Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15996 |
|
Vulnerability in dos (CVE-2026-15996)
vulnerability in dos (CVE-2026-15996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18839 |
|
Vulnerability in dos (CVE-2026-18839)
vulnerability in dos (CVE-2026-18839). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18959 |
|
Path Traversal in path-traversal (CVE-2026-18959)
path traversal in path-traversal (CVE-2026-18959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34966 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34966)
SSRF in ssrf (CVE-2026-34966). Confidential information can be exposed externally.
|
| CVE-2026-69111 |
|
Vulnerability in dos (CVE-2026-69111)
vulnerability in dos (CVE-2026-69111). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66885 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66885)
vulnerability in csrf (CVE-2026-66885). Confidential information can be exposed externally.
|
| CVE-2026-66881 |
|
Vulnerability in path-traversal (CVE-2026-66881)
vulnerability in path-traversal (CVE-2026-66881). Data can be tampered with by attackers.
|
| CVE-2026-55522 |
|
Code Injection in praisonaiagents (CVE-2026-55522)
code injection in praisonaiagents (CVE-2026-55522). Successful exploitation can lead to full system takeover. Exploitable via ``tools.py``. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-55524 |
|
Vulnerability in praisonaiagents (CVE-2026-55524)
vulnerability in praisonaiagents (CVE-2026-55524). Confidential information can be exposed externally. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-55523 |
|
SSRF (Server-Side Request Forgery) in praisonaiagents (CVE-2026-55523)
SSRF in praisonaiagents (CVE-2026-55523). Risk of unauthorized operations or information disclosure. Exploitable via ``web_crawl``. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-18958 |
|
Vulnerability in sqli (CVE-2026-18958)
vulnerability in sqli (CVE-2026-18958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17556 |
|
Path Traversal in path-traversal (CVE-2026-17556)
path traversal in path-traversal (CVE-2026-17556). Data can be tampered with by attackers.
|
| CVE-2026-7869 |
|
Path Traversal in path-traversal (CVE-2026-7869)
path traversal in path-traversal (CVE-2026-7869). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge_bases`.
|
| CVE-2026-7658 |
|
Path Traversal in path-traversal (CVE-2026-7658)
path traversal in path-traversal (CVE-2026-7658). Data can be tampered with by attackers.
|
| CVE-2026-63457 |
|
Vulnerability in dos (CVE-2026-63457)
vulnerability in dos (CVE-2026-63457). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18485 |
|
Vulnerability in privilege-escalation (CVE-2026-18485)
vulnerability in privilege-escalation (CVE-2026-18485). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10547 |
|
Vulnerability in dos (CVE-2026-10547)
vulnerability in dos (CVE-2026-10547). Data can be tampered with by attackers. Exploitable via `POST /api/v1/build/{flow_id}/vertices`.
|
| CVE-2026-9081 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9081)
SSRF in ssrf (CVE-2026-9081). Confidential information can be exposed externally.
|
| CVE-2026-7657 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-7657)
SSRF in ssrf (CVE-2026-7657). Confidential information can be exposed externally.
|
| CVE-2026-70441 |
|
Cross-Site Scripting (XSS) in CVE-2026-70441 (CVE-2026-70441)
cross-site scripting in CVE-2026-70441 (CVE-2026-70441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70434 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70434)
vulnerability in csrf (CVE-2026-70434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70440 |
|
Cross-Site Scripting (XSS) in CVE-2026-70440 (CVE-2026-70440)
cross-site scripting in CVE-2026-70440 (CVE-2026-70440). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70432 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70432)
vulnerability in csrf (CVE-2026-70432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10716 |
|
SQL Injection in sqli (CVE-2026-10716)
SQL injection in sqli (CVE-2026-10716). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70428 |
|
Path Traversal in path-traversal (CVE-2026-70428)
path traversal in path-traversal (CVE-2026-70428). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7646 |
|
Path Traversal in path-traversal (CVE-2026-7646)
path traversal in path-traversal (CVE-2026-7646). Confidential information can be exposed externally.
|
| CVE-2026-44605 |
|
Vulnerability in dos (CVE-2026-44605)
vulnerability in dos (CVE-2026-44605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70426 |
|
Unsafe Deserialization in deserialization (CVE-2026-70426)
vulnerability in deserialization (CVE-2026-70426). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17617 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-17617)
SSRF in ssrf (CVE-2026-17617). Confidential information can be exposed externally.
|
| CVE-2026-8446 |
|
Vulnerability in langflow (CVE-2026-8446)
vulnerability in langflow (CVE-2026-8446). Confidential information can be exposed externally.
|
| CVE-2026-20308 |
|
Privilege Escalation in Cisco dos (CVE-2026-20308)
vulnerability in Cisco dos (CVE-2026-20308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20311 |
|
Vulnerability in Cisco dos (CVE-2026-20311)
vulnerability in Cisco dos (CVE-2026-20311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20263 |
|
Vulnerability in Cisco dos (CVE-2026-20263)
vulnerability in Cisco dos (CVE-2026-20263). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20124 |
|
Vulnerability in Cisco dos (CVE-2026-20124)
vulnerability in Cisco dos (CVE-2026-20124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20301 |
|
Vulnerability in Cisco dos (CVE-2026-20301)
vulnerability in Cisco dos (CVE-2026-20301). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20198 |
|
Cross-Site Scripting (XSS) in cisco (CVE-2026-20198)
cross-site scripting in cisco (CVE-2026-20198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9195 |
|
Path Traversal in CVE-2026-9195 (CVE-2026-9195)
path traversal in CVE-2026-9195 (CVE-2026-9195). Confidential information can be exposed externally.
|
| CVE-2026-9192 |
|
Authentication Bypass in CVE-2026-9192 (CVE-2026-9192)
authentication bypass in CVE-2026-9192 (CVE-2026-9192). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53992 |
|
Cross-Site Scripting (XSS) in CVE-2026-53992 (CVE-2026-53992)
cross-site scripting in CVE-2026-53992 (CVE-2026-53992). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48834 |
|
Vulnerability in apache (CVE-2026-48834)
vulnerability in apache (CVE-2026-48834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54876 |
|
Vulnerability in dos (CVE-2026-54876)
vulnerability in dos (CVE-2026-54876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70596 |
|
Cross-Site Scripting (XSS) in ghost (CVE-2026-70596)
cross-site scripting in ghost (CVE-2026-70596). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-67623 |
|
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
|
| CVE-2026-17506 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15979 |
|
Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
|
| CVE-2026-71294 |
|
Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
vulnerability in CVE-2026-71294 (CVE-2026-71294). Confidential information can be exposed externally. Exploitable via ``allowed_classes``.
|
| CVE-2026-71288 |
|
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
|
| CVE-2026-71291 |
|
Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
|
| CVE-2026-71287 |
|
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
|
| CVE-2026-71286 |
|
Vulnerability in CVE-2026-71286 (CVE-2026-71286)
vulnerability in CVE-2026-71286 (CVE-2026-71286). Risk of unauthorized operations or information disclosure. Exploitable via ``templateString``.
|