Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16488 |
|
Command Injection in CVE-2026-16488 (CVE-2026-16488)
command injection in CVE-2026-16488 (CVE-2026-16488). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64824 |
|
Path Traversal in path-traversal (CVE-2026-64824)
path traversal in path-traversal (CVE-2026-64824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8169 |
|
Vulnerability in CVE-2026-8169 (CVE-2026-8169)
vulnerability in CVE-2026-8169 (CVE-2026-8169). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42566 |
|
Vulnerability in meshtastic (CVE-2026-42566)
vulnerability in meshtastic (CVE-2026-42566). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12484 |
|
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
|
| CVE-2026-9323 |
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
| CVE-2026-9147 |
|
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
|
| CVE-2026-8476 |
|
Unsafe Deserialization in langflow (CVE-2026-8476)
vulnerability in langflow (CVE-2026-8476). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8481 |
|
Code Injection in c (CVE-2026-8481)
code injection in c (CVE-2026-8481). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/validate/code`.
|
| CVE-2026-14499 |
|
OS Command Injection in langflow (CVE-2026-14499)
OS command injection in langflow (CVE-2026-14499). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9135 |
|
Code Injection in langflow (CVE-2026-9135)
code injection in langflow (CVE-2026-9135). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54552 |
|
Vulnerability in sh (CVE-2026-54552)
vulnerability in sh (CVE-2026-54552). Confidential information can be exposed externally. Exploitable via ``_uid``. Mitigation: upgrade to `2.2.4` or later.
|
| CVE-2026-15737 |
|
Vulnerability in Amazon aws (CVE-2026-15737)
vulnerability in Amazon aws (CVE-2026-15737). Confidential information can be exposed externally.
|
| CVE-2026-11386 |
|
Vulnerability in CVE-2026-11386 (CVE-2026-11386)
vulnerability in CVE-2026-11386 (CVE-2026-11386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59862 |
|
Code Injection in Microsoft.OpenAPI.Kiota (CVE-2026-59862)
code injection in Microsoft.OpenAPI.Kiota (CVE-2026-59862). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-15925 |
|
Vulnerability in CVE-2026-15925 (CVE-2026-15925)
vulnerability in CVE-2026-15925 (CVE-2026-15925). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50271 |
|
Vulnerability in ddtrace (CVE-2026-50271)
vulnerability in ddtrace (CVE-2026-50271). Risk of unauthorized operations or information disclosure. Exploitable via ``baggage``. Mitigation: upgrade to `4.8.2` or later.
|
| CVE-2026-63175 |
|
Vulnerability in CVE-2026-63175 (CVE-2026-63175)
vulnerability in CVE-2026-63175 (CVE-2026-63175). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59950 |
|
Vulnerability in mcp (CVE-2026-59950)
vulnerability in mcp (CVE-2026-59950). Confidential information can be exposed externally. Exploitable via ``mcp.server.websocket.websocket_server``. Mitigation: upgrade to `1.28.1` or later.
|
| CVE-2026-52869 |
|
Vulnerability in mcp (CVE-2026-52869)
vulnerability in mcp (CVE-2026-52869). Confidential information can be exposed externally. Exploitable via ``session_id``. Mitigation: upgrade to `1.27.2` or later.
|
| CVE-2026-52870 |
|
Vulnerability in mcp (CVE-2026-52870)
vulnerability in mcp (CVE-2026-52870). Confidential information can be exposed externally. Exploitable via ``TaskStore``. Mitigation: upgrade to `1.27.2` or later.
|
| CVE-2026-15746 |
|
SSRF (Server-Side Request Forgery) in Amazon aws (CVE-2026-15746)
SSRF in Amazon aws (CVE-2026-15746). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-61446 |
|
Code Injection in path-traversal (CVE-2026-61446)
code injection in path-traversal (CVE-2026-61446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61433 |
|
Code Injection in CVE-2026-61433 (CVE-2026-61433)
code injection in CVE-2026-61433 (CVE-2026-61433). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59886 |
|
Vulnerability in pyasn1 (CVE-2026-59886)
vulnerability in pyasn1 (CVE-2026-59886). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.4` or later.
|
| CVE-2026-59197 |
|
Vulnerability in Pillow (CVE-2026-59197)
vulnerability in Pillow (CVE-2026-59197). Risk of unauthorized operations or information disclosure. Exploitable via ``INT_MAX``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59200 |
|
Vulnerability in Pillow (CVE-2026-59200)
vulnerability in Pillow (CVE-2026-59200). Risk of unauthorized operations or information disclosure. Exploitable via ``PdfParser.py``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59884 |
|
Vulnerability in pyssn1 (CVE-2026-59884)
vulnerability in pyssn1 (CVE-2026-59884). Risk of unauthorized operations or information disclosure. Exploitable via ``ValueError``. Mitigation: upgrade to `0.6.4` or later.
|
| CVE-2026-59885 |
|
Vulnerability in pyasn1 (CVE-2026-59885)
vulnerability in pyasn1 (CVE-2026-59885). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.4` or later.
|
| CVE-2026-54058 |
|
Out-of-Bounds Read in pillow (CVE-2026-54058)
vulnerability in pillow (CVE-2026-54058). Confidential information can be exposed externally. Exploitable via ``raw``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59203 |
|
Vulnerability in pillow (CVE-2026-59203)
vulnerability in pillow (CVE-2026-59203). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59204 |
|
Vulnerability in pillow (CVE-2026-59204)
vulnerability in pillow (CVE-2026-59204). Risk of unauthorized operations or information disclosure. Exploitable via ``total_component_width``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59205 |
|
Out-of-Bounds Write in pillow (CVE-2026-59205)
out-of-bounds write in pillow (CVE-2026-59205). Risk of unauthorized operations or information disclosure. Exploitable via ``imOut``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59198 |
|
Out-of-Bounds Read in Pillow (CVE-2026-59198)
vulnerability in Pillow (CVE-2026-59198). Confidential information can be exposed externally. Exploitable via ``tga_rle``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59199 |
|
Vulnerability in Pillow (CVE-2026-59199)
vulnerability in Pillow (CVE-2026-59199). Risk of unauthorized operations or information disclosure. Exploitable via ``RGBA``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-12482 |
|
Path Traversal in keras (CVE-2026-12482)
path traversal in keras (CVE-2026-12482). Risk of unauthorized operations or information disclosure. Exploitable via ``filter_safe_tarinfos``. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-13014 |
|
Path Traversal in django (CVE-2026-13014)
path traversal in django (CVE-2026-13014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61447 |
|
Code Injection in CVE-2026-61447 (CVE-2026-61447)
code injection in CVE-2026-61447 (CVE-2026-61447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55659 |
|
Cross-Site Scripting (XSS) in CVE-2026-55659 (CVE-2026-55659)
cross-site scripting in CVE-2026-55659 (CVE-2026-55659). Confidential information can be exposed externally.
|
| CVE-2026-55664 |
|
Information Disclosure in CVE-2026-55664 (CVE-2026-55664)
vulnerability in CVE-2026-55664 (CVE-2026-55664). Risk of unauthorized operations or information disclosure. Exploitable via `GET /forms`.
|
| CVE-2026-55665 |
|
Cross-Site Scripting (XSS) in CVE-2026-55665 (CVE-2026-55665)
cross-site scripting in CVE-2026-55665 (CVE-2026-55665). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54071 |
|
Unsafe Deserialization in BabelDOC (CVE-2026-54071)
vulnerability in BabelDOC (CVE-2026-54071). Successful exploitation can lead to full system takeover. Exploitable via ``psparser._parse_literal_hex``. Mitigation: upgrade to `0.6.3` or later.
|
| CVE-2026-61437 |
|
Vulnerability in CVE-2026-61437 (CVE-2026-61437)
vulnerability in CVE-2026-61437 (CVE-2026-61437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61444 |
|
Code Injection in CVE-2026-61444 (CVE-2026-61444)
code injection in CVE-2026-61444 (CVE-2026-61444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15308 |
|
Vulnerability in CVE-2026-15308 (CVE-2026-15308)
vulnerability in CVE-2026-15308 (CVE-2026-15308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59214 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-59214)
cross-site scripting in open-webui (CVE-2026-59214). Confidential information can be exposed externally. Exploitable via ``pyodide.http.pyfetch``. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-59216 |
|
Code Injection in open-webui (CVE-2026-59216)
code injection in open-webui (CVE-2026-59216). Confidential information can be exposed externally. Exploitable via `POST /api/v1/chat/completions`. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-14480 |
|
Vulnerability in cisa (CVE-2026-14480)
vulnerability in cisa (CVE-2026-14480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55830 |
|
Vulnerability in RestrictedPython (CVE-2026-55830)
vulnerability in RestrictedPython (CVE-2026-55830). Confidential information can be exposed externally. Exploitable via ``_write_``. Mitigation: upgrade to `8.3` or later.
|
| CVE-2026-54591 |
|
Path Traversal in asyncssh (CVE-2026-54591)
path traversal in asyncssh (CVE-2026-54591). Data can be tampered with by attackers. Exploitable via ``_parse_cd_args``. Mitigation: upgrade to `2.23.1` or later.
|