Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-6516 |
|
OS Command Injection in CVE-2026-6516 (CVE-2026-6516)
OS command injection in CVE-2026-6516 (CVE-2026-6516). Confidential information can be exposed externally.
|
| CVE-2026-65700 |
|
Path Traversal in path-traversal (CVE-2026-65700)
path traversal in path-traversal (CVE-2026-65700). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65608 |
|
Vulnerability in CVE-2026-65608 (CVE-2026-65608)
vulnerability in CVE-2026-65608 (CVE-2026-65608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59543 |
|
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
|
| CVE-2026-14282 |
|
Unrestricted File Upload in wordpress (CVE-2026-14282)
vulnerability in wordpress (CVE-2026-14282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16723 |
|
Vulnerability in com.alibaba:fastjson (CVE-2026-16723)
vulnerability in com.alibaba:fastjson (CVE-2026-16723). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16606 |
|
Code Injection in CVE-2026-16606 (CVE-2026-16606)
code injection in CVE-2026-16606 (CVE-2026-16606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53910 |
|
Vulnerability in CVE-2026-53910 (CVE-2026-53910)
vulnerability in CVE-2026-53910 (CVE-2026-53910). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13185 |
|
Unsafe Deserialization in progress (CVE-2026-13185)
vulnerability in progress (CVE-2026-13185). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13186 |
|
Path Traversal in path-traversal (CVE-2026-13186)
path traversal in path-traversal (CVE-2026-13186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13190 |
|
Unsafe Deserialization in deserialization (CVE-2026-13190)
vulnerability in deserialization (CVE-2026-13190). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13181 |
|
Vulnerability in progress (CVE-2026-13181)
vulnerability in progress (CVE-2026-13181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44191 |
|
OS Command Injection in CVE-2026-44191 (CVE-2026-44191)
OS command injection in CVE-2026-44191 (CVE-2026-44191). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65603 |
|
Privilege Escalation in privilege-escalation (CVE-2026-65603)
vulnerability in privilege-escalation (CVE-2026-65603). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.8.12` or later.
|
| CVE-2026-65595 |
|
Privilege Escalation in n8n (CVE-2026-65595)
vulnerability in n8n (CVE-2026-65595). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.29.8` or later.
|
| CVE-2026-63048 |
|
Unrestricted File Upload in CVE-2026-63048 (CVE-2026-63048)
vulnerability in CVE-2026-63048 (CVE-2026-63048). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15802 |
|
Vulnerability in wordpress (CVE-2026-15802)
vulnerability in wordpress (CVE-2026-15802). Data can be tampered with by attackers.
|
| CVE-2026-8984 |
|
Code Injection in autel (CVE-2026-8984)
code injection in autel (CVE-2026-8984). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64878 |
|
OS Command Injection in tenable (CVE-2026-64878)
OS command injection in tenable (CVE-2026-64878). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63454 |
|
Path Traversal in path-traversal (CVE-2026-63454)
path traversal in path-traversal (CVE-2026-63454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21575 |
|
Code Injection in atlassian (CVE-2026-21575)
code injection in atlassian (CVE-2026-21575). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64824 |
|
Path Traversal in path-traversal (CVE-2026-64824)
path traversal in path-traversal (CVE-2026-64824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28305 |
|
Vulnerability in solarwinds (CVE-2026-28305)
vulnerability in solarwinds (CVE-2026-28305). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28308 |
|
Vulnerability in solarwinds (CVE-2026-28308)
vulnerability in solarwinds (CVE-2026-28308). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28302 |
|
Vulnerability in privilege-escalation (CVE-2026-28302)
vulnerability in privilege-escalation (CVE-2026-28302). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28304 |
|
Vulnerability in solarwinds (CVE-2026-28304)
vulnerability in solarwinds (CVE-2026-28304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65008 |
|
Code Injection in CVE-2026-65008 (CVE-2026-65008)
code injection in CVE-2026-65008 (CVE-2026-65008). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.7` or later.
|
| CVE-2026-1771 |
|
Vulnerability in wordpress (CVE-2026-1771)
vulnerability in wordpress (CVE-2026-1771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0770 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-0770)
vulnerability in langflow (CVE-2026-0770). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-16337 |
|
Privilege Escalation in CVE-2026-16337 (CVE-2026-16337)
vulnerability in CVE-2026-16337 (CVE-2026-16337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61900 |
|
Unrestricted File Upload in CVE-2026-61900 (CVE-2026-61900)
vulnerability in CVE-2026-61900 (CVE-2026-61900). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61424 |
|
Unrestricted File Upload in CVE-2026-61424 (CVE-2026-61424)
vulnerability in CVE-2026-61424 (CVE-2026-61424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60032 |
|
Unrestricted File Upload in CVE-2026-60032 (CVE-2026-60032)
vulnerability in CVE-2026-60032 (CVE-2026-60032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34239 |
|
Vulnerability in CVE-2026-34239 (CVE-2026-34239)
vulnerability in CVE-2026-34239 (CVE-2026-34239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41252 |
|
Vulnerability in dos (CVE-2026-41252)
vulnerability in dos (CVE-2026-41252). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53421 |
|
Vulnerability in apache (CVE-2026-53421)
vulnerability in apache (CVE-2026-53421). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57311 |
|
Unrestricted File Upload in CVE-2026-57311 (CVE-2026-57311)
vulnerability in CVE-2026-57311 (CVE-2026-57311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12484 |
|
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
|
| CVE-2026-9323 |
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
| CVE-2026-11826 |
|
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
|
| CVE-2024-58366 |
|
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
|
| CVE-2024-58362 |
|
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
|
| CVE-2026-9147 |
|
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
|
| CVE-2026-47869 |
|
Code Injection in broadcom (CVE-2026-47869)
code injection in broadcom (CVE-2026-47869). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47867 |
|
Code Injection in broadcom (CVE-2026-47867)
code injection in broadcom (CVE-2026-47867). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-8505 |
|
Vulnerability in langflow (CVE-2026-8505)
vulnerability in langflow (CVE-2026-8505). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7755 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
|
| CVE-2026-8056 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
|
| CVE-2026-8476 |
|
Unsafe Deserialization in langflow (CVE-2026-8476)
vulnerability in langflow (CVE-2026-8476). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8481 |
|
Code Injection in c (CVE-2026-8481)
code injection in c (CVE-2026-8481). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/validate/code`.
|