Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7344 |
|
Use-After-Free in google (CVE-2026-7344)
vulnerability in google (CVE-2026-7344). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7333 |
|
Use-After-Free in google (CVE-2026-7333)
vulnerability in google (CVE-2026-7333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7334 |
|
Use-After-Free in google (CVE-2026-7334)
vulnerability in google (CVE-2026-7334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40296 |
|
Cross-Site Scripting (XSS) in phpoffice/phpspreadsheet (CVE-2026-40296)
cross-site scripting in phpoffice/phpspreadsheet (CVE-2026-40296). Risk of unauthorized operations or information disclosure. Exploitable via ``General``. Mitigation: upgrade to `1.30.4` or later.
|
| CVE-2026-7296 |
|
Cross-Site Scripting (XSS) in CVE-2026-7296 (CVE-2026-7296)
cross-site scripting in CVE-2026-7296 (CVE-2026-7296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7297 |
|
Cross-Site Scripting (XSS) in CVE-2026-7297 (CVE-2026-7297)
cross-site scripting in CVE-2026-7297 (CVE-2026-7297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37750 |
|
Cross-Site Scripting (XSS) in CVE-2026-37750 (CVE-2026-37750)
cross-site scripting in CVE-2026-37750 (CVE-2026-37750). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7295 |
|
Cross-Site Scripting (XSS) in CVE-2026-7295 (CVE-2026-7295)
cross-site scripting in CVE-2026-7295 (CVE-2026-7295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7324 |
|
Buffer Overflow in mozilla (CVE-2026-7324)
vulnerability in mozilla (CVE-2026-7324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7320 |
|
Buffer Overflow in mozilla (CVE-2026-7320)
vulnerability in mozilla (CVE-2026-7320). Confidential information can be exposed externally.
|
| CVE-2026-7322 |
|
Buffer Overflow in mozilla (CVE-2026-7322)
vulnerability in mozilla (CVE-2026-7322). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7323 |
|
Buffer Overflow in mozilla (CVE-2026-7323)
vulnerability in mozilla (CVE-2026-7323). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27760 |
|
Code Injection in CVE-2026-27760 (CVE-2026-27760)
code injection in CVE-2026-27760 (CVE-2026-27760). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41603 |
|
Vulnerability in thrift (CVE-2026-41603)
vulnerability in thrift (CVE-2026-41603). Confidential information can be exposed externally. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-41604 |
|
Out-of-Bounds Read in thrift (CVE-2026-41604)
vulnerability in thrift (CVE-2026-41604). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-41607 |
|
Out-of-Bounds Read in thrift (CVE-2026-41607)
vulnerability in thrift (CVE-2026-41607). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-41605 |
|
Vulnerability in thrift (CVE-2026-41605)
vulnerability in thrift (CVE-2026-41605). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-41606 |
|
Vulnerability in thrift (CVE-2026-41606)
vulnerability in thrift (CVE-2026-41606). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2025-48431 |
|
Vulnerability in thrift (CVE-2025-48431)
vulnerability in thrift (CVE-2025-48431). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-41602 |
|
Vulnerability in thrift (CVE-2026-41602)
vulnerability in thrift (CVE-2026-41602). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-7222 |
|
Cross-Site Scripting (XSS) in CVE-2026-7222 (CVE-2026-7222)
cross-site scripting in CVE-2026-7222 (CVE-2026-7222). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7200 |
|
Cross-Site Scripting (XSS) in CVE-2026-7200 (CVE-2026-7200)
cross-site scripting in CVE-2026-7200 (CVE-2026-7200). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7199 |
|
Vulnerability in sqli (CVE-2026-7199)
vulnerability in sqli (CVE-2026-7199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32202 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-32202)
vulnerability in Microsoft windows (CVE-2026-32202). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-1708 KEV |
|
[KEV] Path Traversal in Connectwise screenconnect (CVE-2024-1708)
path traversal in Connectwise screenconnect (CVE-2024-1708). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-7194 |
|
Vulnerability in sqli (CVE-2026-7194)
vulnerability in sqli (CVE-2026-7194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3087 |
|
Path Traversal in libpython (CVE-2026-3087)
path traversal in libpython (CVE-2026-3087). Data can be tampered with by attackers. Mitigation: upgrade to `3.14.5` or later.
|
| CVE-2026-38934 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-38934 (CVE-2026-38934)
vulnerability in CVE-2026-38934 (CVE-2026-38934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38935 |
|
Cross-Site Scripting (XSS) in CVE-2026-38935 (CVE-2026-38935)
cross-site scripting in CVE-2026-38935 (CVE-2026-38935). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38936 |
|
Cross-Site Scripting (XSS) in CVE-2026-38936 (CVE-2026-38936)
cross-site scripting in CVE-2026-38936 (CVE-2026-38936). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41465 |
|
Path Traversal in path-traversal (CVE-2026-41465)
path traversal in path-traversal (CVE-2026-41465). Confidential information can be exposed externally.
|
| CVE-2026-40514 |
|
Vulnerability in smartertools (CVE-2026-40514)
vulnerability in smartertools (CVE-2026-40514). Confidential information can be exposed externally.
|
| CVE-2026-40022 |
|
Vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022)
vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022). Confidential information can be exposed externally. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-27172 |
|
Unsafe Deserialization in apache (CVE-2026-27172)
vulnerability in apache (CVE-2026-27172). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33453 |
|
Vulnerability in apache (CVE-2026-33453)
vulnerability in apache (CVE-2026-33453). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40858 |
|
Unsafe Deserialization in apache (CVE-2026-40858)
vulnerability in apache (CVE-2026-40858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33454 |
|
Unsafe Deserialization in apache (CVE-2026-33454)
vulnerability in apache (CVE-2026-33454). Confidential information can be exposed externally.
|
| CVE-2026-40453 |
|
Vulnerability in org.apache.camel:camel-coap (CVE-2026-40453)
vulnerability in org.apache.camel:camel-coap (CVE-2026-40453). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-40860 |
|
Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-40860)
vulnerability in org.apache.camel:camel-jms (CVE-2026-40860). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-40048 |
|
Unsafe Deserialization in apache (CVE-2026-40048)
vulnerability in apache (CVE-2026-40048). Successful exploitation can lead to full system takeover. Exploitable via ``java.security.KeyPair``.
|
| CVE-2026-40473 |
|
Unsafe Deserialization in apache (CVE-2026-40473)
vulnerability in apache (CVE-2026-40473). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6786 |
|
Out-of-Bounds Read in mozilla (CVE-2026-6786)
vulnerability in mozilla (CVE-2026-6786). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6785 |
|
Out-of-Bounds Read in mozilla (CVE-2026-6785)
vulnerability in mozilla (CVE-2026-6785). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41473 |
|
Vulnerability in dos (CVE-2026-41473)
vulnerability in dos (CVE-2026-41473). Data can be tampered with by attackers.
|
| CVE-2026-41472 |
|
Cross-Site Scripting (XSS) in cyberpanel (CVE-2026-41472)
cross-site scripting in cyberpanel (CVE-2026-41472). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/ai-scanner/callback`.
|
| CVE-2026-40466 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-41044 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-21728 |
|
Vulnerability in github.com/grafana/tempo (CVE-2026-21728)
vulnerability in github.com/grafana/tempo (CVE-2026-21728). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5488 |
|
Vulnerability in wordpress (CVE-2026-5488)
vulnerability in wordpress (CVE-2026-5488). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-29635 KEV |
|
[KEV] Command Injection in D-link dir-823x (CVE-2025-29635)
command injection in D-link dir-823x (CVE-2025-29635). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|