Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-27026 |
|
Vulnerability in pypdf (CVE-2026-27026)
vulnerability in pypdf (CVE-2026-27026). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.7.1` or later.
|
| CVE-2026-27024 |
|
Vulnerability in pypdf (CVE-2026-27024)
vulnerability in pypdf (CVE-2026-27024). Risk of unauthorized operations or information disclosure. Exploitable via ``TreeObject``. Mitigation: upgrade to `6.7.1` or later.
|
| CVE-2026-2654 |
|
SSRF (Server-Side Request Forgery) in smolagents (CVE-2026-2654)
SSRF in smolagents (CVE-2026-2654). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-33253 |
|
Unsafe Deserialization in nemo-toolkit (CVE-2025-33253)
vulnerability in nemo-toolkit (CVE-2025-33253). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2025-33245 |
|
Unsafe Deserialization in nemo-toolkit (CVE-2025-33245)
vulnerability in nemo-toolkit (CVE-2025-33245). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-26057 |
|
Vulnerability in cisco-ai-skill-scanner (CVE-2026-26057)
vulnerability in cisco-ai-skill-scanner (CVE-2026-26057). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.2` or later.
|
| CVE-2026-25650 |
|
Information Disclosure in mcp-salesforce-connector (CVE-2026-25650)
vulnerability in mcp-salesforce-connector (CVE-2026-25650). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.1.10` or later.
|
| CVE-2026-25905 |
|
Vulnerability in mcp-run-python (CVE-2026-25905)
vulnerability in mcp-run-python (CVE-2026-25905). Risk of unauthorized operations or information disclosure. Exploitable via ``runPython``.
|
| CVE-2026-25904 |
|
SSRF (Server-Side Request Forgery) in mcp-run-python (CVE-2026-25904)
SSRF in mcp-run-python (CVE-2026-25904). Risk of unauthorized operations or information disclosure. Exploitable via ``localhost``.
|
| CVE-2026-25528 |
|
SSRF (Server-Side Request Forgery) in langsmith (CVE-2026-25528)
SSRF in langsmith (CVE-2026-25528). Risk of unauthorized operations or information disclosure. Exploitable via ``api_url``. Mitigation: upgrade to `0.6.3` or later.
|
| CVE-2026-26013 |
|
SSRF (Server-Side Request Forgery) in langchain-core (CVE-2026-26013)
SSRF in langchain-core (CVE-2026-26013). Risk of unauthorized operations or information disclosure. Exploitable via ``image_url``. Mitigation: upgrade to `1.2.11` or later.
|
| CVE-2026-25577 |
|
Vulnerability in emmett-core (CVE-2026-25577)
vulnerability in emmett-core (CVE-2026-25577). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`. Mitigation: upgrade to `1.3.11` or later.
|
| CVE-2026-25198 |
|
Open Redirect in web2py (CVE-2026-25198)
vulnerability in web2py (CVE-2026-25198). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1` or later.
|
| CVE-2026-1707 |
|
Vulnerability in pgadmin4 (CVE-2026-1707)
vulnerability in pgadmin4 (CVE-2026-1707). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.12` or later.
|
| MAL-2026-10453 |
|
Vulnerability in router-processor (MAL-2026-10453)
vulnerability in router-processor (MAL-2026-10453). Risk of unauthorized operations or information disclosure. Exploitable via ``credits``.
|
| MAL-2026-10450 |
|
Vulnerability in font-hub (MAL-2026-10450)
vulnerability in font-hub (MAL-2026-10450). Risk of unauthorized operations or information disclosure. Exploitable via ``credits``.
|
| MAL-2026-10449 |
|
Vulnerability in auth-gen-next (MAL-2026-10449)
vulnerability in auth-gen-next (MAL-2026-10449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6847 |
|
Vulnerability in CVE-2026-6847 (CVE-2026-6847)
vulnerability in CVE-2026-6847 (CVE-2026-6847). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61498 |
|
OS Command Injection in vitec (CVE-2026-61498)
OS command injection in vitec (CVE-2026-61498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60121 |
|
OS Command Injection in vitec (CVE-2026-60121)
OS command injection in vitec (CVE-2026-60121). Successful exploitation can lead to full system takeover.
|
| MINI-wmp4-8j2x-h75m |
|
MINI-wmp4-8j2x-h75m |
| MINI-rvf3-g9vg-2pj3 |
|
MINI-rvf3-g9vg-2pj3 |
| MINI-j7f6-mrmm-9rv5 |
|
MINI-j7f6-mrmm-9rv5 |
| MINI-hc9g-6mwx-g6vh |
|
MINI-hc9g-6mwx-g6vh |
| MINI-gg4m-24w5-3434 |
|
MINI-gg4m-24w5-3434 |
| MINI-8hjj-gp82-x58p |
|
MINI-8hjj-gp82-x58p |
| MINI-v5pv-5446-9wj3 |
|
MINI-v5pv-5446-9wj3 |
| MINI-8wq6-86mp-436p |
|
MINI-8wq6-86mp-436p |
| MINI-mcr6-f8h3-36px |
|
MINI-mcr6-f8h3-36px |
| MINI-g2m8-49hm-8q6p |
|
MINI-g2m8-49hm-8q6p |
| MINI-8q4m-9j29-3vw7 |
|
MINI-8q4m-9j29-3vw7 |
| MINI-mq24-6984-4mf7 |
|
MINI-mq24-6984-4mf7 |
| MINI-4gqm-r786-4mcv |
|
MINI-4gqm-r786-4mcv |
| MINI-m9ph-753q-4547 |
|
MINI-m9ph-753q-4547 |
| MINI-ccww-c94w-pf5j |
|
MINI-ccww-c94w-pf5j |
| MINI-f4fr-q929-4gxg |
|
MINI-f4fr-q929-4gxg |
| MINI-499r-9r63-fjjp |
|
MINI-499r-9r63-fjjp |
| MINI-gh88-qm6j-m52p |
|
MINI-gh88-qm6j-m52p |
| MINI-8322-rwmg-4p85 |
|
MINI-8322-rwmg-4p85 |
| MINI-6cmx-w644-wv9j |
|
MINI-6cmx-w644-wv9j |
| MINI-7mpr-g3mg-jw8c |
|
MINI-7mpr-g3mg-jw8c |
| MINI-6589-pqv6-93x2 |
|
MINI-6589-pqv6-93x2 |
| MINI-46gp-8cvw-gh93 |
|
MINI-46gp-8cvw-gh93 |
| MINI-9jvq-pw9q-px3v |
|
MINI-9jvq-pw9q-px3v |
| MINI-4pxg-w544-f5mx |
|
MINI-4pxg-w544-f5mx |
| MINI-429x-mx2w-r3mf |
|
MINI-429x-mx2w-r3mf |
| MINI-5w2f-73rr-5qm6 |
|
MINI-5w2f-73rr-5qm6 |
| MINI-2xfc-38m3-5pp8 |
|
MINI-2xfc-38m3-5pp8 |
| MINI-2p2j-jh7x-8g86 |
|
MINI-2p2j-jh7x-8g86 |
| MINI-2fxm-jm2h-37q4 |
|
MINI-2fxm-jm2h-37q4 |