Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42043 |
|
Vulnerability in axios (CVE-2026-42043)
vulnerability in axios (CVE-2026-42043). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.15.1` or later.
|
| CVE-2026-42033 |
|
Vulnerability in axios (CVE-2026-42033)
vulnerability in axios (CVE-2026-42033). Confidential information can be exposed externally. Mitigation: upgrade to `1.15.1` or later.
|
| CVE-2026-41676 |
|
Vulnerability in rust-openssl-project (CVE-2026-41676)
vulnerability in rust-openssl-project (CVE-2026-41676). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.78` or later.
|
| CVE-2026-41681 |
|
Vulnerability in rust-openssl-project (CVE-2026-41681)
vulnerability in rust-openssl-project (CVE-2026-41681). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.78` or later.
|
| CVE-2026-41678 |
|
Out-of-Bounds Write in rust-openssl-project (CVE-2026-41678)
out-of-bounds write in rust-openssl-project (CVE-2026-41678). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.10.78` or later.
|
| CVE-2026-41140 |
|
Path Traversal in poetry (CVE-2026-41140)
path traversal in poetry (CVE-2026-41140). Data can be tampered with by attackers. Exploitable via ``tarfile.data_filter``. Mitigation: upgrade to `2.3.4` or later.
|
| CVE-2026-40897 |
|
Vulnerability in mathjs (CVE-2026-40897)
vulnerability in mathjs (CVE-2026-40897). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `15.2.0` or later.
|
| CVE-2026-40068 |
|
Vulnerability in @anthropic-ai/claude-code (CVE-2026-40068)
vulnerability in @anthropic-ai/claude-code (CVE-2026-40068). Successful exploitation can lead to full system takeover. Exploitable via ``commondir``. Mitigation: upgrade to `2.1.84` or later.
|
| CVE-2026-42239 |
|
Vulnerability in @budibase/backend-core (CVE-2026-42239)
vulnerability in @budibase/backend-core (CVE-2026-42239). Confidential information can be exposed externally. Exploitable via ``document.cookie``. Mitigation: upgrade to `3.35.10` or later.
|
| CVE-2026-41316 |
|
Vulnerability in erb (CVE-2026-41316)
vulnerability in erb (CVE-2026-41316). Successful exploitation can lead to full system takeover. Exploitable via ``Marshal.load``. Mitigation: upgrade to `6.0.4` or later.
|
| CVE-2026-31635 |
|
Vulnerability in c (CVE-2026-31635)
vulnerability in c (CVE-2026-31635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31641 |
|
Out-of-Bounds Read in linux (CVE-2026-31641)
vulnerability in linux (CVE-2026-31641). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5367 |
|
Vulnerability in CVE-2026-5367 (CVE-2026-5367)
vulnerability in CVE-2026-5367 (CVE-2026-5367). Confidential information can be exposed externally.
|
| CVE-2026-41246 |
|
Code Injection in github.com/projectcontour/contour (CVE-2026-41246)
code injection in github.com/projectcontour/contour (CVE-2026-41246). Confidential information can be exposed externally. Mitigation: upgrade to `1.33.4` or later.
|
| CVE-2026-31665 |
|
Use-After-Free in c (CVE-2026-31665)
vulnerability in c (CVE-2026-31665). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31663 |
|
Vulnerability in linux (CVE-2026-31663)
vulnerability in linux (CVE-2026-31663). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31656 |
|
Vulnerability in linux (CVE-2026-31656)
vulnerability in linux (CVE-2026-31656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31627 |
|
Vulnerability in linux (CVE-2026-31627)
vulnerability in linux (CVE-2026-31627). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31630 |
|
Vulnerability in c (CVE-2026-31630)
vulnerability in c (CVE-2026-31630). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31629 |
|
Vulnerability in linux (CVE-2026-31629)
vulnerability in linux (CVE-2026-31629). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31622 |
|
Vulnerability in linux (CVE-2026-31622)
vulnerability in linux (CVE-2026-31622). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31626 |
|
Vulnerability in c (CVE-2026-31626)
vulnerability in c (CVE-2026-31626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31613 |
|
Out-of-Bounds Read in linux (CVE-2026-31613)
vulnerability in linux (CVE-2026-31613). Confidential information can be exposed externally.
|
| CVE-2026-31611 |
|
Vulnerability in linux (CVE-2026-31611)
vulnerability in linux (CVE-2026-31611). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31612 |
|
Vulnerability in linux (CVE-2026-31612)
vulnerability in linux (CVE-2026-31612). Confidential information can be exposed externally.
|
| CVE-2026-31602 |
|
Vulnerability in linux (CVE-2026-31602)
vulnerability in linux (CVE-2026-31602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31597 |
|
Use-After-Free in c (CVE-2026-31597)
vulnerability in c (CVE-2026-31597). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31598 |
|
Vulnerability in linux (CVE-2026-31598)
vulnerability in linux (CVE-2026-31598). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31583 |
|
Use-After-Free in linux (CVE-2026-31583)
vulnerability in linux (CVE-2026-31583). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31586 |
|
Use-After-Free in c (CVE-2026-31586)
vulnerability in c (CVE-2026-31586). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31587 |
|
Use-After-Free in c (CVE-2026-31587)
vulnerability in c (CVE-2026-31587). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31588 |
|
Use-After-Free in linux (CVE-2026-31588)
vulnerability in linux (CVE-2026-31588). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31576 |
|
Use-After-Free in linux (CVE-2026-31576)
vulnerability in linux (CVE-2026-31576). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31578 |
|
Use-After-Free in c (CVE-2026-31578)
vulnerability in c (CVE-2026-31578). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31580 |
|
Use-After-Free in linux (CVE-2026-31580)
vulnerability in linux (CVE-2026-31580). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31581 |
|
Use-After-Free in c (CVE-2026-31581)
vulnerability in c (CVE-2026-31581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31563 |
|
Vulnerability in c (CVE-2026-31563)
vulnerability in c (CVE-2026-31563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40466 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-41044 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-21728 |
|
Vulnerability in github.com/grafana/tempo (CVE-2026-21728)
vulnerability in github.com/grafana/tempo (CVE-2026-21728). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6947 |
|
Vulnerability in CVE-2026-6947 (CVE-2026-6947)
vulnerability in CVE-2026-6947 (CVE-2026-6947). Data can be tampered with by attackers.
|
| CVE-2026-33317 |
|
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, mis...
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()` in `ta/pkcs11/src/object.c` can lead to out-of-bounds...
|
| CVE-2025-29635 KEV |
|
[KEV] Command Injection in D-link dir-823x (CVE-2025-29635)
command injection in D-link dir-823x (CVE-2025-29635). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-7399 KEV |
|
[KEV] Path Traversal in Samsung magicinfo-9-server (CVE-2024-7399)
path traversal in Samsung magicinfo-9-server (CVE-2024-7399). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-57728 KEV |
|
[KEV] Path Traversal in Simplehelp path-traversal (CVE-2024-57728)
path traversal in Simplehelp path-traversal (CVE-2024-57728). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-57726 KEV |
|
[KEV] Vulnerability in Simplehelp auth (CVE-2024-57726)
vulnerability in Simplehelp auth (CVE-2024-57726). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-41355 |
|
Vulnerability in openclaw (CVE-2026-41355)
vulnerability in openclaw (CVE-2026-41355). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33694 |
|
Vulnerability in tenable (CVE-2026-33694)
vulnerability in tenable (CVE-2026-33694). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40886 |
|
Vulnerability in github.com/argoproj/argo-workflows/v4 (CVE-2026-40886)
vulnerability in github.com/argoproj/argo-workflows/v4 (CVE-2026-40886). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-6921 |
|
Vulnerability in google (CVE-2026-6921)
vulnerability in google (CVE-2026-6921). Successful exploitation can lead to full system takeover.
|