Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-27091 |
|
Cross-Site Scripting (XSS) in geonode (CVE-2024-27091)
cross-site scripting in geonode (CVE-2024-27091). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.2.3` or later.
|
| ECHO-584a-b2f6-d7a8 |
|
ECHO-584a-b2f6-d7a8 |
| CVE-2026-61692 |
|
Vulnerability in CVE-2026-61692 (CVE-2026-61692)
vulnerability in CVE-2026-61692 (CVE-2026-61692). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59245 |
|
Privilege Escalation in apache (CVE-2026-59245)
vulnerability in apache (CVE-2026-59245). Confidential information can be exposed externally. Exploitable via ``dag_id``.
|
| CVE-2026-58065 |
|
Vulnerability in apache (CVE-2026-58065)
vulnerability in apache (CVE-2026-58065). Successful exploitation can lead to full system takeover. Exploitable via ``known_hosts``.
|
| CVE-2026-42079 |
|
Vulnerability in pptagent (CVE-2026-42079)
vulnerability in pptagent (CVE-2026-42079). Successful exploitation can lead to full system takeover. Exploitable via ``CodeExecutor.execute_actions``. Mitigation: upgrade to `1.1.36` or later.
|
| CVE-2026-42078 |
|
Path Traversal in pptagent (CVE-2026-42078)
path traversal in pptagent (CVE-2026-42078). Risk of unauthorized operations or information disclosure. Exploitable via ``markdown_table_to_image``. Mitigation: upgrade to `1.1.36` or later.
|
| CVE-2026-42080 |
|
Path Traversal in pptagent (CVE-2026-42080)
path traversal in pptagent (CVE-2026-42080). Risk of unauthorized operations or information disclosure. Exploitable via ``save_generated_slides``. Mitigation: upgrade to `1.1.36` or later.
|
| CVE-2026-7669 |
|
Vulnerability in sglang (CVE-2026-7669)
vulnerability in sglang (CVE-2026-7669). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7597 |
|
Vulnerability in mem0ai (CVE-2026-7597)
vulnerability in mem0ai (CVE-2026-7597). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0b2` or later.
|
| CVE-2026-7404 |
|
Path Traversal in mcpo-simple-server (CVE-2026-7404)
path traversal in mcpo-simple-server (CVE-2026-7404). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13030 |
|
Vulnerability in django-mdeditor (CVE-2025-13030)
vulnerability in django-mdeditor (CVE-2025-13030). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7158 |
|
SSRF (Server-Side Request Forgery) in mcp-url-downloader (CVE-2026-7158)
SSRF in mcp-url-downloader (CVE-2026-7158). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7159 |
|
Path Traversal in mkdocs-mcp-plugin (CVE-2026-7159)
path traversal in mkdocs-mcp-plugin (CVE-2026-7159). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7150 |
|
SSRF (Server-Side Request Forgery) in auto-favicon (CVE-2026-7150)
SSRF in auto-favicon (CVE-2026-7150). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7142 |
|
Vulnerability in wooey (CVE-2026-7142)
vulnerability in wooey (CVE-2026-7142). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.13.3rc1` or later.
|
| CVE-2026-6357 |
|
Vulnerability in pip (CVE-2026-6357)
vulnerability in pip (CVE-2026-6357). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.1` or later.
|
| CVE-2026-7149 |
|
Path Traversal in kaggle-mcp (CVE-2026-7149)
path traversal in kaggle-mcp (CVE-2026-7149). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6984 |
|
Vulnerability in astrbot (CVE-2026-6984)
vulnerability in astrbot (CVE-2026-6984). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6878 |
|
Vulnerability in verl (CVE-2026-6878)
vulnerability in verl (CVE-2026-6878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33626 |
|
SSRF (Server-Side Request Forgery) in lmdeploy (CVE-2026-33626)
SSRF in lmdeploy (CVE-2026-33626). Confidential information can be exposed externally. Exploitable via `POST /v1/chat/completions`.
|
| CVE-2025-66335 |
|
SQL Injection in doris-mcp-server (CVE-2025-66335)
SQL injection in doris-mcp-server (CVE-2025-66335). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.1` or later.
|
| CVE-2026-6606 |
|
SSRF (Server-Side Request Forgery) in agentscope (CVE-2026-6606)
SSRF in agentscope (CVE-2026-6606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6608 |
|
Vulnerability in fschat (CVE-2026-6608)
vulnerability in fschat (CVE-2026-6608). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6607 |
|
Vulnerability in fschat (CVE-2026-6607)
vulnerability in fschat (CVE-2026-6607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6599 |
|
Vulnerability in langflow (CVE-2026-6599)
vulnerability in langflow (CVE-2026-6599). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6598 |
|
Vulnerability in langflow (CVE-2026-6598)
vulnerability in langflow (CVE-2026-6598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-6597 |
|
Vulnerability in langflow (CVE-2026-6597)
vulnerability in langflow (CVE-2026-6597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6604 |
|
SSRF (Server-Side Request Forgery) in agentscope (CVE-2026-6604)
SSRF in agentscope (CVE-2026-6604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6605 |
|
SSRF (Server-Side Request Forgery) in agentscope (CVE-2026-6605)
SSRF in agentscope (CVE-2026-6605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6603 |
|
Vulnerability in agentscope (CVE-2026-6603)
vulnerability in agentscope (CVE-2026-6603). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41314 |
|
Vulnerability in pypdf (CVE-2026-41314)
vulnerability in pypdf (CVE-2026-41314). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.2` or later.
|
| CVE-2026-41312 |
|
Vulnerability in pypdf (CVE-2026-41312)
vulnerability in pypdf (CVE-2026-41312). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.2` or later.
|
| CVE-2026-41313 |
|
Vulnerability in pypdf (CVE-2026-41313)
vulnerability in pypdf (CVE-2026-41313). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.2` or later.
|
| CVE-2026-35402 |
|
Vulnerability in mcp-neo4j-cypher (CVE-2026-35402)
vulnerability in mcp-neo4j-cypher (CVE-2026-35402). Risk of unauthorized operations or information disclosure. Exploitable via ``read_only``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-40602 |
|
Vulnerability in homeassistant-cli (CVE-2026-40602)
vulnerability in homeassistant-cli (CVE-2026-40602). Confidential information can be exposed externally. Exploitable via ``ImmutableSandboxedEnvironment``. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-40474 |
|
Vulnerability in wger (CVE-2026-40474)
vulnerability in wger (CVE-2026-40474). Data can be tampered with by attackers. Exploitable via ``GymConfigUpdateView``.
|
| CVE-2026-40353 |
|
Cross-Site Scripting (XSS) in wger (CVE-2026-40353)
cross-site scripting in wger (CVE-2026-40353). Risk of unauthorized operations or information disclosure. Exploitable via ``AbstractLicenseModel.attribution_link``.
|
| CVE-2026-40347 |
|
Vulnerability in python-multipart (CVE-2026-40347)
vulnerability in python-multipart (CVE-2026-40347). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.26` or later.
|
| CVE-2026-41206 |
|
Vulnerability in pyspector (CVE-2026-41206)
vulnerability in pyspector (CVE-2026-41206). Risk of unauthorized operations or information disclosure. Exploitable via ``PluginSecurity.validate_plugin_code``. Mitigation: upgrade to `0.1.8` or later.
|
| CVE-2026-40260 |
|
Vulnerability in pypdf (CVE-2026-40260)
vulnerability in pypdf (CVE-2026-40260). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.0` or later.
|
| CVE-2026-41168 |
|
Vulnerability in pypdf (CVE-2026-41168)
vulnerability in pypdf (CVE-2026-41168). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1` or later.
|
| CVE-2026-40319 |
|
Vulnerability in giskard-checks (CVE-2026-40319)
vulnerability in giskard-checks (CVE-2026-40319). Risk of unauthorized operations or information disclosure. Exploitable via ``text_matching.py``. Mitigation: upgrade to `1.0.2b1` or later.
|
| CVE-2026-40320 |
|
Vulnerability in giskard-checks (CVE-2026-40320)
vulnerability in giskard-checks (CVE-2026-40320). Successful exploitation can lead to full system takeover. Exploitable via ``ConformityCheck``. Mitigation: upgrade to `1.0.2b1` or later.
|
| CVE-2026-41133 |
|
Vulnerability in pyload-ng (CVE-2026-41133)
vulnerability in pyload-ng (CVE-2026-41133). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
|
| CVE-2026-6110 |
|
Vulnerability in metagpt (CVE-2026-6110)
vulnerability in metagpt (CVE-2026-6110). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6111 |
|
SSRF (Server-Side Request Forgery) in metagpt (CVE-2026-6111)
SSRF in metagpt (CVE-2026-6111). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6109 |
|
Cross-Site Request Forgery (CSRF) in metagpt (CVE-2026-6109)
vulnerability in metagpt (CVE-2026-6109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40178 |
|
Authentication Bypass in ajenti-plugin-core (CVE-2026-40178)
authentication bypass in ajenti-plugin-core (CVE-2026-40178). Data can be tampered with by attackers. Mitigation: upgrade to `0.112` or later.
|
| CVE-2026-40315 |
|
SQL Injection in praisonai (CVE-2026-40315)
SQL injection in praisonai (CVE-2026-40315). Risk of unauthorized operations or information disclosure. Exploitable via ``table_prefix``. Mitigation: upgrade to `4.5.133` or later.
|