Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55532 |
|
Vulnerability in PraisonAI (CVE-2026-55532)
vulnerability in PraisonAI (CVE-2026-55532). Data can be tampered with by attackers. Exploitable via `Host header`. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-55529 |
|
Vulnerability in PraisonAI (CVE-2026-55529)
vulnerability in PraisonAI (CVE-2026-55529). Confidential information can be exposed externally. Exploitable via ``Origin``. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-62316 |
|
Information Disclosure in CVE-2026-62316 (CVE-2026-62316)
vulnerability in CVE-2026-62316 (CVE-2026-62316). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67448 |
|
Vulnerability in github.com/axllent/mailpit (CVE-2026-67448)
vulnerability in github.com/axllent/mailpit (CVE-2026-67448). Confidential information can be exposed externally. Mitigation: upgrade to `1.30.6` or later.
|
| CVE-2026-60765 |
|
Vulnerability in c (CVE-2026-60765)
vulnerability in c (CVE-2026-60765). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74960 |
|
Vulnerability in mozilla (CVE-2026-74960)
vulnerability in mozilla (CVE-2026-74960). Confidential information can be exposed externally.
|
| CVE-2026-74934 |
|
Information Disclosure in mozilla (CVE-2026-74934)
vulnerability in mozilla (CVE-2026-74934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19418 |
|
Vulnerability in CVE-2026-19418 (CVE-2026-19418)
vulnerability in CVE-2026-19418 (CVE-2026-19418). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46409 |
|
Code Injection in CVE-2026-46409 (CVE-2026-46409)
code injection in CVE-2026-46409 (CVE-2026-46409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54605 |
|
Information Disclosure in oauth (CVE-2026-54605)
vulnerability in oauth (CVE-2026-54605). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.1.6` or later.
|
| CVE-2026-73419 |
|
Vulnerability in @auth/core (CVE-2026-73419)
vulnerability in @auth/core (CVE-2026-73419). Confidential information can be exposed externally. Exploitable via ``state``. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-16398 |
|
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153.
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16387 |
|
Information Disclosure in mozilla (CVE-2026-16387)
vulnerability in mozilla (CVE-2026-16387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46555 |
|
Path Traversal in path-traversal (CVE-2026-46555)
path traversal in path-traversal (CVE-2026-46555). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2026-15075 |
|
Information Disclosure in eclipse (CVE-2026-15075)
vulnerability in eclipse (CVE-2026-15075). Confidential information can be exposed externally.
|
| CVE-2026-59208 |
|
Authentication Bypass in n8n (CVE-2026-59208)
authentication bypass in n8n (CVE-2026-59208). Confidential information can be exposed externally. Exploitable via ``sub``. Mitigation: upgrade to `2.27.4` or later.
|
| CVE-2026-42341 |
|
Vulnerability in CVE-2026-42341 (CVE-2026-42341)
vulnerability in CVE-2026-42341 (CVE-2026-42341). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59152 |
|
Path Traversal in langsmith (CVE-2026-59152)
path traversal in langsmith (CVE-2026-59152). Confidential information can be exposed externally. Exploitable via ``TracingMiddleware``. Mitigation: upgrade to `0.8.18` or later.
|
| CVE-2026-13887 |
|
Vulnerability in google (CVE-2026-13887)
vulnerability in google (CVE-2026-13887). Confidential information can be exposed externally.
|
| CVE-2026-13826 |
|
Vulnerability in google (CVE-2026-13826)
vulnerability in google (CVE-2026-13826). Confidential information can be exposed externally.
|
| CVE-2026-55487 |
|
Vulnerability in pnpm (CVE-2026-55487)
vulnerability in pnpm (CVE-2026-55487). Successful exploitation can lead to full system takeover. Exploitable via ``bf1b731ee6``. Mitigation: upgrade to `10.34.2` or later.
|
| CVE-2026-55660 |
|
Vulnerability in tinacms (CVE-2026-55660)
vulnerability in tinacms (CVE-2026-55660). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.3` or later.
|
| CVE-2026-6734 |
|
Vulnerability in undici (CVE-2026-6734)
vulnerability in undici (CVE-2026-6734). Successful exploitation can lead to full system takeover. Exploitable via ``Socks5ProxyAgent``. Mitigation: upgrade to `8.2.0` or later.
|
| CVE-2026-50168 |
|
Vulnerability in @angular/platform-server (CVE-2026-50168)
vulnerability in @angular/platform-server (CVE-2026-50168). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `21.2.15` or later.
|
| CVE-2026-9595 |
|
Vulnerability in webpack-dev-server (CVE-2026-9595)
vulnerability in webpack-dev-server (CVE-2026-9595). Risk of unauthorized operations or information disclosure. Exploitable via ``Origin``. Mitigation: upgrade to `5.2.5` or later.
|
| CVE-2026-48022 |
|
Vulnerability in @hapi/wreck (CVE-2026-48022)
vulnerability in @hapi/wreck (CVE-2026-48022). Confidential information can be exposed externally. Exploitable via ``beforeRedirect``. Mitigation: upgrade to `18.1.2` or later.
|
| CVE-2026-42558 |
|
Cross-Site Scripting (XSS) in CVE-2026-42558 (CVE-2026-42558)
cross-site scripting in CVE-2026-42558 (CVE-2026-42558). Confidential information can be exposed externally.
|
| CVE-2026-48063 |
|
Vulnerability in baileys (CVE-2026-48063)
vulnerability in baileys (CVE-2026-48063). Risk of unauthorized operations or information disclosure. Exploitable via ``messages.upsert``. Mitigation: upgrade to `7.0.0-rc12` or later.
|
| CVE-2026-44894 |
|
Vulnerability in io.netty:netty-codec-classes-quic (CVE-2026-44894)
vulnerability in io.netty:netty-codec-classes-quic (CVE-2026-44894). Data can be tampered with by attackers. Mitigation: upgrade to `4.2.15.Final` or later.
|
| CVE-2026-11214 |
|
Vulnerability in google (CVE-2026-11214)
vulnerability in google (CVE-2026-11214). Confidential information can be exposed externally.
|
| CVE-2026-11200 |
|
Vulnerability in google (CVE-2026-11200)
vulnerability in google (CVE-2026-11200). Confidential information can be exposed externally.
|
| CVE-2026-11194 |
|
Vulnerability in google (CVE-2026-11194)
vulnerability in google (CVE-2026-11194). Confidential information can be exposed externally.
|
| CVE-2026-11195 |
|
Vulnerability in google (CVE-2026-11195)
vulnerability in google (CVE-2026-11195). Confidential information can be exposed externally.
|
| CVE-2026-11083 |
|
Vulnerability in google (CVE-2026-11083)
vulnerability in google (CVE-2026-11083). Confidential information can be exposed externally.
|
| CVE-2026-11084 |
|
Vulnerability in google (CVE-2026-11084)
vulnerability in google (CVE-2026-11084). Confidential information can be exposed externally.
|
| CVE-2026-11020 |
|
Vulnerability in google (CVE-2026-11020)
vulnerability in google (CVE-2026-11020). Confidential information can be exposed externally.
|
| CVE-2026-47703 |
|
Vulnerability in github.com/AdguardTeam/AdGuardHome (CVE-2026-47703)
vulnerability in github.com/AdguardTeam/AdGuardHome (CVE-2026-47703). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.107.75` or later.
|
| CVE-2026-34460 |
|
Vulnerability in csrf (CVE-2026-34460)
vulnerability in csrf (CVE-2026-34460). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44698 |
|
Code Injection in CVE-2026-44698 (CVE-2026-44698)
code injection in CVE-2026-44698 (CVE-2026-44698). Successful exploitation can lead to full system takeover. Exploitable via ``window.externalApp``. Mitigation: upgrade to `2026.4.1` or later.
|
| CVE-2026-46685 |
|
Vulnerability in CVE-2026-46685 (CVE-2026-46685)
vulnerability in CVE-2026-46685 (CVE-2026-46685). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-2611 |
|
Vulnerability in mlflow (CVE-2026-2611)
vulnerability in mlflow (CVE-2026-2611). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-44649 |
|
Vulnerability in sillytavern (CVE-2026-44649)
vulnerability in sillytavern (CVE-2026-44649). Successful exploitation can lead to full system takeover. Exploitable via ``config.yaml``. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-41886 |
|
Vulnerability in locize (CVE-2026-41886)
vulnerability in locize (CVE-2026-41886). Data can be tampered with by attackers. Exploitable via ``locize``. Mitigation: upgrade to `4.0.21` or later.
|
| CVE-2026-35253 |
|
Open Redirect in oracle (CVE-2026-35253)
vulnerability in oracle (CVE-2026-35253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6903 |
|
Path Traversal in CVE-2026-6903 (CVE-2026-6903)
path traversal in CVE-2026-6903 (CVE-2026-6903). Confidential information can be exposed externally.
|
| CVE-2026-5918 |
|
Vulnerability in google (CVE-2026-5918)
vulnerability in google (CVE-2026-5918). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35408 |
|
Vulnerability in monospace (CVE-2026-35408)
vulnerability in monospace (CVE-2026-35408). Confidential information can be exposed externally. Mitigation: upgrade to `11.17.0` or later.
|
| CVE-2026-34083 |
|
Vulnerability in signalk (CVE-2026-34083)
vulnerability in signalk (CVE-2026-34083). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-28861 |
|
Cross-Site Scripting (XSS) in apple (CVE-2026-28861)
cross-site scripting in apple (CVE-2026-28861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27148 |
|
Vulnerability in storybook (CVE-2026-27148)
vulnerability in storybook (CVE-2026-27148). Successful exploitation can lead to full system takeover.
|