Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-41604 |
|
Out-of-Bounds Read in thrift (CVE-2026-41604)
vulnerability in thrift (CVE-2026-41604). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-41605 |
|
Vulnerability in thrift (CVE-2026-41605)
vulnerability in thrift (CVE-2026-41605). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-3323 |
|
Vulnerability in vega (CVE-2026-3323)
vulnerability in vega (CVE-2026-3323). Confidential information can be exposed externally.
|
| CVE-2026-41602 |
|
Vulnerability in thrift (CVE-2026-41602)
vulnerability in thrift (CVE-2026-41602). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2024-54013 |
|
Vulnerability in hanwhavision (CVE-2024-54013)
vulnerability in hanwhavision (CVE-2024-54013). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7223 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-7223 (CVE-2026-7223)
SSRF in CVE-2026-7223 (CVE-2026-7223). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7220 |
|
Command Injection in CVE-2026-7220 (CVE-2026-7220)
command injection in CVE-2026-7220 (CVE-2026-7220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7221 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-7221 (CVE-2026-7221)
SSRF in CVE-2026-7221 (CVE-2026-7221). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7219 |
|
Buffer Overflow in CVE-2026-7219 (CVE-2026-7219)
vulnerability in CVE-2026-7219 (CVE-2026-7219). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7215 |
|
Vulnerability in CVE-2026-7215 (CVE-2026-7215)
vulnerability in CVE-2026-7215 (CVE-2026-7215). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7216 |
|
Path Traversal in path-traversal (CVE-2026-7216)
path traversal in path-traversal (CVE-2026-7216). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7218 |
|
Buffer Overflow in CVE-2026-7218 (CVE-2026-7218)
vulnerability in CVE-2026-7218 (CVE-2026-7218). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1460 |
|
OS Command Injection in zyxel (CVE-2026-1460)
OS command injection in zyxel (CVE-2026-1460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7213 |
|
Path Traversal in path-traversal (CVE-2026-7213)
path traversal in path-traversal (CVE-2026-7213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7214 |
|
Path Traversal in path-traversal (CVE-2026-7214)
path traversal in path-traversal (CVE-2026-7214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7212 |
|
Path Traversal in notes-mcp (CVE-2026-7212)
path traversal in notes-mcp (CVE-2026-7212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7211 |
|
Vulnerability in CVE-2026-7211 (CVE-2026-7211)
vulnerability in CVE-2026-7211 (CVE-2026-7211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7206 |
|
Vulnerability in sqlite-mcp (CVE-2026-7206)
vulnerability in sqlite-mcp (CVE-2026-7206). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7205 |
|
Path Traversal in path-traversal (CVE-2026-7205)
path traversal in path-traversal (CVE-2026-7205). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20766 |
|
Vulnerability in CVE-2026-20766 (CVE-2026-20766)
vulnerability in CVE-2026-20766 (CVE-2026-20766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40973 |
|
Vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973)
vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973). Successful exploitation can lead to full system takeover. Exploitable via ``ApplicationTemp``.
|
| CVE-2026-41371 |
|
Vulnerability in openclaw (CVE-2026-41371)
vulnerability in openclaw (CVE-2026-41371). Data can be tampered with by attackers. Exploitable via ``chat.send``. Mitigation: upgrade to `>= 2026.3.28` or later.
|
| CVE-2026-7199 |
|
Vulnerability in sqli (CVE-2026-7199)
vulnerability in sqli (CVE-2026-7199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41364 |
|
Vulnerability in openclaw (CVE-2026-41364)
vulnerability in openclaw (CVE-2026-41364). Data can be tampered with by attackers.
|
| CVE-2026-40972 |
|
Vulnerability in spring (CVE-2026-40972)
vulnerability in spring (CVE-2026-40972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27785 |
|
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
|
| CVE-2024-1708 KEV |
|
[KEV] Path Traversal in Connectwise screenconnect (CVE-2024-1708)
path traversal in Connectwise screenconnect (CVE-2024-1708). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-7194 |
|
Vulnerability in sqli (CVE-2026-7194)
vulnerability in sqli (CVE-2026-7194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28747 |
|
Vulnerability in CVE-2026-28747 (CVE-2026-28747)
vulnerability in CVE-2026-28747 (CVE-2026-28747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7178 |
|
SSRF (Server-Side Request Forgery) in nextchat (CVE-2026-7178)
SSRF in nextchat (CVE-2026-7178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3087 |
|
Path Traversal in libpython (CVE-2026-3087)
path traversal in libpython (CVE-2026-3087). Data can be tampered with by attackers. Mitigation: upgrade to `3.14.5` or later.
|
| CVE-2026-31686 |
|
Vulnerability in linux (CVE-2026-31686)
vulnerability in linux (CVE-2026-31686). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38934 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-38934 (CVE-2026-38934)
vulnerability in CVE-2026-38934 (CVE-2026-38934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40022 |
|
Vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022)
vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022). Confidential information can be exposed externally. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-27172 |
|
Unsafe Deserialization in apache (CVE-2026-27172)
vulnerability in apache (CVE-2026-27172). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40858 |
|
Unsafe Deserialization in apache (CVE-2026-40858)
vulnerability in apache (CVE-2026-40858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7101 |
|
Buffer Overflow in tenda (CVE-2026-7101)
vulnerability in tenda (CVE-2026-7101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40048 |
|
Unsafe Deserialization in apache (CVE-2026-40048)
vulnerability in apache (CVE-2026-40048). Successful exploitation can lead to full system takeover. Exploitable via ``java.security.KeyPair``.
|
| CVE-2026-40473 |
|
Unsafe Deserialization in apache (CVE-2026-40473)
vulnerability in apache (CVE-2026-40473). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3006 |
|
Vulnerability in privilege-escalation (CVE-2026-3006)
vulnerability in privilege-escalation (CVE-2026-3006). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6786 |
|
Out-of-Bounds Read in mozilla (CVE-2026-6786)
vulnerability in mozilla (CVE-2026-6786). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6785 |
|
Out-of-Bounds Read in mozilla (CVE-2026-6785)
vulnerability in mozilla (CVE-2026-6785). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31676 |
|
Vulnerability in linux (CVE-2026-31676)
vulnerability in linux (CVE-2026-31676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31680 |
|
Vulnerability in linux (CVE-2026-31680)
vulnerability in linux (CVE-2026-31680). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31673 |
|
Vulnerability in linux (CVE-2026-31673)
vulnerability in linux (CVE-2026-31673). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31674 |
|
Vulnerability in linux (CVE-2026-31674)
vulnerability in linux (CVE-2026-31674). Confidential information can be exposed externally.
|
| CVE-2026-42171 |
|
Vulnerability in nullsoft (CVE-2026-42171)
vulnerability in nullsoft (CVE-2026-42171). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41433 |
|
Path Traversal in go.opentelemetry.io/obi (CVE-2026-41433)
path traversal in go.opentelemetry.io/obi (CVE-2026-41433). Data can be tampered with by attackers. Exploitable via ``TMPDIR``. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-41907 |
|
Vulnerability in uuid (CVE-2026-41907)
vulnerability in uuid (CVE-2026-41907). Data can be tampered with by attackers. Exploitable via ``uuid``. Mitigation: upgrade to `13.0.1` or later.
|
| CVE-2026-33662 |
|
Vulnerability in c (CVE-2026-33662)
vulnerability in c (CVE-2026-33662). Risk of unauthorized operations or information disclosure.
|