Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-58351 |
|
Vulnerability in flowise (CVE-2024-58351)
vulnerability in flowise (CVE-2024-58351). Successful exploitation can lead to full system takeover. Exploitable via ``overrideConfig``. Mitigation: upgrade to `2.1.4` or later.
|
| CVE-2022-50972 |
|
Code Injection in CVE-2022-50972 (CVE-2022-50972)
code injection in CVE-2022-50972 (CVE-2022-50972). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25763 |
|
Vulnerability in wordpress (CVE-2019-25763)
vulnerability in wordpress (CVE-2019-25763). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48939 KEV |
|
[KEV] Unrestricted File Upload in Icagenda joomlic (CVE-2026-48939)
vulnerability in Icagenda joomlic (CVE-2026-48939). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-48908 KEV |
|
[KEV] Unrestricted File Upload in Joomshaper ollyo (CVE-2026-48908)
vulnerability in Joomshaper ollyo (CVE-2026-48908). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-9265 |
|
Out-of-Bounds Read in CVE-2026-9265 (CVE-2026-9265)
vulnerability in CVE-2026-9265 (CVE-2026-9265). Confidential information can be exposed externally.
|
| CVE-2026-11551 |
|
Vulnerability in wordpress (CVE-2026-11551)
vulnerability in wordpress (CVE-2026-11551). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56081 |
|
Vulnerability in CVE-2026-56081 (CVE-2026-56081)
vulnerability in CVE-2026-56081 (CVE-2026-56081). Confidential information can be exposed externally.
|
| CVE-2026-56073 |
|
Vulnerability in CVE-2026-56073 (CVE-2026-56073)
vulnerability in CVE-2026-56073 (CVE-2026-56073). Confidential information can be exposed externally.
|
| CVE-2026-45480 |
|
Authentication Bypass in microsoft (CVE-2026-45480)
authentication bypass in microsoft (CVE-2026-45480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48582 |
|
Vulnerability in microsoft (CVE-2026-48582)
vulnerability in microsoft (CVE-2026-48582). Confidential information can be exposed externally.
|
| CVE-2026-48584 |
|
Vulnerability in microsoft (CVE-2026-48584)
vulnerability in microsoft (CVE-2026-48584). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55447 |
|
Information Disclosure in langflow (CVE-2026-55447)
vulnerability in langflow (CVE-2026-55447). Successful exploitation can lead to full system takeover. Exploitable via ``BaseFileComponent``. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-54906 |
|
Vulnerability in concurrent-ruby (CVE-2026-54906)
vulnerability in concurrent-ruby (CVE-2026-54906). Successful exploitation can lead to full system takeover. Exploitable via ``release_write_lock``. Mitigation: upgrade to `1.3.7` or later.
|
| CVE-2026-54782 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54782)
vulnerability in CoreWCF.Primitives (CVE-2026-54782). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-48772 |
|
Vulnerability in proxysql (CVE-2026-48772)
vulnerability in proxysql (CVE-2026-48772). Confidential information can be exposed externally. Exploitable via ``UNKNOWN``.
|
| CVE-2026-48773 |
|
Out-of-Bounds Write in proxysql (CVE-2026-48773)
out-of-bounds write in proxysql (CVE-2026-48773). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54527 |
|
Cross-Site Scripting (XSS) in jupyterlab-git (CVE-2026-54527)
cross-site scripting in jupyterlab-git (CVE-2026-54527). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/terminals`. Mitigation: upgrade to `0.54.0` or later.
|
| CVE-2026-53492 |
|
Vulnerability in github.com/containerd/containerd/v2 (CVE-2026-53492)
vulnerability in github.com/containerd/containerd/v2 (CVE-2026-53492). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.2` or later.
|
| CVE-2026-51844 |
|
Vulnerability in tenda (CVE-2026-51844)
vulnerability in tenda (CVE-2026-51844). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51843 |
|
Vulnerability in tenda (CVE-2026-51843)
vulnerability in tenda (CVE-2026-51843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51846 |
|
Vulnerability in tenda (CVE-2026-51846)
vulnerability in tenda (CVE-2026-51846). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51845 |
|
Vulnerability in tenda (CVE-2026-51845)
vulnerability in tenda (CVE-2026-51845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49871 |
|
Cross-Site Request Forgery (CSRF) in apisix (CVE-2026-49871)
vulnerability in apisix (CVE-2026-49871). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-49230 |
|
Vulnerability in apisix (CVE-2026-49230)
vulnerability in apisix (CVE-2026-49230). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-44087 |
|
Vulnerability in apisix (CVE-2026-44087)
vulnerability in apisix (CVE-2026-44087). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-39999 |
|
Vulnerability in apisix (CVE-2026-39999)
vulnerability in apisix (CVE-2026-39999). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2025-62821 |
|
Out-of-Bounds Read in microsoft (CVE-2025-62821)
vulnerability in microsoft (CVE-2025-62821). Confidential information can be exposed externally.
|
| CVE-2026-9142 |
|
Vulnerability in ni (CVE-2026-9142)
vulnerability in ni (CVE-2026-9142). Confidential information can be exposed externally.
|
| CVE-2026-48137 |
|
Vulnerability in ni (CVE-2026-48137)
vulnerability in ni (CVE-2026-48137). Confidential information can be exposed externally.
|
| CVE-2026-54051 |
|
OS Command Injection in network-ai (CVE-2026-54051)
OS command injection in network-ai (CVE-2026-54051). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxPolicy.isCommandAllowed``. Mitigation: upgrade to `5.9.1` or later.
|
| CVE-2026-56142 |
|
Vulnerability in privilege-escalation (CVE-2026-56142)
vulnerability in privilege-escalation (CVE-2026-56142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56141 |
|
Vulnerability in jetbrains (CVE-2026-56141)
vulnerability in jetbrains (CVE-2026-56141). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50242 |
|
Vulnerability in jetbrains (CVE-2026-50242)
vulnerability in jetbrains (CVE-2026-50242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54414 |
|
Path Traversal in path-traversal (CVE-2026-54414)
path traversal in path-traversal (CVE-2026-54414). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.16.0` or later.
|
| CVE-2026-7515 |
|
Vulnerability in wordpress (CVE-2026-7515)
vulnerability in wordpress (CVE-2026-7515). Successful exploitation can lead to full system takeover. Exploitable via ``doc_style``.
|
| CVE-2026-8713 |
|
Path Traversal in wordpress (CVE-2026-8713)
path traversal in wordpress (CVE-2026-8713). Data can be tampered with by attackers.
|
| CVE-2026-50195 |
|
Vulnerability in Amazon github.com/containerd/containerd/v2 (CVE-2026-50195)
vulnerability in Amazon github.com/containerd/containerd/v2 (CVE-2026-50195). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.9, 2.2.5, 2.3.2` or later.
|
| CVE-2026-12048 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-12048)
cross-site scripting in react (CVE-2026-12048). Confidential information can be exposed externally.
|
| CVE-2026-12045 |
|
Command Injection in pgadmin (CVE-2026-12045)
command injection in pgadmin (CVE-2026-12045). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12046 |
|
Vulnerability in flask (CVE-2026-12046)
vulnerability in flask (CVE-2026-12046). Successful exploitation can lead to full system takeover. Exploitable via `DELETE /sqleditor/close/`.
|
| CVE-2026-54130 |
|
Vulnerability in microsoft (CVE-2026-54130)
vulnerability in microsoft (CVE-2026-54130). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47647 |
|
Vulnerability in microsoft (CVE-2026-47647)
vulnerability in microsoft (CVE-2026-47647). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49252 |
|
Vulnerability in @deepstream/server (CVE-2026-49252)
vulnerability in @deepstream/server (CVE-2026-49252). Confidential information can be exposed externally. Exploitable via ``__proto__``. Mitigation: upgrade to `10.0.5` or later.
|
| CVE-2026-49257 |
|
Vulnerability in mcp-pinot-server (CVE-2026-49257)
vulnerability in mcp-pinot-server (CVE-2026-49257). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49454 |
|
Authentication Bypass in relyra (CVE-2026-49454)
authentication bypass in relyra (CVE-2026-49454). Confidential information can be exposed externally. Exploitable via ``SignatureValue``. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-47846 |
|
Vulnerability in cassandra (CVE-2026-47846)
vulnerability in cassandra (CVE-2026-47846). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.20-0, 4.1.11-0, 5.0.8-0` or later.
|
| CVE-2026-54390 |
|
Vulnerability in CVE-2026-54390 (CVE-2026-54390)
vulnerability in CVE-2026-54390 (CVE-2026-54390). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38717 |
|
Command Injection in inhandnetworks (CVE-2026-38717)
command injection in inhandnetworks (CVE-2026-38717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54103 |
|
Vulnerability in CVE-2026-54103 (CVE-2026-54103)
vulnerability in CVE-2026-54103 (CVE-2026-54103). Successful exploitation can lead to full system takeover.
|