Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-17625 |
|
OS Command Injection in langflow (CVE-2026-17625)
OS command injection in langflow (CVE-2026-17625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70431 |
|
Code Injection in CVE-2026-70431 (CVE-2026-70431)
code injection in CVE-2026-70431 (CVE-2026-70431). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20313 |
|
Vulnerability in CVE-2026-20313 (CVE-2026-20313)
vulnerability in CVE-2026-20313 (CVE-2026-20313). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20312 |
|
Vulnerability in CVE-2026-20312 (CVE-2026-20312)
vulnerability in CVE-2026-20312 (CVE-2026-20312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9077 |
|
Vulnerability in langflow (CVE-2026-9077)
vulnerability in langflow (CVE-2026-9077). Data can be tampered with by attackers.
|
| CVE-2026-20270 |
|
Vulnerability in cisco (CVE-2026-20270)
vulnerability in cisco (CVE-2026-20270). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20269 |
|
Vulnerability in cisco (CVE-2026-20269)
vulnerability in cisco (CVE-2026-20269). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20271 |
|
Vulnerability in cisco (CVE-2026-20271)
vulnerability in cisco (CVE-2026-20271). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20268 |
|
Buffer Overflow in cisco (CVE-2026-20268)
vulnerability in cisco (CVE-2026-20268). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17630 |
|
Vulnerability in langflow (CVE-2026-17630)
vulnerability in langflow (CVE-2026-17630). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14587 |
|
Vulnerability in neo4j (CVE-2026-14587)
vulnerability in neo4j (CVE-2026-14587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17626 |
|
Vulnerability in langflow (CVE-2026-17626)
vulnerability in langflow (CVE-2026-17626). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17623 |
|
OS Command Injection in langflow (CVE-2026-17623)
OS command injection in langflow (CVE-2026-17623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17617 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-17617)
SSRF in ssrf (CVE-2026-17617). Confidential information can be exposed externally.
|
| CVE-2026-70608 |
|
Vulnerability in electron (CVE-2026-70608)
vulnerability in electron (CVE-2026-70608). Risk of unauthorized operations or information disclosure. Exploitable via ``setWindowOpenHandler``. Mitigation: upgrade to `39.8.10` or later.
|
| CVE-2026-8446 |
|
Vulnerability in langflow (CVE-2026-8446)
vulnerability in langflow (CVE-2026-8446). Confidential information can be exposed externally.
|
| CVE-2026-20200 |
|
Vulnerability in cisco (CVE-2026-20200)
vulnerability in cisco (CVE-2026-20200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20273 |
|
Vulnerability in Cisco ios-xe (CVE-2026-20273)
vulnerability in Cisco ios-xe (CVE-2026-20273). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20301 |
|
Vulnerability in Cisco dos (CVE-2026-20301)
vulnerability in Cisco dos (CVE-2026-20301). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20124 |
|
Vulnerability in Cisco dos (CVE-2026-20124)
vulnerability in Cisco dos (CVE-2026-20124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20263 |
|
Vulnerability in Cisco dos (CVE-2026-20263)
vulnerability in Cisco dos (CVE-2026-20263). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9203 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-9203 (CVE-2026-9203)
SSRF in CVE-2026-9203 (CVE-2026-9203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8400 |
|
Vulnerability in ibm (CVE-2026-8400)
vulnerability in ibm (CVE-2026-8400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7327 |
|
Privilege Escalation in CVE-2026-7327 (CVE-2026-7327)
vulnerability in CVE-2026-7327 (CVE-2026-7327). Confidential information can be exposed externally.
|
| CVE-2026-7326 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-7326 (CVE-2026-7326)
vulnerability in CVE-2026-7326 (CVE-2026-7326). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60023 |
|
Information Disclosure in apache (CVE-2026-60023)
vulnerability in apache (CVE-2026-60023). Confidential information can be exposed externally.
|
| CVE-2026-48911 |
|
Vulnerability in apache (CVE-2026-48911)
vulnerability in apache (CVE-2026-48911). Data can be tampered with by attackers.
|
| CVE-2026-48834 |
|
Vulnerability in apache (CVE-2026-48834)
vulnerability in apache (CVE-2026-48834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39923 |
|
Vulnerability in CVE-2026-39923 (CVE-2026-39923)
vulnerability in CVE-2026-39923 (CVE-2026-39923). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16442 |
|
Vulnerability in redhat (CVE-2026-16442)
vulnerability in redhat (CVE-2026-16442). Confidential information can be exposed externally.
|
| CVE-2026-15572 |
|
Vulnerability in redhat (CVE-2026-15572)
vulnerability in redhat (CVE-2026-15572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10025 |
|
XXE (XML External Entity) in ibm (CVE-2026-10025)
vulnerability in ibm (CVE-2026-10025). Confidential information can be exposed externally.
|
| CVE-2026-70604 |
|
Vulnerability in electron (CVE-2026-70604)
vulnerability in electron (CVE-2026-70604). Confidential information can be exposed externally. Exploitable via ``XMLHttpRequest``. Mitigation: upgrade to `39.8.10` or later.
|
| CVE-2026-70601 |
|
Vulnerability in electron (CVE-2026-70601)
vulnerability in electron (CVE-2026-70601). Confidential information can be exposed externally. Exploitable via ``contextBridge``. Mitigation: upgrade to `42.0.0-beta.5` or later.
|
| CVE-2026-54876 |
|
Vulnerability in dos (CVE-2026-54876)
vulnerability in dos (CVE-2026-54876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16102 |
|
Vulnerability in redhat (CVE-2026-16102)
vulnerability in redhat (CVE-2026-16102). Confidential information can be exposed externally.
|
| CVE-2026-15573 |
|
Vulnerability in redhat (CVE-2026-15573)
vulnerability in redhat (CVE-2026-15573). Confidential information can be exposed externally.
|
| CVE-2026-17613 |
|
Vulnerability in CVE-2026-17613 (CVE-2026-17613)
vulnerability in CVE-2026-17613 (CVE-2026-17613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12410 |
|
Vulnerability in CVE-2026-12410 (CVE-2026-12410)
vulnerability in CVE-2026-12410 (CVE-2026-12410). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7529 |
|
Vulnerability in wordpress (CVE-2026-7529)
vulnerability in wordpress (CVE-2026-7529). Data can be tampered with by attackers.
|
| CVE-2026-67623 |
|
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
|
| CVE-2026-17506 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16443 |
|
Vulnerability in redhat (CVE-2026-16443)
vulnerability in redhat (CVE-2026-16443). Confidential information can be exposed externally.
|
| CVE-2026-15979 |
|
Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
|
| CVE-2025-70962 |
|
Vulnerability in CVE-2025-70962 (CVE-2025-70962)
vulnerability in CVE-2025-70962 (CVE-2025-70962). Confidential information can be exposed externally.
|
| CVE-2026-71294 |
|
Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
vulnerability in CVE-2026-71294 (CVE-2026-71294). Confidential information can be exposed externally. Exploitable via ``allowed_classes``.
|
| CVE-2026-71292 |
|
SQL Injection in CVE-2026-71292 (CVE-2026-71292)
SQL injection in CVE-2026-71292 (CVE-2026-71292). Successful exploitation can lead to full system takeover. Exploitable via ``dir``.
|
| CVE-2026-71291 |
|
Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
|
| CVE-2026-71288 |
|
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
|
| CVE-2026-71287 |
|
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
|