Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-0596 |
|
OS Command Injection in mlflow (CVE-2026-0596)
OS command injection in mlflow (CVE-2026-0596). Successful exploitation can lead to full system takeover. Exploitable via ``model_uri``. Mitigation: upgrade to `3.9.0` or later.
|
| CVE-2026-34165 |
|
Vulnerability in dos (CVE-2026-34165)
vulnerability in dos (CVE-2026-34165). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34202 |
|
Code Injection in deserialization (CVE-2026-34202)
code injection in deserialization (CVE-2026-34202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34172 |
|
Vulnerability in giskard-agents (CVE-2026-34172)
vulnerability in giskard-agents (CVE-2026-34172). Successful exploitation can lead to full system takeover. Exploitable via ``Environment``. Mitigation: upgrade to `1.0.2b1` or later.
|
| CVE-2026-34163 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34163)
SSRF in ssrf (CVE-2026-34163). Confidential information can be exposed externally.
|
| CVE-2026-33276 |
|
Cross-Site Scripting (XSS) in checkmk (CVE-2026-33276)
cross-site scripting in checkmk (CVE-2026-33276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33579 |
|
Authorization Flaw in privilege-escalation (CVE-2026-33579)
vulnerability in privilege-escalation (CVE-2026-33579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30312 |
|
OS Command Injection in CVE-2026-30312 (CVE-2026-30312)
OS command injection in CVE-2026-30312 (CVE-2026-30312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30314 |
|
OS Command Injection in ridvay (CVE-2026-30314)
OS command injection in ridvay (CVE-2026-30314). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30311 |
|
OS Command Injection in ridvay (CVE-2026-30311)
OS command injection in ridvay (CVE-2026-30311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29870 |
|
Path Traversal in path-traversal (CVE-2026-29870)
path traversal in path-traversal (CVE-2026-29870). Data can be tampered with by attackers.
|
| CVE-2026-20915 |
|
Cross-Site Scripting (XSS) in checkmk (CVE-2026-20915)
cross-site scripting in checkmk (CVE-2026-20915). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34156 |
|
Vulnerability in nocobase (CVE-2026-34156)
vulnerability in nocobase (CVE-2026-34156). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5198 |
|
Vulnerability in sqli (CVE-2026-5198)
vulnerability in sqli (CVE-2026-5198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4267 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4267)
cross-site scripting in wordpress (CVE-2026-4267). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27854 |
|
Use-After-Free in dos (CVE-2026-27854)
vulnerability in dos (CVE-2026-27854). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24028 |
|
Vulnerability in dos (CVE-2026-24028)
vulnerability in dos (CVE-2026-24028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24030 |
|
Vulnerability in dos (CVE-2026-24030)
vulnerability in dos (CVE-2026-24030). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27853 |
|
Out-of-Bounds Write in dos (CVE-2026-27853)
out-of-bounds write in dos (CVE-2026-27853). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4317 |
|
SQL Injection in sqli (CVE-2026-4317)
SQL injection in sqli (CVE-2026-4317). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5201 |
|
Vulnerability in dos (CVE-2026-5201)
vulnerability in dos (CVE-2026-5201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34881 |
|
SSRF (Server-Side Request Forgery) in glance (CVE-2026-34881)
SSRF in glance (CVE-2026-34881). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `31.1.0` or later.
|
| CVE-2026-34070 |
|
Path Traversal in langchain-core (CVE-2026-34070)
path traversal in langchain-core (CVE-2026-34070). Confidential information can be exposed externally. Exploitable via ``langchain_core.prompts.loading``. Mitigation: upgrade to `1.2.22` or later.
|
| CVE-2026-33983 |
|
Vulnerability in dos (CVE-2026-33983)
vulnerability in dos (CVE-2026-33983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29597 |
|
Vulnerability in privilege-escalation (CVE-2026-29597)
vulnerability in privilege-escalation (CVE-2026-29597). Confidential information can be exposed externally.
|
| CVE-2026-30082 |
|
Cross-Site Scripting (XSS) in CVE-2026-30082 (CVE-2026-30082)
cross-site scripting in CVE-2026-30082 (CVE-2026-30082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4315 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-4315)
vulnerability in csrf (CVE-2026-4315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4266 |
|
Unsafe Deserialization in deserialization (CVE-2026-4266)
vulnerability in deserialization (CVE-2026-4266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3945 |
|
Vulnerability in dos (CVE-2026-3945)
vulnerability in dos (CVE-2026-3945). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15036 |
|
Vulnerability in mlflow (CVE-2025-15036)
vulnerability in mlflow (CVE-2025-15036). Successful exploitation can lead to full system takeover. Exploitable via ``extract_archive_to_dir``. Mitigation: upgrade to `3.9.0rc0` or later.
|
| CVE-2026-73427 |
|
Cross-Site Scripting (XSS) in trix (CVE-2026-73427)
cross-site scripting in trix (CVE-2026-73427). Risk of unauthorized operations or information disclosure. Exploitable via ``StringPiece.fromJSON``. Mitigation: upgrade to `2.1.18` or later.
|
| CVE-2026-33943 |
|
Code Injection in capricorn86 (CVE-2026-33943)
code injection in capricorn86 (CVE-2026-33943). Successful exploitation can lead to full system takeover. Exploitable via ``ECMAScriptModuleCompiler``.
|
| CVE-2026-33939 |
|
Vulnerability in dos (CVE-2026-33939)
vulnerability in dos (CVE-2026-33939). Risk of unauthorized operations or information disclosure. Exploitable via ``undefined``.
|
| CVE-2026-33937 |
|
Code Injection in handlebarsjs (CVE-2026-33937)
code injection in handlebarsjs (CVE-2026-33937). Successful exploitation can lead to full system takeover. Exploitable via ``value``.
|
| CVE-2026-33891 |
|
Vulnerability in dos (CVE-2026-33891)
vulnerability in dos (CVE-2026-33891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65914 |
|
Cross-Site Scripting (XSS) in dompurify (CVE-2026-65914)
cross-site scripting in dompurify (CVE-2026-65914). Risk of unauthorized operations or information disclosure. Exploitable via `POST /sanitize`. Mitigation: upgrade to `3.3.2` or later.
|
| CVE-2026-33871 |
|
Vulnerability in dos (CVE-2026-33871)
vulnerability in dos (CVE-2026-33871). Risk of unauthorized operations or information disclosure. Exploitable via ``CONTINUATION``.
|
| CVE-2026-30567 |
|
Cross-Site Scripting (XSS) in ahsanriaz26gmailcom (CVE-2026-30567)
cross-site scripting in ahsanriaz26gmailcom (CVE-2026-30567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56358 |
|
Cross-Site Scripting (XSS) in n8n (CVE-2026-56358)
cross-site scripting in n8n (CVE-2026-56358). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `1.123.25` or later.
|
| CVE-2026-32983 |
|
Vulnerability in dos (CVE-2026-32983)
vulnerability in dos (CVE-2026-32983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32984 |
|
Out-of-Bounds Read in dos (CVE-2026-32984)
vulnerability in dos (CVE-2026-32984). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5010 |
|
Cross-Site Scripting (XSS) in CVE-2026-5010 (CVE-2026-5010)
cross-site scripting in CVE-2026-5010 (CVE-2026-5010). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5027 |
|
Path Traversal in path-traversal (CVE-2026-5027)
path traversal in path-traversal (CVE-2026-5027). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/files`.
|
| CVE-2026-33758 |
|
Vulnerability in openbao (CVE-2026-33758)
vulnerability in openbao (CVE-2026-33758). Risk of unauthorized operations or information disclosure. Exploitable via ``error_description``.
|
| CVE-2026-27876 |
|
Code Injection in grafana (CVE-2026-27876)
code injection in grafana (CVE-2026-27876). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2025-61190 |
|
Cross-Site Scripting (XSS) in lyrasis (CVE-2025-61190)
cross-site scripting in lyrasis (CVE-2025-61190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32859 |
|
Cross-Site Scripting (XSS) in CVE-2026-32859 (CVE-2026-32859)
cross-site scripting in CVE-2026-32859 (CVE-2026-32859). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3457 |
|
Cross-Site Scripting (XSS) in CVE-2026-3457 (CVE-2026-3457)
cross-site scripting in CVE-2026-3457 (CVE-2026-3457). Data can be tampered with by attackers.
|
| CVE-2026-33559 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-33559)
cross-site scripting in wordpress (CVE-2026-33559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22742 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-22742)
SSRF in ssrf (CVE-2026-22742). Confidential information can be exposed externally.
|