Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-15629 |
|
Vulnerability in tp-link (CVE-2025-15629)
vulnerability in tp-link (CVE-2025-15629). Confidential information can be exposed externally.
|
| CVE-2025-15627 |
|
Vulnerability in tp-link (CVE-2025-15627)
vulnerability in tp-link (CVE-2025-15627). Confidential information can be exposed externally.
|
| CVE-2026-69248 |
|
Vulnerability in cryptography (CVE-2026-69248)
vulnerability in cryptography (CVE-2026-69248). Risk of unauthorized operations or information disclosure. Exploitable via ``foo.example.com``. Mitigation: upgrade to `49.0.0` or later.
|
| CVE-2026-69249 |
|
Vulnerability in cryptography (CVE-2026-69249)
vulnerability in cryptography (CVE-2026-69249). Risk of unauthorized operations or information disclosure. Exploitable via ``build_chain_inner``. Mitigation: upgrade to `49.0.0` or later.
|
| CVE-2026-69247 |
|
Vulnerability in cryptography (CVE-2026-69247)
vulnerability in cryptography (CVE-2026-69247). Risk of unauthorized operations or information disclosure. Exploitable via ``pkcs7_decrypt_der``. Mitigation: upgrade to `50.0.0` or later.
|
| CVE-2026-66065 |
|
Vulnerability in CVE-2026-66065 (CVE-2026-66065)
vulnerability in CVE-2026-66065 (CVE-2026-66065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69246 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69246)
vulnerability in guzzlehttp/guzzle (CVE-2026-69246). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-69245 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69245)
vulnerability in guzzlehttp/guzzle (CVE-2026-69245). Risk of unauthorized operations or information disclosure. Exploitable via ``Domain``. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-69244 |
|
Out-of-Bounds Read in aiohttp (CVE-2026-69244)
vulnerability in aiohttp (CVE-2026-69244). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.3` or later.
|
| CVE-2026-69243 |
|
Vulnerability in aiohttp (CVE-2026-69243)
vulnerability in aiohttp (CVE-2026-69243). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.2` or later.
|
| CVE-2026-18654 |
|
Vulnerability in Amazon awscli (CVE-2026-18654)
vulnerability in Amazon awscli (CVE-2026-18654). Confidential information can be exposed externally. Mitigation: upgrade to `1.45.28` or later.
|
| CVE-2026-69240 |
|
SQL Injection in sequelize (CVE-2026-69240)
SQL injection in sequelize (CVE-2026-69240). Successful exploitation can lead to full system takeover. Exploitable via ``oracle``. Mitigation: upgrade to `6.37.4` or later.
|
| CVE-2026-69207 |
|
Vulnerability in hono (CVE-2026-69207)
vulnerability in hono (CVE-2026-69207). Risk of unauthorized operations or information disclosure. Exploitable via ``OPTIONS``. Mitigation: upgrade to `4.12.34` or later.
|
| GHSA-p538-c434-8v24 |
|
Vulnerability in GitPython (GHSA-p538-c434-8v24)
vulnerability in GitPython (GHSA-p538-c434-8v24). Risk of unauthorized operations or information disclosure. Exploitable via ``rev_list``. Mitigation: upgrade to `3.1.56` or later.
|
| GHSA-539m-9xh6-q6rr |
|
Vulnerability in GitPython (GHSA-539m-9xh6-q6rr)
vulnerability in GitPython (GHSA-539m-9xh6-q6rr). Risk of unauthorized operations or information disclosure. Exploitable via `GET /internal-metadata`. Mitigation: upgrade to `3.1.57` or later.
|
| GHSA-3f7w-8rr8-f37f |
|
Path Traversal in GitPython (GHSA-3f7w-8rr8-f37f)
path traversal in GitPython (GHSA-3f7w-8rr8-f37f). Risk of unauthorized operations or information disclosure. Exploitable via ``allow_unsafe_options``. Mitigation: upgrade to `3.1.57` or later.
|
| CVE-2026-69192 |
|
Vulnerability in ip-address (CVE-2026-69192)
vulnerability in ip-address (CVE-2026-69192). Risk of unauthorized operations or information disclosure. Exploitable via ``Address4``. Mitigation: upgrade to `10.3.1` or later.
|
| CVE-2026-69198 |
|
Vulnerability in ip-address (CVE-2026-69198)
vulnerability in ip-address (CVE-2026-69198). Risk of unauthorized operations or information disclosure. Exploitable via ``isInSubnet``. Mitigation: upgrade to `10.2.2` or later.
|
| CVE-2026-18655 |
|
Vulnerability in Amazon aws (CVE-2026-18655)
vulnerability in Amazon aws (CVE-2026-18655). Confidential information can be exposed externally.
|
| CVE-2026-69185 |
|
Vulnerability in socket.io-parser (CVE-2026-69185)
vulnerability in socket.io-parser (CVE-2026-69185). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.6` or later.
|
| CVE-2026-61524 |
|
Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18613 |
|
Vulnerability in CVE-2026-18613 (CVE-2026-18613)
vulnerability in CVE-2026-18613 (CVE-2026-18613). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61523 |
|
Code Injection in CVE-2026-61523 (CVE-2026-61523)
code injection in CVE-2026-61523 (CVE-2026-61523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18612 |
|
Vulnerability in CVE-2026-18612 (CVE-2026-18612)
vulnerability in CVE-2026-18612 (CVE-2026-18612). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40717 |
|
Vulnerability in dell (CVE-2026-40717)
vulnerability in dell (CVE-2026-40717). Data can be tampered with by attackers.
|
| CVE-2025-9291 |
|
Vulnerability in tp-link (CVE-2025-9291)
vulnerability in tp-link (CVE-2025-9291). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41452 |
|
Vulnerability in CVE-2026-41452 (CVE-2026-41452)
vulnerability in CVE-2026-41452 (CVE-2026-41452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67612 |
|
Cross-Site Scripting (XSS) in CVE-2026-67612 (CVE-2026-67612)
cross-site scripting in CVE-2026-67612 (CVE-2026-67612). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18718 |
|
Vulnerability in CVE-2026-18718 (CVE-2026-18718)
vulnerability in CVE-2026-18718 (CVE-2026-18718). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67611 |
|
Vulnerability in CVE-2026-67611 (CVE-2026-67611)
vulnerability in CVE-2026-67611 (CVE-2026-67611). Confidential information can be exposed externally.
|
| CVE-2026-68869 |
|
Vulnerability in CVE-2026-68869 (CVE-2026-68869)
vulnerability in CVE-2026-68869 (CVE-2026-68869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41453 |
|
SQL Injection in sqli (CVE-2026-41453)
SQL injection in sqli (CVE-2026-41453). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18607 |
|
Buffer Overflow in CVE-2026-18607 (CVE-2026-18607)
vulnerability in CVE-2026-18607 (CVE-2026-18607). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61372 |
|
Path Traversal in apache (CVE-2026-61372)
path traversal in apache (CVE-2026-61372). Confidential information can be exposed externally.
|
| CVE-2026-39931 |
|
Unrestricted File Upload in sqli (CVE-2026-39931)
vulnerability in sqli (CVE-2026-39931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18610 |
|
Authentication Bypass in CVE-2026-18610 (CVE-2026-18610)
authentication bypass in CVE-2026-18610 (CVE-2026-18610). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67610 |
|
Vulnerability in CVE-2026-67610 (CVE-2026-67610)
vulnerability in CVE-2026-67610 (CVE-2026-67610). Confidential information can be exposed externally.
|
| CVE-2026-39932 |
|
Vulnerability in CVE-2026-39932 (CVE-2026-39932)
vulnerability in CVE-2026-39932 (CVE-2026-39932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18606 |
|
Vulnerability in c (CVE-2026-18606)
vulnerability in c (CVE-2026-18606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18602 |
|
Vulnerability in CVE-2026-18602 (CVE-2026-18602)
vulnerability in CVE-2026-18602 (CVE-2026-18602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18477 |
|
Vulnerability in privilege-escalation (CVE-2026-18477)
vulnerability in privilege-escalation (CVE-2026-18477). Data can be tampered with by attackers.
|
| CVE-2026-18243 |
|
Cross-Site Scripting (XSS) in CVE-2026-18243 (CVE-2026-18243)
cross-site scripting in CVE-2026-18243 (CVE-2026-18243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18605 |
|
Vulnerability in CVE-2026-18605 (CVE-2026-18605)
vulnerability in CVE-2026-18605 (CVE-2026-18605). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18604 |
|
Vulnerability in CVE-2026-18604 (CVE-2026-18604)
vulnerability in CVE-2026-18604 (CVE-2026-18604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18651 |
|
Authentication Bypass in redhat (CVE-2026-18651)
authentication bypass in redhat (CVE-2026-18651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18568 |
|
Vulnerability in xml (CVE-2026-18568)
vulnerability in xml (CVE-2026-18568). Data can be tampered with by attackers. Exploitable via ``next``.
|
| CVE-2026-18508 |
|
Vulnerability in gnu (CVE-2026-18508)
vulnerability in gnu (CVE-2026-18508). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15430 |
|
Privilege Escalation in privilege-escalation (CVE-2026-15430)
vulnerability in privilege-escalation (CVE-2026-15430). Confidential information can be exposed externally.
|
| CVE-2026-69153 |
|
Path Traversal in postcss (CVE-2026-69153)
path traversal in postcss (CVE-2026-69153). Risk of unauthorized operations or information disclosure. Exploitable via ``sourceMappingURL``. Mitigation: upgrade to `8.5.23` or later.
|
| CVE-2026-69152 |
|
Vulnerability in brace-expansion (CVE-2026-69152)
vulnerability in brace-expansion (CVE-2026-69152). Risk of unauthorized operations or information disclosure. Exploitable via ``maxLength``. Mitigation: upgrade to `5.0.9` or later.
|