Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-35561 |
|
Vulnerability in amazon (CVE-2026-35561)
vulnerability in amazon (CVE-2026-35561). Confidential information can be exposed externally.
|
| CVE-2026-35560 |
|
Vulnerability in amazon (CVE-2026-35560)
vulnerability in amazon (CVE-2026-35560). Confidential information can be exposed externally.
|
| CVE-2026-35558 |
|
Command Injection in amazon (CVE-2026-35558)
command injection in amazon (CVE-2026-35558). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7024 |
|
Vulnerability in airbus (CVE-2025-7024)
vulnerability in airbus (CVE-2025-7024). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4350 |
|
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
|
| CVE-2026-35535 |
|
Vulnerability in privilege-escalation (CVE-2026-35535)
vulnerability in privilege-escalation (CVE-2026-35535). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34834 |
|
Authentication Bypass in bulwarkmail (CVE-2026-34834)
authentication bypass in bulwarkmail (CVE-2026-34834). Data can be tampered with by attackers.
|
| CVE-2026-34833 |
|
Vulnerability in bulwarkmail (CVE-2026-34833)
vulnerability in bulwarkmail (CVE-2026-34833). Confidential information can be exposed externally. Exploitable via `GET /api/auth/session`.
|
| CVE-2025-43264 |
|
Buffer Overflow in apple (CVE-2025-43264)
vulnerability in apple (CVE-2025-43264). Successful exploitation can lead to full system takeover.
|
| CVE-2025-43257 |
|
Vulnerability in apple (CVE-2025-43257)
vulnerability in apple (CVE-2025-43257). Confidential information can be exposed externally.
|
| CVE-2025-43219 |
|
Out-of-Bounds Write in apple (CVE-2025-43219)
out-of-bounds write in apple (CVE-2025-43219). Successful exploitation can lead to full system takeover.
|
| CVE-2025-43202 |
|
Out-of-Bounds Write in apple (CVE-2025-43202)
out-of-bounds write in apple (CVE-2025-43202). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44303 |
|
Vulnerability in apple (CVE-2024-44303)
vulnerability in apple (CVE-2024-44303). Confidential information can be exposed externally.
|
| CVE-2024-44286 |
|
Vulnerability in apple (CVE-2024-44286)
vulnerability in apple (CVE-2024-44286). Confidential information can be exposed externally.
|
| CVE-2024-44250 |
|
Privilege Escalation in apple (CVE-2024-44250)
vulnerability in apple (CVE-2024-44250). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44219 |
|
Vulnerability in apple (CVE-2024-44219)
vulnerability in apple (CVE-2024-44219). Confidential information can be exposed externally.
|
| CVE-2024-40858 |
|
Vulnerability in apple (CVE-2024-40858)
vulnerability in apple (CVE-2024-40858). Confidential information can be exposed externally.
|
| CVE-2024-40849 |
|
Vulnerability in apple (CVE-2024-40849)
vulnerability in apple (CVE-2024-40849). Confidential information can be exposed externally.
|
| CVE-2026-5368 |
|
Vulnerability in sqli (CVE-2026-5368)
vulnerability in sqli (CVE-2026-5368). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65114 |
|
Vulnerability in apache (CVE-2025-65114)
vulnerability in apache (CVE-2025-65114). Data can be tampered with by attackers.
|
| CVE-2025-58136 |
|
Vulnerability in apache (CVE-2025-58136)
vulnerability in apache (CVE-2025-58136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3502 KEV |
|
[KEV] Vulnerability in Trueconf client (CVE-2026-3502)
vulnerability in Trueconf client (CVE-2026-3502). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-5272 |
|
Vulnerability in google (CVE-2026-5272)
vulnerability in google (CVE-2026-5272). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5281 KEV |
|
[KEV] Use-After-Free in Google dawn (CVE-2026-5281)
vulnerability in Google dawn (CVE-2026-5281). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34731 |
|
Vulnerability in wwbn (CVE-2026-34731)
vulnerability in wwbn (CVE-2026-34731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34381 |
|
Vulnerability in apache (CVE-2026-34381)
vulnerability in apache (CVE-2026-34381). Confidential information can be exposed externally.
|
| CVE-2026-34394 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34394)
vulnerability in csrf (CVE-2026-34394). Confidential information can be exposed externally.
|
| CVE-2026-34204 |
|
Authentication Bypass in minio (CVE-2026-34204)
authentication bypass in minio (CVE-2026-34204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2123 |
|
Vulnerability in privilege-escalation (CVE-2026-2123)
vulnerability in privilege-escalation (CVE-2026-2123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22561 |
|
Vulnerability in privilege-escalation (CVE-2026-22561)
vulnerability in privilege-escalation (CVE-2026-22561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34200 |
|
Vulnerability in nhost (CVE-2026-34200)
vulnerability in nhost (CVE-2026-34200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5198 |
|
Vulnerability in sqli (CVE-2026-5198)
vulnerability in sqli (CVE-2026-5198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2370 |
|
Vulnerability in gitlab (CVE-2026-2370)
vulnerability in gitlab (CVE-2026-2370). Confidential information can be exposed externally. Mitigation: upgrade to `18.8.7, 18.9.3, 18.10.1` or later.
|
| CVE-2026-3055 KEV |
|
[KEV] Out-of-Bounds Read in Citrix netscaler (CVE-2026-3055)
vulnerability in Citrix netscaler (CVE-2026-3055). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-27309 |
|
Use-After-Free in adobe (CVE-2026-27309)
vulnerability in adobe (CVE-2026-27309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34046 |
|
Vulnerability in langflow (CVE-2026-34046)
vulnerability in langflow (CVE-2026-34046). Successful exploitation can lead to full system takeover. Exploitable via ``_read_flow``.
|
| CVE-2026-28367 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28367)
vulnerability in io.undertow:undertow-parent (CVE-2026-28367). Confidential information can be exposed externally.
|
| CVE-2026-5027 |
|
Path Traversal in path-traversal (CVE-2026-5027)
path traversal in path-traversal (CVE-2026-5027). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/files`.
|
| CVE-2026-27880 |
|
Out-of-Bounds Write in grafana (CVE-2026-27880)
out-of-bounds write in grafana (CVE-2026-27880). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2025-53521 KEV |
|
[KEV] Vulnerability in F5 big-ip (CVE-2025-53521)
vulnerability in F5 big-ip (CVE-2025-53521). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-30463 |
|
SQL Injection in sqli (CVE-2026-30463)
SQL injection in sqli (CVE-2026-30463). Confidential information can be exposed externally.
|
| CVE-2026-33634 KEV |
|
[KEV] Vulnerability in github.com/aquasecurity/trivy (CVE-2026-33634)
vulnerability in github.com/aquasecurity/trivy (CVE-2026-33634). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.35.0` or later.
|
| CVE-2026-20622 |
|
Vulnerability in apple (CVE-2026-20622)
vulnerability in apple (CVE-2026-20622). Confidential information can be exposed externally.
|
| CVE-2026-1995 |
|
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded conte...
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any stand...
|
| CVE-2026-4699 |
|
Vulnerability in mozilla (CVE-2026-4699)
vulnerability in mozilla (CVE-2026-4699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4695 |
|
Vulnerability in mozilla (CVE-2026-4695)
vulnerability in mozilla (CVE-2026-4695). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4697 |
|
Vulnerability in mozilla (CVE-2026-4697)
vulnerability in mozilla (CVE-2026-4697). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4694 |
|
Vulnerability in mozilla (CVE-2026-4694)
vulnerability in mozilla (CVE-2026-4694). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4685 |
|
Vulnerability in mozilla (CVE-2026-4685)
vulnerability in mozilla (CVE-2026-4685). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4690 |
|
Vulnerability in mozilla (CVE-2026-4690)
vulnerability in mozilla (CVE-2026-4690). Risk of unauthorized operations or information disclosure.
|