Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-27026 Vulnerability in pypdf (CVE-2026-27026)
vulnerability in pypdf (CVE-2026-27026). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.7.1` or later.
CVE-2026-27024 Vulnerability in pypdf (CVE-2026-27024)
vulnerability in pypdf (CVE-2026-27024). Risk of unauthorized operations or information disclosure. Exploitable via ``TreeObject``. Mitigation: upgrade to `6.7.1` or later.
CVE-2026-2654 SSRF (Server-Side Request Forgery) in smolagents (CVE-2026-2654)
SSRF in smolagents (CVE-2026-2654). Risk of unauthorized operations or information disclosure.
CVE-2025-33253 Unsafe Deserialization in nemo-toolkit (CVE-2025-33253)
vulnerability in nemo-toolkit (CVE-2025-33253). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.6.1` or later.
CVE-2025-33245 Unsafe Deserialization in nemo-toolkit (CVE-2025-33245)
vulnerability in nemo-toolkit (CVE-2025-33245). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.6.1` or later.
CVE-2026-26057 Vulnerability in cisco-ai-skill-scanner (CVE-2026-26057)
vulnerability in cisco-ai-skill-scanner (CVE-2026-26057). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.2` or later.
CVE-2026-25650 Information Disclosure in mcp-salesforce-connector (CVE-2026-25650)
vulnerability in mcp-salesforce-connector (CVE-2026-25650). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.1.10` or later.
CVE-2026-25905 Vulnerability in mcp-run-python (CVE-2026-25905)
vulnerability in mcp-run-python (CVE-2026-25905). Risk of unauthorized operations or information disclosure. Exploitable via ``runPython``.
CVE-2026-25904 SSRF (Server-Side Request Forgery) in mcp-run-python (CVE-2026-25904)
SSRF in mcp-run-python (CVE-2026-25904). Risk of unauthorized operations or information disclosure. Exploitable via ``localhost``.
CVE-2026-25528 SSRF (Server-Side Request Forgery) in langsmith (CVE-2026-25528)
SSRF in langsmith (CVE-2026-25528). Risk of unauthorized operations or information disclosure. Exploitable via ``api_url``. Mitigation: upgrade to `0.6.3` or later.
CVE-2026-26013 SSRF (Server-Side Request Forgery) in langchain-core (CVE-2026-26013)
SSRF in langchain-core (CVE-2026-26013). Risk of unauthorized operations or information disclosure. Exploitable via ``image_url``. Mitigation: upgrade to `1.2.11` or later.
CVE-2026-25577 Vulnerability in emmett-core (CVE-2026-25577)
vulnerability in emmett-core (CVE-2026-25577). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`. Mitigation: upgrade to `1.3.11` or later.
CVE-2026-25198 Open Redirect in web2py (CVE-2026-25198)
vulnerability in web2py (CVE-2026-25198). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1` or later.
CVE-2026-1707 Vulnerability in pgadmin4 (CVE-2026-1707)
vulnerability in pgadmin4 (CVE-2026-1707). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.12` or later.
MAL-2026-10453 Vulnerability in router-processor (MAL-2026-10453)
vulnerability in router-processor (MAL-2026-10453). Risk of unauthorized operations or information disclosure. Exploitable via ``credits``.
MAL-2026-10450 Vulnerability in font-hub (MAL-2026-10450)
vulnerability in font-hub (MAL-2026-10450). Risk of unauthorized operations or information disclosure. Exploitable via ``credits``.
MAL-2026-10449 Vulnerability in auth-gen-next (MAL-2026-10449)
vulnerability in auth-gen-next (MAL-2026-10449). Risk of unauthorized operations or information disclosure.
CVE-2026-6847 Vulnerability in CVE-2026-6847 (CVE-2026-6847)
vulnerability in CVE-2026-6847 (CVE-2026-6847). Risk of unauthorized operations or information disclosure.
CVE-2026-61498 OS Command Injection in vitec (CVE-2026-61498)
OS command injection in vitec (CVE-2026-61498). Successful exploitation can lead to full system takeover.
CVE-2026-60121 OS Command Injection in vitec (CVE-2026-60121)
OS command injection in vitec (CVE-2026-60121). Successful exploitation can lead to full system takeover.
MINI-wmp4-8j2x-h75m MINI-wmp4-8j2x-h75m
MINI-rvf3-g9vg-2pj3 MINI-rvf3-g9vg-2pj3
MINI-j7f6-mrmm-9rv5 MINI-j7f6-mrmm-9rv5
MINI-hc9g-6mwx-g6vh MINI-hc9g-6mwx-g6vh
MINI-gg4m-24w5-3434 MINI-gg4m-24w5-3434
MINI-8hjj-gp82-x58p MINI-8hjj-gp82-x58p
MINI-v5pv-5446-9wj3 MINI-v5pv-5446-9wj3
MINI-8wq6-86mp-436p MINI-8wq6-86mp-436p
MINI-mcr6-f8h3-36px MINI-mcr6-f8h3-36px
MINI-g2m8-49hm-8q6p MINI-g2m8-49hm-8q6p
MINI-8q4m-9j29-3vw7 MINI-8q4m-9j29-3vw7
MINI-mq24-6984-4mf7 MINI-mq24-6984-4mf7
MINI-4gqm-r786-4mcv MINI-4gqm-r786-4mcv
MINI-m9ph-753q-4547 MINI-m9ph-753q-4547
MINI-ccww-c94w-pf5j MINI-ccww-c94w-pf5j
MINI-f4fr-q929-4gxg MINI-f4fr-q929-4gxg
MINI-499r-9r63-fjjp MINI-499r-9r63-fjjp
MINI-gh88-qm6j-m52p MINI-gh88-qm6j-m52p
MINI-8322-rwmg-4p85 MINI-8322-rwmg-4p85
MINI-6cmx-w644-wv9j MINI-6cmx-w644-wv9j
MINI-7mpr-g3mg-jw8c MINI-7mpr-g3mg-jw8c
MINI-6589-pqv6-93x2 MINI-6589-pqv6-93x2
MINI-46gp-8cvw-gh93 MINI-46gp-8cvw-gh93
MINI-9jvq-pw9q-px3v MINI-9jvq-pw9q-px3v
MINI-4pxg-w544-f5mx MINI-4pxg-w544-f5mx
MINI-429x-mx2w-r3mf MINI-429x-mx2w-r3mf
MINI-5w2f-73rr-5qm6 MINI-5w2f-73rr-5qm6
MINI-2xfc-38m3-5pp8 MINI-2xfc-38m3-5pp8
MINI-2p2j-jh7x-8g86 MINI-2p2j-jh7x-8g86
MINI-2fxm-jm2h-37q4 MINI-2fxm-jm2h-37q4

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →