Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-21643 KEV |
|
[KEV] SQL Injection in Fortinet forticlient-ems (CVE-2026-21643)
SQL injection in Fortinet forticlient-ems (CVE-2026-21643). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-3055 KEV |
|
[KEV] Out-of-Bounds Read in Citrix netscaler (CVE-2026-3055)
vulnerability in Citrix netscaler (CVE-2026-3055). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-3256 |
|
Vulnerability in ktat (CVE-2026-3256)
vulnerability in ktat (CVE-2026-3256). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33186 |
|
Vulnerability in grpc (CVE-2026-33186)
vulnerability in grpc (CVE-2026-33186). Confidential information can be exposed externally. Exploitable via ``info.FullMethod``.
|
| CVE-2024-5971 |
|
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not s...
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource co...
|
| CVE-2023-48795 |
|
Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
|
| CVE-2023-44487 KEV |
|
[KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
|
| CVE-2022-45597 |
|
Vulnerability in componentspace (CVE-2022-45597)
vulnerability in componentspace (CVE-2022-45597). Successful exploitation can lead to full system takeover.
|
| CVE-2022-20773 |
|
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance...
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance...
|
| CVE-2021-22703 |
|
Vulnerability in schneider-electric (CVE-2021-22703)
vulnerability in schneider-electric (CVE-2021-22703). Confidential information can be exposed externally.
|
| CVE-2017-1000245 |
|
Vulnerability in jenkins (CVE-2017-1000245)
vulnerability in jenkins (CVE-2017-1000245). Successful exploitation can lead to full system takeover.
|
| CVE-2017-14623 |
|
Authentication Bypass in go-ldap-project (CVE-2017-14623)
authentication bypass in go-ldap-project (CVE-2017-14623). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9506 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2017-9506)
SSRF in ssrf (CVE-2017-9506). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9431 |
|
Out-of-Bounds Write in c (CVE-2017-9431)
out-of-bounds write in c (CVE-2017-9431). Successful exploitation can lead to full system takeover.
|
| CVE-2017-2171 |
|
Cross-Site Scripting (XSS) in bestwebsoft (CVE-2017-2171)
cross-site scripting in bestwebsoft (CVE-2017-2171). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-8359 |
|
Out-of-Bounds Write in c (CVE-2017-8359)
out-of-bounds write in c (CVE-2017-8359). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7860 |
|
Out-of-Bounds Write in c (CVE-2017-7860)
out-of-bounds write in c (CVE-2017-7860). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7861 |
|
Out-of-Bounds Write in c (CVE-2017-7861)
out-of-bounds write in c (CVE-2017-7861). Successful exploitation can lead to full system takeover.
|
| CVE-2008-5161 |
|
Information Disclosure in openbsd (CVE-2008-5161)
vulnerability in openbsd (CVE-2008-5161). Risk of unauthorized operations or information disclosure.
|