Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-1731 KEV [KEV] OS Command Injection in Beyondtrust remote-support-rs-and-privileged-remote-access-pra (CVE-2026-1731)
OS command injection in Beyondtrust remote-support-rs-and-privileged-remote-access-pra (CVE-2026-1731). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-25949 Vulnerability in github.com/traefik/traefik/v3 (CVE-2026-25949)
vulnerability in github.com/traefik/traefik/v3 (CVE-2026-25949). Risk of unauthorized operations or information disclosure. Exploitable via ``respondingTimeouts.readTimeout``. Mitigation: upgrade to `3.6.8` or later.
CVE-2026-26217 Path Traversal in crawl4ai (CVE-2026-26217)
path traversal in crawl4ai (CVE-2026-26217). Confidential information can be exposed externally. Exploitable via `POST /execute_js`. Mitigation: upgrade to `0.8.0` or later.
CVE-2026-26214 Vulnerability in apache (CVE-2026-26214)
vulnerability in apache (CVE-2026-26214). Confidential information can be exposed externally.
CVE-2025-13002 Cross-Site Scripting (XSS) in farktor (CVE-2025-13002)
cross-site scripting in farktor (CVE-2025-13002). Risk of unauthorized operations or information disclosure.
CVE-2026-2004 Vulnerability in postgresql (CVE-2026-2004)
vulnerability in postgresql (CVE-2026-2004). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.21.0, 15.16.0, 16.12.0, 17.8.0, 18.2.0` or later.
CVE-2026-2005 Vulnerability in postgresql (CVE-2026-2005)
vulnerability in postgresql (CVE-2026-2005). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.21.0, 15.16.0, 16.12.0, 17.8.0, 18.2.0` or later.
CVE-2026-2006 Vulnerability in postgresql (CVE-2026-2006)
vulnerability in postgresql (CVE-2026-2006). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.21.0, 15.16.0, 16.12.0, 17.8.0, 18.2.0` or later.
CVE-2026-2007 Vulnerability in postgresql (CVE-2026-2007)
vulnerability in postgresql (CVE-2026-2007). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.2.0` or later.
CVE-2026-20700 KEV [KEV] Buffer Overflow in Apple multiple-products (CVE-2026-20700)
vulnerability in Apple multiple-products (CVE-2026-20700). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-43468 KEV [KEV] SQL Injection in Microsoft configuration-manager (CVE-2024-43468)
SQL injection in Microsoft configuration-manager (CVE-2024-43468). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-15556 KEV [KEV] Vulnerability in Notepad++ notepad (CVE-2025-15556)
vulnerability in Notepad++ notepad (CVE-2025-15556). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-40536 KEV [KEV] Vulnerability in Solarwinds web-help-desk (CVE-2025-40536)
vulnerability in Solarwinds web-help-desk (CVE-2025-40536). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-20615 Path Traversal in apple (CVE-2026-20615)
path traversal in apple (CVE-2026-20615). Successful exploitation can lead to full system takeover.
CVE-2026-20617 Vulnerability in apple (CVE-2026-20617)
vulnerability in apple (CVE-2026-20617). Successful exploitation can lead to full system takeover.
CVE-2026-1669 Information Disclosure in keras (CVE-2026-1669)
vulnerability in keras (CVE-2026-1669). Confidential information can be exposed externally. Exploitable via ``ExternalLink``. Mitigation: upgrade to `3.12.1` or later.
CVE-2026-26157 Vulnerability in CVE-2026-26157 (CVE-2026-26157)
vulnerability in CVE-2026-26157 (CVE-2026-26157). Successful exploitation can lead to full system takeover.
CVE-2026-26158 Vulnerability in privilege-escalation (CVE-2026-26158)
vulnerability in privilege-escalation (CVE-2026-26158). Successful exploitation can lead to full system takeover.
CVE-2026-25990 Out-of-Bounds Write in pillow (CVE-2026-25990)
out-of-bounds write in pillow (CVE-2026-25990). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.1.1` or later.
CVE-2020-37208 SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste i...
SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.
CVE-2020-37209 Vulnerability in dos (CVE-2020-37209)
vulnerability in dos (CVE-2020-37209). Confidential information can be exposed externally.
CVE-2020-37210 SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste i...
SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.
CVE-2020-37211 SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character...
SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.
CVE-2020-37212 SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste...
SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.
CVE-2020-37204 Vulnerability in dos (CVE-2020-37204)
vulnerability in dos (CVE-2020-37204). Risk of unauthorized operations or information disclosure.
CVE-2020-37205 Vulnerability in dos (CVE-2020-37205)
vulnerability in dos (CVE-2020-37205). Risk of unauthorized operations or information disclosure.
CVE-2020-37206 Vulnerability in dos (CVE-2020-37206)
vulnerability in dos (CVE-2020-37206). Risk of unauthorized operations or information disclosure.
CVE-2020-37207 Vulnerability in dos (CVE-2020-37207)
vulnerability in dos (CVE-2020-37207). Risk of unauthorized operations or information disclosure.
CVE-2020-37196 Vulnerability in dos (CVE-2020-37196)
vulnerability in dos (CVE-2020-37196). Risk of unauthorized operations or information disclosure.
CVE-2020-37197 Vulnerability in dos (CVE-2020-37197)
vulnerability in dos (CVE-2020-37197). Risk of unauthorized operations or information disclosure.
CVE-2020-37199 Vulnerability in dos (CVE-2020-37199)
vulnerability in dos (CVE-2020-37199). Risk of unauthorized operations or information disclosure.
CVE-2020-37200 Vulnerability in nsasoft (CVE-2020-37200)
vulnerability in nsasoft (CVE-2020-37200). Risk of unauthorized operations or information disclosure.
CVE-2020-37201 Vulnerability in nsasoft (CVE-2020-37201)
vulnerability in nsasoft (CVE-2020-37201). Risk of unauthorized operations or information disclosure.
CVE-2026-1837 Vulnerability in libjxl-project (CVE-2026-1837)
vulnerability in libjxl-project (CVE-2026-1837). Risk of unauthorized operations or information disclosure.
CVE-2025-65480 OS Command Injection in CVE-2025-65480 (CVE-2025-65480)
OS command injection in CVE-2025-65480 (CVE-2025-65480). Successful exploitation can lead to full system takeover.
CVE-2026-25869 Path Traversal in path-traversal (CVE-2026-25869)
path traversal in path-traversal (CVE-2026-25869). Confidential information can be exposed externally.
CVE-2025-10174 Vulnerability in CVE-2025-10174 (CVE-2025-10174)
vulnerability in CVE-2025-10174 (CVE-2025-10174). Confidential information can be exposed externally.
CVE-2025-9986 Vulnerability in CVE-2025-9986 (CVE-2025-9986)
vulnerability in CVE-2025-9986 (CVE-2025-9986). Confidential information can be exposed externally.
CVE-2025-10913 Cross-Site Scripting (XSS) in CVE-2025-10913 (CVE-2025-10913)
cross-site scripting in CVE-2025-10913 (CVE-2025-10913). Data can be tampered with by attackers.
CVE-2026-21349 Out-of-Bounds Write in adobe (CVE-2026-21349)
out-of-bounds write in adobe (CVE-2026-21349). Successful exploitation can lead to full system takeover.
CVE-2026-25506 Out-of-Bounds Write in opensuse (CVE-2026-25506)
out-of-bounds write in opensuse (CVE-2026-25506). Confidential information can be exposed externally. Mitigation: upgrade to `0.5.18` or later.
CVE-2026-21352 Out-of-Bounds Write in adobe (CVE-2026-21352)
out-of-bounds write in adobe (CVE-2026-21352). Successful exploitation can lead to full system takeover.
CVE-2026-21353 Vulnerability in adobe (CVE-2026-21353)
vulnerability in adobe (CVE-2026-21353). Successful exploitation can lead to full system takeover.
CVE-2026-21344 Out-of-Bounds Read in adobe (CVE-2026-21344)
vulnerability in adobe (CVE-2026-21344). Successful exploitation can lead to full system takeover.
CVE-2026-21345 Out-of-Bounds Read in adobe (CVE-2026-21345)
vulnerability in adobe (CVE-2026-21345). Successful exploitation can lead to full system takeover.
CVE-2026-21346 Out-of-Bounds Write in adobe (CVE-2026-21346)
out-of-bounds write in adobe (CVE-2026-21346). Successful exploitation can lead to full system takeover.
CVE-2026-21347 Vulnerability in adobe (CVE-2026-21347)
vulnerability in adobe (CVE-2026-21347). Successful exploitation can lead to full system takeover.
CVE-2026-21342 Out-of-Bounds Write in adobe (CVE-2026-21342)
out-of-bounds write in adobe (CVE-2026-21342). Successful exploitation can lead to full system takeover.
CVE-2026-21343 Out-of-Bounds Read in adobe (CVE-2026-21343)
vulnerability in adobe (CVE-2026-21343). Successful exploitation can lead to full system takeover.
CVE-2026-21341 Out-of-Bounds Write in adobe (CVE-2026-21341)
out-of-bounds write in adobe (CVE-2026-21341). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →