Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-31731 |
|
Use-After-Free in linux (CVE-2026-31731)
vulnerability in linux (CVE-2026-31731). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31712 |
|
Out-of-Bounds Write in linux (CVE-2026-31712)
out-of-bounds write in linux (CVE-2026-31712). Confidential information can be exposed externally.
|
| CVE-2026-31715 |
|
Use-After-Free in linux (CVE-2026-31715)
vulnerability in linux (CVE-2026-31715). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31711 |
|
Vulnerability in linux (CVE-2026-31711)
vulnerability in linux (CVE-2026-31711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31716 |
|
Out-of-Bounds Write in linux (CVE-2026-31716)
out-of-bounds write in linux (CVE-2026-31716). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31717 |
|
Vulnerability in linux (CVE-2026-31717)
vulnerability in linux (CVE-2026-31717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31709 |
|
Vulnerability in linux (CVE-2026-31709)
vulnerability in linux (CVE-2026-31709). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31707 |
|
Out-of-Bounds Write in c (CVE-2026-31707)
out-of-bounds write in c (CVE-2026-31707). Confidential information can be exposed externally.
|
| CVE-2026-31703 |
|
Use-After-Free in linux (CVE-2026-31703)
vulnerability in linux (CVE-2026-31703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31702 |
|
Use-After-Free in c (CVE-2026-31702)
vulnerability in c (CVE-2026-31702). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31708 |
|
Out-of-Bounds Read in linux (CVE-2026-31708)
vulnerability in linux (CVE-2026-31708). Confidential information can be exposed externally.
|
| CVE-2026-31694 |
|
Vulnerability in linux (CVE-2026-31694)
vulnerability in linux (CVE-2026-31694). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31696 |
|
Out-of-Bounds Write in c (CVE-2026-31696)
out-of-bounds write in c (CVE-2026-31696). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31697 |
|
Out-of-Bounds Write in c (CVE-2026-31697)
out-of-bounds write in c (CVE-2026-31697). Confidential information can be exposed externally.
|
| CVE-2026-31698 |
|
Out-of-Bounds Write in c (CVE-2026-31698)
out-of-bounds write in c (CVE-2026-31698). Confidential information can be exposed externally.
|
| CVE-2026-31699 |
|
Out-of-Bounds Write in c (CVE-2026-31699)
out-of-bounds write in c (CVE-2026-31699). Confidential information can be exposed externally.
|
| CVE-2026-31700 |
|
Vulnerability in c (CVE-2026-31700)
vulnerability in c (CVE-2026-31700). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43001 |
|
Authorization Flaw in keystone (CVE-2026-43001)
vulnerability in keystone (CVE-2026-43001). Confidential information can be exposed externally. Exploitable via `POST /v3/credentials`.
|
| CVE-2026-43003 |
|
OS Command Injection in ironic-python-agent (CVE-2026-43003)
OS command injection in ironic-python-agent (CVE-2026-43003). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.6.0` or later.
|
| CVE-2026-5405 |
|
Vulnerability in dos (CVE-2026-5405)
vulnerability in dos (CVE-2026-5405). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5403 |
|
Vulnerability in dos (CVE-2026-5403)
vulnerability in dos (CVE-2026-5403). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5656 |
|
Path Traversal in path-traversal (CVE-2026-5656)
path traversal in path-traversal (CVE-2026-5656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31431 KEV |
|
[KEV] Vulnerability in Linux redhat (CVE-2026-31431)
vulnerability in Linux redhat (CVE-2026-31431). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-6543 |
|
Code Injection in langflow (CVE-2026-6543)
code injection in langflow (CVE-2026-6543). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4503 |
|
Vulnerability in langflow (CVE-2026-4503)
vulnerability in langflow (CVE-2026-4503). Confidential information can be exposed externally.
|
| CVE-2026-40912 |
|
Path Traversal in github.com/traefik/traefik/v3 (CVE-2026-40912)
path traversal in github.com/traefik/traefik/v3 (CVE-2026-40912). Confidential information can be exposed externally. Mitigation: upgrade to `3.6.14, 3.7.0-rc.2` or later.
|
| CVE-2026-33845 |
|
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero...
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero...
|
| CVE-2026-41654 |
|
Vulnerability in weblate (CVE-2026-41654)
vulnerability in weblate (CVE-2026-41654). Confidential information can be exposed externally. Exploitable via ``project.add``. Mitigation: upgrade to `5.17.1` or later.
|
| CVE-2026-36960 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-36960)
vulnerability in csrf (CVE-2026-36960). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14576 |
|
Vulnerability in dos (CVE-2025-14576)
vulnerability in dos (CVE-2025-14576). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36959 |
|
Vulnerability in u-speed (CVE-2026-36959)
vulnerability in u-speed (CVE-2026-36959). Confidential information can be exposed externally.
|
| CVE-2026-36956 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-36956)
vulnerability in csrf (CVE-2026-36956). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36957 |
|
Vulnerability in dos (CVE-2026-36957)
vulnerability in dos (CVE-2026-36957). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36958 |
|
Vulnerability in u-speed (CVE-2026-36958)
vulnerability in u-speed (CVE-2026-36958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7246 |
|
Command Injection in click (CVE-2026-7246)
command injection in click (CVE-2026-7246). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.3.3` or later.
|
| CVE-2026-7399 |
|
Vulnerability in CVE-2026-7399 (CVE-2026-7399)
vulnerability in CVE-2026-7399 (CVE-2026-7399). Confidential information can be exposed externally.
|
| CVE-2026-7402 |
|
Vulnerability in CVE-2026-7402 (CVE-2026-7402)
vulnerability in CVE-2026-7402 (CVE-2026-7402). Data can be tampered with by attackers.
|
| CVE-2024-13971 |
|
XXE (XML External Entity) in lobster-world (CVE-2024-13971)
vulnerability in lobster-world (CVE-2024-13971). Confidential information can be exposed externally.
|
| CVE-2026-5402 |
|
Vulnerability in dos (CVE-2026-5402)
vulnerability in dos (CVE-2026-5402). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7270 |
|
Vulnerability in freebsd (CVE-2026-7270)
vulnerability in freebsd (CVE-2026-7270). Successful exploitation can lead to full system takeover.
|
| CVE-2024-39847 |
|
XXE (XML External Entity) in 4d (CVE-2024-39847)
vulnerability in 4d (CVE-2024-39847). Confidential information can be exposed externally.
|
| CVE-2026-41940 KEV |
|
[KEV] Vulnerability in Webpros cpanel-whm-and-wp2-wordpress-squared (CVE-2026-41940)
vulnerability in Webpros cpanel-whm-and-wp2-wordpress-squared (CVE-2026-41940). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-44015 |
|
SSRF (Server-Side Request Forgery) in github.com/0xJacky/Nginx-UI (CVE-2026-44015)
SSRF in github.com/0xJacky/Nginx-UI (CVE-2026-44015). Confidential information can be exposed externally. Exploitable via `GET /api/settings`.
|
| CVE-2018-25304 |
|
Vulnerability in CVE-2018-25304 (CVE-2018-25304)
vulnerability in CVE-2018-25304 (CVE-2018-25304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37555 |
|
Vulnerability in dos (CVE-2026-37555)
vulnerability in dos (CVE-2026-37555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6849 |
|
Improper neutralization of special elements used in an OS command ('OS command injection')...
Improper neutralization of special elements used in an OS command ('OS command injection')...
|
| CVE-2026-42198 |
|
Vulnerability in dos (CVE-2026-42198)
vulnerability in dos (CVE-2026-42198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7111 |
|
Use-After-Free in hmbrand (CVE-2026-7111)
vulnerability in hmbrand (CVE-2026-7111). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5161 |
|
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM...
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM...
|
| CVE-2026-5141 |
|
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
|