Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-20242 |
|
Vulnerability in CVE-2017-20242 (CVE-2017-20242)
vulnerability in CVE-2017-20242 (CVE-2017-20242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47621 |
|
Vulnerability in dos (CVE-2026-47621)
vulnerability in dos (CVE-2026-47621). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47620 |
|
Vulnerability in dos (CVE-2026-47620)
vulnerability in dos (CVE-2026-47620). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47623 |
|
Unsafe Deserialization in dos (CVE-2026-47623)
vulnerability in dos (CVE-2026-47623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47622 |
|
Vulnerability in nvidia (CVE-2026-47622)
vulnerability in nvidia (CVE-2026-47622). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24254 |
|
Vulnerability in dos (CVE-2026-24254)
vulnerability in dos (CVE-2026-24254). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18790 |
|
Buffer Overflow in c (CVE-2026-18790)
vulnerability in c (CVE-2026-18790). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24253 |
|
Out-of-Bounds Write in dos (CVE-2026-24253)
out-of-bounds write in dos (CVE-2026-24253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64633 |
|
A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing remote unauthenticated code execution on the agent host.
|
| CVE-2026-64634 |
|
A vulnerability allowing local privilege escalation to the Reporter service context.
A vulnerability allowing local privilege escalation to the Reporter service context.
|
| CVE-2026-47615 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47615)
SSRF in nvidia (CVE-2026-47615). Confidential information can be exposed externally.
|
| CVE-2026-47616 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47616)
SSRF in nvidia (CVE-2026-47616). Confidential information can be exposed externally.
|
| CVE-2026-47614 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47614)
SSRF in nvidia (CVE-2026-47614). Confidential information can be exposed externally.
|
| CVE-2026-47613 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47613)
SSRF in nvidia (CVE-2026-47613). Confidential information can be exposed externally.
|
| CVE-2026-47617 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47617)
SSRF in nvidia (CVE-2026-47617). Confidential information can be exposed externally.
|
| CVE-2026-47618 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47618)
SSRF in nvidia (CVE-2026-47618). Confidential information can be exposed externally.
|
| CVE-2026-47487 |
|
Path Traversal in dos (CVE-2026-47487)
path traversal in dos (CVE-2026-47487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47612 |
|
Path Traversal in nvidia (CVE-2026-47612)
path traversal in nvidia (CVE-2026-47612). Confidential information can be exposed externally.
|
| CVE-2026-18788 |
|
Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64630 |
|
Authorization Flaw in CVE-2026-64630 (CVE-2026-64630)
vulnerability in CVE-2026-64630 (CVE-2026-64630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58072 |
|
Path Traversal in CVE-2026-58072 (CVE-2026-58072)
path traversal in CVE-2026-58072 (CVE-2026-58072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58075 |
|
Authentication Bypass in CVE-2026-58075 (CVE-2026-58075)
authentication bypass in CVE-2026-58075 (CVE-2026-58075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63456 |
|
Authentication Bypass in CVE-2026-63456 (CVE-2026-63456)
authentication bypass in CVE-2026-63456 (CVE-2026-63456). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58074 |
|
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
|
| CVE-2026-64631 |
|
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
|
| CVE-2026-58073 |
|
Vulnerability in CVE-2026-58073 (CVE-2026-58073)
vulnerability in CVE-2026-58073 (CVE-2026-58073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58071 |
|
Vulnerability in CVE-2026-58071 (CVE-2026-58071)
vulnerability in CVE-2026-58071 (CVE-2026-58071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63455 |
|
Vulnerability in CVE-2026-63455 (CVE-2026-63455)
vulnerability in CVE-2026-63455 (CVE-2026-63455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18784 |
|
Buffer Overflow in c (CVE-2026-18784)
vulnerability in c (CVE-2026-18784). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15314 |
|
Vulnerability in tp-link (CVE-2026-15314)
vulnerability in tp-link (CVE-2026-15314). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18787 |
|
Vulnerability in CVE-2026-18787 (CVE-2026-18787)
vulnerability in CVE-2026-18787 (CVE-2026-18787). Successful exploitation can lead to full system takeover.
|
| CVE-2025-29296 |
|
Command Injection in CVE-2025-29296 (CVE-2025-29296)
command injection in CVE-2025-29296 (CVE-2025-29296). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18774 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18774 (CVE-2026-18774)
SSRF in CVE-2026-18774 (CVE-2026-18774). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18775 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18775 (CVE-2026-18775)
SSRF in CVE-2026-18775 (CVE-2026-18775). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15307 |
|
Vulnerability in django (CVE-2026-15307)
vulnerability in django (CVE-2026-15307). Successful exploitation can lead to full system takeover. Exploitable via ``django.contrib.gis.gdal.GDALRaster``.
|
| CVE-2026-18785 |
|
Buffer Overflow in c (CVE-2026-18785)
vulnerability in c (CVE-2026-18785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56848 |
|
Use-After-Free in CVE-2026-56848 (CVE-2026-56848)
vulnerability in CVE-2026-56848 (CVE-2026-56848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18830 |
|
Vulnerability in Amazon aws (CVE-2026-18830)
vulnerability in Amazon aws (CVE-2026-18830). Confidential information can be exposed externally.
|
| CVE-2026-70474 |
|
Authorization Flaw in flowise (CVE-2026-70474)
vulnerability in flowise (CVE-2026-70474). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/authorize/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70473 |
|
Information Disclosure in flowise (CVE-2026-70473)
vulnerability in flowise (CVE-2026-70473). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/upsert-history`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70472 |
|
Vulnerability in flowise (CVE-2026-70472)
vulnerability in flowise (CVE-2026-70472). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/openai-assistants-vector-store`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69264 |
|
Code Injection in flowise (CVE-2026-69264)
code injection in flowise (CVE-2026-69264). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70471 |
|
Authorization Flaw in flowise (CVE-2026-70471)
vulnerability in flowise (CVE-2026-70471). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70470 |
|
Vulnerability in flowise (CVE-2026-70470)
vulnerability in flowise (CVE-2026-70470). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/{chatflowId}`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69263 |
|
Vulnerability in flowise (CVE-2026-69263)
vulnerability in flowise (CVE-2026-69263). Risk of unauthorized operations or information disclosure. Exploitable via ``npx``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69262 |
|
Authorization Flaw in flowise (CVE-2026-69262)
vulnerability in flowise (CVE-2026-69262). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/v1/chatflows/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69098 |
|
Unsafe Deserialization in c (CVE-2026-69098)
vulnerability in c (CVE-2026-69098). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69110 |
|
Path Traversal in CVE-2026-69110 (CVE-2026-69110)
path traversal in CVE-2026-69110 (CVE-2026-69110). Confidential information can be exposed externally. Exploitable via `GET /api/tmp/`.
|
| CVE-2026-69100 |
|
Code Injection in CVE-2026-69100 (CVE-2026-69100)
code injection in CVE-2026-69100 (CVE-2026-69100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24083 |
|
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
|