Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-55520 |
|
Vulnerability in Protego (CVE-2026-55520)
vulnerability in Protego (CVE-2026-55520). Risk of unauthorized operations or information disclosure. Exploitable via ``robots.txt``. Mitigation: upgrade to `0.6.2` or later.
|
| CVE-2026-55485 |
|
Information Disclosure in piccolo-admin (CVE-2026-55485)
vulnerability in piccolo-admin (CVE-2026-55485). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/tables/piccolo_user/2/`. Mitigation: upgrade to `1.14.0` or later.
|
| CVE-2026-10036 |
|
Unsafe Deserialization in CVE-2026-10036 (CVE-2026-10036)
vulnerability in CVE-2026-10036 (CVE-2026-10036). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81724 |
|
Vulnerability in dos (CVE-2026-81724)
vulnerability in dos (CVE-2026-81724). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81096 |
|
Code Injection in CVE-2026-81096 (CVE-2026-81096)
code injection in CVE-2026-81096 (CVE-2026-81096). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81662 |
|
Vulnerability in CVE-2026-81662 (CVE-2026-81662)
vulnerability in CVE-2026-81662 (CVE-2026-81662). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66003 |
|
Authorization Flaw in CVE-2026-66003 (CVE-2026-66003)
vulnerability in CVE-2026-66003 (CVE-2026-66003). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58474 |
|
Code Injection in CVE-2026-58474 (CVE-2026-58474)
code injection in CVE-2026-58474 (CVE-2026-58474). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54569 |
|
Vulnerability in senaite.core (CVE-2026-54569)
vulnerability in senaite.core (CVE-2026-54569). Successful exploitation can lead to full system takeover. Exploitable via `GET /senaite/bika_setup/`.
|
| CVE-2026-75062 |
|
Vulnerability in CVE-2026-75062 (CVE-2026-75062)
vulnerability in CVE-2026-75062 (CVE-2026-75062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54553 |
|
Information Disclosure in starlette-admin (CVE-2026-54553)
vulnerability in starlette-admin (CVE-2026-54553). Risk of unauthorized operations or information disclosure. Exploitable via ``metadata``. Mitigation: upgrade to `0.16.1` or later.
|
| CVE-2026-80205 |
|
Vulnerability in dos (CVE-2026-80205)
vulnerability in dos (CVE-2026-80205). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57170 |
|
Code Injection in CVE-2026-57170 (CVE-2026-57170)
code injection in CVE-2026-57170 (CVE-2026-57170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57171 |
|
Path Traversal in CVE-2026-57171 (CVE-2026-57171)
path traversal in CVE-2026-57171 (CVE-2026-57171). Data can be tampered with by attackers.
|
| CVE-2026-54757 |
|
Code Injection in compliance-trestle (CVE-2026-54757)
code injection in compliance-trestle (CVE-2026-54757). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxedEnvironment``. Mitigation: upgrade to `4.1.0` or later.
|
| CVE-2026-80104 |
|
Path Traversal in CVE-2026-80104 (CVE-2026-80104)
path traversal in CVE-2026-80104 (CVE-2026-80104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77357 |
|
Vulnerability in CVE-2026-77357 (CVE-2026-77357)
vulnerability in CVE-2026-77357 (CVE-2026-77357). Risk of unauthorized operations or information disclosure. Exploitable via `GET /hot-reload`.
|
| CVE-2026-68514 |
|
Vulnerability in CVE-2026-68514 (CVE-2026-68514)
vulnerability in CVE-2026-68514 (CVE-2026-68514). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78379 |
|
Vulnerability in Amazon aws (CVE-2026-78379)
vulnerability in Amazon aws (CVE-2026-78379). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55099 |
|
Vulnerability in icalendar (CVE-2026-55099)
vulnerability in icalendar (CVE-2026-55099). Risk of unauthorized operations or information disclosure. Exploitable via ``Component.__eq__``. Mitigation: upgrade to `7.1.3` or later.
|
| CVE-2026-45019 |
|
SSRF (Server-Side Request Forgery) in chainlit (CVE-2026-45019)
SSRF in chainlit (CVE-2026-45019). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`. Mitigation: upgrade to `2.12.0` or later.
|
| CVE-2026-45018 |
|
OS Command Injection in chainlit (CVE-2026-45018)
OS command injection in chainlit (CVE-2026-45018). Successful exploitation can lead to full system takeover. Exploitable via `POST /mcp`. Mitigation: upgrade to `2.12.0` or later.
|
| CVE-2026-62986 |
|
Information Disclosure in CVE-2026-62986 (CVE-2026-62986)
vulnerability in CVE-2026-62986 (CVE-2026-62986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55620 |
|
Vulnerability in eml_parser (CVE-2026-55620)
vulnerability in eml_parser (CVE-2026-55620). Risk of unauthorized operations or information disclosure. Exploitable via ``eml_parser``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-55619 |
|
Vulnerability in eml_parser (CVE-2026-55619)
vulnerability in eml_parser (CVE-2026-55619). Risk of unauthorized operations or information disclosure. Exploitable via ``eml_parser``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-55618 |
|
Vulnerability in eml_parser (CVE-2026-55618)
vulnerability in eml_parser (CVE-2026-55618). Data can be tampered with by attackers. Exploitable via ``eml_parser``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-55585 |
|
Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-15310 |
|
Vulnerability in CVE-2026-15310 (CVE-2026-15310)
vulnerability in CVE-2026-15310 (CVE-2026-15310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55546 |
|
Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
|
| CVE-2026-78683 |
|
Unsafe Deserialization in deserialization (CVE-2026-78683)
vulnerability in deserialization (CVE-2026-78683). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-78680 |
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
| CVE-2026-78677 |
|
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
|
| CVE-2026-78681 |
|
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
|
| CVE-2026-78675 |
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
| CVE-2026-76098 |
|
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee...
|
| CVE-2026-75509 |
|
Vulnerability in CVE-2026-75509 (CVE-2026-75509)
vulnerability in CVE-2026-75509 (CVE-2026-75509). Data can be tampered with by attackers.
|
| CVE-2026-76841 |
|
Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76843 |
|
Unsafe Deserialization in CVE-2026-76843 (CVE-2026-76843)
vulnerability in CVE-2026-76843 (CVE-2026-76843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9769 |
|
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
|
| CVE-2026-78136 |
|
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
|
| CVE-2026-66393 |
|
Vulnerability in dos (CVE-2026-66393)
vulnerability in dos (CVE-2026-66393). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68508 |
|
Code Injection in hydra-core (CVE-2026-68508)
code injection in hydra-core (CVE-2026-68508). Successful exploitation can lead to full system takeover. Exploitable via ``_target_``. Mitigation: upgrade to `1.3.4` or later.
|
| CVE-2026-61539 |
|
Vulnerability in xinference (CVE-2026-61539)
vulnerability in xinference (CVE-2026-61539). Successful exploitation can lead to full system takeover. Exploitable via ``tools``. Mitigation: upgrade to `2.7.0` or later.
|
| CVE-2026-62675 |
|
Code Injection in CVE-2026-62675 (CVE-2026-62675)
code injection in CVE-2026-62675 (CVE-2026-62675). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/sessions`.
|
| CVE-2026-18286 |
|
Code Injection in CVE-2026-18286 (CVE-2026-18286)
code injection in CVE-2026-18286 (CVE-2026-18286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18287 |
|
Code Injection in CVE-2026-18287 (CVE-2026-18287)
code injection in CVE-2026-18287 (CVE-2026-18287). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76832 |
|
Path Traversal in path-traversal (CVE-2026-76832)
path traversal in path-traversal (CVE-2026-76832). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44901 |
|
Unsafe Deserialization in CVE-2026-44901 (CVE-2026-44901)
vulnerability in CVE-2026-44901 (CVE-2026-44901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45272 |
|
Code Injection in CVE-2026-45272 (CVE-2026-45272)
code injection in CVE-2026-45272 (CVE-2026-45272). Risk of unauthorized operations or information disclosure.
|