Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-40192 |
|
Vulnerability in pillow (CVE-2026-40192)
vulnerability in pillow (CVE-2026-40192). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.2.0` or later.
|
| CVE-2026-41589 |
|
Path Traversal in charm.land/wish/v2 (CVE-2026-41589)
path traversal in charm.land/wish/v2 (CVE-2026-41589). Confidential information can be exposed externally. Exploitable via ``main``. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2026-40346 |
|
SSRF (Server-Side Request Forgery) in @nocobase/plugin-workflow-request (CVE-2026-40346)
SSRF in @nocobase/plugin-workflow-request (CVE-2026-40346). Confidential information can be exposed externally. Exploitable via ``url``. Mitigation: upgrade to `2.0.37` or later.
|
| CVE-2026-5720 |
|
Out-of-Bounds Read in dos (CVE-2026-5720)
vulnerability in dos (CVE-2026-5720). Confidential information can be exposed externally.
|
| CVE-2026-33436 |
|
Vulnerability in stirlingpdf (CVE-2026-33436)
vulnerability in stirlingpdf (CVE-2026-33436). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40066 |
|
Vulnerability in anviz (CVE-2026-40066)
vulnerability in anviz (CVE-2026-40066). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31927 |
|
Vulnerability in path-traversal (CVE-2026-31927)
vulnerability in path-traversal (CVE-2026-31927). Data can be tampered with by attackers.
|
| CVE-2026-40525 |
|
Vulnerability in openviking (CVE-2026-40525)
vulnerability in openviking (CVE-2026-40525). Confidential information can be exposed externally. Exploitable via `X-API-Key header`. Mitigation: upgrade to `0.3.9` or later.
|
| CVE-2026-5718 |
|
Unrestricted File Upload in wordpress (CVE-2026-5718)
vulnerability in wordpress (CVE-2026-5718). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40518 |
|
Path Traversal in path-traversal (CVE-2026-40518)
path traversal in path-traversal (CVE-2026-40518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6507 |
|
Out-of-Bounds Write in dos (CVE-2026-6507)
out-of-bounds write in dos (CVE-2026-6507). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41481 |
|
SSRF (Server-Side Request Forgery) in langchain-text-splitters (CVE-2026-41481)
SSRF in langchain-text-splitters (CVE-2026-41481). Confidential information can be exposed externally. Exploitable via ``Document``. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-41113 |
|
OS Command Injection in c (CVE-2026-41113)
OS command injection in c (CVE-2026-41113). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40170 |
|
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buf...
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transpo...
|
| CVE-2025-54502 |
|
Vulnerability in privilege-escalation (CVE-2025-54502)
vulnerability in privilege-escalation (CVE-2025-54502). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43995 |
|
SSRF (Server-Side Request Forgery) in flowise (CVE-2026-43995)
SSRF in flowise (CVE-2026-43995). Successful exploitation can lead to full system takeover. Exploitable via ``httpSecurity.ts``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-56269 |
|
Vulnerability in flowise (CVE-2026-56269)
vulnerability in flowise (CVE-2026-56269). Confidential information can be exposed externally. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-41205 |
|
Path Traversal in Mako (CVE-2026-41205)
path traversal in Mako (CVE-2026-41205). Confidential information can be exposed externally. Exploitable via ``Template.__init__``. Mitigation: upgrade to `1.3.11` or later.
|
| CVE-2026-2336 |
|
Vulnerability in privilege-escalation (CVE-2026-2336)
vulnerability in privilege-escalation (CVE-2026-2336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5426 |
|
Vulnerability in csharp (CVE-2026-5426)
vulnerability in csharp (CVE-2026-5426). Confidential information can be exposed externally.
|
| CVE-2026-3324 |
|
Vulnerability in zohocorp (CVE-2026-3324)
vulnerability in zohocorp (CVE-2026-3324). Confidential information can be exposed externally.
|
| CVE-2026-31843 |
|
Vulnerability in goodoneuz/pay-uz (CVE-2026-31843)
vulnerability in goodoneuz/pay-uz (CVE-2026-31843). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.0.0` or later.
|
| CVE-2026-41035 |
|
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort...
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort...
|
| CVE-2026-3885 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3885)
cross-site scripting in wordpress (CVE-2026-3885). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40503 |
|
Path Traversal in path-traversal (CVE-2026-40503)
path traversal in path-traversal (CVE-2026-40503). Confidential information can be exposed externally.
|
| CVE-2026-6388 |
|
Vulnerability in privilege-escalation (CVE-2026-6388)
vulnerability in privilege-escalation (CVE-2026-6388). Data can be tampered with by attackers.
|
| CVE-2026-34197 KEV |
|
[KEV] Vulnerability in Apache activemq (CVE-2026-34197)
vulnerability in Apache activemq (CVE-2026-34197). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-40316 |
|
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflo...
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run with...
|
| CVE-2026-40500 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-40500)
SSRF in ssrf (CVE-2026-40500). Confidential information can be exposed externally.
|
| CVE-2026-6384 |
|
Vulnerability in dos (CVE-2026-6384)
vulnerability in dos (CVE-2026-6384). Successful exploitation can lead to full system takeover. Exploitable via ``ReadJeffsImage``.
|
| CVE-2026-6245 |
|
Vulnerability in c (CVE-2026-6245)
vulnerability in c (CVE-2026-6245). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20186 |
|
Command Injection in dos (CVE-2026-20186)
command injection in dos (CVE-2026-20186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20148 |
|
Path Traversal in path-traversal (CVE-2026-20148)
path traversal in path-traversal (CVE-2026-20148). Confidential information can be exposed externally.
|
| CVE-2026-30461 |
|
Command Injection in thedaylightstudio (CVE-2026-30461)
command injection in thedaylightstudio (CVE-2026-30461). Confidential information can be exposed externally.
|
| CVE-2025-40899 |
|
Cross-Site Scripting (XSS) in c (CVE-2025-40899)
cross-site scripting in c (CVE-2025-40899). Data can be tampered with by attackers.
|
| CVE-2026-26291 |
|
Cross-Site Scripting (XSS) in CVE-2026-26291 (CVE-2026-26291)
cross-site scripting in CVE-2026-26291 (CVE-2026-26291). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56370 |
|
Out-of-Bounds Read in Magick.NET-Q16-AnyCPU (CVE-2026-56370)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-56370). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.12.0` or later.
|
| CVE-2026-39387 |
|
Vulnerability in path-traversal (CVE-2026-39387)
vulnerability in path-traversal (CVE-2026-39387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39399 |
|
Vulnerability in CVE-2026-39399 (CVE-2026-39399)
vulnerability in CVE-2026-39399 (CVE-2026-39399). Data can be tampered with by attackers.
|
| CVE-2026-35031 |
|
Vulnerability in path-traversal (CVE-2026-35031)
vulnerability in path-traversal (CVE-2026-35031). Successful exploitation can lead to full system takeover. Exploitable via `POST /Videos/{itemId}/Subtitles`.
|
| CVE-2026-35032 |
|
Vulnerability in ssrf (CVE-2026-35032)
vulnerability in ssrf (CVE-2026-35032). Confidential information can be exposed externally. Exploitable via `POST /LiveTv/TunerHosts`.
|
| CVE-2026-34457 |
|
Vulnerability in oauth2-proxy (CVE-2026-34457)
vulnerability in oauth2-proxy (CVE-2026-34457). Confidential information can be exposed externally. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-35034 |
|
Vulnerability in dos (CVE-2026-35034)
vulnerability in dos (CVE-2026-35034). Risk of unauthorized operations or information disclosure. Exploitable via `POST /SyncPlay/New`.
|
| CVE-2026-25133 |
|
Cross-Site Scripting (XSS) in october/rain (CVE-2026-25133)
cross-site scripting in october/rain (CVE-2026-25133). Risk of unauthorized operations or information disclosure. Exploitable via ``media.library.create``. Mitigation: upgrade to `3.7.14` or later.
|
| CVE-2026-39906 |
|
Vulnerability in csharp (CVE-2026-39906)
vulnerability in csharp (CVE-2026-39906). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39907 |
|
Vulnerability in privilege-escalation (CVE-2026-39907)
vulnerability in privilege-escalation (CVE-2026-39907). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34619 |
|
Path Traversal in path-traversal (CVE-2026-34619)
path traversal in path-traversal (CVE-2026-34619). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33193 |
|
Cross-Site Scripting (XSS) in docmost (CVE-2026-33193)
cross-site scripting in docmost (CVE-2026-33193). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27305 |
|
Path Traversal in path-traversal (CVE-2026-27305)
path traversal in path-traversal (CVE-2026-27305). Confidential information can be exposed externally.
|
| CVE-2026-34161 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-34161)
cross-site scripting in privilege-escalation (CVE-2026-34161). Risk of unauthorized operations or information disclosure.
|