Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72884 |
|
OS Command Injection in CVE-2026-72884 (CVE-2026-72884)
OS command injection in CVE-2026-72884 (CVE-2026-72884). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72885 |
|
OS Command Injection in CVE-2026-72885 (CVE-2026-72885)
OS command injection in CVE-2026-72885 (CVE-2026-72885). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72901 |
|
OS Command Injection in CVE-2026-72901 (CVE-2026-72901)
OS command injection in CVE-2026-72901 (CVE-2026-72901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72902 |
|
OS Command Injection in CVE-2026-72902 (CVE-2026-72902)
OS command injection in CVE-2026-72902 (CVE-2026-72902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72883 |
|
Vulnerability in CVE-2026-72883 (CVE-2026-72883)
vulnerability in CVE-2026-72883 (CVE-2026-72883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72886 |
|
Privilege Escalation in CVE-2026-72886 (CVE-2026-72886)
vulnerability in CVE-2026-72886 (CVE-2026-72886). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72877 |
|
OS Command Injection in CVE-2026-72877 (CVE-2026-72877)
OS command injection in CVE-2026-72877 (CVE-2026-72877). Confidential information can be exposed externally.
|
| CVE-2026-72878 |
|
OS Command Injection in c (CVE-2026-72878)
OS command injection in c (CVE-2026-72878). Confidential information can be exposed externally. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72879 |
|
OS Command Injection in CVE-2026-72879 (CVE-2026-72879)
OS command injection in CVE-2026-72879 (CVE-2026-72879). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72880 |
|
OS Command Injection in CVE-2026-72880 (CVE-2026-72880)
OS command injection in CVE-2026-72880 (CVE-2026-72880). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72881 |
|
OS Command Injection in CVE-2026-72881 (CVE-2026-72881)
OS command injection in CVE-2026-72881 (CVE-2026-72881). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72882 |
|
OS Command Injection in CVE-2026-72882 (CVE-2026-72882)
OS command injection in CVE-2026-72882 (CVE-2026-72882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72874 |
|
OS Command Injection in CVE-2026-72874 (CVE-2026-72874)
OS command injection in CVE-2026-72874 (CVE-2026-72874). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72875 |
|
OS Command Injection in CVE-2026-72875 (CVE-2026-72875)
OS command injection in CVE-2026-72875 (CVE-2026-72875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72876 |
|
OS Command Injection in CVE-2026-72876 (CVE-2026-72876)
OS command injection in CVE-2026-72876 (CVE-2026-72876). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72873 |
|
Information Disclosure in CVE-2026-72873 (CVE-2026-72873)
vulnerability in CVE-2026-72873 (CVE-2026-72873). Confidential information can be exposed externally.
|
| CVE-2026-69118 |
|
Authorization Flaw in CVE-2026-69118 (CVE-2026-69118)
vulnerability in CVE-2026-69118 (CVE-2026-69118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69116 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-69116)
cross-site scripting in vue (CVE-2026-69116). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71966 |
|
OS Command Injection in c (CVE-2026-71966)
OS command injection in c (CVE-2026-71966). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69112 |
|
Path Traversal in path-traversal (CVE-2026-69112)
path traversal in path-traversal (CVE-2026-69112). Confidential information can be exposed externally.
|
| CVE-2026-44401 |
|
Cross-Site Scripting (XSS) in CVE-2026-44401 (CVE-2026-44401)
cross-site scripting in CVE-2026-44401 (CVE-2026-44401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14886 |
|
Vulnerability in CVE-2026-14886 (CVE-2026-14886)
vulnerability in CVE-2026-14886 (CVE-2026-14886). Data can be tampered with by attackers.
|
| CVE-2025-15682 |
|
Vulnerability in CVE-2025-15682 (CVE-2025-15682)
vulnerability in CVE-2025-15682 (CVE-2025-15682). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15680 |
|
Vulnerability in CVE-2025-15680 (CVE-2025-15680)
vulnerability in CVE-2025-15680 (CVE-2025-15680). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15681 |
|
Vulnerability in CVE-2025-15681 (CVE-2025-15681)
vulnerability in CVE-2025-15681 (CVE-2025-15681). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15683 |
|
Vulnerability in CVE-2025-15683 (CVE-2025-15683)
vulnerability in CVE-2025-15683 (CVE-2025-15683). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13294 |
|
SQL Injection in sqli (CVE-2025-13294)
SQL injection in sqli (CVE-2025-13294). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13293 |
|
Vulnerability in CVE-2025-13293 (CVE-2025-13293)
vulnerability in CVE-2025-13293 (CVE-2025-13293). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72871 |
|
Vulnerability in CVE-2026-72871 (CVE-2026-72871)
vulnerability in CVE-2026-72871 (CVE-2026-72871). Data can be tampered with by attackers.
|
| CVE-2026-72872 |
|
OS Command Injection in CVE-2026-72872 (CVE-2026-72872)
OS command injection in CVE-2026-72872 (CVE-2026-72872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72865 |
|
OS Command Injection in c (CVE-2026-72865)
OS command injection in c (CVE-2026-72865). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72868 |
|
OS Command Injection in CVE-2026-72868 (CVE-2026-72868)
OS command injection in CVE-2026-72868 (CVE-2026-72868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72870 |
|
OS Command Injection in CVE-2026-72870 (CVE-2026-72870)
OS command injection in CVE-2026-72870 (CVE-2026-72870). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72864 |
|
Vulnerability in CVE-2026-72864 (CVE-2026-72864)
vulnerability in CVE-2026-72864 (CVE-2026-72864). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72866 |
|
Vulnerability in CVE-2026-72866 (CVE-2026-72866)
vulnerability in CVE-2026-72866 (CVE-2026-72866). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72869 |
|
Command Injection in CVE-2026-72869 (CVE-2026-72869)
command injection in CVE-2026-72869 (CVE-2026-72869). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72867 |
|
Vulnerability in CVE-2026-72867 (CVE-2026-72867)
vulnerability in CVE-2026-72867 (CVE-2026-72867). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72863 |
|
Privilege Escalation in CVE-2026-72863 (CVE-2026-72863)
vulnerability in CVE-2026-72863 (CVE-2026-72863). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-71968 |
|
Vulnerability in CVE-2026-71968 (CVE-2026-71968)
vulnerability in CVE-2026-71968 (CVE-2026-71968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71967 |
|
Vulnerability in dos (CVE-2026-71967)
vulnerability in dos (CVE-2026-71967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71969 |
|
Vulnerability in CVE-2026-71969 (CVE-2026-71969)
vulnerability in CVE-2026-71969 (CVE-2026-71969). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71962 |
|
Vulnerability in flowiseai (CVE-2026-71962)
vulnerability in flowiseai (CVE-2026-71962). Confidential information can be exposed externally. Exploitable via `POST /api/v1/openai-assistants-file/download`.
|
| CVE-2026-71964 |
|
Vulnerability in CVE-2026-71964 (CVE-2026-71964)
vulnerability in CVE-2026-71964 (CVE-2026-71964). Confidential information can be exposed externally.
|
| CVE-2026-59091 |
|
Out-of-Bounds Write in gimp (CVE-2026-59091)
out-of-bounds write in gimp (CVE-2026-59091). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6368 |
|
Vulnerability in c (CVE-2026-6368)
vulnerability in c (CVE-2026-6368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6791 |
|
Vulnerability in CVE-2026-6791 (CVE-2026-6791)
vulnerability in CVE-2026-6791 (CVE-2026-6791). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12339 |
|
Path Traversal in path-traversal (CVE-2026-12339)
path traversal in path-traversal (CVE-2026-12339). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72900 |
|
Vulnerability in CVE-2026-72900 (CVE-2026-72900)
vulnerability in CVE-2026-72900 (CVE-2026-72900). Confidential information can be exposed externally.
|
| CVE-2026-72862 |
|
OS Command Injection in CVE-2026-72862 (CVE-2026-72862)
OS command injection in CVE-2026-72862 (CVE-2026-72862). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72898 KEV |
|
[KEV] SQL Injection in metabase (CVE-2026-72898)
SQL injection in metabase (CVE-2026-72898). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|