Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-54591 |
|
Path Traversal in asyncssh (CVE-2026-54591)
path traversal in asyncssh (CVE-2026-54591). Data can be tampered with by attackers. Exploitable via ``_parse_cd_args``. Mitigation: upgrade to `2.23.1` or later.
|
| CVE-2026-35210 |
|
Vulnerability in citeum (CVE-2026-35210)
vulnerability in citeum (CVE-2026-35210). Data can be tampered with by attackers.
|
| CVE-2026-35211 |
|
Code Injection in citeum (CVE-2026-35211)
code injection in citeum (CVE-2026-35211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49456 |
|
Open Redirect in waku (CVE-2026-49456)
vulnerability in waku (CVE-2026-49456). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.0.0-beta.1` or later.
|
| CVE-2026-49455 |
|
Cross-Site Request Forgery (CSRF) in waku (CVE-2026-49455)
vulnerability in waku (CVE-2026-49455). Data can be tampered with by attackers. Exploitable via ``Origin``. Mitigation: upgrade to `1.0.0-beta.1` or later.
|
| CVE-2026-53649 |
|
Vulnerability in github.com/BishopFox/joro (CVE-2026-53649)
vulnerability in github.com/BishopFox/joro (CVE-2026-53649). Successful exploitation can lead to full system takeover. Exploitable via ``AuthMiddleware``. Mitigation: upgrade to `0.0.0-20260601151442-5c0ca35db828` or later.
|
| CVE-2026-49833 |
|
Path Traversal in org.dspace:dspace-api (CVE-2026-49833)
path traversal in org.dspace:dspace-api (CVE-2026-49833). Confidential information can be exposed externally. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
|
| CVE-2026-49830 |
|
Vulnerability in org.dspace:dspace-api (CVE-2026-49830)
vulnerability in org.dspace:dspace-api (CVE-2026-49830). Confidential information can be exposed externally. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
|
| CVE-2026-49831 |
|
Path Traversal in org.dspace:dspace-api (CVE-2026-49831)
path traversal in org.dspace:dspace-api (CVE-2026-49831). Risk of unauthorized operations or information disclosure. Exploitable via ``curate``. Mitigation: upgrade to `10.0` or later.
|
| CVE-2026-49832 |
|
Code Injection in org.dspace:dspace-api (CVE-2026-49832)
code injection in org.dspace:dspace-api (CVE-2026-49832). Successful exploitation can lead to full system takeover. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
|
| CVE-2026-52831 |
|
OS Command Injection in github.com/nuclio/nuclio (CVE-2026-52831)
OS command injection in github.com/nuclio/nuclio (CVE-2026-52831). Successful exploitation can lead to full system takeover. Exploitable via ``curl``. Mitigation: upgrade to `0.0.0-20260601075854-3356b86a8bfa` or later.
|
| CVE-2026-53600 |
|
Vulnerability in async-tar (CVE-2026-53600)
vulnerability in async-tar (CVE-2026-53600). Risk of unauthorized operations or information disclosure. Exploitable via ``size``. Mitigation: upgrade to `0.6.1` or later.
|
| CVE-2026-50197 |
|
Vulnerability in github.com/zalando/skipper (CVE-2026-50197)
vulnerability in github.com/zalando/skipper (CVE-2026-50197). Risk of unauthorized operations or information disclosure. Exploitable via `POST /priv`. Mitigation: upgrade to `0.26.10` or later.
|
| CVE-2026-49825 |
|
Cross-Site Scripting (XSS) in lxml_html_clean (CVE-2026-49825)
cross-site scripting in lxml_html_clean (CVE-2026-49825). Confidential information can be exposed externally. Exploitable via ``lxml_html_clean.Cleaner``. Mitigation: upgrade to `0.4.5` or later.
|
| CVE-2026-59948 |
|
Path Traversal in composer/composer (CVE-2026-59948)
path traversal in composer/composer (CVE-2026-59948). Successful exploitation can lead to full system takeover. Exploitable via ``install``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59936 |
|
Vulnerability in pypdf (CVE-2026-59936)
vulnerability in pypdf (CVE-2026-59936). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.14.1` or later.
|
| CVE-2026-59946 |
|
Path Traversal in composer/composer (CVE-2026-59946)
path traversal in composer/composer (CVE-2026-59946). Confidential information can be exposed externally. Exploitable via ``bin``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59935 |
|
Vulnerability in pypdf (CVE-2026-59935)
vulnerability in pypdf (CVE-2026-59935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.14.2` or later.
|
| CVE-2026-59947 |
|
Vulnerability in composer/composer (CVE-2026-59947)
vulnerability in composer/composer (CVE-2026-59947). Confidential information can be exposed externally. Exploitable via ``repositories``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59819 |
|
Vulnerability in litellm (CVE-2026-59819)
vulnerability in litellm (CVE-2026-59819). Confidential information can be exposed externally. Exploitable via ``litellm_params``. Mitigation: upgrade to `1.83.10-stable` or later.
|
| CVE-2026-59821 |
|
Code Injection in litellm (CVE-2026-59821)
code injection in litellm (CVE-2026-59821). Successful exploitation can lead to full system takeover. Exploitable via `POST /guardrails`. Mitigation: upgrade to `1.82.0-stable` or later.
|
| CVE-2026-59820 |
|
Path Traversal in litellm (CVE-2026-59820)
path traversal in litellm (CVE-2026-59820). Data can be tampered with by attackers. Exploitable via `POST /v1/skills`. Mitigation: upgrade to `1.83.7-stable` or later.
|
| CVE-2026-59822 KEV |
|
[KEV] Authentication Bypass in Berriai litellm (CVE-2026-59822)
authentication bypass in Berriai litellm (CVE-2026-59822). Confidential information can be exposed externally. Exploitable via ``Authorization``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.84.0` or later.
|
| CVE-2026-58254 |
|
Authorization Flaw in linuxfoundation (CVE-2026-58254)
vulnerability in linuxfoundation (CVE-2026-58254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58501 |
|
SSRF (Server-Side Request Forgery) in python-zeep (CVE-2026-58501)
SSRF in python-zeep (CVE-2026-58501). Confidential information can be exposed externally.
|
| CVE-2026-58214 |
|
Authorization Flaw in linuxfoundation (CVE-2026-58214)
vulnerability in linuxfoundation (CVE-2026-58214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58253 |
|
Authentication Bypass in linuxfoundation (CVE-2026-58253)
authentication bypass in linuxfoundation (CVE-2026-58253). Data can be tampered with by attackers.
|
| CVE-2026-58251 |
|
Vulnerability in linuxfoundation (CVE-2026-58251)
vulnerability in linuxfoundation (CVE-2026-58251). Confidential information can be exposed externally.
|
| CVE-2026-58252 |
|
Vulnerability in linuxfoundation (CVE-2026-58252)
vulnerability in linuxfoundation (CVE-2026-58252). Confidential information can be exposed externally.
|
| CVE-2026-58213 |
|
Vulnerability in linuxfoundation (CVE-2026-58213)
vulnerability in linuxfoundation (CVE-2026-58213). Confidential information can be exposed externally.
|
| CVE-2026-58250 |
|
Vulnerability in c (CVE-2026-58250)
vulnerability in c (CVE-2026-58250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55575 |
|
Vulnerability in liquidjs (CVE-2026-55575)
vulnerability in liquidjs (CVE-2026-55575). Risk of unauthorized operations or information disclosure. Exploitable via ``pop``. Mitigation: upgrade to `10.27.1` or later.
|
| CVE-2026-58210 |
|
Vulnerability in linuxfoundation (CVE-2026-58210)
vulnerability in linuxfoundation (CVE-2026-58210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58209 |
|
Authorization Flaw in linuxfoundation (CVE-2026-58209)
vulnerability in linuxfoundation (CVE-2026-58209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55404 |
|
Vulnerability in yt-dlp (CVE-2026-55404)
vulnerability in yt-dlp (CVE-2026-55404). Successful exploitation can lead to full system takeover. Exploitable via ``webpage_url``. Mitigation: upgrade to `2026.7.4` or later.
|
| CVE-2026-50812 |
|
Vulnerability in dos (CVE-2026-50812)
vulnerability in dos (CVE-2026-50812). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14362 |
|
Vulnerability in CVE-2026-14362 (CVE-2026-14362)
vulnerability in CVE-2026-14362 (CVE-2026-14362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59937 |
|
Vulnerability in pypdf (CVE-2026-59937)
vulnerability in pypdf (CVE-2026-59937). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.14.0` or later.
|
| CVE-2026-59924 |
|
Path Traversal in mistune (CVE-2026-59924)
path traversal in mistune (CVE-2026-59924). Confidential information can be exposed externally. Exploitable via ``Include``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59927 |
|
Vulnerability in mistune (CVE-2026-59927)
vulnerability in mistune (CVE-2026-59927). Risk of unauthorized operations or information disclosure. Exploitable via ``Include``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59926 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-59926)
cross-site scripting in mistune (CVE-2026-59926). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59929 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-59929)
cross-site scripting in mistune (CVE-2026-59929). Risk of unauthorized operations or information disclosure. Exploitable via ``safe_url``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-60102 |
|
OS Command Injection in c (CVE-2026-60102)
OS command injection in c (CVE-2026-60102). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59896 |
|
Vulnerability in hono (CVE-2026-59896)
vulnerability in hono (CVE-2026-59896). Confidential information can be exposed externally. Exploitable via ``await``. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59890 |
|
Vulnerability in setuptools (CVE-2026-59890)
vulnerability in setuptools (CVE-2026-59890). Confidential information can be exposed externally. Exploitable via ``FileList``. Mitigation: upgrade to `83.0.0` or later.
|
| CVE-2026-59895 |
|
Cross-Site Scripting (XSS) in hono (CVE-2026-59895)
cross-site scripting in hono (CVE-2026-59895). Risk of unauthorized operations or information disclosure. Exploitable via ``class``. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59923 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-59923)
cross-site scripting in mistune (CVE-2026-59923). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59879 |
|
Vulnerability in immutable (CVE-2026-59879)
vulnerability in immutable (CVE-2026-59879). Risk of unauthorized operations or information disclosure. Exploitable via ``set``. Mitigation: upgrade to `5.1.8` or later.
|
| CVE-2026-59882 |
|
Vulnerability in guzzlehttp/psr7 (CVE-2026-59882)
vulnerability in guzzlehttp/psr7 (CVE-2026-59882). Risk of unauthorized operations or information disclosure. Exploitable via ``SERVER_NAME``. Mitigation: upgrade to `2.12.3` or later.
|
| CVE-2026-59261 |
|
Vulnerability in openclaw (CVE-2026-59261)
vulnerability in openclaw (CVE-2026-59261). Confidential information can be exposed externally.
|