Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-17625 OS Command Injection in langflow (CVE-2026-17625)
OS command injection in langflow (CVE-2026-17625). Successful exploitation can lead to full system takeover.
CVE-2026-70431 Code Injection in CVE-2026-70431 (CVE-2026-70431)
code injection in CVE-2026-70431 (CVE-2026-70431). Successful exploitation can lead to full system takeover.
CVE-2026-20313 Vulnerability in CVE-2026-20313 (CVE-2026-20313)
vulnerability in CVE-2026-20313 (CVE-2026-20313). Risk of unauthorized operations or information disclosure.
CVE-2026-20312 Vulnerability in CVE-2026-20312 (CVE-2026-20312)
vulnerability in CVE-2026-20312 (CVE-2026-20312). Successful exploitation can lead to full system takeover.
CVE-2026-9077 Vulnerability in langflow (CVE-2026-9077)
vulnerability in langflow (CVE-2026-9077). Data can be tampered with by attackers.
CVE-2026-20270 Vulnerability in cisco (CVE-2026-20270)
vulnerability in cisco (CVE-2026-20270). Risk of unauthorized operations or information disclosure.
CVE-2026-20269 Vulnerability in cisco (CVE-2026-20269)
vulnerability in cisco (CVE-2026-20269). Risk of unauthorized operations or information disclosure.
CVE-2026-20271 Vulnerability in cisco (CVE-2026-20271)
vulnerability in cisco (CVE-2026-20271). Risk of unauthorized operations or information disclosure.
CVE-2026-20268 Buffer Overflow in cisco (CVE-2026-20268)
vulnerability in cisco (CVE-2026-20268). Risk of unauthorized operations or information disclosure.
CVE-2026-17630 Vulnerability in langflow (CVE-2026-17630)
vulnerability in langflow (CVE-2026-17630). Successful exploitation can lead to full system takeover.
CVE-2026-14587 Vulnerability in neo4j (CVE-2026-14587)
vulnerability in neo4j (CVE-2026-14587). Risk of unauthorized operations or information disclosure.
CVE-2026-17626 Vulnerability in langflow (CVE-2026-17626)
vulnerability in langflow (CVE-2026-17626). Successful exploitation can lead to full system takeover.
CVE-2026-17623 OS Command Injection in langflow (CVE-2026-17623)
OS command injection in langflow (CVE-2026-17623). Successful exploitation can lead to full system takeover.
CVE-2026-17617 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-17617)
SSRF in ssrf (CVE-2026-17617). Confidential information can be exposed externally.
CVE-2026-70608 Vulnerability in electron (CVE-2026-70608)
vulnerability in electron (CVE-2026-70608). Risk of unauthorized operations or information disclosure. Exploitable via ``setWindowOpenHandler``. Mitigation: upgrade to `39.8.10` or later.
CVE-2026-8446 Vulnerability in langflow (CVE-2026-8446)
vulnerability in langflow (CVE-2026-8446). Confidential information can be exposed externally.
CVE-2026-20200 Vulnerability in cisco (CVE-2026-20200)
vulnerability in cisco (CVE-2026-20200). Successful exploitation can lead to full system takeover.
CVE-2026-20273 Vulnerability in Cisco ios-xe (CVE-2026-20273)
vulnerability in Cisco ios-xe (CVE-2026-20273). Risk of unauthorized operations or information disclosure.
CVE-2026-20301 Vulnerability in Cisco dos (CVE-2026-20301)
vulnerability in Cisco dos (CVE-2026-20301). Risk of unauthorized operations or information disclosure.
CVE-2026-20124 Vulnerability in Cisco dos (CVE-2026-20124)
vulnerability in Cisco dos (CVE-2026-20124). Risk of unauthorized operations or information disclosure.
CVE-2026-20263 Vulnerability in Cisco dos (CVE-2026-20263)
vulnerability in Cisco dos (CVE-2026-20263). Risk of unauthorized operations or information disclosure.
CVE-2026-9203 SSRF (Server-Side Request Forgery) in CVE-2026-9203 (CVE-2026-9203)
SSRF in CVE-2026-9203 (CVE-2026-9203). Successful exploitation can lead to full system takeover.
CVE-2026-8400 Vulnerability in ibm (CVE-2026-8400)
vulnerability in ibm (CVE-2026-8400). Successful exploitation can lead to full system takeover.
CVE-2026-7327 Privilege Escalation in CVE-2026-7327 (CVE-2026-7327)
vulnerability in CVE-2026-7327 (CVE-2026-7327). Confidential information can be exposed externally.
CVE-2026-7326 Cross-Site Request Forgery (CSRF) in CVE-2026-7326 (CVE-2026-7326)
vulnerability in CVE-2026-7326 (CVE-2026-7326). Successful exploitation can lead to full system takeover.
CVE-2026-60023 Information Disclosure in apache (CVE-2026-60023)
vulnerability in apache (CVE-2026-60023). Confidential information can be exposed externally.
CVE-2026-48911 Vulnerability in apache (CVE-2026-48911)
vulnerability in apache (CVE-2026-48911). Data can be tampered with by attackers.
CVE-2026-48834 Vulnerability in apache (CVE-2026-48834)
vulnerability in apache (CVE-2026-48834). Risk of unauthorized operations or information disclosure.
CVE-2026-39923 Vulnerability in CVE-2026-39923 (CVE-2026-39923)
vulnerability in CVE-2026-39923 (CVE-2026-39923). Successful exploitation can lead to full system takeover.
CVE-2026-16442 Vulnerability in redhat (CVE-2026-16442)
vulnerability in redhat (CVE-2026-16442). Confidential information can be exposed externally.
CVE-2026-15572 Vulnerability in redhat (CVE-2026-15572)
vulnerability in redhat (CVE-2026-15572). Successful exploitation can lead to full system takeover.
CVE-2026-10025 XXE (XML External Entity) in ibm (CVE-2026-10025)
vulnerability in ibm (CVE-2026-10025). Confidential information can be exposed externally.
CVE-2026-70604 Vulnerability in electron (CVE-2026-70604)
vulnerability in electron (CVE-2026-70604). Confidential information can be exposed externally. Exploitable via ``XMLHttpRequest``. Mitigation: upgrade to `39.8.10` or later.
CVE-2026-70601 Vulnerability in electron (CVE-2026-70601)
vulnerability in electron (CVE-2026-70601). Confidential information can be exposed externally. Exploitable via ``contextBridge``. Mitigation: upgrade to `42.0.0-beta.5` or later.
CVE-2026-54876 Vulnerability in dos (CVE-2026-54876)
vulnerability in dos (CVE-2026-54876). Risk of unauthorized operations or information disclosure.
CVE-2026-16102 Vulnerability in redhat (CVE-2026-16102)
vulnerability in redhat (CVE-2026-16102). Confidential information can be exposed externally.
CVE-2026-15573 Vulnerability in redhat (CVE-2026-15573)
vulnerability in redhat (CVE-2026-15573). Confidential information can be exposed externally.
CVE-2026-17613 Vulnerability in CVE-2026-17613 (CVE-2026-17613)
vulnerability in CVE-2026-17613 (CVE-2026-17613). Risk of unauthorized operations or information disclosure.
CVE-2026-12410 Vulnerability in CVE-2026-12410 (CVE-2026-12410)
vulnerability in CVE-2026-12410 (CVE-2026-12410). Successful exploitation can lead to full system takeover.
CVE-2026-7529 Vulnerability in wordpress (CVE-2026-7529)
vulnerability in wordpress (CVE-2026-7529). Data can be tampered with by attackers.
CVE-2026-67623 Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
CVE-2026-17506 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
CVE-2026-16443 Vulnerability in redhat (CVE-2026-16443)
vulnerability in redhat (CVE-2026-16443). Confidential information can be exposed externally.
CVE-2026-15979 Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
CVE-2025-70962 Vulnerability in CVE-2025-70962 (CVE-2025-70962)
vulnerability in CVE-2025-70962 (CVE-2025-70962). Confidential information can be exposed externally.
CVE-2026-71294 Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
vulnerability in CVE-2026-71294 (CVE-2026-71294). Confidential information can be exposed externally. Exploitable via ``allowed_classes``.
CVE-2026-71292 SQL Injection in CVE-2026-71292 (CVE-2026-71292)
SQL injection in CVE-2026-71292 (CVE-2026-71292). Successful exploitation can lead to full system takeover. Exploitable via ``dir``.
CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
CVE-2026-71288 Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
CVE-2026-71287 Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →