Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2025-71058 Code Injection in CVE-2025-71058 (CVE-2025-71058)
code injection in CVE-2025-71058 (CVE-2025-71058). Data can be tampered with by attackers.
CVE-2026-4631 OS Command Injection in CVE-2026-4631 (CVE-2026-4631)
OS command injection in CVE-2026-4631 (CVE-2026-4631). Successful exploitation can lead to full system takeover.
CVE-2026-23696 SQL Injection in sqli (CVE-2026-23696)
SQL injection in sqli (CVE-2026-23696). Successful exploitation can lead to full system takeover.
CVE-2026-33815 Out-of-Bounds Write in github.com/jackc/pgx/v5 (CVE-2026-33815)
out-of-bounds write in github.com/jackc/pgx/v5 (CVE-2026-33815). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.9.0` or later.
CVE-2026-20889 Vulnerability in libraw (CVE-2026-20889)
vulnerability in libraw (CVE-2026-20889). Successful exploitation can lead to full system takeover.
CVE-2026-21413 Vulnerability in libraw (CVE-2026-21413)
vulnerability in libraw (CVE-2026-21413). Successful exploitation can lead to full system takeover.
CVE-2026-20911 Vulnerability in libraw (CVE-2026-20911)
vulnerability in libraw (CVE-2026-20911). Successful exploitation can lead to full system takeover.
CVE-2026-5735 Out-of-Bounds Write in mozilla (CVE-2026-5735)
out-of-bounds write in mozilla (CVE-2026-5735). Successful exploitation can lead to full system takeover.
CVE-2026-5731 Buffer Overflow in mozilla (CVE-2026-5731)
vulnerability in mozilla (CVE-2026-5731). Successful exploitation can lead to full system takeover.
CVE-2026-5734 Out-of-Bounds Write in mozilla (CVE-2026-5734)
out-of-bounds write in mozilla (CVE-2026-5734). Successful exploitation can lead to full system takeover.
CVE-2026-33816 CVE-2026-33816 in github.com/jackc/pgx
CVE-2026-33816 in github.com/jackc/pgx
CVE-2026-28808 Authorization Flaw in erlang (CVE-2026-28808)
vulnerability in erlang (CVE-2026-28808). Successful exploitation can lead to full system takeover.
CVE-2026-35471 Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
CVE-2026-35393 Path Traversal in github.com/patrickhener/goshs (CVE-2026-35393)
path traversal in github.com/patrickhener/goshs (CVE-2026-35393). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
CVE-2026-35392 Path Traversal in github.com/patrickhener/goshs (CVE-2026-35392)
path traversal in github.com/patrickhener/goshs (CVE-2026-35392). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
CVE-2026-35459 SSRF (Server-Side Request Forgery) in pyload-ng (CVE-2026-35459)
SSRF in pyload-ng (CVE-2026-35459). Confidential information can be exposed externally. Exploitable via ``CURLOPT_REDIR_PROTOCOLS``.
CVE-2026-35184 SQL Injection in sqli (CVE-2026-35184)
SQL injection in sqli (CVE-2026-35184). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.0` or later.
CVE-2026-35178 Code Injection in forceworkbench (CVE-2026-35178)
code injection in forceworkbench (CVE-2026-35178). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `65.0.0` or later.
CVE-2025-54328 Vulnerability in samsung (CVE-2025-54328)
vulnerability in samsung (CVE-2025-54328). Successful exploitation can lead to full system takeover.
CVE-2025-58349 Vulnerability in samsung (CVE-2025-58349)
vulnerability in samsung (CVE-2025-58349). Confidential information can be exposed externally.
CVE-2026-35174 Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
CVE-2026-35030 Authentication Bypass in litellm (CVE-2026-35030)
authentication bypass in litellm (CVE-2026-35030). Confidential information can be exposed externally. Mitigation: upgrade to `1.83.0` or later.
CVE-2026-34977 OS Command Injection in c (CVE-2026-34977)
OS command injection in c (CVE-2026-34977). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.1` or later.
CVE-2026-34444 Vulnerability in lupa (CVE-2026-34444)
vulnerability in lupa (CVE-2026-34444). Successful exploitation can lead to full system takeover. Exploitable via ``attribute_filter``.
CVE-2026-31405 Out-of-Bounds Read in linux (CVE-2026-31405)
vulnerability in linux (CVE-2026-31405). Successful exploitation can lead to full system takeover.
CVE-2026-35616 KEV [KEV] Vulnerability in Fortinet forticlient-ems (CVE-2026-35616)
vulnerability in Fortinet forticlient-ems (CVE-2026-35616). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2019-25687 Path Traversal in wisdom (CVE-2019-25687)
path traversal in wisdom (CVE-2019-25687). Successful exploitation can lead to full system takeover.
CVE-2018-25254 Out-of-Bounds Write in nico-ftp-project (CVE-2018-25254)
out-of-bounds write in nico-ftp-project (CVE-2018-25254). Successful exploitation can lead to full system takeover.
CVE-2016-20052 Unrestricted File Upload in snewscms (CVE-2016-20052)
vulnerability in snewscms (CVE-2016-20052). Successful exploitation can lead to full system takeover.
CVE-2026-34953 Authorization Flaw in praisonai (CVE-2026-34953)
vulnerability in praisonai (CVE-2026-34953). Confidential information can be exposed externally. Exploitable via ``True``. Mitigation: upgrade to `4.5.97` or later.
CVE-2026-34952 Vulnerability in praisonai (CVE-2026-34952)
vulnerability in praisonai (CVE-2026-34952). Confidential information can be exposed externally. Exploitable via ``GatewayConfig``. Mitigation: upgrade to `4.5.97` or later.
CVE-2026-34938 Vulnerability in praisonaiagents (CVE-2026-34938)
vulnerability in praisonaiagents (CVE-2026-34938). Successful exploitation can lead to full system takeover. Exploitable via ``str``. Mitigation: upgrade to `1.5.90` or later.
CVE-2026-34935 OS Command Injection in praisonai (CVE-2026-34935)
OS command injection in praisonai (CVE-2026-34935). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.69` or later.
CVE-2026-34934 SQL Injection in praisonai (CVE-2026-34934)
SQL injection in praisonai (CVE-2026-34934). Successful exploitation can lead to full system takeover. Exploitable via ``get_all_user_threads``. Mitigation: upgrade to `4.5.90` or later.
CVE-2026-34612 SQL Injection in sqli (CVE-2026-34612)
SQL injection in sqli (CVE-2026-34612). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/main/flows/search`.
CVE-2021-4477 Vulnerability in CVE-2021-4477 (CVE-2021-4477)
vulnerability in CVE-2021-4477 (CVE-2021-4477). Confidential information can be exposed externally.
CVE-2018-25236 Authentication Bypass in CVE-2018-25236 (CVE-2018-25236)
authentication bypass in CVE-2018-25236 (CVE-2018-25236). Successful exploitation can lead to full system takeover.
CVE-2017-20236 OS Command Injection in prosoft-technology (CVE-2017-20236)
OS command injection in prosoft-technology (CVE-2017-20236). Successful exploitation can lead to full system takeover.
CVE-2017-20235 Authentication Bypass in prosoft-technology (CVE-2017-20235)
authentication bypass in prosoft-technology (CVE-2017-20235). Confidential information can be exposed externally.
CVE-2017-20234 Vulnerability in CVE-2017-20234 (CVE-2017-20234)
vulnerability in CVE-2017-20234 (CVE-2017-20234). Successful exploitation can lead to full system takeover.
CVE-2026-27634 SQL Injection in piwigo (CVE-2026-27634)
SQL injection in piwigo (CVE-2026-27634). Successful exploitation can lead to full system takeover.
CVE-2018-25237 Vulnerability in dos (CVE-2018-25237)
vulnerability in dos (CVE-2018-25237). Successful exploitation can lead to full system takeover.
CVE-2026-28766 Vulnerability in mygardyn (CVE-2026-28766)
vulnerability in mygardyn (CVE-2026-28766). Confidential information can be exposed externally.
CVE-2026-25197 Vulnerability in mygardyn (CVE-2026-25197)
vulnerability in mygardyn (CVE-2026-25197). Confidential information can be exposed externally.
CVE-2017-20237 Authentication Bypass in CVE-2017-20237 (CVE-2017-20237)
authentication bypass in CVE-2017-20237 (CVE-2017-20237). Successful exploitation can lead to full system takeover.
CVE-2026-28798 SSRF (Server-Side Request Forgery) in zimaspace (CVE-2026-28798)
SSRF in zimaspace (CVE-2026-28798). Successful exploitation can lead to full system takeover.
CVE-2026-31402 Out-of-Bounds Write in linux (CVE-2026-31402)
out-of-bounds write in linux (CVE-2026-31402). Successful exploitation can lead to full system takeover.
CVE-2026-32186 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32186)
SSRF in ssrf (CVE-2026-32186). Successful exploitation can lead to full system takeover.
CVE-2026-0545 Vulnerability in mlflow (CVE-2026-0545)
vulnerability in mlflow (CVE-2026-0545). Confidential information can be exposed externally.
CVE-2026-28373 Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →