Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-37252 |
|
Vulnerability in CVE-2020-37252 (CVE-2020-37252)
vulnerability in CVE-2020-37252 (CVE-2020-37252). Successful exploitation can lead to full system takeover.
|
| CVE-2020-37253 |
|
Vulnerability in CVE-2020-37253 (CVE-2020-37253)
vulnerability in CVE-2020-37253 (CVE-2020-37253). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48895 |
|
Open Redirect in apisix (CVE-2026-48895)
vulnerability in apisix (CVE-2026-48895). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-49872 |
|
Authentication Bypass in apisix (CVE-2026-49872)
authentication bypass in apisix (CVE-2026-49872). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-47339 |
|
Authorization Flaw in apisix (CVE-2026-47339)
vulnerability in apisix (CVE-2026-47339). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-39998 |
|
Vulnerability in apisix (CVE-2026-39998)
vulnerability in apisix (CVE-2026-39998). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-55773 |
|
Code Injection in com.cedarpolicy:cedar-java (CVE-2026-55773)
code injection in com.cedarpolicy:cedar-java (CVE-2026-55773). Successful exploitation can lead to full system takeover. Exploitable via ``forbid``. Mitigation: upgrade to `4.9.0` or later.
|
| CVE-2026-55772 |
|
Vulnerability in com.cedarpolicy:cedar-java (CVE-2026-55772)
vulnerability in com.cedarpolicy:cedar-java (CVE-2026-55772). Successful exploitation can lead to full system takeover. Exploitable via ``__entity``. Mitigation: upgrade to `4.9.0` or later.
|
| CVE-2026-48138 |
|
Out-of-Bounds Read in dos (CVE-2026-48138)
vulnerability in dos (CVE-2026-48138). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48139 |
|
Vulnerability in dos (CVE-2026-48139)
vulnerability in dos (CVE-2026-48139). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53915 |
|
Vulnerability in jetbrains (CVE-2026-53915)
vulnerability in jetbrains (CVE-2026-53915). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41156 |
|
Use-After-Free in CVE-2026-41156 (CVE-2026-41156)
vulnerability in CVE-2026-41156 (CVE-2026-41156). Data can be tampered with by attackers.
|
| CVE-2026-34192 |
|
Use-After-Free in CVE-2026-34192 (CVE-2026-34192)
vulnerability in CVE-2026-34192 (CVE-2026-34192). Data can be tampered with by attackers.
|
| CVE-2026-11576 |
|
Vulnerability in eclipse (CVE-2026-11576)
vulnerability in eclipse (CVE-2026-11576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46461 |
|
Vulnerability in dell (CVE-2026-46461)
vulnerability in dell (CVE-2026-46461). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56078 |
|
Path Traversal in praisonai (CVE-2026-56078)
path traversal in praisonai (CVE-2026-56078). Confidential information can be exposed externally. Exploitable via ``MultiAgentLedger``. Mitigation: upgrade to `1.5.115` or later.
|
| CVE-2026-56075 |
|
Authorization Flaw in praisonai (CVE-2026-56075)
vulnerability in praisonai (CVE-2026-56075). Successful exploitation can lead to full system takeover. Exploitable via ``chat.py``. Mitigation: upgrade to `4.5.128` or later.
|
| CVE-2026-56076 |
|
Vulnerability in CVE-2026-56076 (CVE-2026-56076)
vulnerability in CVE-2026-56076 (CVE-2026-56076). Confidential information can be exposed externally. Exploitable via `POST /agui`.
|
| CVE-2026-12044 |
|
SQL Injection in sqli (CVE-2026-12044)
SQL injection in sqli (CVE-2026-12044). Successful exploitation can lead to full system takeover. Exploitable via ``qtLiteral``.
|
| CVE-2026-47633 |
|
Information Disclosure in microsoft (CVE-2026-47633)
vulnerability in microsoft (CVE-2026-47633). Confidential information can be exposed externally.
|
| CVE-2026-32174 |
|
Authentication Bypass in microsoft (CVE-2026-32174)
authentication bypass in microsoft (CVE-2026-32174). Data can be tampered with by attackers.
|
| CVE-2026-25865 |
|
Vulnerability in CVE-2026-25865 (CVE-2026-25865)
vulnerability in CVE-2026-25865 (CVE-2026-25865). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48937 |
|
Vulnerability in nodejs (CVE-2026-48937)
vulnerability in nodejs (CVE-2026-48937). Risk of unauthorized operations or information disclosure. Exploitable via ``GOAWAY``.
|
| CVE-2026-12390 |
|
Vulnerability in azeotech (CVE-2026-12390)
vulnerability in azeotech (CVE-2026-12390). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46699 |
|
Vulnerability in CVE-2026-46699 (CVE-2026-46699)
vulnerability in CVE-2026-46699 (CVE-2026-46699). Data can be tampered with by attackers.
|
| CVE-2026-43994 |
|
Vulnerability in coturn-project (CVE-2026-43994)
vulnerability in coturn-project (CVE-2026-43994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48716 |
|
Path Traversal in CVE-2026-48716 (CVE-2026-48716)
path traversal in CVE-2026-48716 (CVE-2026-48716). Data can be tampered with by attackers.
|
| CVE-2026-55203 |
|
Vulnerability in haproxy (CVE-2026-55203)
vulnerability in haproxy (CVE-2026-55203). Data can be tampered with by attackers. Mitigation: upgrade to `3.4.1` or later.
|
| CVE-2026-55204 |
|
Vulnerability in haproxy (CVE-2026-55204)
vulnerability in haproxy (CVE-2026-55204). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.1` or later.
|
| CVE-2026-54104 |
|
Vulnerability in CVE-2026-54104 (CVE-2026-54104)
vulnerability in CVE-2026-54104 (CVE-2026-54104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48617 |
|
Vulnerability in nodejs (CVE-2026-48617)
vulnerability in nodejs (CVE-2026-48617). Confidential information can be exposed externally.
|
| CVE-2026-38718 |
|
Vulnerability in dos (CVE-2026-38718)
vulnerability in dos (CVE-2026-38718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56020 |
|
Vulnerability in CVE-2026-56020 (CVE-2026-56020)
vulnerability in CVE-2026-56020 (CVE-2026-56020). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.641` or later.
|
| CVE-2026-55237 |
|
Vulnerability in CVE-2026-55237 (CVE-2026-55237)
vulnerability in CVE-2026-55237 (CVE-2026-55237). Confidential information can be exposed externally. Exploitable via ``next``.
|
| CVE-2026-46580 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-46580)
vulnerability in @theia/ai-chat-ui (CVE-2026-46580). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.71.0` or later.
|
| CVE-2026-44691 |
|
Vulnerability in @theia/debug (CVE-2026-44691)
vulnerability in @theia/debug (CVE-2026-44691). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.69.0` or later.
|
| CVE-2026-44688 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-44688)
vulnerability in @theia/ai-chat-ui (CVE-2026-44688). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.71.0` or later.
|
| CVE-2026-56012 |
|
SQL Injection in sqli (CVE-2026-56012)
SQL injection in sqli (CVE-2026-56012). Confidential information can be exposed externally.
|
| CVE-2026-8461 |
|
Out-of-Bounds Write in c (CVE-2026-8461)
out-of-bounds write in c (CVE-2026-8461). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42487 |
|
Vulnerability in c (CVE-2026-42487)
vulnerability in c (CVE-2026-42487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42488 |
|
Buffer Overflow in CVE-2026-42488 (CVE-2026-42488)
vulnerability in CVE-2026-42488 (CVE-2026-42488). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11719 |
|
Vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-11719)
vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-11719). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-54695 |
|
Vulnerability in pipecat-ai (CVE-2026-54695)
vulnerability in pipecat-ai (CVE-2026-54695). Risk of unauthorized operations or information disclosure. Exploitable via `POST /start`. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-65898 |
|
Cross-Site Scripting (XSS) in dompurify (CVE-2026-65898)
cross-site scripting in dompurify (CVE-2026-65898). Risk of unauthorized operations or information disclosure. Exploitable via ``uponSanitizeAttribute``. Mitigation: upgrade to `3.4.11` or later.
|
| CVE-2026-55672 |
|
Authentication Bypass in github.com/zitadel/zitadel (CVE-2026-55672)
authentication bypass in github.com/zitadel/zitadel (CVE-2026-55672). Confidential information can be exposed externally. Mitigation: upgrade to `1.80.0-v2.20.0.20260616131956-0973b074b488` or later.
|
| CVE-2026-55603 |
|
Vulnerability in http-proxy-middleware (CVE-2026-55603)
vulnerability in http-proxy-middleware (CVE-2026-55603). Data can be tampered with by attackers. Exploitable via ``req.body``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-55602 |
|
Vulnerability in http-proxy-middleware (CVE-2026-55602)
vulnerability in http-proxy-middleware (CVE-2026-55602). Data can be tampered with by attackers. Exploitable via ``router``. Mitigation: upgrade to `2.0.10` or later.
|
| CVE-2026-55388 |
|
Vulnerability in piscina (CVE-2026-55388)
vulnerability in piscina (CVE-2026-55388). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`. Mitigation: upgrade to `6.0.0-rc.2` or later.
|
| CVE-2026-55229 |
|
SSRF (Server-Side Request Forgery) in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229)
SSRF in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229). Confidential information can be exposed externally. Exploitable via `GET /secretendpoint`. Mitigation: upgrade to `8.34.0` or later.
|
| CVE-2026-55746 |
|
Cross-Site Scripting (XSS) in cotonti/cotonti (CVE-2026-55746)
cross-site scripting in cotonti/cotonti (CVE-2026-55746). Confidential information can be exposed externally.
|