.
|
| CVE-2026-25794 |
|
Vulnerability in c (CVE-2026-25794)
vulnerability in c (CVE-2026-25794). Risk of unauthorized operations or information disclosure. Exploitable via ``WriteUHDRImage``.
|
| CVE-2026-25108 KEV |
|
[KEV] OS Command Injection in Soliton systems k.k soliton-systems-kk (CVE-2026-25108)
OS command injection in Soliton systems k.k soliton-systems-kk (CVE-2026-25108). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-25747 |
|
Unsafe Deserialization in apache (CVE-2026-25747)
vulnerability in apache (CVE-2026-25747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27134 |
|
Authentication Bypass in apache (CVE-2026-27134)
authentication bypass in apache (CVE-2026-27134). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27504 |
|
Cross-Site Scripting (XSS) in radioinorr (CVE-2026-27504)
cross-site scripting in radioinorr (CVE-2026-27504). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27505 |
|
Cross-Site Scripting (XSS) in radioinorr (CVE-2026-27505)
cross-site scripting in radioinorr (CVE-2026-27505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27506 |
|
Cross-Site Scripting (XSS) in radioinorr (CVE-2026-27506)
cross-site scripting in radioinorr (CVE-2026-27506). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27502 |
|
Cross-Site Scripting (XSS) in radioinorr (CVE-2026-27502)
cross-site scripting in radioinorr (CVE-2026-27502). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27503 |
|
Cross-Site Scripting (XSS) in radioinorr (CVE-2026-27503)
cross-site scripting in radioinorr (CVE-2026-27503). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-49113 KEV |
|
[KEV] Unsafe Deserialization in Roundcube webmail (CVE-2025-49113)
vulnerability in Roundcube webmail (CVE-2025-49113). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-68461 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Roundcube webmail (CVE-2025-68461)
cross-site scripting in Roundcube webmail (CVE-2025-68461). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22175 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in gitlab (CVE-2021-22175)
SSRF in gitlab (CVE-2021-22175). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-22769 KEV |
|
[KEV] Vulnerability in Dell recoverpoint-for-virtual-machines-rp4vms (CVE-2026-22769)
vulnerability in Dell recoverpoint-for-virtual-machines-rp4vms (CVE-2026-22769). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-24734 |
|
Vulnerability in apache (CVE-2026-24734)
vulnerability in apache (CVE-2026-24734). Data can be tampered with by attackers.
|
| CVE-2008-0015 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2008-0015)
vulnerability in Microsoft windows (CVE-2008-0015). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-7796 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Synacor zimbra-collaboration-suite (CVE-2020-7796)
SSRF in Synacor zimbra-collaboration-suite (CVE-2020-7796). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-7694 KEV |
|
[KEV] Unrestricted File Upload in Teamt5 threatsonar-anti-ransomware (CVE-2024-7694)
vulnerability in Teamt5 threatsonar-anti-ransomware (CVE-2024-7694). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-2441 KEV |
|
[KEV] Use-After-Free in Google chromium (CVE-2026-2441)
vulnerability in Google chromium (CVE-2026-2441). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-2447 |
|
Vulnerability in mozilla (CVE-2026-2447)
vulnerability in mozilla (CVE-2026-2447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1731 KEV |
|
[KEV] OS Command Injection in Beyondtrust remote-support-rs-and-privileged-remote-access-pra (CVE-2026-1731)
OS command injection in Beyondtrust remote-support-rs-and-privileged-remote-access-pra (CVE-2026-1731). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-26214 |
|
Vulnerability in apache (CVE-2026-26214)
vulnerability in apache (CVE-2026-26214). Confidential information can be exposed externally.
|
| CVE-2026-20700 KEV |
|
[KEV] Buffer Overflow in Apple multiple-products (CVE-2026-20700)
vulnerability in Apple multiple-products (CVE-2026-20700). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-40536 KEV |
|
[KEV] Vulnerability in Solarwinds web-help-desk (CVE-2025-40536)
vulnerability in Solarwinds web-help-desk (CVE-2025-40536). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-43468 KEV |
|
[KEV] SQL Injection in Microsoft configuration-manager (CVE-2024-43468)
SQL injection in Microsoft configuration-manager (CVE-2024-43468). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-15556 KEV |
|
[KEV] Vulnerability in Notepad++ notepad (CVE-2025-15556)
vulnerability in Notepad++ notepad (CVE-2025-15556). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20677 |
|
Vulnerability in apple (CVE-2026-20677)
vulnerability in apple (CVE-2026-20677). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20627 |
|
Vulnerability in apple (CVE-2026-20627)
vulnerability in apple (CVE-2026-20627). Confidential information can be exposed externally.
|
| CVE-2026-20630 |
|
Vulnerability in apple (CVE-2026-20630)
vulnerability in apple (CVE-2026-20630). Confidential information can be exposed externally.
|
| CVE-2026-20615 |
|
Path Traversal in apple (CVE-2026-20615)
path traversal in apple (CVE-2026-20615). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20617 |
|
Vulnerability in apple (CVE-2026-20617)
vulnerability in apple (CVE-2026-20617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20623 |
|
Information Disclosure in apple (CVE-2026-20623)
vulnerability in apple (CVE-2026-20623). Confidential information can be exposed externally.
|
| CVE-2025-46310 |
|
Privilege Escalation in apple (CVE-2025-46310)
vulnerability in apple (CVE-2025-46310). Data can be tampered with by attackers.
|
| CVE-2025-43417 |
|
Path Traversal in apple (CVE-2025-43417)
path traversal in apple (CVE-2025-43417). Confidential information can be exposed externally.
|
| CVE-2025-43403 |
|
Vulnerability in apple (CVE-2025-43403)
vulnerability in apple (CVE-2025-43403). Confidential information can be exposed externally.
|
| CVE-2026-25868 |
|
Cross-Site Scripting (XSS) in rybber (CVE-2026-25868)
cross-site scripting in rybber (CVE-2026-25868). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25869 |
|
Path Traversal in path-traversal (CVE-2026-25869)
path traversal in path-traversal (CVE-2026-25869). Confidential information can be exposed externally.
|
| CVE-2026-21344 |
|
Out-of-Bounds Read in adobe (CVE-2026-21344)
vulnerability in adobe (CVE-2026-21344). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21345 |
|
Out-of-Bounds Read in adobe (CVE-2026-21345)
vulnerability in adobe (CVE-2026-21345). Successful exploitation can lead to full system takeover.
|