Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82472 |
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
| CVE-2026-82473 |
|
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
|
| CVE-2026-82452 |
|
Vulnerability in c (CVE-2026-82452)
vulnerability in c (CVE-2026-82452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55678 |
|
Vulnerability in github.com/basekick-labs/arc (CVE-2026-55678)
vulnerability in github.com/basekick-labs/arc (CVE-2026-55678). Risk of unauthorized operations or information disclosure. Exploitable via ``cluster.shared_secret``. Mitigation: upgrade to `0.0.0-20260615160325-38402ad2ebdd` or later.
|
| CVE-2026-82282 |
|
Vulnerability in CVE-2026-82282 (CVE-2026-82282)
vulnerability in CVE-2026-82282 (CVE-2026-82282). Confidential information can be exposed externally.
|
| CVE-2026-82276 |
|
Vulnerability in CVE-2026-82276 (CVE-2026-82276)
vulnerability in CVE-2026-82276 (CVE-2026-82276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82277 |
|
Vulnerability in csrf (CVE-2026-82277)
vulnerability in csrf (CVE-2026-82277). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82265 |
|
Vulnerability in spring (CVE-2026-82265)
vulnerability in spring (CVE-2026-82265). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82266 |
|
Vulnerability in CVE-2026-82266 (CVE-2026-82266)
vulnerability in CVE-2026-82266 (CVE-2026-82266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78239 |
|
Vulnerability in CVE-2026-78239 (CVE-2026-78239)
vulnerability in CVE-2026-78239 (CVE-2026-78239). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77977 |
|
Vulnerability in CVE-2026-77977 (CVE-2026-77977)
vulnerability in CVE-2026-77977 (CVE-2026-77977). Data can be tampered with by attackers.
|
| CVE-2026-68929 |
|
Vulnerability in CVE-2026-68929 (CVE-2026-68929)
vulnerability in CVE-2026-68929 (CVE-2026-68929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76639 |
|
Path Traversal in path-traversal (CVE-2026-76639)
path traversal in path-traversal (CVE-2026-76639). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76640 |
|
Vulnerability in CVE-2026-76640 (CVE-2026-76640)
vulnerability in CVE-2026-76640 (CVE-2026-76640). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81735 |
|
Vulnerability in CVE-2026-81735 (CVE-2026-81735)
vulnerability in CVE-2026-81735 (CVE-2026-81735). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81664 |
|
Vulnerability in CVE-2026-81664 (CVE-2026-81664)
vulnerability in CVE-2026-81664 (CVE-2026-81664). Risk of unauthorized operations or information disclosure. Exploitable via `GET /system/telemetry`.
|
| CVE-2026-81098 |
|
Vulnerability in CVE-2026-81098 (CVE-2026-81098)
vulnerability in CVE-2026-81098 (CVE-2026-81098). Confidential information can be exposed externally.
|
| CVE-2026-81094 |
|
Vulnerability in CVE-2026-81094 (CVE-2026-81094)
vulnerability in CVE-2026-81094 (CVE-2026-81094). Confidential information can be exposed externally.
|
| CVE-2026-80208 |
|
Vulnerability in nginx (CVE-2026-80208)
vulnerability in nginx (CVE-2026-80208). Data can be tampered with by attackers.
|
| CVE-2026-80207 |
|
Vulnerability in nginx (CVE-2026-80207)
vulnerability in nginx (CVE-2026-80207). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/internal/notification/create`.
|
| CVE-2026-65956 |
|
Vulnerability in privilege-escalation (CVE-2026-65956)
vulnerability in privilege-escalation (CVE-2026-65956). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81202 |
|
Authentication Bypass in CVE-2026-81202 (CVE-2026-81202)
authentication bypass in CVE-2026-81202 (CVE-2026-81202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75329 |
|
Vulnerability in CVE-2026-75329 (CVE-2026-75329)
vulnerability in CVE-2026-75329 (CVE-2026-75329). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75601 |
|
Vulnerability in CVE-2026-75601 (CVE-2026-75601)
vulnerability in CVE-2026-75601 (CVE-2026-75601). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47837 |
|
Vulnerability in CVE-2026-47837 (CVE-2026-47837)
vulnerability in CVE-2026-47837 (CVE-2026-47837). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81032 |
|
Vulnerability in cpp (CVE-2026-81032)
vulnerability in cpp (CVE-2026-81032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80234 |
|
Vulnerability in CVE-2026-80234 (CVE-2026-80234)
vulnerability in CVE-2026-80234 (CVE-2026-80234). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16646 |
|
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
|
| CVE-2026-65105 |
|
Vulnerability in dos (CVE-2026-65105)
vulnerability in dos (CVE-2026-65105). Confidential information can be exposed externally.
|
| CVE-2026-73125 |
|
Vulnerability in cisa (CVE-2026-73125)
vulnerability in cisa (CVE-2026-73125). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55571 |
|
Vulnerability in djust (CVE-2026-55571)
vulnerability in djust (CVE-2026-55571). Data can be tampered with by attackers. Exploitable via ``LiveViewConsumer``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2026-55640 |
|
Vulnerability in nextcloud-mcp-server (CVE-2026-55640)
vulnerability in nextcloud-mcp-server (CVE-2026-55640). Data can be tampered with by attackers. Exploitable via `POST /webhooks/nextcloud`. Mitigation: upgrade to `0.117.2` or later.
|
| CVE-2026-55533 |
|
Authentication Bypass in PraisonAI (CVE-2026-55533)
authentication bypass in PraisonAI (CVE-2026-55533). Data can be tampered with by attackers. Exploitable via `POST /v1/recipes/run`. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-55539 |
|
Vulnerability in PraisonAI (CVE-2026-55539)
vulnerability in PraisonAI (CVE-2026-55539). Risk of unauthorized operations or information disclosure. Exploitable via `GET /agents`. Mitigation: upgrade to `4.6.34` or later.
|
| CVE-2026-55538 |
|
Vulnerability in PraisonAI (CVE-2026-55538)
vulnerability in PraisonAI (CVE-2026-55538). Risk of unauthorized operations or information disclosure. Exploitable via `POST /agents`. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-55534 |
|
Vulnerability in PraisonAI (CVE-2026-55534)
vulnerability in PraisonAI (CVE-2026-55534). Risk of unauthorized operations or information disclosure. Exploitable via `POST /agents`. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-55528 |
|
Vulnerability in praisonaiagents (CVE-2026-55528)
vulnerability in praisonaiagents (CVE-2026-55528). Data can be tampered with by attackers. Exploitable via `GET /info`. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-55529 |
|
Vulnerability in PraisonAI (CVE-2026-55529)
vulnerability in PraisonAI (CVE-2026-55529). Confidential information can be exposed externally. Exploitable via ``Origin``. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-79668 |
|
Vulnerability in CVE-2026-79668 (CVE-2026-79668)
vulnerability in CVE-2026-79668 (CVE-2026-79668). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/echo/like/`.
|
| CVE-2026-57909 |
|
Code Injection in path-traversal (CVE-2026-57909)
code injection in path-traversal (CVE-2026-57909). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57910 |
|
Vulnerability in CVE-2026-57910 (CVE-2026-57910)
vulnerability in CVE-2026-57910 (CVE-2026-57910). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67578 |
|
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
|
| CVE-2026-78434 |
|
Authentication Bypass in CVE-2026-78434 (CVE-2026-78434)
authentication bypass in CVE-2026-78434 (CVE-2026-78434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77915 |
|
Vulnerability in CVE-2026-77915 (CVE-2026-77915)
vulnerability in CVE-2026-77915 (CVE-2026-77915). Successful exploitation can lead to full system takeover. Exploitable via `POST /register`.
|
| CVE-2026-78369 |
|
Vulnerability in CVE-2026-78369 (CVE-2026-78369)
vulnerability in CVE-2026-78369 (CVE-2026-78369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6017 |
|
Vulnerability in CVE-2026-6017 (CVE-2026-6017)
vulnerability in CVE-2026-6017 (CVE-2026-6017). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78306 |
|
Vulnerability in CVE-2026-78306 (CVE-2026-78306)
vulnerability in CVE-2026-78306 (CVE-2026-78306). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78255 |
|
Vulnerability in CVE-2026-78255 (CVE-2026-78255)
vulnerability in CVE-2026-78255 (CVE-2026-78255). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19853 |
|
Vulnerability in CVE-2026-19853 (CVE-2026-19853)
vulnerability in CVE-2026-19853 (CVE-2026-19853). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78154 |
|
Authentication Bypass in CVE-2026-78154 (CVE-2026-78154)
authentication bypass in CVE-2026-78154 (CVE-2026-78154). Risk of unauthorized operations or information disclosure.
|