Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-35053 |
|
Vulnerability in hackerbay (CVE-2026-35053)
vulnerability in hackerbay (CVE-2026-35053). Successful exploitation can lead to full system takeover. Exploitable via `GET /workflow/manual/run/`.
|
| CVE-2026-34758 |
|
Vulnerability in hackerbay (CVE-2026-34758)
vulnerability in hackerbay (CVE-2026-34758). Confidential information can be exposed externally.
|
| CVE-2026-33951 |
|
Vulnerability in signalk (CVE-2026-33951)
vulnerability in signalk (CVE-2026-33951). Data can be tampered with by attackers. Exploitable via `PUT /signalk/v1/api/sourcePriorities`.
|
| CVE-2026-34072 |
|
Authentication Bypass in fccview (CVE-2026-34072)
authentication bypass in fccview (CVE-2026-34072). Confidential information can be exposed externally.
|
| CVE-2025-67805 |
|
Information Disclosure in sagedpw (CVE-2025-67805)
vulnerability in sagedpw (CVE-2025-67805). Confidential information can be exposed externally.
|
| CVE-2026-34999 |
|
Vulnerability in volcengine (CVE-2026-34999)
vulnerability in volcengine (CVE-2026-34999). Risk of unauthorized operations or information disclosure. Exploitable via `POST /bot/v1/chat`.
|
| CVE-2026-34731 |
|
Vulnerability in wwbn (CVE-2026-34731)
vulnerability in wwbn (CVE-2026-34731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34732 |
|
Vulnerability in wwbn (CVE-2026-34732)
vulnerability in wwbn (CVE-2026-34732). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1579 |
|
Vulnerability in px4 (CVE-2026-1579)
vulnerability in px4 (CVE-2026-1579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3356 |
|
Vulnerability in CVE-2026-3356 (CVE-2026-3356)
vulnerability in CVE-2026-3356 (CVE-2026-3356). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34227 |
|
Vulnerability in github.com/bishopfox/sliver (CVE-2026-34227)
vulnerability in github.com/bishopfox/sliver (CVE-2026-34227). Successful exploitation can lead to full system takeover. Exploitable via ``ntds.dit``. Mitigation: upgrade to `1.7.4` or later.
|
| CVE-2026-34200 |
|
Vulnerability in nhost (CVE-2026-34200)
vulnerability in nhost (CVE-2026-34200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34162 |
|
Vulnerability in fastgpt (CVE-2026-34162)
vulnerability in fastgpt (CVE-2026-34162). Confidential information can be exposed externally.
|
| CVE-2026-34411 |
|
Vulnerability in appsmith (CVE-2026-34411)
vulnerability in appsmith (CVE-2026-34411). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24068 |
|
Vulnerability in privilege-escalation (CVE-2026-24068)
vulnerability in privilege-escalation (CVE-2026-24068). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33017 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-33017)
vulnerability in langflow (CVE-2026-33017). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/build_public_tmp/{flow_id}/flow`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2026-31846 |
|
Vulnerability in CVE-2026-31846 (CVE-2026-31846)
vulnerability in CVE-2026-31846 (CVE-2026-31846). Confidential information can be exposed externally.
|
| CVE-2026-32896 |
|
Vulnerability in openclaw (CVE-2026-32896)
vulnerability in openclaw (CVE-2026-32896). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33231 |
|
Vulnerability in dos (CVE-2026-33231)
vulnerability in dos (CVE-2026-33231). Risk of unauthorized operations or information disclosure. Exploitable via `GET /SHUTDOWN`.
|
| CVE-2026-29796 |
|
Vulnerability in privilege-escalation (CVE-2026-29796)
vulnerability in privilege-escalation (CVE-2026-29796). Confidential information can be exposed externally.
|
| CVE-2025-71257 |
|
Vulnerability in bmc (CVE-2025-71257)
vulnerability in bmc (CVE-2025-71257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24062 |
|
Vulnerability in privilege-escalation (CVE-2026-24062)
vulnerability in privilege-escalation (CVE-2026-24062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2603 |
|
Vulnerability in org.keycloak:keycloak-services (CVE-2026-2603)
vulnerability in org.keycloak:keycloak-services (CVE-2026-2603). Confidential information can be exposed externally. Mitigation: upgrade to `26.5.5` or later.
|
| CVE-2026-4312 |
|
Vulnerability in dragonsoft (CVE-2026-4312)
vulnerability in dragonsoft (CVE-2026-4312). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15515 |
|
Vulnerability in vivo (CVE-2025-15515)
vulnerability in vivo (CVE-2025-15515). Confidential information can be exposed externally.
|
| CVE-2025-13778 |
|
Vulnerability in CVE-2025-13778 (CVE-2025-13778)
vulnerability in CVE-2025-13778 (CVE-2025-13778). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13779 |
|
Vulnerability in CVE-2025-13779 (CVE-2025-13779)
vulnerability in CVE-2025-13779 (CVE-2025-13779). Confidential information can be exposed externally.
|
| CVE-2026-3611 |
|
Vulnerability in honeywell (CVE-2026-3611)
vulnerability in honeywell (CVE-2026-3611). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28229 |
|
Authorization Flaw in github.com/argoproj/argo-workflows/v4 (CVE-2026-28229)
vulnerability in github.com/argoproj/argo-workflows/v4 (CVE-2026-28229). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.2` or later.
|
| CVE-2026-2339 |
|
Vulnerability in CVE-2026-2339 (CVE-2026-2339)
vulnerability in CVE-2026-2339 (CVE-2026-2339). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2754 |
|
Vulnerability in navtor (CVE-2026-2754)
vulnerability in navtor (CVE-2026-2754). Confidential information can be exposed externally.
|
| CVE-2026-27446 |
|
Vulnerability in org.apache.activemq:artemis-server (CVE-2026-27446)
vulnerability in org.apache.activemq:artemis-server (CVE-2026-27446). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.52.0` or later.
|
| CVE-2026-27509 |
|
Vulnerability in unitree (CVE-2026-27509)
vulnerability in unitree (CVE-2026-27509). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2624 |
|
Vulnerability in epati (CVE-2026-2624)
vulnerability in epati (CVE-2026-2624). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27595 |
|
Vulnerability in csrf (CVE-2026-27595)
vulnerability in csrf (CVE-2026-27595). Data can be tampered with by attackers. Exploitable via ``readOnlyMasterKey``.
|
| CVE-2025-8350 |
|
Vulnerability in CVE-2025-8350 (CVE-2025-8350)
vulnerability in CVE-2025-8350 (CVE-2025-8350). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7706 |
|
Vulnerability in CVE-2025-7706 (CVE-2025-7706)
vulnerability in CVE-2025-7706 (CVE-2025-7706). Confidential information can be exposed externally.
|
| CVE-2025-14349 |
|
Vulnerability in privilege-escalation (CVE-2025-14349)
vulnerability in privilege-escalation (CVE-2025-14349). Successful exploitation can lead to full system takeover.
|
| CVE-2025-8025 |
|
Vulnerability in CVE-2025-8025 (CVE-2025-8025)
vulnerability in CVE-2025-8025 (CVE-2025-8025). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24423 KEV |
|
[KEV] Vulnerability in Smartertools smartermail (CVE-2026-24423)
vulnerability in Smartertools smartermail (CVE-2026-24423). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-1341 |
|
Vulnerability in CVE-2026-1341 (CVE-2026-1341)
vulnerability in CVE-2026-1341 (CVE-2026-1341). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-52024 |
|
Vulnerability in aptsys (CVE-2025-52024)
vulnerability in aptsys (CVE-2025-52024). Confidential information can be exposed externally.
|
| CVE-2025-62582 |
|
Delta Electronics DIAView has multiple vulnerabilities.
Delta Electronics DIAView has multiple vulnerabilities.
|
| CVE-2026-20803 |
|
Vulnerability in microsoft (CVE-2026-20803)
vulnerability in microsoft (CVE-2026-20803). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0650 |
|
Vulnerability in CVE-2026-0650 (CVE-2026-0650)
vulnerability in CVE-2026-0650 (CVE-2026-0650). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0625 |
|
Vulnerability in CVE-2026-0625 (CVE-2026-0625)
vulnerability in CVE-2026-0625 (CVE-2026-0625). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-3646 |
|
Vulnerability in petlibro (CVE-2025-3646)
vulnerability in petlibro (CVE-2025-3646). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14300 |
|
Vulnerability in dos (CVE-2025-14300)
vulnerability in dos (CVE-2025-14300). Data can be tampered with by attackers.
|
| CVE-2025-67780 |
|
Vulnerability in CVE-2025-67780 (CVE-2025-67780)
vulnerability in CVE-2025-67780 (CVE-2025-67780). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2025-65828 |
|
Vulnerability in dos (CVE-2025-65828)
vulnerability in dos (CVE-2025-65828). Risk of unauthorized operations or information disclosure.
|