Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-30310 |
|
Command Injection in CVE-2026-30310 (CVE-2026-30310)
command injection in CVE-2026-30310 (CVE-2026-30310). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32917 |
|
OS Command Injection in openclaw (CVE-2026-32917)
OS command injection in openclaw (CVE-2026-32917). Successful exploitation can lead to full system takeover. Exploitable via ``openclaw``. Mitigation: upgrade to `2026.3.13` or later.
|
| CVE-2026-32916 |
|
Vulnerability in openclaw (CVE-2026-32916)
vulnerability in openclaw (CVE-2026-32916). Confidential information can be exposed externally.
|
| CVE-2026-34060 |
|
Code Injection in shopify (CVE-2026-34060)
code injection in shopify (CVE-2026-34060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34714 |
|
OS Command Injection in vim (CVE-2026-34714)
OS command injection in vim (CVE-2026-34714). Confidential information can be exposed externally.
|
| CVE-2025-15379 |
|
Command Injection in mlflow (CVE-2025-15379)
command injection in mlflow (CVE-2025-15379). Successful exploitation can lead to full system takeover. Exploitable via ``python_env.yaml``. Mitigation: upgrade to `3.8.1` or later.
|
| CVE-2025-15036 |
|
Vulnerability in mlflow (CVE-2025-15036)
vulnerability in mlflow (CVE-2025-15036). Successful exploitation can lead to full system takeover. Exploitable via ``extract_archive_to_dir``. Mitigation: upgrade to `3.9.0rc0` or later.
|
| CVE-2026-3256 |
|
Vulnerability in ktat (CVE-2026-3256)
vulnerability in ktat (CVE-2026-3256). Successful exploitation can lead to full system takeover.
|
| CVE-2025-9497 |
|
Vulnerability in microchip (CVE-2025-9497)
vulnerability in microchip (CVE-2025-9497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33937 |
|
Code Injection in handlebarsjs (CVE-2026-33937)
code injection in handlebarsjs (CVE-2026-33937). Successful exploitation can lead to full system takeover. Exploitable via ``value``.
|
| CVE-2026-33757 |
|
Vulnerability in openbao (CVE-2026-33757)
vulnerability in openbao (CVE-2026-33757). Confidential information can be exposed externally. Exploitable via ``callback_mode``.
|
| CVE-2026-27876 |
|
Code Injection in grafana (CVE-2026-27876)
code injection in grafana (CVE-2026-27876). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2026-22738 |
|
Vulnerability in org.springframework.ai:spring-ai-vector-store (CVE-2026-22738)
vulnerability in org.springframework.ai:spring-ai-vector-store (CVE-2026-22738). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.1.4` or later.
|
| CVE-2026-33728 |
|
Unsafe Deserialization in com.datadoghq:dd-java-agent (CVE-2026-33728)
vulnerability in com.datadoghq:dd-java-agent (CVE-2026-33728). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.60.3` or later.
|
| CVE-2026-33701 |
|
Unsafe Deserialization in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-33701)
vulnerability in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-33701). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.26.1` or later.
|
| CVE-2026-30458 |
|
Vulnerability in thedaylightstudio (CVE-2026-30458)
vulnerability in thedaylightstudio (CVE-2026-30458). Confidential information can be exposed externally.
|
| CVE-2026-30457 |
|
Code Injection in thedaylightstudio (CVE-2026-30457)
code injection in thedaylightstudio (CVE-2026-30457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26213 |
|
OS Command Injection in thingino (CVE-2026-26213)
OS command injection in thingino (CVE-2026-26213). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4809 |
|
Unrestricted File Upload in laravel (CVE-2026-4809)
vulnerability in laravel (CVE-2026-4809). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26832 |
|
OS Command Injection in zapolnoch (CVE-2026-26832)
OS command injection in zapolnoch (CVE-2026-26832). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33017 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-33017)
vulnerability in langflow (CVE-2026-33017). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/build_public_tmp/{flow_id}/flow`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2026-4729 |
|
Vulnerability in mozilla (CVE-2026-4729)
vulnerability in mozilla (CVE-2026-4729). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4720 |
|
Vulnerability in mozilla (CVE-2026-4720)
vulnerability in mozilla (CVE-2026-4720). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4721 |
|
Vulnerability in mozilla (CVE-2026-4721)
vulnerability in mozilla (CVE-2026-4721). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4700 |
|
Vulnerability in mozilla (CVE-2026-4700)
vulnerability in mozilla (CVE-2026-4700). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4696 |
|
Use-After-Free in mozilla (CVE-2026-4696)
vulnerability in mozilla (CVE-2026-4696). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4688 |
|
Use-After-Free in mozilla (CVE-2026-4688)
vulnerability in mozilla (CVE-2026-4688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4692 |
|
Vulnerability in mozilla (CVE-2026-4692)
vulnerability in mozilla (CVE-2026-4692). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4689 |
|
Vulnerability in mozilla (CVE-2026-4689)
vulnerability in mozilla (CVE-2026-4689). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4691 |
|
Use-After-Free in mozilla (CVE-2026-4691)
vulnerability in mozilla (CVE-2026-4691). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4698 |
|
Vulnerability in mozilla (CVE-2026-4698)
vulnerability in mozilla (CVE-2026-4698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33211 |
|
Path Traversal in path-traversal (CVE-2026-33211)
path traversal in path-traversal (CVE-2026-33211). Confidential information can be exposed externally. Exploitable via ``pathInRepo``.
|
| CVE-2026-33195 |
|
Path Traversal in activestorage (CVE-2026-33195)
path traversal in activestorage (CVE-2026-33195). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.3.1` or later.
|
| CVE-2026-4404 |
|
Vulnerability in linuxfoundation (CVE-2026-4404)
vulnerability in linuxfoundation (CVE-2026-4404). Confidential information can be exposed externally.
|
| CVE-2026-31848 |
|
Vulnerability in nexxtsolutions (CVE-2026-31848)
vulnerability in nexxtsolutions (CVE-2026-31848). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4599 |
|
Vulnerability in jsrsasign (CVE-2026-4599)
vulnerability in jsrsasign (CVE-2026-4599). Confidential information can be exposed externally. Mitigation: upgrade to `11.1.1` or later.
|
| CVE-2026-33228 |
|
Vulnerability in webreflection (CVE-2026-33228)
vulnerability in webreflection (CVE-2026-33228). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29796 |
|
Vulnerability in privilege-escalation (CVE-2026-29796)
vulnerability in privilege-escalation (CVE-2026-29796). Confidential information can be exposed externally.
|
| CVE-2026-33210 |
|
Vulnerability in dos (CVE-2026-33210)
vulnerability in dos (CVE-2026-33210). Confidential information can be exposed externally.
|
| CVE-2026-33186 |
|
Vulnerability in grpc (CVE-2026-33186)
vulnerability in grpc (CVE-2026-33186). Confidential information can be exposed externally. Exploitable via ``info.FullMethod``.
|
| CVE-2025-15608 |
|
Vulnerability in tp-link (CVE-2025-15608)
vulnerability in tp-link (CVE-2025-15608). Successful exploitation can lead to full system takeover.
|
| CVE-2006-10003 |
|
Vulnerability in toddr (CVE-2006-10003)
vulnerability in toddr (CVE-2006-10003). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15031 |
|
Path Traversal in mlflow (CVE-2025-15031)
path traversal in mlflow (CVE-2025-15031). Confidential information can be exposed externally. Exploitable via ``tarfile.extractall``. Mitigation: upgrade to `3.11.1` or later.
|
| CVE-2026-25873 |
|
Unsafe Deserialization in deserialization (CVE-2026-25873)
vulnerability in deserialization (CVE-2026-25873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31938 |
|
Cross-Site Scripting (XSS) in parall (CVE-2026-31938)
cross-site scripting in parall (CVE-2026-31938). Confidential information can be exposed externally. Exploitable via ``options``.
|
| CVE-2026-27459 |
|
Vulnerability in pyopenssl (CVE-2026-27459)
vulnerability in pyopenssl (CVE-2026-27459). Successful exploitation can lead to full system takeover. Exploitable via ``set_cookie_generate_callback``. Mitigation: upgrade to `26.0.0` or later.
|
| CVE-2026-3564 |
|
Vulnerability in CVE-2026-3564 (CVE-2026-3564)
vulnerability in CVE-2026-3564 (CVE-2026-3564). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4312 |
|
Vulnerability in dragonsoft (CVE-2026-4312)
vulnerability in dragonsoft (CVE-2026-4312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4177 |
|
Vulnerability in toddr (CVE-2026-4177)
vulnerability in toddr (CVE-2026-4177). Confidential information can be exposed externally.
|
| CVE-2026-27962 |
|
Vulnerability in authlib (CVE-2026-27962)
vulnerability in authlib (CVE-2026-27962). Confidential information can be exposed externally. Exploitable via ``authlib``. Mitigation: upgrade to `1.6.9` or later.
|