Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-31585 |
|
Vulnerability in c (CVE-2026-31585)
vulnerability in c (CVE-2026-31585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31586 |
|
Use-After-Free in c (CVE-2026-31586)
vulnerability in c (CVE-2026-31586). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31587 |
|
Use-After-Free in c (CVE-2026-31587)
vulnerability in c (CVE-2026-31587). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31578 |
|
Use-After-Free in c (CVE-2026-31578)
vulnerability in c (CVE-2026-31578). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31581 |
|
Use-After-Free in c (CVE-2026-31581)
vulnerability in c (CVE-2026-31581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31563 |
|
Vulnerability in c (CVE-2026-31563)
vulnerability in c (CVE-2026-31563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31555 |
|
Vulnerability in c (CVE-2026-31555)
vulnerability in c (CVE-2026-31555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31546 |
|
Vulnerability in c (CVE-2026-31546)
vulnerability in c (CVE-2026-31546). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33317 |
|
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, mis...
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()` in `ta/pkcs11/src/object.c` can lead to out-of-bounds...
|
| CVE-2026-28525 |
|
Out-of-Bounds Read in c (CVE-2026-28525)
vulnerability in c (CVE-2026-28525). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41650 |
|
Vulnerability in fast-xml-parser (CVE-2026-41650)
vulnerability in fast-xml-parser (CVE-2026-41650). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.7.0` or later.
|
| CVE-2026-41651 |
|
Vulnerability in c (CVE-2026-41651)
vulnerability in c (CVE-2026-41651). Successful exploitation can lead to full system takeover. Exploitable via ``RUNNING``.
|
| CVE-2026-31515 |
|
Vulnerability in c (CVE-2026-31515)
vulnerability in c (CVE-2026-31515). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31500 |
|
Use-After-Free in c (CVE-2026-31500)
vulnerability in c (CVE-2026-31500). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31503 |
|
Vulnerability in c (CVE-2026-31503)
vulnerability in c (CVE-2026-31503). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31494 |
|
Out-of-Bounds Write in c (CVE-2026-31494)
out-of-bounds write in c (CVE-2026-31494). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31469 |
|
Use-After-Free in c (CVE-2026-31469)
vulnerability in c (CVE-2026-31469). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31448 |
|
Vulnerability in c (CVE-2026-31448)
vulnerability in c (CVE-2026-31448). Data can be tampered with by attackers.
|
| CVE-2026-31437 |
|
Vulnerability in c (CVE-2026-31437)
vulnerability in c (CVE-2026-31437). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22016 |
|
Information Disclosure in java (CVE-2026-22016)
vulnerability in java (CVE-2026-22016). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.0, 8.0.491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1` or later.
|
| CVE-2026-35244 |
|
Vulnerability in c (CVE-2026-35244)
vulnerability in c (CVE-2026-35244). Data can be tampered with by attackers.
|
| CVE-2026-34314 |
|
Vulnerability in c (CVE-2026-34314)
vulnerability in c (CVE-2026-34314). Confidential information can be exposed externally.
|
| CVE-2026-21999 |
|
Information Disclosure in c (CVE-2026-21999)
vulnerability in c (CVE-2026-21999). Confidential information can be exposed externally.
|
| CVE-2026-6058 |
|
Vulnerability in c (CVE-2026-6058)
vulnerability in c (CVE-2026-6058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5450 |
|
Vulnerability in c (CVE-2026-5450)
vulnerability in c (CVE-2026-5450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5928 |
|
Vulnerability in c (CVE-2026-5928)
vulnerability in c (CVE-2026-5928). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41445 |
|
Vulnerability in c (CVE-2026-41445)
vulnerability in c (CVE-2026-41445). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41253 |
|
Vulnerability in c (CVE-2026-41253)
vulnerability in c (CVE-2026-41253). Confidential information can be exposed externally.
|
| CVE-2026-29013 |
|
Out-of-Bounds Read in c (CVE-2026-29013)
vulnerability in c (CVE-2026-29013). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41113 |
|
OS Command Injection in c (CVE-2026-41113)
OS command injection in c (CVE-2026-41113). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40170 |
|
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buf...
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transpo...
|
| CVE-2026-43995 |
|
SSRF (Server-Side Request Forgery) in flowise (CVE-2026-43995)
SSRF in flowise (CVE-2026-43995). Successful exploitation can lead to full system takeover. Exploitable via ``httpSecurity.ts``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-56270 |
|
Vulnerability in flowise (CVE-2026-56270)
vulnerability in flowise (CVE-2026-56270). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/loginmethod`. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2025-41118 |
|
Information Disclosure in github.com/grafana/pyroscope (CVE-2025-41118)
vulnerability in github.com/grafana/pyroscope (CVE-2025-41118). Confidential information can be exposed externally. Mitigation: upgrade to `1.15.2, 1.16.1` or later.
|
| CVE-2026-6245 |
|
Vulnerability in c (CVE-2026-6245)
vulnerability in c (CVE-2026-6245). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-40899 |
|
Cross-Site Scripting (XSS) in c (CVE-2025-40899)
cross-site scripting in c (CVE-2025-40899). Data can be tampered with by attackers.
|
| CVE-2026-33023 |
|
Use-After-Free in c (CVE-2026-33023)
vulnerability in c (CVE-2026-33023). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33018 |
|
Use-After-Free in c (CVE-2026-33018)
vulnerability in c (CVE-2026-33018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33020 |
|
Vulnerability in c (CVE-2026-33020)
vulnerability in c (CVE-2026-33020). Data can be tampered with by attackers.
|
| CVE-2026-6192 |
|
Vulnerability in c (CVE-2026-6192)
vulnerability in c (CVE-2026-6192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31423 |
|
Vulnerability in c (CVE-2026-31423)
vulnerability in c (CVE-2026-31423). Risk of unauthorized operations or information disclosure. Exploitable via ``dsm``.
|
| CVE-2026-31424 |
|
Vulnerability in c (CVE-2026-31424)
vulnerability in c (CVE-2026-31424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31425 |
|
Vulnerability in c (CVE-2026-31425)
vulnerability in c (CVE-2026-31425). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31426 |
|
Use-After-Free in c (CVE-2026-31426)
vulnerability in c (CVE-2026-31426). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31427 |
|
Vulnerability in c (CVE-2026-31427)
vulnerability in c (CVE-2026-31427). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31421 |
|
Vulnerability in c (CVE-2026-31421)
vulnerability in c (CVE-2026-31421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31422 |
|
Vulnerability in c (CVE-2026-31422)
vulnerability in c (CVE-2026-31422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31419 |
|
Use-After-Free in c (CVE-2026-31419)
vulnerability in c (CVE-2026-31419). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31415 |
|
Vulnerability in c (CVE-2026-31415)
vulnerability in c (CVE-2026-31415). Risk of unauthorized operations or information disclosure. Exploitable via ``__u16``.
|
| CVE-2026-40194 |
|
Vulnerability in phpseclib/phpseclib (CVE-2026-40194)
vulnerability in phpseclib/phpseclib (CVE-2026-40194). Risk of unauthorized operations or information disclosure. Exploitable via ``e819a163c``. Mitigation: upgrade to `1.0.28` or later.
|