Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-35216 |
|
OS Command Injection in budibase (CVE-2026-35216)
OS command injection in budibase (CVE-2026-35216). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31818 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-31818)
SSRF in ssrf (CVE-2026-31818). Confidential information can be exposed externally.
|
| CVE-2026-23455 |
|
Out-of-Bounds Read in linux (CVE-2026-23455)
vulnerability in linux (CVE-2026-23455). Confidential information can be exposed externally.
|
| CVE-2026-23450 |
|
Use-After-Free in linux (CVE-2026-23450)
vulnerability in linux (CVE-2026-23450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35171 |
|
Code Injection in kedro (CVE-2026-35171)
code injection in kedro (CVE-2026-35171). Successful exploitation can lead to full system takeover. Exploitable via ``KEDRO_LOGGING_CONFIG``. Mitigation: upgrade to `1.3.0` or later.
|
| CVE-2026-33107 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-33107)
SSRF in ssrf (CVE-2026-33107). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33105 |
|
Vulnerability in microsoft (CVE-2026-33105)
vulnerability in microsoft (CVE-2026-33105). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26135 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-26135)
SSRF in ssrf (CVE-2026-26135). Confidential information can be exposed externally.
|
| CVE-2026-32211 |
|
Vulnerability in microsoft (CVE-2026-32211)
vulnerability in microsoft (CVE-2026-32211). Confidential information can be exposed externally.
|
| CVE-2026-32213 |
|
Vulnerability in microsoft (CVE-2026-32213)
vulnerability in microsoft (CVE-2026-32213). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35053 |
|
Vulnerability in hackerbay (CVE-2026-35053)
vulnerability in hackerbay (CVE-2026-35053). Successful exploitation can lead to full system takeover. Exploitable via `GET /workflow/manual/run/`.
|
| CVE-2026-34838 |
|
Unsafe Deserialization in deserialization (CVE-2026-34838)
vulnerability in deserialization (CVE-2026-34838). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34931 |
|
Open Redirect in hoppscotch (CVE-2026-34931)
vulnerability in hoppscotch (CVE-2026-34931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34932 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-34932)
cross-site scripting in csrf (CVE-2026-34932). Confidential information can be exposed externally.
|
| CVE-2024-14034 |
|
Authentication Bypass in CVE-2024-14034 (CVE-2024-14034)
authentication bypass in CVE-2024-14034 (CVE-2024-14034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34745 |
|
Path Traversal in shaneisrael (CVE-2026-34745)
path traversal in shaneisrael (CVE-2026-34745). Data can be tampered with by attackers.
|
| CVE-2026-34758 |
|
Vulnerability in hackerbay (CVE-2026-34758)
vulnerability in hackerbay (CVE-2026-34758). Confidential information can be exposed externally.
|
| CVE-2026-34717 |
|
SQL Injection in openproject (CVE-2026-34717)
SQL injection in openproject (CVE-2026-34717). Data can be tampered with by attackers.
|
| CVE-2026-34877 |
|
Vulnerability in arm (CVE-2026-34877)
vulnerability in arm (CVE-2026-34877). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33950 |
|
Vulnerability in privilege-escalation (CVE-2026-33950)
vulnerability in privilege-escalation (CVE-2026-33950). Confidential information can be exposed externally.
|
| CVE-2026-25212 |
|
Vulnerability in percona (CVE-2026-25212)
vulnerability in percona (CVE-2026-25212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33746 |
|
Authentication Bypass in convoypanel (CVE-2026-33746)
authentication bypass in convoypanel (CVE-2026-33746). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35002 |
|
Vulnerability in agno (CVE-2026-35002)
vulnerability in agno (CVE-2026-35002). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.3.24` or later.
|
| CVE-2026-32871 |
|
SSRF (Server-Side Request Forgery) in fastmcp (CVE-2026-32871)
SSRF in fastmcp (CVE-2026-32871). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-34873 |
|
Authentication Bypass in trustedfirmware (CVE-2026-34873)
authentication bypass in trustedfirmware (CVE-2026-34873). Confidential information can be exposed externally.
|
| CVE-2026-34875 |
|
Vulnerability in trustedfirmware (CVE-2026-34875)
vulnerability in trustedfirmware (CVE-2026-34875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4374 |
|
XXE (XML External Entity) in rti (CVE-2026-4374)
vulnerability in rti (CVE-2026-4374). Confidential information can be exposed externally.
|
| CVE-2026-34448 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448). Successful exploitation can lead to full system takeover. Exploitable via ``mAsse``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34449 |
|
Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449). Successful exploitation can lead to full system takeover. Exploitable via ``Origin``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34400 |
|
SQL Injection in alerta-server (CVE-2026-34400)
SQL injection in alerta-server (CVE-2026-34400). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.1.0` or later.
|
| CVE-2026-1579 |
|
Vulnerability in px4 (CVE-2026-1579)
vulnerability in px4 (CVE-2026-1579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30285 |
|
Path Traversal in zora (CVE-2026-30285)
path traversal in zora (CVE-2026-30285). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30282 |
|
Path Traversal in uxgroupllc (CVE-2026-30282)
path traversal in uxgroupllc (CVE-2026-30282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30283 |
|
Path Traversal in peaksel (CVE-2026-30283)
path traversal in peaksel (CVE-2026-30283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30286 |
|
Path Traversal in funambol (CVE-2026-30286)
path traversal in funambol (CVE-2026-30286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30278 |
|
Path Traversal in funair (CVE-2026-30278)
path traversal in funair (CVE-2026-30278). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34361 |
|
Vulnerability in hapifhir (CVE-2026-34361)
vulnerability in hapifhir (CVE-2026-34361). Confidential information can be exposed externally.
|
| CVE-2026-34243 |
|
Command Injection in njzjz (CVE-2026-34243)
command injection in njzjz (CVE-2026-34243). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34220 |
|
SQL Injection in sqli (CVE-2026-34220)
SQL injection in sqli (CVE-2026-34220). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34235 |
|
Out-of-Bounds Read in c (CVE-2026-34235)
vulnerability in c (CVE-2026-34235). Confidential information can be exposed externally.
|
| CVE-2026-34221 |
|
Vulnerability in mikro-orm (CVE-2026-34221)
vulnerability in mikro-orm (CVE-2026-34221). Data can be tampered with by attackers.
|
| CVE-2026-30276 |
|
Vulnerability in deftpdf (CVE-2026-30276)
vulnerability in deftpdf (CVE-2026-30276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30281 |
|
Vulnerability in maru (CVE-2026-30281)
vulnerability in maru (CVE-2026-30281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34532 |
|
Authorization Flaw in parseplatform (CVE-2026-34532)
vulnerability in parseplatform (CVE-2026-34532). Confidential information can be exposed externally.
|
| CVE-2026-34162 |
|
Vulnerability in fastgpt (CVE-2026-34162)
vulnerability in fastgpt (CVE-2026-34162). Confidential information can be exposed externally.
|
| CVE-2026-33579 |
|
Authorization Flaw in privilege-escalation (CVE-2026-33579)
vulnerability in privilege-escalation (CVE-2026-33579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30314 |
|
OS Command Injection in ridvay (CVE-2026-30314)
OS command injection in ridvay (CVE-2026-30314). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30312 |
|
OS Command Injection in CVE-2026-30312 (CVE-2026-30312)
OS command injection in CVE-2026-30312 (CVE-2026-30312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30311 |
|
OS Command Injection in ridvay (CVE-2026-30311)
OS command injection in ridvay (CVE-2026-30311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34156 |
|
Vulnerability in nocobase (CVE-2026-34156)
vulnerability in nocobase (CVE-2026-34156). Successful exploitation can lead to full system takeover.
|