Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48781 |
|
Vulnerability in CVE-2026-48781 (CVE-2026-48781)
vulnerability in CVE-2026-48781 (CVE-2026-48781). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48776 |
|
Path Traversal in langgraph-sdk (CVE-2026-48776)
path traversal in langgraph-sdk (CVE-2026-48776). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.15` or later.
|
| CVE-2026-26231 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-26231)
vulnerability in code.gitea.io/gitea (CVE-2026-26231). Data can be tampered with by attackers. Exploitable via ``Read``. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-28699 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-28699)
vulnerability in code.gitea.io/gitea (CVE-2026-28699). Confidential information can be exposed externally. Exploitable via `PATCH /api/v1/user/settings`. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-28744 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-28744)
vulnerability in code.gitea.io/gitea (CVE-2026-28744). Confidential information can be exposed externally. Exploitable via ``ctx.IsBasicAuth``. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-54307 |
|
Authorization Flaw in n8n (CVE-2026-54307)
vulnerability in n8n (CVE-2026-54307). Confidential information can be exposed externally. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54321 |
|
Vulnerability in github.com/daytonaio/daytona (CVE-2026-54321)
vulnerability in github.com/daytonaio/daytona (CVE-2026-54321). Confidential information can be exposed externally. Mitigation: upgrade to `0.184.0` or later.
|
| CVE-2026-53860 |
|
Authorization Flaw in openclaw (CVE-2026-53860)
vulnerability in openclaw (CVE-2026-53860). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.7` or later.
|
| CVE-2026-53853 |
|
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
|
| CVE-2026-53854 |
|
Authorization Flaw in openclaw (CVE-2026-53854)
vulnerability in openclaw (CVE-2026-53854). Data can be tampered with by attackers. Mitigation: upgrade to `2026.4.25` or later.
|
| CVE-2026-53855 |
|
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
|
| CVE-2026-49983 |
|
Authorization Flaw in deno (CVE-2026-49983)
vulnerability in deno (CVE-2026-49983). Risk of unauthorized operations or information disclosure. Exploitable via ``env``. Mitigation: upgrade to `2.8.1` or later.
|
| CVE-2026-5149 |
|
Authorization Flaw in wordpress (CVE-2026-5149)
vulnerability in wordpress (CVE-2026-5149). Confidential information can be exposed externally.
|
| CVE-2026-54281 |
|
Authorization Flaw in @nestjs/platform-fastify (CVE-2026-54281)
vulnerability in @nestjs/platform-fastify (CVE-2026-54281). Risk of unauthorized operations or information disclosure. Exploitable via `GET /resource`. Mitigation: upgrade to `11.1.24` or later.
|
| CVE-2026-47777 |
|
Vulnerability in mastodon (CVE-2026-47777)
vulnerability in mastodon (CVE-2026-47777). Data can be tampered with by attackers. Mitigation: upgrade to `4.6.0` or later.
|
| CVE-2026-48489 |
|
Authorization Flaw in symfony/security-http (CVE-2026-48489)
vulnerability in symfony/security-http (CVE-2026-48489). Confidential information can be exposed externally. Exploitable via ``DefaultAuthenticationFailureHandler``. Mitigation: upgrade to `8.0.13` or later.
|
| CVE-2016-20075 |
|
Authorization Flaw in wordpress (CVE-2016-20075)
vulnerability in wordpress (CVE-2016-20075). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34023 |
|
Authorization Flaw in CVE-2026-34023 (CVE-2026-34023)
vulnerability in CVE-2026-34023 (CVE-2026-34023). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2470 |
|
Authorization Flaw in wordpress (CVE-2026-2470)
vulnerability in wordpress (CVE-2026-2470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54398 |
|
Authorization Flaw in CVE-2026-54398 (CVE-2026-54398)
vulnerability in CVE-2026-54398 (CVE-2026-54398). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53834 |
|
Authorization Flaw in openclaw (CVE-2026-53834)
vulnerability in openclaw (CVE-2026-53834). Data can be tampered with by attackers. Mitigation: upgrade to `2026.4.27` or later.
|
| CVE-2026-53835 |
|
Vulnerability in openclaw (CVE-2026-53835)
vulnerability in openclaw (CVE-2026-53835). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.6` or later.
|
| CVE-2026-53828 |
|
Authorization Flaw in openclaw (CVE-2026-53828)
vulnerability in openclaw (CVE-2026-53828). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.6` or later.
|
| CVE-2026-53521 |
|
Authorization Flaw in github.com/nezhahq/nezha (CVE-2026-53521)
vulnerability in github.com/nezhahq/nezha (CVE-2026-53521). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /server/{id}`. Mitigation: upgrade to `2.1.0` or later.
|
| CVE-2026-54091 |
|
Authorization Flaw in github.com/filebrowser/filebrowser/v2 (CVE-2026-54091)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54091). Confidential information can be exposed externally. Mitigation: upgrade to `2.63.6` or later.
|
| CVE-2026-54362 |
|
Authorization Flaw in CVE-2026-54362 (CVE-2026-54362)
vulnerability in CVE-2026-54362 (CVE-2026-54362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54397 |
|
Authorization Flaw in CVE-2026-54397 (CVE-2026-54397)
vulnerability in CVE-2026-54397 (CVE-2026-54397). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54096 |
|
Vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54096)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54096). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.63.7` or later.
|
| CVE-2026-54357 |
|
Vulnerability in CVE-2026-54357 (CVE-2026-54357)
vulnerability in CVE-2026-54357 (CVE-2026-54357). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54358 |
|
Authorization Flaw in privilege-escalation (CVE-2026-54358)
vulnerability in privilege-escalation (CVE-2026-54358). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42604 |
|
Authorization Flaw in CVE-2026-42604 (CVE-2026-42604)
vulnerability in CVE-2026-42604 (CVE-2026-42604). Risk of unauthorized operations or information disclosure. Exploitable via `POST /openid/config`.
|
| CVE-2026-50008 |
|
Authorization Flaw in parse-server (CVE-2026-50008)
vulnerability in parse-server (CVE-2026-50008). Risk of unauthorized operations or information disclosure. Exploitable via ``routeAllowList``. Mitigation: upgrade to `9.9.1-alpha.3` or later.
|
| CVE-2026-47236 |
|
Authorization Flaw in CVE-2026-47236 (CVE-2026-47236)
vulnerability in CVE-2026-47236 (CVE-2026-47236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7387 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-7387)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-7387). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-6739 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-6739)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-6739). Confidential information can be exposed externally. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-44173 |
|
Authorization Flaw in mariadb (CVE-2026-44173)
vulnerability in mariadb (CVE-2026-44173). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44169 |
|
Authorization Flaw in mariadb (CVE-2026-44169)
vulnerability in mariadb (CVE-2026-44169). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.4.11, 11.8.7, 12.3.2` or later.
|
| CVE-2026-45831 |
|
Authorization Flaw in chromadb (CVE-2026-45831)
vulnerability in chromadb (CVE-2026-45831). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53721 |
|
Vulnerability in nuxt (CVE-2026-53721)
vulnerability in nuxt (CVE-2026-53721). Confidential information can be exposed externally. Exploitable via ``routeRules``. Mitigation: upgrade to `3.21.7` or later.
|
| CVE-2026-48113 |
|
Authorization Flaw in github.com/jpillora/chisel (CVE-2026-48113)
vulnerability in github.com/jpillora/chisel (CVE-2026-48113). Risk of unauthorized operations or information disclosure. Exploitable via ``tunnel.Config``. Mitigation: upgrade to `1.11.5` or later.
|
| CVE-2026-47195 |
|
Authorization Flaw in CVE-2026-47195 (CVE-2026-47195)
vulnerability in CVE-2026-47195 (CVE-2026-47195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47238 |
|
Vulnerability in CVE-2026-47238 (CVE-2026-47238)
vulnerability in CVE-2026-47238 (CVE-2026-47238). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53808 |
|
Vulnerability in openclaw (CVE-2026-53808)
vulnerability in openclaw (CVE-2026-53808). Data can be tampered with by attackers. Mitigation: upgrade to `2026.5.6` or later.
|
| CVE-2026-53807 |
|
Authorization Flaw in openclaw (CVE-2026-53807)
vulnerability in openclaw (CVE-2026-53807). Successful exploitation can lead to full system takeover. Exploitable via ``commands.allowFrom``. Mitigation: upgrade to `2026.5.6` or later.
|
| CVE-2026-53809 |
|
Authorization Flaw in openclaw (CVE-2026-53809)
vulnerability in openclaw (CVE-2026-53809). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.4.25` or later.
|
| CVE-2026-48089 |
|
Vulnerability in github.com/l3montree-dev/devguard (CVE-2026-48089)
vulnerability in github.com/l3montree-dev/devguard (CVE-2026-48089). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.2` or later.
|
| CVE-2026-6269 |
|
Authorization Flaw in gitlab (CVE-2026-6269)
vulnerability in gitlab (CVE-2026-6269). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-6277 |
|
Authorization Flaw in gitlab (CVE-2026-6277)
vulnerability in gitlab (CVE-2026-6277). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-3553 |
|
Authorization Flaw in gitlab (CVE-2026-3553)
vulnerability in gitlab (CVE-2026-3553). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-49219 |
|
Information Disclosure in Magick.NET-Q16-AnyCPU (CVE-2026-49219)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-49219). Confidential information can be exposed externally. Mitigation: upgrade to `14.14.0` or later.
|