Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42311 |
|
Vulnerability in CVE-2026-42311 (CVE-2026-42311)
vulnerability in CVE-2026-42311 (CVE-2026-42311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42310 |
|
Vulnerability in CVE-2026-42310 (CVE-2026-42310)
vulnerability in CVE-2026-42310 (CVE-2026-42310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42309 |
|
Vulnerability in CVE-2026-42309 (CVE-2026-42309)
vulnerability in CVE-2026-42309 (CVE-2026-42309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42308 |
|
Vulnerability in CVE-2026-42308 (CVE-2026-42308)
vulnerability in CVE-2026-42308 (CVE-2026-42308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42301 |
|
Vulnerability in CVE-2026-42301 (CVE-2026-42301)
vulnerability in CVE-2026-42301 (CVE-2026-42301). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42352 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42352 (CVE-2026-42352)
SSRF in CVE-2026-42352 (CVE-2026-42352). Confidential information can be exposed externally.
|
| CVE-2026-42351 |
|
Path Traversal in CVE-2026-42351 (CVE-2026-42351)
path traversal in CVE-2026-42351 (CVE-2026-42351). Confidential information can be exposed externally.
|
| CVE-2026-38360 |
|
Path Traversal in path-traversal (CVE-2026-38360)
path traversal in path-traversal (CVE-2026-38360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41588 |
|
Vulnerability in timing-attack (CVE-2026-41588)
vulnerability in timing-attack (CVE-2026-41588). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44336 |
|
Vulnerability in praison (CVE-2026-44336)
vulnerability in praison (CVE-2026-44336). Successful exploitation can lead to full system takeover. Exploitable via ``praisonai.rules.create``.
|
| CVE-2026-44335 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44335)
SSRF in ssrf (CVE-2026-44335). Successful exploitation can lead to full system takeover. Exploitable via ``requests``. Mitigation: upgrade to `>= 1.6.32` or later.
|
| CVE-2026-41497 |
|
Command Injection in praison (CVE-2026-41497)
command injection in praison (CVE-2026-41497). Successful exploitation can lead to full system takeover. Exploitable via ``bash``. Mitigation: upgrade to `>= 4.6.9` or later.
|
| CVE-2026-42284 |
|
Vulnerability in GitPython (CVE-2026-42284)
vulnerability in GitPython (CVE-2026-42284). Successful exploitation can lead to full system takeover. Exploitable via ``multi_options``. Mitigation: upgrade to `3.1.47` or later.
|
| CVE-2026-42215 |
|
OS Command Injection in GitPython (CVE-2026-42215)
OS command injection in GitPython (CVE-2026-42215). Successful exploitation can lead to full system takeover. Exploitable via ``upload_pack``. Mitigation: upgrade to `3.1.47` or later.
|
| SUSE-SU-2026:1744-1 |
|
Vulnerability in dos (SUSE-SU-2026:1744-1)
vulnerability in dos (SUSE-SU-2026:1744-1). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:1740-1 |
|
Vulnerability in django (SUSE-SU-2026:1740-1)
vulnerability in django (SUSE-SU-2026:1740-1). Risk of unauthorized operations or information disclosure. Exploitable via ``ASGIRequest``.
|
| CVE-2025-32414 |
|
Vulnerability in java (CVE-2025-32414)
vulnerability in java (CVE-2025-32414). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.0, 8.0.461` or later.
|
| CVE-2026-32936 |
|
Vulnerability in github.com/coredns/coredns (CVE-2026-32936)
vulnerability in github.com/coredns/coredns (CVE-2026-32936). Risk of unauthorized operations or information disclosure. Exploitable via ``dns``. Mitigation: upgrade to `1.14.3` or later.
|
| CVE-2026-44015 |
|
SSRF (Server-Side Request Forgery) in github.com/0xJacky/Nginx-UI (CVE-2026-44015)
SSRF in github.com/0xJacky/Nginx-UI (CVE-2026-44015). Confidential information can be exposed externally. Exploitable via `GET /api/settings`.
|