Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-27246 Cross-Site Scripting (XSS) in adobe (CVE-2026-27246)
cross-site scripting in adobe (CVE-2026-27246). Confidential information can be exposed externally.
CVE-2026-27243 Cross-Site Scripting (XSS) in adobe (CVE-2026-27243)
cross-site scripting in adobe (CVE-2026-27243). Confidential information can be exposed externally.
CVE-2026-27245 Cross-Site Scripting (XSS) in adobe (CVE-2026-27245)
cross-site scripting in adobe (CVE-2026-27245). Confidential information can be exposed externally.
CVE-2026-39813 Vulnerability in path-traversal (CVE-2026-39813)
vulnerability in path-traversal (CVE-2026-39813). Successful exploitation can lead to full system takeover.
CVE-2025-61260 Code Injection in CVE-2025-61260 (CVE-2025-61260)
code injection in CVE-2025-61260 (CVE-2025-61260). Successful exploitation can lead to full system takeover.
CVE-2026-31414 Vulnerability in linux (CVE-2026-31414)
vulnerability in linux (CVE-2026-31414). Successful exploitation can lead to full system takeover.
CVE-2026-0234 Vulnerability in paloaltonetworks (CVE-2026-0234)
vulnerability in paloaltonetworks (CVE-2026-0234). Confidential information can be exposed externally.
CVE-2026-31845 Cross-Site Scripting (XSS) in CVE-2026-31845 (CVE-2026-31845)
cross-site scripting in CVE-2026-31845 (CVE-2026-31845). Confidential information can be exposed externally.
CVE-2026-6068 Use-After-Free in nasm (CVE-2026-6068)
vulnerability in nasm (CVE-2026-6068). Successful exploitation can lead to full system takeover.
CVE-2026-6057 Path Traversal in path-traversal (CVE-2026-6057)
path traversal in path-traversal (CVE-2026-6057). Successful exploitation can lead to full system takeover.
CVE-2026-33784 Vulnerability in juniper (CVE-2026-33784)
vulnerability in juniper (CVE-2026-33784). Successful exploitation can lead to full system takeover.
CVE-2026-5194 Vulnerability in wolfssl (CVE-2026-5194)
vulnerability in wolfssl (CVE-2026-5194). Confidential information can be exposed externally.
CVE-2026-40089 SSRF (Server-Side Request Forgery) in c (CVE-2026-40089)
SSRF in c (CVE-2026-40089). Confidential information can be exposed externally.
CVE-2026-39912 Vulnerability in CVE-2026-39912 (CVE-2026-39912)
vulnerability in CVE-2026-39912 (CVE-2026-39912). Confidential information can be exposed externally.
CVE-2025-62718 Vulnerability in axios (CVE-2025-62718)
vulnerability in axios (CVE-2025-62718). Confidential information can be exposed externally. Exploitable via ``NO_PROXY``. Mitigation: upgrade to `0.31.0` or later.
CVE-2026-39962 Vulnerability in misp-project (CVE-2026-39962)
vulnerability in misp-project (CVE-2026-39962). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.5.36` or later.
CVE-2026-34184 Vulnerability in hydrosystempoznan (CVE-2026-34184)
vulnerability in hydrosystempoznan (CVE-2026-34184). Confidential information can be exposed externally.
CVE-2026-5902 Vulnerability in google (CVE-2026-5902)
vulnerability in google (CVE-2026-5902). Successful exploitation can lead to full system takeover.
CVE-2026-5874 Use-After-Free in google (CVE-2026-5874)
vulnerability in google (CVE-2026-5874). Successful exploitation can lead to full system takeover.
CVE-2026-40035 Vulnerability in dfir-unfurl (CVE-2026-40035)
vulnerability in dfir-unfurl (CVE-2026-40035). Confidential information can be exposed externally. Exploitable via ``debug``.
CVE-2026-39860 Vulnerability in nixos (CVE-2026-39860)
vulnerability in nixos (CVE-2026-39860). Confidential information can be exposed externally. Mitigation: upgrade to `2.34.5` or later.
CVE-2026-39888 Vulnerability in praisonaiagents (CVE-2026-39888)
vulnerability in praisonaiagents (CVE-2026-39888). Successful exploitation can lead to full system takeover. Exploitable via ``praisonaiagents.tools.python_tools``. Mitigation: upgrade to `1.5.115` or later.
CVE-2026-2942 Unrestricted File Upload in wordpress (CVE-2026-2942)
vulnerability in wordpress (CVE-2026-2942). Successful exploitation can lead to full system takeover.
CVE-2026-39892 Buffer Overflow in cryptography (CVE-2026-39892)
vulnerability in cryptography (CVE-2026-39892). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `46.0.7` or later.
CVE-2026-39890 Unsafe Deserialization in praisonai (CVE-2026-39890)
vulnerability in praisonai (CVE-2026-39890). Successful exploitation can lead to full system takeover. Exploitable via ``AgentService.loadAgentFromFile``. Mitigation: upgrade to `4.5.115` or later.
CVE-2025-52221 Out-of-Bounds Write in tenda (CVE-2025-52221)
out-of-bounds write in tenda (CVE-2025-52221). Successful exploitation can lead to full system takeover.
CVE-2026-31017 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-31017)
SSRF in ssrf (CVE-2026-31017). Confidential information can be exposed externally.
CVE-2023-46945 QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
CVE-2026-33229 Vulnerability in xwiki (CVE-2026-33229)
vulnerability in xwiki (CVE-2026-33229). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.4.8` or later.
CVE-2026-31040 Code Injection in stata-mcp (CVE-2026-31040)
code injection in stata-mcp (CVE-2026-31040). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.13.0` or later.
CVE-2026-39640 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39640)
vulnerability in csrf (CVE-2026-39640). Successful exploitation can lead to full system takeover.
CVE-2026-39620 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39620)
vulnerability in csrf (CVE-2026-39620). Successful exploitation can lead to full system takeover.
CVE-2026-39617 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39617)
vulnerability in csrf (CVE-2026-39617). Successful exploitation can lead to full system takeover.
CVE-2026-39619 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39619)
vulnerability in csrf (CVE-2026-39619). Successful exploitation can lead to full system takeover.
CVE-2026-25776 Code Injection in sixapart (CVE-2026-25776)
code injection in sixapart (CVE-2026-25776). Successful exploitation can lead to full system takeover.
CVE-2026-3535 Unrestricted File Upload in wordpress (CVE-2026-3535)
vulnerability in wordpress (CVE-2026-3535). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_``.
CVE-2026-4003 Vulnerability in wordpress (CVE-2026-4003)
vulnerability in wordpress (CVE-2026-4003). Successful exploitation can lead to full system takeover.
CVE-2026-3296 Unsafe Deserialization in wordpress (CVE-2026-3296)
vulnerability in wordpress (CVE-2026-3296). Successful exploitation can lead to full system takeover.
CVE-2026-1346 Vulnerability in ibm (CVE-2026-1346)
vulnerability in ibm (CVE-2026-1346). Successful exploitation can lead to full system takeover.
CVE-2026-39847 Path Traversal in emmett (CVE-2026-39847)
path traversal in emmett (CVE-2026-39847). Confidential information can be exposed externally. Mitigation: upgrade to `2.8.1` or later.
CVE-2026-27143 Vulnerability in toolchain (CVE-2026-27143)
vulnerability in toolchain (CVE-2026-27143). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.25.9, 1.26.2` or later.
CVE-2026-39846 Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846). Successful exploitation can lead to full system takeover. Exploitable via ``nodeIntegration``. Mitigation: upgrade to `0.0.0-20260407035653-2f416e5253f1` or later.
CVE-2026-34582 Vulnerability in c (CVE-2026-34582)
vulnerability in c (CVE-2026-34582). Confidential information can be exposed externally. Mitigation: upgrade to `3.11.1` or later.
CVE-2026-31789 Out-of-Bounds Write in openssl (CVE-2026-31789)
out-of-bounds write in openssl (CVE-2026-31789). Successful exploitation can lead to full system takeover.
CVE-2026-34078 Vulnerability in flatpak (CVE-2026-34078)
vulnerability in flatpak (CVE-2026-34078). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.16.4` or later.
CVE-2026-39397 Vulnerability in delmaredigital (CVE-2026-39397)
vulnerability in delmaredigital (CVE-2026-39397). Confidential information can be exposed externally. Mitigation: upgrade to `0.6.23` or later.
CVE-2026-33439 Unsafe Deserialization in deserialization (CVE-2026-33439)
vulnerability in deserialization (CVE-2026-33439). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.0.6` or later.
CVE-2025-69515 Vulnerability in CVE-2025-69515 (CVE-2025-69515)
vulnerability in CVE-2025-69515 (CVE-2025-69515). Data can be tampered with by attackers.
CVE-2026-39351 Vulnerability in frappe (CVE-2026-39351)
vulnerability in frappe (CVE-2026-39351). Confidential information can be exposed externally.
CVE-2026-39355 Vulnerability in kreaweb (CVE-2026-39355)
vulnerability in kreaweb (CVE-2026-39355). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.9.1` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →