Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-h4mf-4v27-hggj |
|
Vulnerability in github.com/rclone/rclone (GHSA-h4mf-4v27-hggj)
vulnerability in github.com/rclone/rclone (GHSA-h4mf-4v27-hggj). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`. Mitigation: upgrade to `1.75.0` or later.
|
| CVE-2026-71311 |
|
Vulnerability in github.com/rclone/rclone (CVE-2026-71311)
vulnerability in github.com/rclone/rclone (CVE-2026-71311). Data can be tampered with by attackers. Exploitable via ``DELE``. Mitigation: upgrade to `1.75.0` or later.
|
| GHSA-8mxv-9xhp-86h4 |
|
Information Disclosure in github.com/rclone/rclone (GHSA-8mxv-9xhp-86h4)
vulnerability in github.com/rclone/rclone (GHSA-8mxv-9xhp-86h4). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `1.75.0` or later.
|
| GHSA-8v25-v8p6-qf7v |
|
Path Traversal in github.com/rclone/rclone (GHSA-8v25-v8p6-qf7v)
path traversal in github.com/rclone/rclone (GHSA-8v25-v8p6-qf7v). Risk of unauthorized operations or information disclosure. Exploitable via `GET /bucket/../root-secret.txt`. Mitigation: upgrade to `1.74.4` or later.
|
| GHSA-3x6r-wxxg-53vv |
|
Vulnerability in github.com/rclone/rclone (GHSA-3x6r-wxxg-53vv)
vulnerability in github.com/rclone/rclone (GHSA-3x6r-wxxg-53vv). Risk of unauthorized operations or information disclosure. Exploitable via ``CreateUploader``. Mitigation: upgrade to `1.75.0` or later.
|
| CVE-2026-71310 |
|
Vulnerability in github.com/rclone/rclone (CVE-2026-71310)
vulnerability in github.com/rclone/rclone (CVE-2026-71310). Risk of unauthorized operations or information disclosure. Exploitable via ``http.ReadResponse``. Mitigation: upgrade to `1.75.0` or later.
|
| CVE-2026-70618 |
|
Vulnerability in CVE-2026-70618 (CVE-2026-70618)
vulnerability in CVE-2026-70618 (CVE-2026-70618). Risk of unauthorized operations or information disclosure. Exploitable via `GET /guilds/{guild_id}/roles/{role_id}/member-ids`.
|
| CVE-2026-70617 |
|
Vulnerability in CVE-2026-70617 (CVE-2026-70617)
vulnerability in CVE-2026-70617 (CVE-2026-70617). Confidential information can be exposed externally. Exploitable via `PUT /channels/{channel_id}/recipients/{user_id}`.
|
| CVE-2026-70616 |
|
Vulnerability in CVE-2026-70616 (CVE-2026-70616)
vulnerability in CVE-2026-70616 (CVE-2026-70616). Risk of unauthorized operations or information disclosure. Exploitable via `GET /loading`.
|
| CVE-2026-70615 |
|
Vulnerability in CVE-2026-70615 (CVE-2026-70615)
vulnerability in CVE-2026-70615 (CVE-2026-70615). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69111 |
|
Vulnerability in dos (CVE-2026-69111)
vulnerability in dos (CVE-2026-69111). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68746 |
|
Vulnerability in livebook (CVE-2026-68746)
vulnerability in livebook (CVE-2026-68746). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66885 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66885)
vulnerability in csrf (CVE-2026-66885). Confidential information can be exposed externally.
|
| CVE-2026-66881 |
|
Vulnerability in path-traversal (CVE-2026-66881)
vulnerability in path-traversal (CVE-2026-66881). Data can be tampered with by attackers.
|
| CVE-2026-66298 |
|
Vulnerability in livebook (CVE-2026-66298)
vulnerability in livebook (CVE-2026-66298). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66297 |
|
OS Command Injection in livebook (CVE-2026-66297)
OS command injection in livebook (CVE-2026-66297). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55524 |
|
Vulnerability in praisonaiagents (CVE-2026-55524)
vulnerability in praisonaiagents (CVE-2026-55524). Confidential information can be exposed externally. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-55523 |
|
SSRF (Server-Side Request Forgery) in praisonaiagents (CVE-2026-55523)
SSRF in praisonaiagents (CVE-2026-55523). Risk of unauthorized operations or information disclosure. Exploitable via ``web_crawl``. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-55522 |
|
Code Injection in praisonaiagents (CVE-2026-55522)
code injection in praisonaiagents (CVE-2026-55522). Successful exploitation can lead to full system takeover. Exploitable via ``tools.py``. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-21766 |
|
Vulnerability in CVE-2026-21766 (CVE-2026-21766)
vulnerability in CVE-2026-21766 (CVE-2026-21766). Confidential information can be exposed externally.
|
| CVE-2026-18958 |
|
Vulnerability in sqli (CVE-2026-18958)
vulnerability in sqli (CVE-2026-18958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18954 |
|
Authorization Flaw in Amazon aws (CVE-2026-18954)
vulnerability in Amazon aws (CVE-2026-18954). Data can be tampered with by attackers.
|
| CVE-2026-18953 |
|
Path Traversal in Amazon aws (CVE-2026-18953)
path traversal in Amazon aws (CVE-2026-18953). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17556 |
|
Path Traversal in path-traversal (CVE-2026-17556)
path traversal in path-traversal (CVE-2026-17556). Data can be tampered with by attackers.
|
| CVE-2026-71309 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-71309)
path traversal in github.com/rclone/rclone (CVE-2026-71309). Risk of unauthorized operations or information disclosure. Exploitable via `GET /../`. Mitigation: upgrade to `1.75.0` or later.
|
| GHSA-945v-v9p3-v5xw |
|
Vulnerability in github.com/rclone/rclone (GHSA-945v-v9p3-v5xw)
vulnerability in github.com/rclone/rclone (GHSA-945v-v9p3-v5xw). Risk of unauthorized operations or information disclosure. Exploitable via ``mode``. Mitigation: upgrade to `1.74.4` or later.
|
| GHSA-gwfq-86j8-7qhv |
|
Vulnerability in github.com/rclone/rclone (GHSA-gwfq-86j8-7qhv)
vulnerability in github.com/rclone/rclone (GHSA-gwfq-86j8-7qhv). Risk of unauthorized operations or information disclosure. Exploitable via ``j.Error``. Mitigation: upgrade to `1.75.0` or later.
|
| CVE-2026-9205 |
|
Vulnerability in langflow (CVE-2026-9205)
vulnerability in langflow (CVE-2026-9205). Confidential information can be exposed externally.
|
| CVE-2026-9201 |
|
Vulnerability in langflow (CVE-2026-9201)
vulnerability in langflow (CVE-2026-9201). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9196 |
|
Code Injection in langflow (CVE-2026-9196)
code injection in langflow (CVE-2026-9196). Confidential information can be exposed externally.
|
| CVE-2026-9130 |
|
Vulnerability in langflow (CVE-2026-9130)
vulnerability in langflow (CVE-2026-9130). Confidential information can be exposed externally.
|
| CVE-2026-8478 |
|
Code Injection in langflow (CVE-2026-8478)
code injection in langflow (CVE-2026-8478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8470 |
|
Vulnerability in langflow (CVE-2026-8470)
vulnerability in langflow (CVE-2026-8470). Data can be tampered with by attackers.
|
| CVE-2026-8183 |
|
Path Traversal in langflow (CVE-2026-8183)
path traversal in langflow (CVE-2026-8183). Confidential information can be exposed externally.
|
| CVE-2026-8182 |
|
Code Injection in langflow (CVE-2026-8182)
code injection in langflow (CVE-2026-8182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7869 |
|
Path Traversal in path-traversal (CVE-2026-7869)
path traversal in path-traversal (CVE-2026-7869). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge_bases`.
|
| CVE-2026-7658 |
|
Path Traversal in path-traversal (CVE-2026-7658)
path traversal in path-traversal (CVE-2026-7658). Data can be tampered with by attackers.
|
| CVE-2026-63457 |
|
Vulnerability in dos (CVE-2026-63457)
vulnerability in dos (CVE-2026-63457). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48168 |
|
Vulnerability in CVE-2026-48168 (CVE-2026-48168)
vulnerability in CVE-2026-48168 (CVE-2026-48168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18485 |
|
Vulnerability in privilege-escalation (CVE-2026-18485)
vulnerability in privilege-escalation (CVE-2026-18485). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17633 |
|
Code Injection in langflow (CVE-2026-17633)
code injection in langflow (CVE-2026-17633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17632 |
|
Code Injection in langflow (CVE-2026-17632)
code injection in langflow (CVE-2026-17632). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17624 |
|
Code Injection in langflow (CVE-2026-17624)
code injection in langflow (CVE-2026-17624). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10547 |
|
Vulnerability in dos (CVE-2026-10547)
vulnerability in dos (CVE-2026-10547). Data can be tampered with by attackers. Exploitable via `POST /api/v1/build/{flow_id}/vertices`.
|
| CVE-2026-9081 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9081)
SSRF in ssrf (CVE-2026-9081). Confidential information can be exposed externally.
|
| CVE-2026-7657 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-7657)
SSRF in ssrf (CVE-2026-7657). Confidential information can be exposed externally.
|
| CVE-2026-70446 |
|
Vulnerability in CVE-2026-70446 (CVE-2026-70446)
vulnerability in CVE-2026-70446 (CVE-2026-70446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70443 |
|
Privilege Escalation in CVE-2026-70443 (CVE-2026-70443)
vulnerability in CVE-2026-70443 (CVE-2026-70443). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70447 |
|
Vulnerability in CVE-2026-70447 (CVE-2026-70447)
vulnerability in CVE-2026-70447 (CVE-2026-70447). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70441 |
|
Cross-Site Scripting (XSS) in CVE-2026-70441 (CVE-2026-70441)
cross-site scripting in CVE-2026-70441 (CVE-2026-70441). Risk of unauthorized operations or information disclosure.
|