Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59283 |
|
Vulnerability in spring (CVE-2026-59283)
vulnerability in spring (CVE-2026-59283). Data can be tampered with by attackers.
|
| CVE-2026-48105 |
|
Path Traversal in CVE-2026-48105 (CVE-2026-48105)
path traversal in CVE-2026-48105 (CVE-2026-48105). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.06.1` or later.
|
| CVE-2026-76023 |
|
Vulnerability in google (CVE-2026-76023)
vulnerability in google (CVE-2026-76023). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71470 |
|
Vulnerability in privilege-escalation (CVE-2026-71470)
vulnerability in privilege-escalation (CVE-2026-71470). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47698 |
|
Vulnerability in vm2 (CVE-2026-47698)
vulnerability in vm2 (CVE-2026-47698). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.6` or later.
|
| CVE-2026-73226 |
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions t...
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handle...
|
| CVE-2026-53753 |
|
Code Injection in crawl4ai (CVE-2026-53753)
code injection in crawl4ai (CVE-2026-53753). Successful exploitation can lead to full system takeover. Exploitable via `POST /crawl`. Mitigation: upgrade to `0.8.7` or later.
|
| CVE-2026-48775 |
|
Unsafe Deserialization in langgraph-checkpoint (CVE-2026-48775)
vulnerability in langgraph-checkpoint (CVE-2026-48775). Successful exploitation can lead to full system takeover. Exploitable via ``JsonPlusSerializer``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-47210 |
|
Vulnerability in vm2 (CVE-2026-47210)
vulnerability in vm2 (CVE-2026-47210). Successful exploitation can lead to full system takeover. Exploitable via ``vm2``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47137 |
|
Vulnerability in vm2 (CVE-2026-47137)
vulnerability in vm2 (CVE-2026-47137). Successful exploitation can lead to full system takeover. Exploitable via ``nodevm.js``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47208 |
|
Vulnerability in vm2 (CVE-2026-47208)
vulnerability in vm2 (CVE-2026-47208). Successful exploitation can lead to full system takeover. Exploitable via ``localPromise``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47131 |
|
Vulnerability in vm2 (CVE-2026-47131)
vulnerability in vm2 (CVE-2026-47131). Successful exploitation can lead to full system takeover. Exploitable via ``ERR_INVALID_ARG_TYPE``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-48700 |
|
Vulnerability in CVE-2026-48700 (CVE-2026-48700)
vulnerability in CVE-2026-48700 (CVE-2026-48700). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44336 |
|
Vulnerability in praison (CVE-2026-44336)
vulnerability in praison (CVE-2026-44336). Successful exploitation can lead to full system takeover. Exploitable via ``praisonai.rules.create``.
|
| CVE-2026-34156 |
|
Vulnerability in nocobase (CVE-2026-34156)
vulnerability in nocobase (CVE-2026-34156). Successful exploitation can lead to full system takeover.
|
| CVE-2025-68613 KEV |
|
[KEV] Vulnerability in n8n (CVE-2025-68613)
vulnerability in n8n (CVE-2025-68613). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-9852 |
|
Vulnerability in c (CVE-2014-9852)
vulnerability in c (CVE-2014-9852). Successful exploitation can lead to full system takeover.
|