Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75062 |
|
Vulnerability in CVE-2026-75062 (CVE-2026-75062)
vulnerability in CVE-2026-75062 (CVE-2026-75062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55581 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55581)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55581). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-77915 |
|
Vulnerability in CVE-2026-77915 (CVE-2026-77915)
vulnerability in CVE-2026-77915 (CVE-2026-77915). Successful exploitation can lead to full system takeover. Exploitable via `POST /register`.
|
| CVE-2026-62388 |
|
Vulnerability in path-traversal (CVE-2026-62388)
vulnerability in path-traversal (CVE-2026-62388). Confidential information can be exposed externally.
|
| CVE-2026-75926 |
|
Vulnerability in CVE-2026-75926 (CVE-2026-75926)
vulnerability in CVE-2026-75926 (CVE-2026-75926). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59321 |
|
Vulnerability in CVE-2025-59321 (CVE-2025-59321)
vulnerability in CVE-2025-59321 (CVE-2025-59321). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33921 |
|
Vulnerability in CVE-2026-33921 (CVE-2026-33921)
vulnerability in CVE-2026-33921 (CVE-2026-33921). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63563 |
|
Vulnerability in CVE-2026-63563 (CVE-2026-63563)
vulnerability in CVE-2026-63563 (CVE-2026-63563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62416 |
|
Vulnerability in dos (CVE-2026-62416)
vulnerability in dos (CVE-2026-62416). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16504 |
|
Vulnerability in CVE-2026-16504 (CVE-2026-16504)
vulnerability in CVE-2026-16504 (CVE-2026-16504). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16503 |
|
Vulnerability in CVE-2026-16503 (CVE-2026-16503)
vulnerability in CVE-2026-16503 (CVE-2026-16503). Confidential information can be exposed externally.
|
| CVE-2026-67208 |
|
Vulnerability in CVE-2026-67208 (CVE-2026-67208)
vulnerability in CVE-2026-67208 (CVE-2026-67208). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66066 |
|
Vulnerability in activestorage (CVE-2026-66066)
vulnerability in activestorage (CVE-2026-66066). Risk of unauthorized operations or information disclosure. Exploitable via ``secret_key_base``. Mitigation: upgrade to `8.1.3.1` or later.
|
| CVE-2026-65881 |
|
Information Disclosure in CVE-2026-65881 (CVE-2026-65881)
vulnerability in CVE-2026-65881 (CVE-2026-65881). Confidential information can be exposed externally.
|
| CVE-2026-9680 |
|
Vulnerability in CVE-2026-9680 (CVE-2026-9680)
vulnerability in CVE-2026-9680 (CVE-2026-9680). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55708 |
|
Vulnerability in nlnetlabs (CVE-2026-55708)
vulnerability in nlnetlabs (CVE-2026-55708). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62415 |
|
Vulnerability in CVE-2026-62415 (CVE-2026-62415)
vulnerability in CVE-2026-62415 (CVE-2026-62415). Confidential information can be exposed externally.
|
| CVE-2026-60024 |
|
Vulnerability in CVE-2026-60024 (CVE-2026-60024)
vulnerability in CVE-2026-60024 (CVE-2026-60024). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10671 |
|
Vulnerability in c (CVE-2026-10671)
vulnerability in c (CVE-2026-10671). Data can be tampered with by attackers.
|
| CVE-2026-62185 |
|
Vulnerability in CVE-2026-62185 (CVE-2026-62185)
vulnerability in CVE-2026-62185 (CVE-2026-62185). Confidential information can be exposed externally.
|
| CVE-2026-61439 |
|
Vulnerability in CVE-2026-61439 (CVE-2026-61439)
vulnerability in CVE-2026-61439 (CVE-2026-61439). Confidential information can be exposed externally.
|
| CVE-2026-54800 |
|
Vulnerability in CVE-2026-54800 (CVE-2026-54800)
vulnerability in CVE-2026-54800 (CVE-2026-54800). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14474 |
|
Vulnerability in CVE-2026-14474 (CVE-2026-14474)
vulnerability in CVE-2026-14474 (CVE-2026-14474). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56285 |
|
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
|
| CVE-2026-46386 |
|
Unsafe Deserialization in rails (CVE-2026-46386)
vulnerability in rails (CVE-2026-46386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55454 |
|
Vulnerability in ssrf (CVE-2026-55454)
vulnerability in ssrf (CVE-2026-55454). Successful exploitation can lead to full system takeover. Exploitable via `POST /load`. Mitigation: upgrade to `2.1` or later.
|
| CVE-2026-54067 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-54067)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-54067). Successful exploitation can lead to full system takeover. Exploitable via ``insertAdjacentHTML``. Mitigation: upgrade to `0.0.0-20260628153353-2d5d72223df4` or later.
|
| CVE-2026-54066 |
|
Path Traversal in github.com/siyuan-note/siyuan/kernel (CVE-2026-54066)
path traversal in github.com/siyuan-note/siyuan/kernel (CVE-2026-54066). Confidential information can be exposed externally. Exploitable via `GET /assets/`. Mitigation: upgrade to `0.0.0-20260628153353-2d5d72223df4` or later.
|
| CVE-2026-54158 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-54158)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-54158). Successful exploitation can lead to full system takeover. Exploitable via ``genAVValueHTML``. Mitigation: upgrade to `0.0.0-20260628153353-2d5d72223df4` or later.
|
| CVE-2026-48509 |
|
Vulnerability in MessagePack (CVE-2026-48509)
vulnerability in MessagePack (CVE-2026-48509). Data can be tampered with by attackers. Exploitable via ``MessagePackSerializerOptions.Standard``. Mitigation: upgrade to `3.1.7` or later.
|
| CVE-2026-48502 |
|
Vulnerability in MessagePack (CVE-2026-48502)
vulnerability in MessagePack (CVE-2026-48502). Risk of unauthorized operations or information disclosure. Exploitable via ``tokenSize``. Mitigation: upgrade to `3.1.7` or later.
|
| CVE-2026-50519 |
|
Vulnerability in microsoft (CVE-2026-50519)
vulnerability in microsoft (CVE-2026-50519). Confidential information can be exposed externally.
|
| CVE-2026-20265 |
|
Vulnerability in splunk (CVE-2026-20265)
vulnerability in splunk (CVE-2026-20265). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0134 |
|
Vulnerability in cpp (CVE-2026-0134)
vulnerability in cpp (CVE-2026-0134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9262 |
|
Vulnerability in canon (CVE-2026-9262)
vulnerability in canon (CVE-2026-9262). Confidential information can be exposed externally.
|
| CVE-2026-54359 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-54359 (CVE-2026-54359)
vulnerability in CVE-2026-54359 (CVE-2026-54359). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40994 |
|
Vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-40994)
vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-40994). Data can be tampered with by attackers.
|
| CVE-2026-44892 |
|
Vulnerability in io.netty:netty-codec-http3 (CVE-2026-44892)
vulnerability in io.netty:netty-codec-http3 (CVE-2026-44892). Risk of unauthorized operations or information disclosure. Exploitable via ``Http3ConnectionHandler``. Mitigation: upgrade to `4.2.15.Final` or later.
|
| CVE-2026-47668 |
|
Vulnerability in dbgate-serve (CVE-2026-47668)
vulnerability in dbgate-serve (CVE-2026-47668). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/start`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-36616 |
|
Vulnerability in CVE-2026-36616 (CVE-2026-36616)
vulnerability in CVE-2026-36616 (CVE-2026-36616). Confidential information can be exposed externally.
|
| CVE-2026-36612 |
|
Vulnerability in CVE-2026-36612 (CVE-2026-36612)
vulnerability in CVE-2026-36612 (CVE-2026-36612). Confidential information can be exposed externally.
|
| CVE-2026-44825 |
|
Vulnerability in solr (CVE-2026-44825)
vulnerability in solr (CVE-2026-44825). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.0.0` or later.
|
| CVE-2026-47393 |
|
Vulnerability in PraisonAI (CVE-2026-47393)
vulnerability in PraisonAI (CVE-2026-47393). Successful exploitation can lead to full system takeover. Exploitable via ``auth_enabled``. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-9039 |
|
Vulnerability in CVE-2026-9039 (CVE-2026-9039)
vulnerability in CVE-2026-9039 (CVE-2026-9039). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24197 |
|
Vulnerability in dos (CVE-2026-24197)
vulnerability in dos (CVE-2026-24197). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46517 |
|
Code Injection in lmdeploy (CVE-2026-46517)
code injection in lmdeploy (CVE-2026-46517). Successful exploitation can lead to full system takeover. Exploitable via ``get_model_arch``.
|
| CVE-2026-35672 |
|
Vulnerability in thorsten/phpmyfaq (CVE-2026-35672)
vulnerability in thorsten/phpmyfaq (CVE-2026-35672). Data can be tampered with by attackers. Exploitable via `POST /api/v4.0/faq/create`. Mitigation: upgrade to `4.1.3` or later.
|
| CVE-2026-46430 |
|
Vulnerability in github.com/xyproto/algernon (CVE-2026-46430)
vulnerability in github.com/xyproto/algernon (CVE-2026-46430). Risk of unauthorized operations or information disclosure. Exploitable via ``http.Server.Addr``. Mitigation: upgrade to `1.17.7` or later.
|
| CVE-2026-45728 |
|
Vulnerability in github.com/xyproto/algernon (CVE-2026-45728)
vulnerability in github.com/xyproto/algernon (CVE-2026-45728). Confidential information can be exposed externally. Exploitable via ``singleFileMode``. Mitigation: upgrade to `1.17.7` or later.
|
| CVE-2026-33376 |
|
Vulnerability in grafana (CVE-2026-33376)
vulnerability in grafana (CVE-2026-33376). Confidential information can be exposed externally. Mitigation: upgrade to `11.6.14, 12.2.8, 12.3.6, 12.4.3, 13.0.1` or later.
|