Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-10126 Buffer Overflow in CVE-2026-10126 (CVE-2026-10126)
vulnerability in CVE-2026-10126 (CVE-2026-10126). Successful exploitation can lead to full system takeover.
CVE-2026-10121 Buffer Overflow in CVE-2026-10121 (CVE-2026-10121)
vulnerability in CVE-2026-10121 (CVE-2026-10121). Successful exploitation can lead to full system takeover.
CVE-2026-10122 Buffer Overflow in CVE-2026-10122 (CVE-2026-10122)
vulnerability in CVE-2026-10122 (CVE-2026-10122). Successful exploitation can lead to full system takeover.
CVE-2026-10123 Buffer Overflow in CVE-2026-10123 (CVE-2026-10123)
vulnerability in CVE-2026-10123 (CVE-2026-10123). Successful exploitation can lead to full system takeover.
CVE-2026-10124 Buffer Overflow in CVE-2026-10124 (CVE-2026-10124)
vulnerability in CVE-2026-10124 (CVE-2026-10124). Successful exploitation can lead to full system takeover.
CVE-2026-10125 Buffer Overflow in CVE-2026-10125 (CVE-2026-10125)
vulnerability in CVE-2026-10125 (CVE-2026-10125). Successful exploitation can lead to full system takeover.
CVE-2018-25420 SQL Injection in sqli (CVE-2018-25420)
SQL injection in sqli (CVE-2018-25420). Confidential information can be exposed externally.
CVE-2018-25422 SQL Injection in sqli (CVE-2018-25422)
SQL injection in sqli (CVE-2018-25422). Confidential information can be exposed externally.
CVE-2018-25424 SQL Injection in sqli (CVE-2018-25424)
SQL injection in sqli (CVE-2018-25424). Confidential information can be exposed externally.
CVE-2018-25425 SQL Injection in c (CVE-2018-25425)
SQL injection in c (CVE-2018-25425). Confidential information can be exposed externally.
CVE-2018-25426 Vulnerability in dos (CVE-2018-25426)
vulnerability in dos (CVE-2018-25426). Risk of unauthorized operations or information disclosure.
CVE-2018-25413 SQL Injection in sqli (CVE-2018-25413)
SQL injection in sqli (CVE-2018-25413). Confidential information can be exposed externally.
CVE-2018-25414 SQL Injection in sqli (CVE-2018-25414)
SQL injection in sqli (CVE-2018-25414). Confidential information can be exposed externally.
CVE-2018-25415 SQL Injection in sqli (CVE-2018-25415)
SQL injection in sqli (CVE-2018-25415). Confidential information can be exposed externally.
CVE-2018-25416 SQL Injection in sqli (CVE-2018-25416)
SQL injection in sqli (CVE-2018-25416). Confidential information can be exposed externally.
CVE-2018-25417 SQL Injection in sqli (CVE-2018-25417)
SQL injection in sqli (CVE-2018-25417). Confidential information can be exposed externally.
CVE-2018-25418 SQL Injection in sqli (CVE-2018-25418)
SQL injection in sqli (CVE-2018-25418). Confidential information can be exposed externally.
CVE-2018-25419 SQL Injection in sqli (CVE-2018-25419)
SQL injection in sqli (CVE-2018-25419). Confidential information can be exposed externally.
CVE-2018-25407 SQL Injection in sqli (CVE-2018-25407)
SQL injection in sqli (CVE-2018-25407). Confidential information can be exposed externally.
CVE-2018-25408 Path Traversal in path-traversal (CVE-2018-25408)
path traversal in path-traversal (CVE-2018-25408). Confidential information can be exposed externally.
CVE-2018-25409 Unrestricted File Upload in CVE-2018-25409 (CVE-2018-25409)
vulnerability in CVE-2018-25409 (CVE-2018-25409). Successful exploitation can lead to full system takeover.
CVE-2018-25410 SQL Injection in sqli (CVE-2018-25410)
SQL injection in sqli (CVE-2018-25410). Confidential information can be exposed externally.
CVE-2018-25411 SQL Injection in sqli (CVE-2018-25411)
SQL injection in sqli (CVE-2018-25411). Confidential information can be exposed externally.
CVE-2018-25406 SQL Injection in sqli (CVE-2018-25406)
SQL injection in sqli (CVE-2018-25406). Confidential information can be exposed externally.
CVE-2018-25405 SQL Injection in sqli (CVE-2018-25405)
SQL injection in sqli (CVE-2018-25405). Confidential information can be exposed externally.
CVE-2026-10120 Buffer Overflow in CVE-2026-10120 (CVE-2026-10120)
vulnerability in CVE-2026-10120 (CVE-2026-10120). Successful exploitation can lead to full system takeover.
CVE-2026-10119 Buffer Overflow in CVE-2026-10119 (CVE-2026-10119)
vulnerability in CVE-2026-10119 (CVE-2026-10119). Successful exploitation can lead to full system takeover.
CVE-2026-46242 Use-After-Free in Google linux (CVE-2026-46242)
vulnerability in Google linux (CVE-2026-46242). Successful exploitation can lead to full system takeover.
CVE-2026-7465 Privilege Escalation in wordpress (CVE-2026-7465)
vulnerability in wordpress (CVE-2026-7465). Successful exploitation can lead to full system takeover.
CVE-2026-9757 SQL Injection in wordpress (CVE-2026-9757)
SQL injection in wordpress (CVE-2026-9757). Confidential information can be exposed externally.
CVE-2026-7459 Vulnerability in wordpress (CVE-2026-7459)
vulnerability in wordpress (CVE-2026-7459). Successful exploitation can lead to full system takeover.
CVE-2026-10111 Vulnerability in sqli (CVE-2026-10111)
vulnerability in sqli (CVE-2026-10111). Risk of unauthorized operations or information disclosure.
CVE-2026-10110 Vulnerability in sqli (CVE-2026-10110)
vulnerability in sqli (CVE-2026-10110). Risk of unauthorized operations or information disclosure.
CVE-2026-47409 Privilege Escalation in praisonai-platform (CVE-2026-47409)
vulnerability in praisonai-platform (CVE-2026-47409). Data can be tampered with by attackers. Exploitable via `DELETE /workspaces/{workspace_id}/members/{user_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47414 Vulnerability in praisonai-platform (CVE-2026-47414)
vulnerability in praisonai-platform (CVE-2026-47414). Data can be tampered with by attackers. Exploitable via `PATCH /workspaces/{workspace_id}/labels/{label_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47406 Vulnerability in praisonai-platform (CVE-2026-47406)
vulnerability in praisonai-platform (CVE-2026-47406). Confidential information can be exposed externally. Exploitable via `GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47405 Vulnerability in praisonai-platform (CVE-2026-47405)
vulnerability in praisonai-platform (CVE-2026-47405). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /workspaces/{workspace_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47399 Vulnerability in praisonai-platform (CVE-2026-47399)
vulnerability in praisonai-platform (CVE-2026-47399). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_attacker}/agents/{victim_agent_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-48169 Vulnerability in praisonai-platform (CVE-2026-48169)
vulnerability in praisonai-platform (CVE-2026-48169). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_id}/issues/{issue_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47398 Code Injection in PraisonAI (CVE-2026-47398)
code injection in PraisonAI (CVE-2026-47398). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/recipes/run`. Mitigation: upgrade to `4.6.40` or later.
CVE-2026-47231 Vulnerability in admidio/admidio (CVE-2026-47231)
vulnerability in admidio/admidio (CVE-2026-47231). Confidential information can be exposed externally. Exploitable via `GET /modules/documents-files.php`. Mitigation: upgrade to `5.0.10` or later.
CVE-2026-47201 Vulnerability in goauthentik.io (CVE-2026-47201)
vulnerability in goauthentik.io (CVE-2026-47201). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.0-20260528144335-a370d76d23c7` or later.
CVE-2026-46599 Vulnerability in golang.org/x/image (CVE-2026-46599)
vulnerability in golang.org/x/image (CVE-2026-46599). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.0` or later.
CVE-2026-46527 Vulnerability in c (CVE-2026-46527)
vulnerability in c (CVE-2026-46527). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
CVE-2026-47123 Vulnerability in laravel (CVE-2026-47123)
vulnerability in laravel (CVE-2026-47123). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.220` or later.
CVE-2026-48555 SSRF (Server-Side Request Forgery) in spatie/laravel-medialibrary (CVE-2026-48555)
SSRF in spatie/laravel-medialibrary (CVE-2026-48555). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.23.0` or later.
CVE-2026-48557 Spatie Laravel Media Library contains a file upload restriction bypass
Spatie Laravel Media Library contains a file upload restriction bypass
CVE-2026-44285 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network prot...
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi...
CVE-2026-44420 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel b...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process...
CVE-2026-44421 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs....
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →