Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-cf72-6wrv-f629 |
|
MINI-cf72-6wrv-f629 |
| MINI-3pjh-mr2q-g7vr |
|
MINI-3pjh-mr2q-g7vr |
| MINI-c43j-xcx3-g4c5 |
|
MINI-c43j-xcx3-g4c5 |
| ECHO-b826-4d3a-4f4e |
|
ECHO-b826-4d3a-4f4e |
| ECHO-9157-e0cb-829d |
|
ECHO-9157-e0cb-829d |
| CVE-2026-55890 |
|
Cross-Site Scripting (XSS) in getgrav/grav (CVE-2026-55890)
cross-site scripting in getgrav/grav (CVE-2026-55890). Risk of unauthorized operations or information disclosure. Exploitable via ``style``. Mitigation: upgrade to `2.0.0-rc.9` or later.
|
| GHSA-2fjj-qqg8-fg7x |
|
Vulnerability in praisonai-platform (GHSA-2fjj-qqg8-fg7x)
vulnerability in praisonai-platform (GHSA-2fjj-qqg8-fg7x). Risk of unauthorized operations or information disclosure. Exploitable via `GET /workspaces/W_A/projects/P_A/stats`. Mitigation: upgrade to `0.1.4` or later.
|
| MINI-xf6j-cw8v-hg9x |
|
MINI-xf6j-cw8v-hg9x |
| MINI-45g9-xv4j-7f78 |
|
MINI-45g9-xv4j-7f78 |
| MINI-pf65-5pfj-mfm9 |
|
MINI-pf65-5pfj-mfm9 |
| MINI-325f-3884-w8f2 |
|
MINI-325f-3884-w8f2 |
| MINI-7vcr-39x6-gpvq |
|
MINI-7vcr-39x6-gpvq |
| MINI-m8vv-5gfg-c5x8 |
|
MINI-m8vv-5gfg-c5x8 |
| MINI-g7r3-339q-q378 |
|
MINI-g7r3-339q-q378 |
| MINI-w433-583w-f4x2 |
|
MINI-w433-583w-f4x2 |
| MINI-2h5x-qjvm-9phx |
|
MINI-2h5x-qjvm-9phx |
| MINI-2h3c-x55h-jmc9 |
|
MINI-2h3c-x55h-jmc9 |
| MINI-8r5p-qq6w-8jg4 |
|
MINI-8r5p-qq6w-8jg4 |
| MINI-xmxr-2fr9-cf22 |
|
MINI-xmxr-2fr9-cf22 |
| MINI-qq8x-rj5f-x78q |
|
MINI-qq8x-rj5f-x78q |
| MINI-vf8f-38v7-m438 |
|
MINI-vf8f-38v7-m438 |
| MINI-7v73-v68x-gfjm |
|
MINI-7v73-v68x-gfjm |
| SUSE-SU-2026:22160-1 |
|
Vulnerability in unbound (SUSE-SU-2026:22160-1)
vulnerability in unbound (SUSE-SU-2026:22160-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.24.1-160000.2.1` or later.
|
| SUSE-SU-2026:22213-1 |
|
Vulnerability in unbound (SUSE-SU-2026:22213-1)
vulnerability in unbound (SUSE-SU-2026:22213-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.24.1-160000.2.1` or later.
|
| CVE-2026-55885 |
|
Vulnerability in getgrav/grav (CVE-2026-55885)
vulnerability in getgrav/grav (CVE-2026-55885). Confidential information can be exposed externally. Exploitable via ``root``. Mitigation: upgrade to `1.7.53` or later.
|
| openSUSE-SU-2026:21083-1 |
|
Vulnerability in unbound (openSUSE-SU-2026:21083-1)
vulnerability in unbound (openSUSE-SU-2026:21083-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.24.1-160000.2.1` or later.
|
| CVE-2026-57441 |
|
Vulnerability in @bitbonsai/mcpvault (CVE-2026-57441)
vulnerability in @bitbonsai/mcpvault (CVE-2026-57441). Risk of unauthorized operations or information disclosure. Exploitable via ``node_modules``. Mitigation: upgrade to `0.11.4` or later.
|
| SUSE-SU-2026:22159-1 |
|
Vulnerability in distribution (SUSE-SU-2026:22159-1)
vulnerability in distribution (SUSE-SU-2026:22159-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1-160000.1.1` or later.
|
| openSUSE-SU-2026:21084-1 |
|
Vulnerability in distribution (openSUSE-SU-2026:21084-1)
vulnerability in distribution (openSUSE-SU-2026:21084-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1-160000.1.1` or later.
|
| GHSA-jm82-fx9c-mx94 |
|
Vulnerability in pypdf (GHSA-jm82-fx9c-mx94)
vulnerability in pypdf (GHSA-jm82-fx9c-mx94). Risk of unauthorized operations or information disclosure. Exploitable via ``MAX_DECLARED_STREAM_LENGTH``. Mitigation: upgrade to `6.13.3` or later.
|
| CVE-2026-55686 |
|
Vulnerability in github.com/containers/podman/v5 (CVE-2026-55686)
vulnerability in github.com/containers/podman/v5 (CVE-2026-55686). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.7.1` or later.
|
| GHSA-p6gq-j5cr-w38f |
|
Vulnerability in nodemailer (GHSA-p6gq-j5cr-w38f)
vulnerability in nodemailer (GHSA-p6gq-j5cr-w38f). Confidential information can be exposed externally. Exploitable via ``raw``. Mitigation: upgrade to `9.0.1` or later.
|
| CVE-2026-65898 |
|
Cross-Site Scripting (XSS) in dompurify (CVE-2026-65898)
cross-site scripting in dompurify (CVE-2026-65898). Risk of unauthorized operations or information disclosure. Exploitable via ``uponSanitizeAttribute``. Mitigation: upgrade to `3.4.11` or later.
|
| CVE-2026-57147 |
|
Vulnerability in praisonai-platform (CVE-2026-57147)
vulnerability in praisonai-platform (CVE-2026-57147). Risk of unauthorized operations or information disclosure. Exploitable via ``PLATFORM_JWT_SECRET``. Mitigation: upgrade to `0.1.6` or later.
|
| CVE-2026-57144 |
|
Vulnerability in praisonai (CVE-2026-57144)
vulnerability in praisonai (CVE-2026-57144). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai.sandbox.SandlockSandbox``. Mitigation: upgrade to `4.6.61` or later.
|
| CVE-2026-57132 |
|
Authentication Bypass in praisonai (CVE-2026-57132)
authentication bypass in praisonai (CVE-2026-57132). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/agents/any-agent/invoke`. Mitigation: upgrade to `4.6.61` or later.
|
| CVE-2026-57143 |
|
Vulnerability in praisonaiagents (CVE-2026-57143)
vulnerability in praisonaiagents (CVE-2026-57143). Risk of unauthorized operations or information disclosure. Exploitable via ``search_web``. Mitigation: upgrade to `1.6.61` or later.
|
| CVE-2026-57148 |
|
Authentication Bypass in praisonai-platform (CVE-2026-57148)
authentication bypass in praisonai-platform (CVE-2026-57148). Risk of unauthorized operations or information disclosure. Exploitable via `GET /{workspace_id}/members`. Mitigation: upgrade to `0.1.6` or later.
|
| CVE-2026-57145 |
|
Path Traversal in praisonai (CVE-2026-57145)
path traversal in praisonai (CVE-2026-57145). Risk of unauthorized operations or information disclosure. Exploitable via ``multiedit``. Mitigation: upgrade to `4.6.61` or later.
|
| CVE-2026-57146 |
|
Information Disclosure in praisonai (CVE-2026-57146)
vulnerability in praisonai (CVE-2026-57146). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai``. Mitigation: upgrade to `4.6.61` or later.
|
| CVE-2026-57142 |
|
OS Command Injection in praisonai (CVE-2026-57142)
OS command injection in praisonai (CVE-2026-57142). Risk of unauthorized operations or information disclosure. Exploitable via ``TEMPLATE.yaml``. Mitigation: upgrade to `4.6.61` or later.
|
| CVE-2026-57133 |
|
OS Command Injection in praisonai (CVE-2026-57133)
OS command injection in praisonai (CVE-2026-57133). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai``. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57137 |
|
Vulnerability in praisonai (CVE-2026-57137)
vulnerability in praisonai (CVE-2026-57137). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai``. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57139 |
|
Vulnerability in praisonai (CVE-2026-57139)
vulnerability in praisonai (CVE-2026-57139). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai``. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57140 |
|
Vulnerability in praisonai (CVE-2026-57140)
vulnerability in praisonai (CVE-2026-57140). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/agents`. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57141 |
|
Code Injection in praisonai (CVE-2026-57141)
code injection in praisonai (CVE-2026-57141). Risk of unauthorized operations or information disclosure. Exploitable via ``codeMode``. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57136 |
|
OS Command Injection in praisonai (CVE-2026-57136)
OS command injection in praisonai (CVE-2026-57136). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai``. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57138 |
|
Vulnerability in praisonai (CVE-2026-57138)
vulnerability in praisonai (CVE-2026-57138). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai``. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57135 |
|
Vulnerability in praisonai (CVE-2026-57135)
vulnerability in praisonai (CVE-2026-57135). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai``. Mitigation: upgrade to `1.7.2` or later.
|
| CVE-2026-57134 |
|
Authentication Bypass in praisonai (CVE-2026-57134)
authentication bypass in praisonai (CVE-2026-57134). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.7.2` or later.
|