Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5709 |
|
OS Command Injection in c (CVE-2026-5709)
OS command injection in c (CVE-2026-5709). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5684 |
|
Buffer Overflow in tenda (CVE-2026-5684)
vulnerability in tenda (CVE-2026-5684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5685 |
|
Buffer Overflow in tenda (CVE-2026-5685)
vulnerability in tenda (CVE-2026-5685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5686 |
|
Buffer Overflow in tenda (CVE-2026-5686)
vulnerability in tenda (CVE-2026-5686). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35444 |
|
Out-of-Bounds Read in c (CVE-2026-35444)
vulnerability in c (CVE-2026-35444). Confidential information can be exposed externally.
|
| CVE-2026-35412 |
|
Authorization Flaw in monospace (CVE-2026-35412)
vulnerability in monospace (CVE-2026-35412). Data can be tampered with by attackers. Mitigation: upgrade to `11.16.1` or later.
|
| CVE-2026-35442 |
|
Information Disclosure in monospace (CVE-2026-35442)
vulnerability in monospace (CVE-2026-35442). Confidential information can be exposed externally. Mitigation: upgrade to `11.17.0` or later.
|
| CVE-2026-35408 |
|
Vulnerability in monospace (CVE-2026-35408)
vulnerability in monospace (CVE-2026-35408). Confidential information can be exposed externally. Mitigation: upgrade to `11.17.0` or later.
|
| CVE-2026-35409 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-35409)
SSRF in ssrf (CVE-2026-35409). Confidential information can be exposed externally. Mitigation: upgrade to `11.16.0` or later.
|
| CVE-2026-35394 |
|
Vulnerability in mobilenexthq (CVE-2026-35394)
vulnerability in mobilenexthq (CVE-2026-35394). Data can be tampered with by attackers. Mitigation: upgrade to `0.0.50` or later.
|
| CVE-2026-35395 |
|
SQL Injection in sqli (CVE-2026-35395)
SQL injection in sqli (CVE-2026-35395). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.9` or later.
|
| CVE-2026-35213 |
|
Vulnerability in dos (CVE-2026-35213)
vulnerability in dos (CVE-2026-35213). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.1` or later.
|
| CVE-2026-35389 |
|
Vulnerability in bulwarkmail (CVE-2026-35389)
vulnerability in bulwarkmail (CVE-2026-35389). Data can be tampered with by attackers. Mitigation: upgrade to `1.4.11` or later.
|
| CVE-2026-35391 |
|
Vulnerability in bulwarkmail (CVE-2026-35391)
vulnerability in bulwarkmail (CVE-2026-35391). Data can be tampered with by attackers. Mitigation: upgrade to `1.4.11` or later.
|
| CVE-2025-54601 |
|
Vulnerability in samsung (CVE-2025-54601)
vulnerability in samsung (CVE-2025-54601). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35203 |
|
Out-of-Bounds Read in cpp (CVE-2026-35203)
vulnerability in cpp (CVE-2026-35203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35187 |
|
SSRF (Server-Side Request Forgery) in pyload-ng (CVE-2026-35187)
SSRF in pyload-ng (CVE-2026-35187). Confidential information can be exposed externally. Exploitable via ``parse_urls``.
|
| CVE-2026-35185 |
|
Vulnerability in psu (CVE-2026-35185)
vulnerability in psu (CVE-2026-35185). Confidential information can be exposed externally. Mitigation: upgrade to `25.0.0` or later.
|
| CVE-2026-35182 |
|
Vulnerability in ajax30 (CVE-2026-35182)
vulnerability in ajax30 (CVE-2026-35182). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-35183 |
|
Vulnerability in ajax30 (CVE-2026-35183)
vulnerability in ajax30 (CVE-2026-35183). Data can be tampered with by attackers. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-35172 |
|
Vulnerability in distribution (CVE-2026-35172)
vulnerability in distribution (CVE-2026-35172). Confidential information can be exposed externally. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-35170 |
|
Out-of-Bounds Read in trabucayre (CVE-2026-35170)
vulnerability in trabucayre (CVE-2026-35170). Confidential information can be exposed externally.
|
| CVE-2026-35176 |
|
Out-of-Bounds Read in trabucayre (CVE-2026-35176)
vulnerability in trabucayre (CVE-2026-35176). Confidential information can be exposed externally.
|
| CVE-2025-57834 |
|
Vulnerability in dos (CVE-2025-57834)
vulnerability in dos (CVE-2025-57834). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54602 |
|
Vulnerability in samsung (CVE-2025-54602)
vulnerability in samsung (CVE-2025-54602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5677 |
|
Command Injection in CVE-2026-5677 (CVE-2026-5677)
command injection in CVE-2026-5677 (CVE-2026-5677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5676 |
|
Authentication Bypass in CVE-2026-5676 (CVE-2026-5676)
authentication bypass in CVE-2026-5676 (CVE-2026-5676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5678 |
|
Command Injection in CVE-2026-5678 (CVE-2026-5678)
command injection in CVE-2026-5678 (CVE-2026-5678). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54324 |
|
Vulnerability in dos (CVE-2025-54324)
vulnerability in dos (CVE-2025-54324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5672 |
|
Vulnerability in sqli (CVE-2026-5672)
vulnerability in sqli (CVE-2026-5672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35209 |
|
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or...
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype...
|
| CVE-2026-35470 |
|
SQL Injection in sqli (CVE-2026-35470)
SQL injection in sqli (CVE-2026-35470). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.10.2` or later.
|
| CVE-2026-35029 |
|
Authorization Flaw in litellm (CVE-2026-35029)
vulnerability in litellm (CVE-2026-35029). Successful exploitation can lead to full system takeover. Exploitable via ``proxy_admin``. Mitigation: upgrade to `1.83.0` or later.
|
| CVE-2026-34982 |
|
OS Command Injection in vim (CVE-2026-34982)
OS command injection in vim (CVE-2026-34982). Confidential information can be exposed externally. Exploitable via ``complete``.
|
| CVE-2026-34379 |
|
Vulnerability in c (CVE-2026-34379)
vulnerability in c (CVE-2026-34379). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.7` or later.
|
| CVE-2026-34588 |
|
Out-of-Bounds Read in openexr (CVE-2026-34588)
vulnerability in openexr (CVE-2026-34588). Successful exploitation can lead to full system takeover. Exploitable via ``wcount``. Mitigation: upgrade to `3.4.9` or later.
|
| CVE-2026-3524 |
|
Vulnerability in mattermost (CVE-2026-3524)
vulnerability in mattermost (CVE-2026-3524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5633 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-5633 (CVE-2026-5633)
SSRF in CVE-2026-5633 (CVE-2026-5633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5634 |
|
Vulnerability in sqli (CVE-2026-5634)
vulnerability in sqli (CVE-2026-5634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31406 |
|
Vulnerability in linux (CVE-2026-31406)
vulnerability in linux (CVE-2026-31406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31407 |
|
Out-of-Bounds Write in linux (CVE-2026-31407)
out-of-bounds write in linux (CVE-2026-31407). Confidential information can be exposed externally.
|
| CVE-2026-31409 |
|
Vulnerability in linux (CVE-2026-31409)
vulnerability in linux (CVE-2026-31409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31408 |
|
Use-After-Free in linux (CVE-2026-31408)
vulnerability in linux (CVE-2026-31408). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5632 |
|
Authentication Bypass in CVE-2026-5632 (CVE-2026-5632)
authentication bypass in CVE-2026-5632 (CVE-2026-5632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5631 |
|
Vulnerability in CVE-2026-5631 (CVE-2026-5631)
vulnerability in CVE-2026-5631 (CVE-2026-5631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5628 |
|
Buffer Overflow in belkin (CVE-2026-5628)
vulnerability in belkin (CVE-2026-5628). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5629 |
|
Buffer Overflow in belkin (CVE-2026-5629)
vulnerability in belkin (CVE-2026-5629). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5616 |
|
Authentication Bypass in CVE-2026-5616 (CVE-2026-5616)
authentication bypass in CVE-2026-5616 (CVE-2026-5616). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5614 |
|
Buffer Overflow in belkin (CVE-2026-5614)
vulnerability in belkin (CVE-2026-5614). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5613 |
|
Buffer Overflow in belkin (CVE-2026-5613)
vulnerability in belkin (CVE-2026-5613). Successful exploitation can lead to full system takeover.
|