Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-71058 |
|
Code Injection in CVE-2025-71058 (CVE-2025-71058)
code injection in CVE-2025-71058 (CVE-2025-71058). Data can be tampered with by attackers.
|
| CVE-2026-4631 |
|
OS Command Injection in CVE-2026-4631 (CVE-2026-4631)
OS command injection in CVE-2026-4631 (CVE-2026-4631). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23696 |
|
SQL Injection in sqli (CVE-2026-23696)
SQL injection in sqli (CVE-2026-23696). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33815 |
|
Out-of-Bounds Write in github.com/jackc/pgx/v5 (CVE-2026-33815)
out-of-bounds write in github.com/jackc/pgx/v5 (CVE-2026-33815). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.9.0` or later.
|
| CVE-2026-20889 |
|
Vulnerability in libraw (CVE-2026-20889)
vulnerability in libraw (CVE-2026-20889). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21413 |
|
Vulnerability in libraw (CVE-2026-21413)
vulnerability in libraw (CVE-2026-21413). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20911 |
|
Vulnerability in libraw (CVE-2026-20911)
vulnerability in libraw (CVE-2026-20911). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5735 |
|
Out-of-Bounds Write in mozilla (CVE-2026-5735)
out-of-bounds write in mozilla (CVE-2026-5735). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5731 |
|
Buffer Overflow in mozilla (CVE-2026-5731)
vulnerability in mozilla (CVE-2026-5731). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5734 |
|
Out-of-Bounds Write in mozilla (CVE-2026-5734)
out-of-bounds write in mozilla (CVE-2026-5734). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33816 |
|
CVE-2026-33816 in github.com/jackc/pgx
CVE-2026-33816 in github.com/jackc/pgx
|
| CVE-2026-28808 |
|
Authorization Flaw in erlang (CVE-2026-28808)
vulnerability in erlang (CVE-2026-28808). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35471 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35393 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35393)
path traversal in github.com/patrickhener/goshs (CVE-2026-35393). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35392 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35392)
path traversal in github.com/patrickhener/goshs (CVE-2026-35392). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35459 |
|
SSRF (Server-Side Request Forgery) in pyload-ng (CVE-2026-35459)
SSRF in pyload-ng (CVE-2026-35459). Confidential information can be exposed externally. Exploitable via ``CURLOPT_REDIR_PROTOCOLS``.
|
| CVE-2026-35184 |
|
SQL Injection in sqli (CVE-2026-35184)
SQL injection in sqli (CVE-2026-35184). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.0` or later.
|
| CVE-2026-35178 |
|
Code Injection in forceworkbench (CVE-2026-35178)
code injection in forceworkbench (CVE-2026-35178). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `65.0.0` or later.
|
| CVE-2025-54328 |
|
Vulnerability in samsung (CVE-2025-54328)
vulnerability in samsung (CVE-2025-54328). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58349 |
|
Vulnerability in samsung (CVE-2025-58349)
vulnerability in samsung (CVE-2025-58349). Confidential information can be exposed externally.
|
| CVE-2026-35174 |
|
Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
|
| CVE-2026-35030 |
|
Authentication Bypass in litellm (CVE-2026-35030)
authentication bypass in litellm (CVE-2026-35030). Confidential information can be exposed externally. Mitigation: upgrade to `1.83.0` or later.
|
| CVE-2026-34977 |
|
OS Command Injection in c (CVE-2026-34977)
OS command injection in c (CVE-2026-34977). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-34444 |
|
Vulnerability in lupa (CVE-2026-34444)
vulnerability in lupa (CVE-2026-34444). Successful exploitation can lead to full system takeover. Exploitable via ``attribute_filter``.
|
| CVE-2026-31405 |
|
Out-of-Bounds Read in linux (CVE-2026-31405)
vulnerability in linux (CVE-2026-31405). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35616 KEV |
|
[KEV] Vulnerability in Fortinet forticlient-ems (CVE-2026-35616)
vulnerability in Fortinet forticlient-ems (CVE-2026-35616). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-25687 |
|
Path Traversal in wisdom (CVE-2019-25687)
path traversal in wisdom (CVE-2019-25687). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25254 |
|
Out-of-Bounds Write in nico-ftp-project (CVE-2018-25254)
out-of-bounds write in nico-ftp-project (CVE-2018-25254). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20052 |
|
Unrestricted File Upload in snewscms (CVE-2016-20052)
vulnerability in snewscms (CVE-2016-20052). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34953 |
|
Authorization Flaw in praisonai (CVE-2026-34953)
vulnerability in praisonai (CVE-2026-34953). Confidential information can be exposed externally. Exploitable via ``True``. Mitigation: upgrade to `4.5.97` or later.
|
| CVE-2026-34952 |
|
Vulnerability in praisonai (CVE-2026-34952)
vulnerability in praisonai (CVE-2026-34952). Confidential information can be exposed externally. Exploitable via ``GatewayConfig``. Mitigation: upgrade to `4.5.97` or later.
|
| CVE-2026-34938 |
|
Vulnerability in praisonaiagents (CVE-2026-34938)
vulnerability in praisonaiagents (CVE-2026-34938). Successful exploitation can lead to full system takeover. Exploitable via ``str``. Mitigation: upgrade to `1.5.90` or later.
|
| CVE-2026-34935 |
|
OS Command Injection in praisonai (CVE-2026-34935)
OS command injection in praisonai (CVE-2026-34935). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.69` or later.
|
| CVE-2026-34934 |
|
SQL Injection in praisonai (CVE-2026-34934)
SQL injection in praisonai (CVE-2026-34934). Successful exploitation can lead to full system takeover. Exploitable via ``get_all_user_threads``. Mitigation: upgrade to `4.5.90` or later.
|
| CVE-2026-34612 |
|
SQL Injection in sqli (CVE-2026-34612)
SQL injection in sqli (CVE-2026-34612). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/main/flows/search`.
|
| CVE-2021-4477 |
|
Vulnerability in CVE-2021-4477 (CVE-2021-4477)
vulnerability in CVE-2021-4477 (CVE-2021-4477). Confidential information can be exposed externally.
|
| CVE-2018-25236 |
|
Authentication Bypass in CVE-2018-25236 (CVE-2018-25236)
authentication bypass in CVE-2018-25236 (CVE-2018-25236). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20236 |
|
OS Command Injection in prosoft-technology (CVE-2017-20236)
OS command injection in prosoft-technology (CVE-2017-20236). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20235 |
|
Authentication Bypass in prosoft-technology (CVE-2017-20235)
authentication bypass in prosoft-technology (CVE-2017-20235). Confidential information can be exposed externally.
|
| CVE-2017-20234 |
|
Vulnerability in CVE-2017-20234 (CVE-2017-20234)
vulnerability in CVE-2017-20234 (CVE-2017-20234). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27634 |
|
SQL Injection in piwigo (CVE-2026-27634)
SQL injection in piwigo (CVE-2026-27634). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25237 |
|
Vulnerability in dos (CVE-2018-25237)
vulnerability in dos (CVE-2018-25237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28766 |
|
Vulnerability in mygardyn (CVE-2026-28766)
vulnerability in mygardyn (CVE-2026-28766). Confidential information can be exposed externally.
|
| CVE-2026-25197 |
|
Vulnerability in mygardyn (CVE-2026-25197)
vulnerability in mygardyn (CVE-2026-25197). Confidential information can be exposed externally.
|
| CVE-2017-20237 |
|
Authentication Bypass in CVE-2017-20237 (CVE-2017-20237)
authentication bypass in CVE-2017-20237 (CVE-2017-20237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28798 |
|
SSRF (Server-Side Request Forgery) in zimaspace (CVE-2026-28798)
SSRF in zimaspace (CVE-2026-28798). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31402 |
|
Out-of-Bounds Write in linux (CVE-2026-31402)
out-of-bounds write in linux (CVE-2026-31402). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32186 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32186)
SSRF in ssrf (CVE-2026-32186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0545 |
|
Vulnerability in mlflow (CVE-2026-0545)
vulnerability in mlflow (CVE-2026-0545). Confidential information can be exposed externally.
|
| CVE-2026-28373 |
|
Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.
|