Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-34601 |
|
Vulnerability in CVE-2026-34601 (CVE-2026-34601)
vulnerability in CVE-2026-34601 (CVE-2026-34601). Data can be tampered with by attackers. Exploitable via ``DOMParser``.
|
| CVE-2026-34593 |
|
Vulnerability in ash-hq (CVE-2026-34593)
vulnerability in ash-hq (CVE-2026-34593). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34576 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34576)
SSRF in ssrf (CVE-2026-34576). Confidential information can be exposed externally. Exploitable via `POST /public/v1/upload-from-url`.
|
| CVE-2026-34577 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34577)
SSRF in ssrf (CVE-2026-34577). Confidential information can be exposed externally. Exploitable via `GET /public/stream`.
|
| CVE-2026-34522 |
|
Path Traversal in path-traversal (CVE-2026-34522)
path traversal in path-traversal (CVE-2026-34522). Data can be tampered with by attackers.
|
| CVE-2026-34524 |
|
Path Traversal in path-traversal (CVE-2026-34524)
path traversal in path-traversal (CVE-2026-34524). Confidential information can be exposed externally.
|
| CVE-2026-34121 |
|
Authentication Bypass in tp-link (CVE-2026-34121)
authentication bypass in tp-link (CVE-2026-34121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33951 |
|
Vulnerability in signalk (CVE-2026-33951)
vulnerability in signalk (CVE-2026-33951). Data can be tampered with by attackers. Exploitable via `PUT /signalk/v1/api/sourcePriorities`.
|
| CVE-2025-65114 |
|
Vulnerability in apache (CVE-2025-65114)
vulnerability in apache (CVE-2025-65114). Data can be tampered with by attackers.
|
| CVE-2025-58136 |
|
Vulnerability in apache (CVE-2025-58136)
vulnerability in apache (CVE-2025-58136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5350 |
|
Buffer Overflow in trendnet (CVE-2026-5350)
vulnerability in trendnet (CVE-2026-5350). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5349 |
|
Buffer Overflow in trendnet (CVE-2026-5349)
vulnerability in trendnet (CVE-2026-5349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34876 |
|
Out-of-Bounds Read in c (CVE-2026-34876)
vulnerability in c (CVE-2026-34876). Confidential information can be exposed externally.
|
| CVE-2026-30332 |
|
Vulnerability in CVE-2026-30332 (CVE-2026-30332)
vulnerability in CVE-2026-30332 (CVE-2026-30332). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5346 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-5346 (CVE-2026-5346)
SSRF in CVE-2026-5346 (CVE-2026-5346). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34796 |
|
OS Command Injection in endian (CVE-2026-34796)
OS command injection in endian (CVE-2026-34796). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34797 |
|
OS Command Injection in endian (CVE-2026-34797)
OS command injection in endian (CVE-2026-34797). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34794 |
|
OS Command Injection in endian (CVE-2026-34794)
OS command injection in endian (CVE-2026-34794). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34795 |
|
OS Command Injection in endian (CVE-2026-34795)
OS command injection in endian (CVE-2026-34795). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34792 |
|
OS Command Injection in endian (CVE-2026-34792)
OS command injection in endian (CVE-2026-34792). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34793 |
|
OS Command Injection in endian (CVE-2026-34793)
OS command injection in endian (CVE-2026-34793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3692 |
|
OS Command Injection in progress (CVE-2026-3692)
OS command injection in progress (CVE-2026-3692). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4634 |
|
Vulnerability in dos (CVE-2026-4634)
vulnerability in dos (CVE-2026-4634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4636 |
|
Vulnerability in redhat (CVE-2026-4636)
vulnerability in redhat (CVE-2026-4636). Confidential information can be exposed externally.
|
| CVE-2026-3872 |
|
Open Redirect in redhat (CVE-2026-3872)
vulnerability in redhat (CVE-2026-3872). Confidential information can be exposed externally.
|
| CVE-2026-4282 |
|
Vulnerability in privilege-escalation (CVE-2026-4282)
vulnerability in privilege-escalation (CVE-2026-4282). Confidential information can be exposed externally.
|
| CVE-2026-23414 |
|
Vulnerability in linux (CVE-2026-23414)
vulnerability in linux (CVE-2026-23414). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3502 KEV |
|
[KEV] Vulnerability in Trueconf client (CVE-2026-3502)
vulnerability in Trueconf client (CVE-2026-3502). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-3987 |
|
Path Traversal in path-traversal (CVE-2026-3987)
path traversal in path-traversal (CVE-2026-3987). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34545 |
|
Vulnerability in openexr (CVE-2026-34545)
vulnerability in openexr (CVE-2026-34545). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34874 |
|
Vulnerability in trustedfirmware (CVE-2026-34874)
vulnerability in trustedfirmware (CVE-2026-34874). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25835 |
|
Vulnerability in arm (CVE-2026-25835)
vulnerability in arm (CVE-2026-25835). Confidential information can be exposed externally.
|
| CVE-2026-25833 |
|
Vulnerability in trustedfirmware (CVE-2026-25833)
vulnerability in trustedfirmware (CVE-2026-25833). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.6` or later.
|
| CVE-2026-34072 |
|
Authentication Bypass in fccview (CVE-2026-34072)
authentication bypass in fccview (CVE-2026-34072). Confidential information can be exposed externally.
|
| CVE-2026-27489 |
|
Vulnerability in onnx (CVE-2026-27489)
vulnerability in onnx (CVE-2026-27489). Confidential information can be exposed externally. Exploitable via ``model.data``. Mitigation: upgrade to `1.21.0` or later.
|
| CVE-2026-35093 |
|
Code Injection in freedesktop (CVE-2026-35093)
code injection in freedesktop (CVE-2026-35093). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35091 |
|
Vulnerability in dos (CVE-2026-35091)
vulnerability in dos (CVE-2026-35091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35092 |
|
Vulnerability in dos (CVE-2026-35092)
vulnerability in dos (CVE-2026-35092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34430 |
|
Vulnerability in deerflow (CVE-2026-34430)
vulnerability in deerflow (CVE-2026-34430). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5272 |
|
Vulnerability in google (CVE-2026-5272)
vulnerability in google (CVE-2026-5272). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5281 KEV |
|
[KEV] Use-After-Free in Google dawn (CVE-2026-5281)
vulnerability in Google dawn (CVE-2026-5281). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34453 |
|
Authorization Flaw in github.com/siyuan-note/siyuan/kernel (CVE-2026-34453)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34453). Confidential information can be exposed externally. Exploitable via `POST /api/bookmark/getBookmark`. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34404 |
|
Vulnerability in vue (CVE-2026-34404)
vulnerability in vue (CVE-2026-34404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34406 |
|
Vulnerability in django (CVE-2026-34406)
vulnerability in django (CVE-2026-34406). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/auth/edituser/`.
|
| CVE-2026-5213 |
|
Buffer Overflow in dlink (CVE-2026-5213)
vulnerability in dlink (CVE-2026-5213). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5212 |
|
Buffer Overflow in dlink (CVE-2026-5212)
vulnerability in dlink (CVE-2026-5212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34731 |
|
Vulnerability in wwbn (CVE-2026-34731)
vulnerability in wwbn (CVE-2026-34731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34381 |
|
Vulnerability in apache (CVE-2026-34381)
vulnerability in apache (CVE-2026-34381). Confidential information can be exposed externally.
|
| CVE-2026-34394 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34394)
vulnerability in csrf (CVE-2026-34394). Confidential information can be exposed externally.
|
| CVE-2026-34366 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34366)
SSRF in ssrf (CVE-2026-34366). Confidential information can be exposed externally.
|