Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-40066 Vulnerability in anviz (CVE-2026-40066)
vulnerability in anviz (CVE-2026-40066). Successful exploitation can lead to full system takeover.
CVE-2026-5718 Unrestricted File Upload in wordpress (CVE-2026-5718)
vulnerability in wordpress (CVE-2026-5718). Successful exploitation can lead to full system takeover.
CVE-2026-21733 Vulnerability in imaginationtech (CVE-2026-21733)
vulnerability in imaginationtech (CVE-2026-21733). Confidential information can be exposed externally.
CVE-2026-40518 Path Traversal in path-traversal (CVE-2026-40518)
path traversal in path-traversal (CVE-2026-40518). Risk of unauthorized operations or information disclosure.
CVE-2026-40515 Authorization Flaw in hkuds (CVE-2026-40515)
vulnerability in hkuds (CVE-2026-40515). Confidential information can be exposed externally.
CVE-2026-40516 SSRF (Server-Side Request Forgery) in hkuds (CVE-2026-40516)
SSRF in hkuds (CVE-2026-40516). Risk of unauthorized operations or information disclosure.
CVE-2026-6507 Out-of-Bounds Write in dos (CVE-2026-6507)
out-of-bounds write in dos (CVE-2026-6507). Risk of unauthorized operations or information disclosure.
CVE-2025-15623 Vulnerability in sparxsystems (CVE-2025-15623)
vulnerability in sparxsystems (CVE-2025-15623). Confidential information can be exposed externally.
CVE-2025-15624 Vulnerability in sparxsystems (CVE-2025-15624)
vulnerability in sparxsystems (CVE-2025-15624). Confidential information can be exposed externally.
CVE-2026-23853 Vulnerability in dell (CVE-2026-23853)
vulnerability in dell (CVE-2026-23853). Successful exploitation can lead to full system takeover.
CVE-2026-5807 Vulnerability in github.com/hashicorp/vault (CVE-2026-5807)
vulnerability in github.com/hashicorp/vault (CVE-2026-5807). Risk of unauthorized operations or information disclosure.
CVE-2026-4525 Vulnerability in github.com/hashicorp/vault (CVE-2026-4525)
vulnerability in github.com/hashicorp/vault (CVE-2026-4525). Successful exploitation can lead to full system takeover.
CVE-2026-3605 Vulnerability in github.com/hashicorp/vault (CVE-2026-3605)
vulnerability in github.com/hashicorp/vault (CVE-2026-3605). Data can be tampered with by attackers.
CVE-2026-6100 Use-After-Free in python (CVE-2026-6100)
vulnerability in python (CVE-2026-6100). Successful exploitation can lead to full system takeover. Exploitable via ``lzma.LZMADecompressor``. Mitigation: upgrade to `3.14.5` or later.
CVE-2026-4786 Command Injection in libpython (CVE-2026-4786)
command injection in libpython (CVE-2026-4786). Confidential information can be exposed externally. Mitigation: upgrade to `3.14.5` or later.
CVE-2026-41113 OS Command Injection in c (CVE-2026-41113)
OS command injection in c (CVE-2026-41113). Successful exploitation can lead to full system takeover.
CVE-2026-40170 ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buf...
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transpo...
CVE-2025-54502 Vulnerability in privilege-escalation (CVE-2025-54502)
vulnerability in privilege-escalation (CVE-2025-54502). Successful exploitation can lead to full system takeover.
CVE-2026-56270 Vulnerability in flowise (CVE-2026-56270)
vulnerability in flowise (CVE-2026-56270). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/loginmethod`. Mitigation: upgrade to `3.1.0` or later.
CVE-2026-41205 Path Traversal in Mako (CVE-2026-41205)
path traversal in Mako (CVE-2026-41205). Confidential information can be exposed externally. Exploitable via ``Template.__init__``. Mitigation: upgrade to `1.3.11` or later.
CVE-2026-41082 Vulnerability in ocaml (CVE-2026-41082)
vulnerability in ocaml (CVE-2026-41082). Data can be tampered with by attackers.
CVE-2026-2336 Vulnerability in privilege-escalation (CVE-2026-2336)
vulnerability in privilege-escalation (CVE-2026-2336). Successful exploitation can lead to full system takeover.
CVE-2026-3324 Vulnerability in zohocorp (CVE-2026-3324)
vulnerability in zohocorp (CVE-2026-3324). Confidential information can be exposed externally.
CVE-2026-33804 Vulnerability in fastify (CVE-2026-33804)
vulnerability in fastify (CVE-2026-33804). Confidential information can be exposed externally.
CVE-2026-30459 Vulnerability in thedaylightstudio (CVE-2026-30459)
vulnerability in thedaylightstudio (CVE-2026-30459). Data can be tampered with by attackers.
CVE-2026-41035 In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort...
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort...
CVE-2026-6351 Vulnerability in CVE-2026-6351 (CVE-2026-6351)
vulnerability in CVE-2026-6351 (CVE-2026-6351). Confidential information can be exposed externally.
CVE-2026-6348 Vulnerability in CVE-2026-6348 (CVE-2026-6348)
vulnerability in CVE-2026-6348 (CVE-2026-6348). Successful exploitation can lead to full system takeover.
CVE-2026-40502 Vulnerability in hkuds (CVE-2026-40502)
vulnerability in hkuds (CVE-2026-40502). Successful exploitation can lead to full system takeover.
CVE-2026-5363 Vulnerability in tp-link (CVE-2026-5363)
vulnerability in tp-link (CVE-2026-5363). Successful exploitation can lead to full system takeover.
CVE-2026-34197 KEV [KEV] Vulnerability in Apache activemq (CVE-2026-34197)
vulnerability in Apache activemq (CVE-2026-34197). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-40316 OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflo...
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run with...
CVE-2026-6384 Vulnerability in dos (CVE-2026-6384)
vulnerability in dos (CVE-2026-6384). Successful exploitation can lead to full system takeover. Exploitable via ``ReadJeffsImage``.
CVE-2026-40176 Vulnerability in composer/composer (CVE-2026-40176)
vulnerability in composer/composer (CVE-2026-40176). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.2.27` or later.
CVE-2026-40261 Vulnerability in composer/composer (CVE-2026-40261)
vulnerability in composer/composer (CVE-2026-40261). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.2.27` or later.
CVE-2026-6361 Vulnerability in google (CVE-2026-6361)
vulnerability in google (CVE-2026-6361). Successful exploitation can lead to full system takeover.
CVE-2026-6363 Vulnerability in google (CVE-2026-6363)
vulnerability in google (CVE-2026-6363). Successful exploitation can lead to full system takeover.
CVE-2026-6360 Use-After-Free in google (CVE-2026-6360)
vulnerability in google (CVE-2026-6360). Successful exploitation can lead to full system takeover.
CVE-2026-6318 Use-After-Free in google (CVE-2026-6318)
vulnerability in google (CVE-2026-6318). Successful exploitation can lead to full system takeover.
CVE-2026-6319 Use-After-Free in google (CVE-2026-6319)
vulnerability in google (CVE-2026-6319). Successful exploitation can lead to full system takeover.
CVE-2026-6358 Use-After-Free in google (CVE-2026-6358)
vulnerability in google (CVE-2026-6358). Successful exploitation can lead to full system takeover.
CVE-2026-6314 Out-of-Bounds Write in google (CVE-2026-6314)
out-of-bounds write in google (CVE-2026-6314). Successful exploitation can lead to full system takeover.
CVE-2026-6315 Use-After-Free in google (CVE-2026-6315)
vulnerability in google (CVE-2026-6315). Successful exploitation can lead to full system takeover.
CVE-2026-6317 Use-After-Free in google (CVE-2026-6317)
vulnerability in google (CVE-2026-6317). Successful exploitation can lead to full system takeover.
CVE-2026-6316 Use-After-Free in google (CVE-2026-6316)
vulnerability in google (CVE-2026-6316). Successful exploitation can lead to full system takeover.
CVE-2026-6308 Out-of-Bounds Read in google (CVE-2026-6308)
vulnerability in google (CVE-2026-6308). Successful exploitation can lead to full system takeover.
CVE-2026-6309 Use-After-Free in google (CVE-2026-6309)
vulnerability in google (CVE-2026-6309). Successful exploitation can lead to full system takeover.
CVE-2026-6310 Use-After-Free in google (CVE-2026-6310)
vulnerability in google (CVE-2026-6310). Successful exploitation can lead to full system takeover.
CVE-2026-6311 Vulnerability in google (CVE-2026-6311)
vulnerability in google (CVE-2026-6311). Successful exploitation can lead to full system takeover.
CVE-2026-6301 Vulnerability in google (CVE-2026-6301)
vulnerability in google (CVE-2026-6301). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →