Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-79770 |
|
Vulnerability in dos (CVE-2026-79770)
vulnerability in dos (CVE-2026-79770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79676 |
|
Path Traversal in path-traversal (CVE-2026-79676)
path traversal in path-traversal (CVE-2026-79676). Confidential information can be exposed externally.
|
| CVE-2026-70550 |
|
Vulnerability in CVE-2026-70550 (CVE-2026-70550)
vulnerability in CVE-2026-70550 (CVE-2026-70550). Confidential information can be exposed externally.
|
| CVE-2026-79675 |
|
Vulnerability in CVE-2026-79675 (CVE-2026-79675)
vulnerability in CVE-2026-79675 (CVE-2026-79675). Successful exploitation can lead to full system takeover.
|
| CVE-2026-79674 |
|
Vulnerability in CVE-2026-79674 (CVE-2026-79674)
vulnerability in CVE-2026-79674 (CVE-2026-79674). Confidential information can be exposed externally.
|
| CVE-2026-70548 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-70548 (CVE-2026-70548)
SSRF in CVE-2026-70548 (CVE-2026-70548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79771 |
|
Vulnerability in dos (CVE-2026-79771)
vulnerability in dos (CVE-2026-79771). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71407 |
|
Out-of-Bounds Write in dos (CVE-2025-71407)
out-of-bounds write in dos (CVE-2025-71407). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71346 |
|
Out-of-Bounds Read in c (CVE-2025-71346)
vulnerability in c (CVE-2025-71346). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71406 |
|
Use-After-Free in CVE-2025-71406 (CVE-2025-71406)
vulnerability in CVE-2025-71406 (CVE-2025-71406). Data can be tampered with by attackers.
|
| CVE-2024-58377 |
|
Out-of-Bounds Read in CVE-2024-58377 (CVE-2024-58377)
vulnerability in CVE-2024-58377 (CVE-2024-58377). Confidential information can be exposed externally.
|
| CVE-2024-58378 |
|
Use-After-Free in CVE-2024-58378 (CVE-2024-58378)
vulnerability in CVE-2024-58378 (CVE-2024-58378). Successful exploitation can lead to full system takeover.
|
| CVE-2022-51000 |
|
Use-After-Free in dos (CVE-2022-51000)
vulnerability in dos (CVE-2022-51000). Successful exploitation can lead to full system takeover.
|
| CVE-2023-54354 |
|
Vulnerability in dos (CVE-2023-54354)
vulnerability in dos (CVE-2023-54354). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47996 |
|
Buffer Overflow in dos (CVE-2021-47996)
vulnerability in dos (CVE-2021-47996). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-50999 |
|
Buffer Overflow in dos (CVE-2022-50999)
vulnerability in dos (CVE-2022-50999). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-50998 |
|
Vulnerability in dos (CVE-2022-50998)
vulnerability in dos (CVE-2022-50998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55620 |
|
Vulnerability in eml_parser (CVE-2026-55620)
vulnerability in eml_parser (CVE-2026-55620). Risk of unauthorized operations or information disclosure. Exploitable via ``eml_parser``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-55619 |
|
Vulnerability in eml_parser (CVE-2026-55619)
vulnerability in eml_parser (CVE-2026-55619). Risk of unauthorized operations or information disclosure. Exploitable via ``eml_parser``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-55618 |
|
Vulnerability in eml_parser (CVE-2026-55618)
vulnerability in eml_parser (CVE-2026-55618). Data can be tampered with by attackers. Exploitable via ``eml_parser``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-59984 |
|
Out-of-Bounds Write in dos (CVE-2026-59984)
out-of-bounds write in dos (CVE-2026-59984). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59983 |
|
Out-of-Bounds Read in c (CVE-2026-59983)
vulnerability in c (CVE-2026-59983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59982 |
|
Vulnerability in CVE-2026-59982 (CVE-2026-59982)
vulnerability in CVE-2026-59982 (CVE-2026-59982). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55663 |
|
Vulnerability in mediasoup (CVE-2026-55663)
vulnerability in mediasoup (CVE-2026-55663). Risk of unauthorized operations or information disclosure. Exploitable via ``localVerificationTag``. Mitigation: upgrade to `3.20.6` or later.
|
| CVE-2026-55637 |
|
Vulnerability in github.com/geiserx/genieacs-mcp (CVE-2026-55637)
vulnerability in github.com/geiserx/genieacs-mcp (CVE-2026-55637). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`. Mitigation: upgrade to `0.3.2` or later.
|
| GHSA-vwf3-4xxj-qg6h |
|
Code Injection in mcp-contextforge-gateway (GHSA-vwf3-4xxj-qg6h)
code injection in mcp-contextforge-gateway (GHSA-vwf3-4xxj-qg6h). Risk of unauthorized operations or information disclosure. Exploitable via `POST /prompts`. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-55419 |
|
Unrestricted File Upload in reachy-mini (CVE-2026-55419)
vulnerability in reachy-mini (CVE-2026-55419). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2` or later.
|
| GHSA-pg62-f8g4-4wqh |
|
Privilege Escalation in phpmyfaq/phpmyfaq (GHSA-pg62-f8g4-4wqh)
vulnerability in phpmyfaq/phpmyfaq (GHSA-pg62-f8g4-4wqh). Risk of unauthorized operations or information disclosure. Exploitable via `POST /admin/group/update/permissions`. Mitigation: upgrade to `4.1.5` or later.
|
| GHSA-mf8r-wm2w-f8c5 |
|
Information Disclosure in thorsten/phpmyfaq (GHSA-mf8r-wm2w-f8c5)
vulnerability in thorsten/phpmyfaq (GHSA-mf8r-wm2w-f8c5). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4.0/faqs/tags/{tagId}`. Mitigation: upgrade to `4.1.5` or later.
|
| GHSA-88g4-74f3-63x9 |
|
Path Traversal in thorsten/phpmyfaq (GHSA-88g4-74f3-63x9)
path traversal in thorsten/phpmyfaq (GHSA-88g4-74f3-63x9). Risk of unauthorized operations or information disclosure. Exploitable via ``false``. Mitigation: upgrade to `4.1.5` or later.
|
| CVE-2026-59189 |
|
Out-of-Bounds Read in CVE-2026-59189 (CVE-2026-59189)
vulnerability in CVE-2026-59189 (CVE-2026-59189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59187 |
|
Vulnerability in CVE-2026-59187 (CVE-2026-59187)
vulnerability in CVE-2026-59187 (CVE-2026-59187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59186 |
|
Vulnerability in CVE-2026-59186 (CVE-2026-59186)
vulnerability in CVE-2026-59186 (CVE-2026-59186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59184 |
|
Use-After-Free in CVE-2026-59184 (CVE-2026-59184)
vulnerability in CVE-2026-59184 (CVE-2026-59184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13478 |
|
Out-of-Bounds Read in c (CVE-2026-13478)
vulnerability in c (CVE-2026-13478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13217 |
|
Vulnerability in c (CVE-2026-13217)
vulnerability in c (CVE-2026-13217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13216 |
|
Out-of-Bounds Write in c (CVE-2026-13216)
out-of-bounds write in c (CVE-2026-13216). Data can be tampered with by attackers.
|
| CVE-2026-55557 |
|
Path Traversal in browse-mcp (CVE-2026-55557)
path traversal in browse-mcp (CVE-2026-55557). Risk of unauthorized operations or information disclosure. Exploitable via ``browser_download``. Mitigation: upgrade to `0.8.2` or later.
|
| CVE-2026-55585 |
|
Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-55553 |
|
Information Disclosure in urllib (CVE-2026-55553)
vulnerability in urllib (CVE-2026-55553). Confidential information can be exposed externally. Exploitable via `Cookie header`. Mitigation: upgrade to `2.44.1` or later.
|
| CVE-2026-55571 |
|
Vulnerability in djust (CVE-2026-55571)
vulnerability in djust (CVE-2026-55571). Data can be tampered with by attackers. Exploitable via ``LiveViewConsumer``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2026-55640 |
|
Vulnerability in nextcloud-mcp-server (CVE-2026-55640)
vulnerability in nextcloud-mcp-server (CVE-2026-55640). Data can be tampered with by attackers. Exploitable via `POST /webhooks/nextcloud`. Mitigation: upgrade to `0.117.2` or later.
|
| GHSA-8qx3-8gm5-9cj2 |
|
Vulnerability in pickem (GHSA-8qx3-8gm5-9cj2)
vulnerability in pickem (GHSA-8qx3-8gm5-9cj2). Risk of unauthorized operations or information disclosure. Exploitable via ``chrome.row``. Mitigation: upgrade to `1.0.7` or later.
|
| GHSA-8cp3-qxj6-px34 |
|
SSRF (Server-Side Request Forgery) in utcp-http (GHSA-8cp3-qxj6-px34)
SSRF in utcp-http (GHSA-8cp3-qxj6-px34). Risk of unauthorized operations or information disclosure. Exploitable via ``tokenUrl``. Mitigation: upgrade to `1.1.4` or later.
|
| GHSA-ppx3-28rw-8fpf |
|
SSRF (Server-Side Request Forgery) in utcp-gql (GHSA-ppx3-28rw-8fpf)
SSRF in utcp-gql (GHSA-ppx3-28rw-8fpf). Risk of unauthorized operations or information disclosure. Exploitable via ``startswith``. Mitigation: upgrade to `1.1.1` or later.
|
| GHSA-9qhg-99ww-9mqc |
|
SSRF (Server-Side Request Forgery) in utcp-http (GHSA-9qhg-99ww-9mqc)
SSRF in utcp-http (GHSA-9qhg-99ww-9mqc). Risk of unauthorized operations or information disclosure. Exploitable via ``HttpCommunicationProtocol.call_tool``. Mitigation: upgrade to `1.1.4` or later.
|
| CVE-2026-55580 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55580)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55580). Risk of unauthorized operations or information disclosure. Exploitable via ``config.go``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-55581 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55581)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55581). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-55582 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55582)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55582). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-79717 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-79717)
SSRF in ssrf (CVE-2026-79717). Risk of unauthorized operations or information disclosure.
|