Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7663 |
|
Vulnerability in langflow (CVE-2026-7663)
vulnerability in langflow (CVE-2026-7663). Confidential information can be exposed externally.
|
| CVE-2026-7874 |
|
Vulnerability in langflow (CVE-2026-7874)
vulnerability in langflow (CVE-2026-7874). Confidential information can be exposed externally.
|
| CVE-2026-7803 |
|
Vulnerability in langflow (CVE-2026-7803)
vulnerability in langflow (CVE-2026-7803). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7873 |
|
Code Injection in langflow (CVE-2026-7873)
code injection in langflow (CVE-2026-7873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10140 |
|
Vulnerability in langflow (CVE-2026-10140)
vulnerability in langflow (CVE-2026-10140). Confidential information can be exposed externally.
|
| CVE-2026-10134 |
|
Code Injection in langflow (CVE-2026-10134)
code injection in langflow (CVE-2026-10134). Successful exploitation can lead to full system takeover. Exploitable via ``tool_code``.
|
| CVE-2026-48807 |
|
Vulnerability in twig/twig (CVE-2026-48807)
vulnerability in twig/twig (CVE-2026-48807). Confidential information can be exposed externally. Exploitable via ``Traversable``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48806 |
|
Vulnerability in twig/twig (CVE-2026-48806)
vulnerability in twig/twig (CVE-2026-48806). Confidential information can be exposed externally. Exploitable via ``CheckToStringNode``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48805 |
|
Vulnerability in twig/twig (CVE-2026-48805)
vulnerability in twig/twig (CVE-2026-48805). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48315 |
|
Vulnerability in adobe (CVE-2026-48315)
vulnerability in adobe (CVE-2026-48315). Confidential information can be exposed externally.
|
| CVE-2026-48286 |
|
Authorization Flaw in adobe (CVE-2026-48286)
vulnerability in adobe (CVE-2026-48286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48282 KEV |
|
[KEV] Path Traversal in Adobe path-traversal (CVE-2026-48282)
path traversal in Adobe path-traversal (CVE-2026-48282). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-48313 |
|
Path Traversal in path-traversal (CVE-2026-48313)
path traversal in path-traversal (CVE-2026-48313). Confidential information can be exposed externally.
|
| CVE-2026-48283 |
|
Unrestricted File Upload in adobe (CVE-2026-48283)
vulnerability in adobe (CVE-2026-48283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48276 |
|
Unrestricted File Upload in adobe (CVE-2026-48276)
vulnerability in adobe (CVE-2026-48276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48281 |
|
Vulnerability in adobe (CVE-2026-48281)
vulnerability in adobe (CVE-2026-48281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48277 |
|
Vulnerability in adobe (CVE-2026-48277)
vulnerability in adobe (CVE-2026-48277). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14241 |
|
Buffer Overflow in c (CVE-2026-14241)
vulnerability in c (CVE-2026-14241). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53434 |
|
Vulnerability in tomcat (CVE-2026-53434)
vulnerability in tomcat (CVE-2026-53434). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-55276 |
|
Vulnerability in tomcat (CVE-2026-55276)
vulnerability in tomcat (CVE-2026-55276). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-37637 |
|
Code Injection in CVE-2026-37637 (CVE-2026-37637)
code injection in CVE-2026-37637 (CVE-2026-37637). Confidential information can be exposed externally.
|
| CVE-2026-39868 |
|
Vulnerability in apple (CVE-2026-39868)
vulnerability in apple (CVE-2026-39868). Data can be tampered with by attackers.
|
| CVE-2026-56057 |
|
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
|
| CVE-2026-56032 |
|
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
|
| CVE-2025-55017 |
|
Path Traversal in apache (CVE-2025-55017)
path traversal in apache (CVE-2025-55017). Confidential information can be exposed externally.
|
| CVE-2025-64152 |
|
Path Traversal in apache (CVE-2025-64152)
path traversal in apache (CVE-2025-64152). Confidential information can be exposed externally.
|
| CVE-2026-40079 |
|
OS Command Injection in cacti (CVE-2026-40079)
OS command injection in cacti (CVE-2026-40079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39955 |
|
SQL Injection in sqli (CVE-2026-39955)
SQL injection in sqli (CVE-2026-39955). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39948 |
|
SQL Injection in cacti (CVE-2026-39948)
SQL injection in cacti (CVE-2026-39948). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39938 |
|
Path Traversal in cacti (CVE-2026-39938)
path traversal in cacti (CVE-2026-39938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39893 |
|
SQL Injection in sqli (CVE-2026-39893)
SQL injection in sqli (CVE-2026-39893). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13032 |
|
Use-After-Free in google (CVE-2026-13032)
vulnerability in google (CVE-2026-13032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13028 |
|
Use-After-Free in Google chrome (CVE-2026-13028)
vulnerability in Google chrome (CVE-2026-13028). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12417 |
|
Vulnerability in wordpress (CVE-2026-12417)
vulnerability in wordpress (CVE-2026-12417). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_pravel_change_password``.
|
| CVE-2026-7664 |
|
Authentication Bypass in langflow (CVE-2026-7664)
authentication bypass in langflow (CVE-2026-7664). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28381 |
|
Vulnerability in grafana (CVE-2026-28381)
vulnerability in grafana (CVE-2026-28381). Confidential information can be exposed externally.
|
| CVE-2026-10561 |
|
Code Injection in langflow (CVE-2026-10561)
code injection in langflow (CVE-2026-10561). Successful exploitation can lead to full system takeover.
|
| CVE-2022-50972 |
|
Code Injection in CVE-2022-50972 (CVE-2022-50972)
code injection in CVE-2022-50972 (CVE-2022-50972). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25763 |
|
Vulnerability in wordpress (CVE-2019-25763)
vulnerability in wordpress (CVE-2019-25763). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48939 KEV |
|
[KEV] Unrestricted File Upload in Icagenda joomlic (CVE-2026-48939)
vulnerability in Icagenda joomlic (CVE-2026-48939). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-48908 KEV |
|
[KEV] Unrestricted File Upload in Joomshaper ollyo (CVE-2026-48908)
vulnerability in Joomshaper ollyo (CVE-2026-48908). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-55447 |
|
Information Disclosure in langflow (CVE-2026-55447)
vulnerability in langflow (CVE-2026-55447). Successful exploitation can lead to full system takeover. Exploitable via ``BaseFileComponent``. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-51845 |
|
Vulnerability in tenda (CVE-2026-51845)
vulnerability in tenda (CVE-2026-51845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51846 |
|
Vulnerability in tenda (CVE-2026-51846)
vulnerability in tenda (CVE-2026-51846). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51843 |
|
Vulnerability in tenda (CVE-2026-51843)
vulnerability in tenda (CVE-2026-51843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51844 |
|
Vulnerability in tenda (CVE-2026-51844)
vulnerability in tenda (CVE-2026-51844). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49230 |
|
Vulnerability in apisix (CVE-2026-49230)
vulnerability in apisix (CVE-2026-49230). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-49871 |
|
Cross-Site Request Forgery (CSRF) in apisix (CVE-2026-49871)
vulnerability in apisix (CVE-2026-49871). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-44087 |
|
Vulnerability in apisix (CVE-2026-44087)
vulnerability in apisix (CVE-2026-44087). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-39999 |
|
Vulnerability in apisix (CVE-2026-39999)
vulnerability in apisix (CVE-2026-39999). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|