CVE Analysis Index
10118 curated vulnerability analyses with independent analyst commentary. Each entry includes executive summary, technical breakdown, business impact, and remediation guidance.
Recent analyses
- CVE-2026-51807 OpenHTJ2K A buffer overflow vulnerability in OpenHTJ2K up to version 0.18.4 allows unauthenticated attackers to execute arbitrary code via a malicious JPEG 2000 file.
- CVE-2026-12512 Unknown The Quotes llama WordPress plugin contains a SQL injection vulnerability that allows unauthenticated attackers to read sensitive database information, including password hashes.
- CVE-2026-16118 Red Hat A heap-based buffer overflow vulnerability in the xdgmime library within Red Hat Enterprise Linux may allow for arbitrary code execution or service disruption via malicious file processing.
- CVE-2026-16154 SourceCodester An unauthenticated SQL injection vulnerability in SourceCodester Class and Exam Timetabling System allows remote attackers to execute arbitrary SQL commands via the edit_room1.php script.
- CVE-2026-12228 parisneo A stored cross-site scripting (XSS) vulnerability in the parisneo lollms API allows attackers to inject malicious scripts that execute in the context of other users, including administrators.
- CVE-2026-16152 SourceCodester A SQL injection vulnerability in the SourceCodester Class and Exam Timetabling System allows remote, unauthenticated attackers to execute arbitrary database queries via the edit_rooma.php file.
- CVE-2026-16200 zevorn An improper authorization vulnerability in the zevorn rt-claw RPC handler allows unauthenticated remote attackers to manipulate system tools and gain elevated privileges.
- CVE-2026-16095 Shibby An out-of-bounds write flaw in the setup_conntrack function of Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 allows unauthenticated remote attackers to trigger memory corruption.
- CVE-2026-16096 Shibby A stack-based buffer overflow in the web monitoring module of Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 allows remote attackers to trigger memory corruption.
- CVE-2026-16097 Shibby A stack-based buffer overflow in the Scheduler Name Handler component of Shibby Tomato 1.28 allows for remote exploitation.
- CVE-2026-22104 Hashtopolis Hashtopolis server contains an authorization bypass vulnerability in the web interface chunk activity component, allowing authenticated users to access unauthorized data.
- CVE-2026-9588 Sangoma A stored cross-site scripting (XSS) vulnerability in Sangoma Switchvox SMB Edition allows authenticated users to inject malicious scripts into the web interface.
- CVE-2026-14871 osTicket osTicket suffers from an incorrect authorization vulnerability that may allow authenticated users to perform unauthorized actions.
- CVE-2026-50163 oras-project The oras-go library is affected by path traversal and improper link resolution vulnerabilities, potentially allowing unauthorized file access.
- CVE-2026-9587 Sangoma Sangoma Switchvox SMB Edition contains an authenticated local file inclusion vulnerability that allows attackers to access sensitive files on the server.
- CVE-2025-71395 SurrealDB SurrealDB is susceptible to a memory exhaustion vulnerability caused by improper handling of excessive size values in string operations.
- CVE-2025-71397 SurrealDB SurrealDB is vulnerable to a CPU exhaustion attack due to an infinite loop flaw triggered by improper handling of nested for loops.
- CVE-2024-58367 SurrealDB SurrealDB contains an improper authorization vulnerability that allows authenticated users with low privileges to access sensitive data through improper select permissions.
- CVE-2025-71391 SurrealDB SurrealDB is susceptible to a denial-of-service vulnerability via the SQL endpoint due to an uncaught exception, which can be triggered by authenticated users.
- CVE-2026-16014 code-projects The Hospital Bed Management System contains a SQL injection vulnerability that allows unauthenticated attackers to potentially access or manipulate database information.
- CVE-2026-16016 poco-ai A Server-Side Request Forgery vulnerability in poco-ai poco-claw allows unauthenticated attackers to manipulate server-side requests.
- CVE-2026-16084 Sipeed A Server-Side Request Forgery vulnerability in Sipeed PicoClaw allows unauthenticated attackers to manipulate server-side requests.
- CVE-2026-16125 zevorn A Server-Side Request Forgery vulnerability exists in zevorn rt-claw, allowing unauthenticated attackers to potentially perform unauthorized requests.
- CVE-2026-16126 zevorn An authorization bypass vulnerability exists in zevorn rt-claw versions 0.1 and 0.2.0, which may allow unauthenticated remote attackers to perform actions restricted to authorized users.
- CVE-2026-16127 zevorn A Server-Side Request Forgery (SSRF) vulnerability has been identified in zevorn rt-claw versions 0.1 and 0.2.0, enabling unauthenticated remote attackers to perform unauthorized network requests.
- CVE-2026-16128 zevorn A Server-Side Request Forgery (SSRF) vulnerability exists in zevorn rt-claw versions 0.1 and 0.2.0, allowing unauthenticated remote attackers to trigger unauthorized network requests.
- CVE-2026-16210 newpanjing The simpleui package by newpanjing contains a critical authentication vulnerability that allows unauthorized access to application functions.
- CVE-2026-7189 Proliz Software Proliz's OBS contains a vulnerability that leads to the unauthorized insertion of sensitive information into outgoing data streams.
- CVE-2026-8396 Netcad Software NetGIS contains an XML external entity (XXE) vulnerability that permits unauthorized information disclosure via improper restriction of XML references.
- CVE-2026-7488 IKAS Technology IKAS Technology E-Commerce software contains a vulnerability involving the improper insertion of sensitive information into sent data.
Browse all
Looking for a specific CVE? The full searchable database has filters by vendor, severity, CISA KEV status, and free-text search.