Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-68792 |
|
Vulnerability in CVE-2025-68792 (CVE-2025-68792)
vulnerability in CVE-2025-68792 (CVE-2025-68792). Successful exploitation can lead to full system takeover.
|
| CVE-2025-68795 |
|
Vulnerability in CVE-2025-68795 (CVE-2025-68795)
vulnerability in CVE-2025-68795 (CVE-2025-68795). Successful exploitation can lead to full system takeover.
|
| CVE-2025-68782 |
|
Vulnerability in CVE-2025-68782 (CVE-2025-68782)
vulnerability in CVE-2025-68782 (CVE-2025-68782). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-68770 |
|
Vulnerability in CVE-2025-68770 (CVE-2025-68770)
vulnerability in CVE-2025-68770 (CVE-2025-68770). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-66698 |
|
Authentication Bypass in semantic-machines (CVE-2025-66698)
authentication bypass in semantic-machines (CVE-2025-66698). Confidential information can be exposed externally.
|
| CVE-2026-0878 |
|
Vulnerability in mozilla (CVE-2026-0878)
vulnerability in mozilla (CVE-2026-0878). Confidential information can be exposed externally.
|
| CVE-2026-0880 |
|
Vulnerability in mozilla (CVE-2026-0880)
vulnerability in mozilla (CVE-2026-0880). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0882 |
|
Use-After-Free in mozilla (CVE-2026-0882)
vulnerability in mozilla (CVE-2026-0882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0877 |
|
Vulnerability in mozilla (CVE-2026-0877)
vulnerability in mozilla (CVE-2026-0877). Confidential information can be exposed externally.
|
| CVE-2026-0891 |
|
Buffer Overflow in mozilla (CVE-2026-0891)
vulnerability in mozilla (CVE-2026-0891). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71066 |
|
Vulnerability in Kernel (CVE-2025-71066)
vulnerability in Kernel (CVE-2025-71066). Successful exploitation can lead to full system takeover. Exploitable via ``ets_qdisc_dequeue``. Mitigation: upgrade to `5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, 6.18.3` or later.
|
| CVE-2025-13444 |
|
OS Command Injection in progress (CVE-2025-13444)
OS command injection in progress (CVE-2025-13444). Successful exploitation can lead to full system takeover.
|
| CVE-2025-40944 |
|
Vulnerability in CVE-2025-40944 (CVE-2025-40944)
vulnerability in CVE-2025-40944 (CVE-2025-40944). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-66176 |
|
Vulnerability in hikvision (CVE-2025-66176)
vulnerability in hikvision (CVE-2025-66176). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66177 |
|
Vulnerability in CVE-2025-66177 (CVE-2025-66177)
vulnerability in CVE-2025-66177 (CVE-2025-66177). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15514 |
|
Vulnerability in dos (CVE-2025-15514)
vulnerability in dos (CVE-2025-15514). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58339 |
|
Vulnerability in llama-index (CVE-2024-58339)
vulnerability in llama-index (CVE-2024-58339). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.12.3` or later.
|
| CVE-2024-14021 |
|
Unsafe Deserialization in llama-index (CVE-2024-14021)
vulnerability in llama-index (CVE-2024-14021). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.11.7` or later.
|
| CVE-2024-58340 |
|
Vulnerability in langchain-exa (CVE-2024-58340)
vulnerability in langchain-exa (CVE-2024-58340). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0a1` or later.
|
| CVE-2026-22771 |
|
Code Injection in envoy-gateway (CVE-2026-22771)
code injection in envoy-gateway (CVE-2026-22771). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.5.7` or later.
|
| CVE-2026-22200 |
|
Vulnerability in enhancesoft (CVE-2026-22200)
vulnerability in enhancesoft (CVE-2026-22200). Confidential information can be exposed externally.
|
| CVE-2025-8110 KEV |
|
[KEV] Path Traversal in gogs (CVE-2025-8110)
path traversal in gogs (CVE-2025-8110). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-68493 |
|
XXE (XML External Entity) in apache (CVE-2025-68493)
vulnerability in apache (CVE-2025-68493). Confidential information can be exposed externally.
|
| CVE-2026-22029 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-22029)
cross-site scripting in react (CVE-2026-22029). Confidential information can be exposed externally.
|
| CVE-2025-59057 |
|
Cross-Site Scripting (XSS) in react (CVE-2025-59057)
cross-site scripting in react (CVE-2025-59057). Confidential information can be exposed externally.
|
| CVE-2026-21884 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-21884)
cross-site scripting in react (CVE-2026-21884). Confidential information can be exposed externally.
|
| CVE-2025-9222 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2025-9222)
cross-site scripting in gitlab (CVE-2025-9222). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
|
| CVE-2025-13761 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2025-13761)
cross-site scripting in gitlab (CVE-2025-13761). Confidential information can be exposed externally. Mitigation: upgrade to `18.6.3, 18.7.1` or later.
|
| CVE-2025-13772 |
|
Vulnerability in gitlab (CVE-2025-13772)
vulnerability in gitlab (CVE-2025-13772). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
|
| CVE-2025-65518 |
|
Vulnerability in dos (CVE-2025-65518)
vulnerability in dos (CVE-2025-65518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21639 |
|
Vulnerability in ui (CVE-2026-21639)
vulnerability in ui (CVE-2026-21639). Successful exploitation can lead to full system takeover.
|
| CVE-2025-50334 |
|
Vulnerability in dos (CVE-2025-50334)
vulnerability in dos (CVE-2025-50334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0719 |
|
Vulnerability in CVE-2026-0719 (CVE-2026-0719)
vulnerability in CVE-2026-0719 (CVE-2026-0719). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69262 |
|
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings....
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code E...
|
| CVE-2026-21441 |
|
Vulnerability in urllib3 (CVE-2026-21441)
vulnerability in urllib3 (CVE-2026-21441). Risk of unauthorized operations or information disclosure. Exploitable via ``gzip``. Mitigation: upgrade to `2.6.3` or later.
|
| CVE-2025-69263 |
|
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve differe...
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package w...
|
| CVE-2025-69264 |
|
Vulnerability in pnpm (CVE-2025-69264)
vulnerability in pnpm (CVE-2025-69264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22184 |
|
Out-of-Bounds Write in zlib (CVE-2026-22184)
out-of-bounds write in zlib (CVE-2026-22184). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22190 |
|
Vulnerability in cmu (CVE-2026-22190)
vulnerability in cmu (CVE-2026-22190). Confidential information can be exposed externally.
|
| CVE-2009-0556 KEV |
|
[KEV] Code Injection in Microsoft office (CVE-2009-0556)
code injection in Microsoft office (CVE-2009-0556). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-37164 KEV |
|
[KEV] Code Injection in Hewlett packard enterprise (hpe) hewlett-packard-enterprise-hpe (CVE-2025-37164)
code injection in Hewlett packard enterprise (hpe) hewlett-packard-enterprise-hpe (CVE-2025-37164). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-69223 |
|
Vulnerability in aiohttp (CVE-2025-69223)
vulnerability in aiohttp (CVE-2025-69223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.3` or later.
|
| CVE-2025-68428 |
|
Vulnerability in path-traversal (CVE-2025-68428)
vulnerability in path-traversal (CVE-2025-68428). Confidential information can be exposed externally. Exploitable via ``addImage``.
|
| CVE-2026-0621 |
|
Vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621)
vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621). Risk of unauthorized operations or information disclosure. Exploitable via ``UriTemplate``. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2025-68761 |
|
Vulnerability in CVE-2025-68761 (CVE-2025-68761)
vulnerability in CVE-2025-68761 (CVE-2025-68761). Successful exploitation can lead to full system takeover.
|
| CVE-2025-68753 |
|
Vulnerability in CVE-2025-68753 (CVE-2025-68753)
vulnerability in CVE-2025-68753 (CVE-2025-68753). Data can be tampered with by attackers.
|
| CVE-2025-68764 |
|
Vulnerability in CVE-2025-68764 (CVE-2025-68764)
vulnerability in CVE-2025-68764 (CVE-2025-68764). Successful exploitation can lead to full system takeover.
|
| CVE-2025-3653 |
|
Vulnerability in petlibro (CVE-2025-3653)
vulnerability in petlibro (CVE-2025-3653). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-3646 |
|
Vulnerability in petlibro (CVE-2025-3646)
vulnerability in petlibro (CVE-2025-3646). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67269 |
|
Vulnerability in c (CVE-2025-67269)
vulnerability in c (CVE-2025-67269). Risk of unauthorized operations or information disclosure. Exploitable via ``ffa1d6f40bca0b035fc7f5e563160ebb67199da7``.
|