Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2018-25422 |
|
SQL Injection in sqli (CVE-2018-25422)
SQL injection in sqli (CVE-2018-25422). Confidential information can be exposed externally.
|
| CVE-2018-25424 |
|
SQL Injection in sqli (CVE-2018-25424)
SQL injection in sqli (CVE-2018-25424). Confidential information can be exposed externally.
|
| CVE-2018-25425 |
|
SQL Injection in c (CVE-2018-25425)
SQL injection in c (CVE-2018-25425). Confidential information can be exposed externally.
|
| CVE-2018-25421 |
|
Path Traversal in path-traversal (CVE-2018-25421)
path traversal in path-traversal (CVE-2018-25421). Confidential information can be exposed externally.
|
| CVE-2018-25413 |
|
SQL Injection in sqli (CVE-2018-25413)
SQL injection in sqli (CVE-2018-25413). Confidential information can be exposed externally.
|
| CVE-2018-25414 |
|
SQL Injection in sqli (CVE-2018-25414)
SQL injection in sqli (CVE-2018-25414). Confidential information can be exposed externally.
|
| CVE-2018-25415 |
|
SQL Injection in sqli (CVE-2018-25415)
SQL injection in sqli (CVE-2018-25415). Confidential information can be exposed externally.
|
| CVE-2018-25416 |
|
SQL Injection in sqli (CVE-2018-25416)
SQL injection in sqli (CVE-2018-25416). Confidential information can be exposed externally.
|
| CVE-2018-25417 |
|
SQL Injection in sqli (CVE-2018-25417)
SQL injection in sqli (CVE-2018-25417). Confidential information can be exposed externally.
|
| CVE-2018-25418 |
|
SQL Injection in sqli (CVE-2018-25418)
SQL injection in sqli (CVE-2018-25418). Confidential information can be exposed externally.
|
| CVE-2018-25419 |
|
SQL Injection in sqli (CVE-2018-25419)
SQL injection in sqli (CVE-2018-25419). Confidential information can be exposed externally.
|
| CVE-2018-25407 |
|
SQL Injection in sqli (CVE-2018-25407)
SQL injection in sqli (CVE-2018-25407). Confidential information can be exposed externally.
|
| CVE-2018-25410 |
|
SQL Injection in sqli (CVE-2018-25410)
SQL injection in sqli (CVE-2018-25410). Confidential information can be exposed externally.
|
| CVE-2018-25411 |
|
SQL Injection in sqli (CVE-2018-25411)
SQL injection in sqli (CVE-2018-25411). Confidential information can be exposed externally.
|
| CVE-2018-25408 |
|
Path Traversal in path-traversal (CVE-2018-25408)
path traversal in path-traversal (CVE-2018-25408). Confidential information can be exposed externally.
|
| CVE-2018-25412 |
|
Vulnerability in deltasql-project (CVE-2018-25412)
vulnerability in deltasql-project (CVE-2018-25412). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25409 |
|
Unrestricted File Upload in CVE-2018-25409 (CVE-2018-25409)
vulnerability in CVE-2018-25409 (CVE-2018-25409). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25406 |
|
SQL Injection in sqli (CVE-2018-25406)
SQL injection in sqli (CVE-2018-25406). Confidential information can be exposed externally.
|
| CVE-2018-25405 |
|
SQL Injection in sqli (CVE-2018-25405)
SQL injection in sqli (CVE-2018-25405). Confidential information can be exposed externally.
|
| CVE-2026-10120 |
|
Buffer Overflow in CVE-2026-10120 (CVE-2026-10120)
vulnerability in CVE-2026-10120 (CVE-2026-10120). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10119 |
|
Buffer Overflow in CVE-2026-10119 (CVE-2026-10119)
vulnerability in CVE-2026-10119 (CVE-2026-10119). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46242 |
|
Use-After-Free in Google linux (CVE-2026-46242)
vulnerability in Google linux (CVE-2026-46242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10117 |
|
Vulnerability in c (CVE-2026-10117)
vulnerability in c (CVE-2026-10117). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10116 |
|
Vulnerability in c (CVE-2026-10116)
vulnerability in c (CVE-2026-10116). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10115 |
|
Vulnerability in c (CVE-2026-10115)
vulnerability in c (CVE-2026-10115). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10114 |
|
Buffer Overflow in c (CVE-2026-10114)
vulnerability in c (CVE-2026-10114). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9757 |
|
SQL Injection in wordpress (CVE-2026-9757)
SQL injection in wordpress (CVE-2026-9757). Confidential information can be exposed externally.
|
| CVE-2026-7465 |
|
Privilege Escalation in wordpress (CVE-2026-7465)
vulnerability in wordpress (CVE-2026-7465). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10113 |
|
Vulnerability in c (CVE-2026-10113)
vulnerability in c (CVE-2026-10113). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10111 |
|
Vulnerability in sqli (CVE-2026-10111)
vulnerability in sqli (CVE-2026-10111). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10112 |
|
Cross-Site Scripting (XSS) in CVE-2026-10112 (CVE-2026-10112)
cross-site scripting in CVE-2026-10112 (CVE-2026-10112). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5071 |
|
Out-of-Bounds Read in zephyrproject (CVE-2026-5071)
vulnerability in zephyrproject (CVE-2026-5071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10110 |
|
Vulnerability in sqli (CVE-2026-10110)
vulnerability in sqli (CVE-2026-10110). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47416 |
|
Privilege Escalation in praisonai-platform (CVE-2026-47416)
vulnerability in praisonai-platform (CVE-2026-47416). Confidential information can be exposed externally. Exploitable via `PATCH /workspaces/{workspace_id}/members/{user_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47409 |
|
Privilege Escalation in praisonai-platform (CVE-2026-47409)
vulnerability in praisonai-platform (CVE-2026-47409). Data can be tampered with by attackers. Exploitable via `DELETE /workspaces/{workspace_id}/members/{user_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47410 |
|
Vulnerability in praisonai-platform (CVE-2026-47410)
vulnerability in praisonai-platform (CVE-2026-47410). Successful exploitation can lead to full system takeover. Exploitable via `POST /auth/register`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47405 |
|
Vulnerability in praisonai-platform (CVE-2026-47405)
vulnerability in praisonai-platform (CVE-2026-47405). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /workspaces/{workspace_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47399 |
|
Vulnerability in praisonai-platform (CVE-2026-47399)
vulnerability in praisonai-platform (CVE-2026-47399). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_attacker}/agents/{victim_agent_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47407 |
|
Privilege Escalation in praisonai-platform (CVE-2026-47407)
vulnerability in praisonai-platform (CVE-2026-47407). Risk of unauthorized operations or information disclosure. Exploitable via `GET /agents/{agent_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-48169 |
|
Vulnerability in praisonai-platform (CVE-2026-48169)
vulnerability in praisonai-platform (CVE-2026-48169). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_id}/issues/{issue_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47397 |
|
Path Traversal in PraisonAI (CVE-2026-47397)
path traversal in PraisonAI (CVE-2026-47397). Risk of unauthorized operations or information disclosure. Exploitable via ``write_file``. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-47391 |
|
Vulnerability in PraisonAI (CVE-2026-47391)
vulnerability in PraisonAI (CVE-2026-47391). Successful exploitation can lead to full system takeover. Exploitable via `POST /a2a`. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-47394 |
|
Path Traversal in PraisonAI (CVE-2026-47394)
path traversal in PraisonAI (CVE-2026-47394). Risk of unauthorized operations or information disclosure. Exploitable via ``praisonai.rules.create``. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-47392 |
|
Vulnerability in praisonaiagents (CVE-2026-47392)
vulnerability in praisonaiagents (CVE-2026-47392). Successful exploitation can lead to full system takeover. Exploitable via ``print.__self__``. Mitigation: upgrade to `1.6.40` or later.
|
| CVE-2026-47395 |
|
Information Disclosure in praisonaiagents (CVE-2026-47395)
vulnerability in praisonaiagents (CVE-2026-47395). Confidential information can be exposed externally. Exploitable via ``MentionsParser``. Mitigation: upgrade to `1.6.40` or later.
|
| CVE-2026-47393 |
|
Vulnerability in PraisonAI (CVE-2026-47393)
vulnerability in PraisonAI (CVE-2026-47393). Successful exploitation can lead to full system takeover. Exploitable via ``auth_enabled``. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-47396 |
|
Vulnerability in PraisonAI (CVE-2026-47396)
vulnerability in PraisonAI (CVE-2026-47396). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/agents`. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-47390 |
|
SSRF (Server-Side Request Forgery) in praisonaiagents (CVE-2026-47390)
SSRF in praisonaiagents (CVE-2026-47390). Confidential information can be exposed externally. Exploitable via ``spider_tools``. Mitigation: upgrade to `1.6.40` or later.
|
| CVE-2026-47398 |
|
Code Injection in PraisonAI (CVE-2026-47398)
code injection in PraisonAI (CVE-2026-47398). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/recipes/run`. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-9831 |
|
Vulnerability in CVE-2026-9831 (CVE-2026-9831)
vulnerability in CVE-2026-9831 (CVE-2026-9831). Confidential information can be exposed externally.
|