Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-29870 |
|
Path Traversal in path-traversal (CVE-2026-29870)
path traversal in path-traversal (CVE-2026-29870). Data can be tampered with by attackers.
|
| CVE-2026-29597 |
|
Vulnerability in privilege-escalation (CVE-2026-29597)
vulnerability in privilege-escalation (CVE-2026-29597). Confidential information can be exposed externally.
|
| CVE-2026-24068 |
|
Vulnerability in privilege-escalation (CVE-2026-24068)
vulnerability in privilege-escalation (CVE-2026-24068). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28529 |
|
Use-After-Free in privilege-escalation (CVE-2026-28529)
vulnerability in privilege-escalation (CVE-2026-28529). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1995 |
|
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded conte...
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any stand...
|
| CVE-2026-4606 |
|
Vulnerability in privilege-escalation (CVE-2026-4606)
vulnerability in privilege-escalation (CVE-2026-4606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29796 |
|
Vulnerability in privilege-escalation (CVE-2026-29796)
vulnerability in privilege-escalation (CVE-2026-29796). Confidential information can be exposed externally.
|
| CVE-2026-23268 |
|
Vulnerability in Kernel (CVE-2026-23268)
vulnerability in Kernel (CVE-2026-23268). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.6.130, 6.12.77, 6.18.18, 6.19.8` or later.
|
| CVE-2026-24062 |
|
Vulnerability in privilege-escalation (CVE-2026-24062)
vulnerability in privilege-escalation (CVE-2026-24062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24063 |
|
Vulnerability in privilege-escalation (CVE-2026-24063)
vulnerability in privilege-escalation (CVE-2026-24063). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3888 |
|
Vulnerability in privilege-escalation (CVE-2026-3888)
vulnerability in privilege-escalation (CVE-2026-3888). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23862 |
|
Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local...
Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
|
| CVE-2016-20024 |
|
Vulnerability in csharp (CVE-2016-20024)
vulnerability in csharp (CVE-2016-20024). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20025 |
|
Vulnerability in privilege-escalation (CVE-2016-20025)
vulnerability in privilege-escalation (CVE-2016-20025). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3999 |
|
Vulnerability in privilege-escalation (CVE-2026-3999)
vulnerability in privilege-escalation (CVE-2026-3999). Successful exploitation can lead to full system takeover.
|
| CVE-2025-8766 |
|
Vulnerability in privilege-escalation (CVE-2025-8766)
vulnerability in privilege-escalation (CVE-2025-8766). Successful exploitation can lead to full system takeover.
|
| CVE-2025-57849 |
|
Vulnerability in privilege-escalation (CVE-2025-57849)
vulnerability in privilege-escalation (CVE-2025-57849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21672 |
|
Vulnerability in privilege-escalation (CVE-2026-21672)
vulnerability in privilege-escalation (CVE-2026-21672). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29773 |
|
Authorization Flaw in privilege-escalation (CVE-2026-29773)
vulnerability in privilege-escalation (CVE-2026-29773). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-66024 |
|
Cross-Site Scripting (XSS) in org.xwiki.contrib.blog:application-blog-ui (CVE-2025-66024)
cross-site scripting in org.xwiki.contrib.blog:application-blog-ui (CVE-2025-66024). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.15.7` or later.
|
| CVE-2025-63409 |
|
Vulnerability in privilege-escalation (CVE-2025-63409)
vulnerability in privilege-escalation (CVE-2025-63409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2777 |
|
Privilege Escalation in privilege-escalation (CVE-2026-2777)
vulnerability in privilege-escalation (CVE-2026-2777). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2492 |
|
Vulnerability in privilege-escalation (CVE-2026-2492)
vulnerability in privilege-escalation (CVE-2026-2492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26369 |
|
Privilege Escalation in privilege-escalation (CVE-2026-26369)
vulnerability in privilege-escalation (CVE-2026-26369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23111 |
|
Use-After-Free in privilege-escalation (CVE-2026-23111)
vulnerability in privilege-escalation (CVE-2026-23111). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14349 |
|
Vulnerability in privilege-escalation (CVE-2025-14349)
vulnerability in privilege-escalation (CVE-2025-14349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1618 |
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc....
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc....
|
| CVE-2026-2007 |
|
Vulnerability in postgresql (CVE-2026-2007)
vulnerability in postgresql (CVE-2026-2007). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.2.0` or later.
|
| CVE-2026-26158 |
|
Vulnerability in privilege-escalation (CVE-2026-26158)
vulnerability in privilege-escalation (CVE-2026-26158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21721 |
|
Authorization Flaw in privilege-escalation (CVE-2026-21721)
vulnerability in privilege-escalation (CVE-2026-21721). Confidential information can be exposed externally.
|
| CVE-2025-9820 |
|
Vulnerability in privilege-escalation (CVE-2025-9820)
vulnerability in privilege-escalation (CVE-2025-9820). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0775 |
|
Vulnerability in privilege-escalation (CVE-2026-0775)
vulnerability in privilege-escalation (CVE-2026-0775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24049 |
|
Path Traversal in wheel (CVE-2026-24049)
path traversal in wheel (CVE-2026-24049). Data can be tampered with by attackers. Mitigation: upgrade to `0.46.2` or later.
|
| CVE-2025-67246 |
|
Privilege Escalation in privilege-escalation (CVE-2025-67246)
vulnerability in privilege-escalation (CVE-2025-67246). Confidential information can be exposed externally.
|
| CVE-2025-2515 |
|
Authorization Flaw in privilege-escalation (CVE-2025-2515)
vulnerability in privilege-escalation (CVE-2025-2515). Successful exploitation can lead to full system takeover.
|
| CVE-2025-34290 |
|
Vulnerability in c (CVE-2025-34290)
vulnerability in c (CVE-2025-34290). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7073 |
|
Vulnerability in c (CVE-2025-7073)
vulnerability in c (CVE-2025-7073). Successful exploitation can lead to full system takeover.
|
| CVE-2025-1161 |
|
Vulnerability in privilege-escalation (CVE-2025-1161)
vulnerability in privilege-escalation (CVE-2025-1161). Successful exploitation can lead to full system takeover.
|
| CVE-2025-64666 |
|
Vulnerability in microsoft (CVE-2025-64666)
vulnerability in microsoft (CVE-2025-64666). Successful exploitation can lead to full system takeover.
|
| CVE-2025-65621 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2025-65621)
cross-site scripting in privilege-escalation (CVE-2025-65621). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-2843 |
|
Vulnerability in privilege-escalation (CVE-2025-2843)
vulnerability in privilege-escalation (CVE-2025-2843). Successful exploitation can lead to full system takeover.
|
| CVE-2025-1549 |
|
Command Injection in privilege-escalation (CVE-2025-1549)
command injection in privilege-escalation (CVE-2025-1549). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-57848 |
|
Vulnerability in privilege-escalation (CVE-2025-57848)
vulnerability in privilege-escalation (CVE-2025-57848). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59249 |
|
Vulnerability in microsoft (CVE-2025-59249)
vulnerability in microsoft (CVE-2025-59249). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53782 |
|
Vulnerability in microsoft (CVE-2025-53782)
vulnerability in microsoft (CVE-2025-53782). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36851 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2020-36851)
SSRF in ssrf (CVE-2020-36851). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7743 |
|
Vulnerability in privilege-escalation (CVE-2025-7743)
vulnerability in privilege-escalation (CVE-2025-7743). Successful exploitation can lead to full system takeover.
|
| CVE-2025-50892 |
|
Privilege Escalation in privilege-escalation (CVE-2025-50892)
vulnerability in privilege-escalation (CVE-2025-50892). Successful exploitation can lead to full system takeover.
|
| CVE-2025-8067 |
|
Out-of-Bounds Read in privilege-escalation (CVE-2025-8067)
vulnerability in privilege-escalation (CVE-2025-8067). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-55366 |
|
Vulnerability in privilege-escalation (CVE-2025-55366)
vulnerability in privilege-escalation (CVE-2025-55366). Risk of unauthorized operations or information disclosure.
|