Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Tag: cwe-303 Clear
ID Title
CVE-2026-59309 Vulnerability in vmware (CVE-2026-59309)
vulnerability in vmware (CVE-2026-59309). Successful exploitation can lead to full system takeover.
CVE-2026-47300 Vulnerability in Microsoft.AspNetCore.Authentication.Negotiate (CVE-2026-47300)
vulnerability in Microsoft.AspNetCore.Authentication.Negotiate (CVE-2026-47300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.29` or later.
CVE-2026-50360 Vulnerability in microsoft (CVE-2026-50360)
vulnerability in microsoft (CVE-2026-50360). Successful exploitation can lead to full system takeover.
CVE-2026-50627 Vulnerability in org.apache.cxf:cxf-rt-rs-security-oauth2 (CVE-2026-50627)
vulnerability in org.apache.cxf:cxf-rt-rs-security-oauth2 (CVE-2026-50627). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.7` or later.
CVE-2026-41103 Vulnerability in microsoft (CVE-2026-41103)
vulnerability in microsoft (CVE-2026-41103). Confidential information can be exposed externally.
CVE-2026-35579 Authentication Bypass in github.com/coredns/coredns (CVE-2026-35579)
authentication bypass in github.com/coredns/coredns (CVE-2026-35579). Successful exploitation can lead to full system takeover. Exploitable via ``tsigStatus``. Mitigation: upgrade to `1.14.3` or later.
CVE-2026-33190 Authentication Bypass in github.com/coredns/coredns (CVE-2026-33190)
authentication bypass in github.com/coredns/coredns (CVE-2026-33190). Confidential information can be exposed externally. Mitigation: upgrade to `1.14.3` or later.
CVE-2026-33557 Vulnerability in kafka (CVE-2026-33557)
vulnerability in kafka (CVE-2026-33557). Confidential information can be exposed externally. Exploitable via ``sasl.oauthbearer.jwt.validator.class``. Mitigation: upgrade to `4.1.2` or later.
CVE-2020-37094 Vulnerability in espocrm (CVE-2020-37094)
vulnerability in espocrm (CVE-2020-37094). Confidential information can be exposed externally. Exploitable via `Authorization header`.
CVE-2025-53782 Vulnerability in microsoft (CVE-2025-53782)
vulnerability in microsoft (CVE-2025-53782). Successful exploitation can lead to full system takeover.
CVE-2024-7593 KEV [KEV] Authentication Bypass in Ivanti virtual-traffic-manager (CVE-2024-7593)
authentication bypass in Ivanti virtual-traffic-manager (CVE-2024-7593). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2023-29357 KEV [KEV] Vulnerability in Microsoft sharepoint-server (CVE-2023-29357)
vulnerability in Microsoft sharepoint-server (CVE-2023-29357). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2016-9463 Vulnerability in nextcloud (CVE-2016-9463)
vulnerability in nextcloud (CVE-2016-9463). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →