Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-35998 |
|
Vulnerability in CVE-2025-35998 (CVE-2025-35998)
vulnerability in CVE-2025-35998 (CVE-2025-35998). Confidential information can be exposed externally.
|
| CVE-2026-0651 |
|
Path Traversal in path-traversal (CVE-2026-0651)
path traversal in path-traversal (CVE-2026-0651). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25646 |
|
Vulnerability in libpng (CVE-2026-25646)
vulnerability in libpng (CVE-2026-25646). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.55` or later.
|
| CVE-2026-21351 |
|
Use-After-Free in adobe (CVE-2026-21351)
vulnerability in adobe (CVE-2026-21351). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21357 |
|
Vulnerability in adobe (CVE-2026-21357)
vulnerability in adobe (CVE-2026-21357). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21334 |
|
Out-of-Bounds Write in adobe (CVE-2026-21334)
out-of-bounds write in adobe (CVE-2026-21334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21335 |
|
Out-of-Bounds Write in adobe (CVE-2026-21335)
out-of-bounds write in adobe (CVE-2026-21335). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21324 |
|
Out-of-Bounds Read in adobe (CVE-2026-21324)
vulnerability in adobe (CVE-2026-21324). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21325 |
|
Out-of-Bounds Read in adobe (CVE-2026-21325)
vulnerability in adobe (CVE-2026-21325). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21326 |
|
Use-After-Free in adobe (CVE-2026-21326)
vulnerability in adobe (CVE-2026-21326). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21327 |
|
Out-of-Bounds Write in adobe (CVE-2026-21327)
out-of-bounds write in adobe (CVE-2026-21327). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21328 |
|
Out-of-Bounds Write in adobe (CVE-2026-21328)
out-of-bounds write in adobe (CVE-2026-21328). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21329 |
|
Use-After-Free in adobe (CVE-2026-21329)
vulnerability in adobe (CVE-2026-21329). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21330 |
|
Vulnerability in adobe (CVE-2026-21330)
vulnerability in adobe (CVE-2026-21330). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21318 |
|
Out-of-Bounds Write in adobe (CVE-2026-21318)
out-of-bounds write in adobe (CVE-2026-21318). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21320 |
|
Use-After-Free in adobe (CVE-2026-21320)
vulnerability in adobe (CVE-2026-21320). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21321 |
|
Vulnerability in adobe (CVE-2026-21321)
vulnerability in adobe (CVE-2026-21321). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21322 |
|
Out-of-Bounds Read in adobe (CVE-2026-21322)
vulnerability in adobe (CVE-2026-21322). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21323 |
|
Use-After-Free in adobe (CVE-2026-21323)
vulnerability in adobe (CVE-2026-21323). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21312 |
|
Out-of-Bounds Write in adobe (CVE-2026-21312)
out-of-bounds write in adobe (CVE-2026-21312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21229 |
|
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
|
| CVE-2026-20846 |
|
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
|
| CVE-2025-6967 |
|
Vulnerability in CVE-2025-6967 (CVE-2025-6967)
vulnerability in CVE-2025-6967 (CVE-2025-6967). Confidential information can be exposed externally.
|
| CVE-2025-7636 |
|
SQL Injection in sqli (CVE-2025-7636)
SQL injection in sqli (CVE-2025-7636). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7347 |
|
Vulnerability in CVE-2025-7347 (CVE-2025-7347)
vulnerability in CVE-2025-7347 (CVE-2025-7347). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23687 |
|
Vulnerability in sap (CVE-2026-23687)
vulnerability in sap (CVE-2026-23687). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21513 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-21513)
vulnerability in Microsoft windows (CVE-2026-21513). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21525 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-21525)
vulnerability in Microsoft windows (CVE-2026-21525). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21510 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-21510)
vulnerability in Microsoft windows (CVE-2026-21510). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21533 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2026-21533)
vulnerability in Microsoft windows (CVE-2026-21533). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21519 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-21519)
vulnerability in Microsoft windows (CVE-2026-21519). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-21514 KEV |
|
[KEV] Vulnerability in Microsoft office (CVE-2026-21514)
vulnerability in Microsoft office (CVE-2026-21514). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-1486 |
|
Vulnerability in CVE-2026-1486 (CVE-2026-1486)
vulnerability in CVE-2026-1486 (CVE-2026-1486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1529 |
|
Vulnerability in CVE-2026-1529 (CVE-2026-1529)
vulnerability in CVE-2026-1529 (CVE-2026-1529). Confidential information can be exposed externally.
|
| CVE-2026-24678 |
|
Use-After-Free in freerdp (CVE-2026-24678)
vulnerability in freerdp (CVE-2026-24678). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.22.0` or later.
|
| CVE-2026-25639 |
|
Vulnerability in axios (CVE-2026-25639)
vulnerability in axios (CVE-2026-25639). Risk of unauthorized operations or information disclosure. Exploitable via ``mergeConfig``. Mitigation: upgrade to `0.30.3` or later.
|
| CVE-2025-10465 |
|
Unrestricted File Upload in CVE-2025-10465 (CVE-2025-10465)
vulnerability in CVE-2025-10465 (CVE-2025-10465). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10463 |
|
Authentication Bypass in CVE-2025-10463 (CVE-2025-10463)
authentication bypass in CVE-2025-10463 (CVE-2025-10463). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7799 |
|
Cross-Site Scripting (XSS) in CVE-2025-7799 (CVE-2025-7799)
cross-site scripting in CVE-2025-7799 (CVE-2025-7799). Data can be tampered with by attackers.
|
| CVE-2026-25859 |
|
Authorization Flaw in wekan-project (CVE-2026-25859)
vulnerability in wekan-project (CVE-2026-25859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25561 |
|
Authorization Flaw in wekan-project (CVE-2026-25561)
vulnerability in wekan-project (CVE-2026-25561). Data can be tampered with by attackers.
|
| CVE-2026-25563 |
|
Vulnerability in wekan-project (CVE-2026-25563)
vulnerability in wekan-project (CVE-2026-25563). Data can be tampered with by attackers.
|
| CVE-2026-25564 |
|
Vulnerability in wekan-project (CVE-2026-25564)
vulnerability in wekan-project (CVE-2026-25564). Data can be tampered with by attackers.
|
| CVE-2026-25580 |
|
SSRF (Server-Side Request Forgery) in pydantic-ai (CVE-2026-25580)
SSRF in pydantic-ai (CVE-2026-25580). Confidential information can be exposed externally. Exploitable via ``Agent.to_web``. Mitigation: upgrade to `1.56.0` or later.
|
| CVE-2026-25640 |
|
Path Traversal in path-traversal (CVE-2026-25640)
path traversal in path-traversal (CVE-2026-25640). Confidential information can be exposed externally. Mitigation: upgrade to `1.51.0` or later.
|
| CVE-2026-25556 |
|
Vulnerability in artifex (CVE-2026-25556)
vulnerability in artifex (CVE-2026-25556). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25293 |
|
Vulnerability in c (CVE-2019-25293)
vulnerability in c (CVE-2019-25293). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61732 |
|
Code Injection in toolchain (CVE-2025-61732)
code injection in toolchain (CVE-2025-61732). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.24.13, 1.25.7` or later.
|
| CVE-2025-11953 KEV |
|
[KEV] OS Command Injection in React native community react-native-community (CVE-2025-11953)
OS command injection in React native community react-native-community (CVE-2025-11953). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-25521 |
|
Vulnerability in locutus (CVE-2026-25521)
vulnerability in locutus (CVE-2026-25521). Successful exploitation can lead to full system takeover.
|