Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-47414 |
|
Vulnerability in praisonai-platform (CVE-2026-47414)
vulnerability in praisonai-platform (CVE-2026-47414). Data can be tampered with by attackers. Exploitable via `PATCH /workspaces/{workspace_id}/labels/{label_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47406 |
|
Vulnerability in praisonai-platform (CVE-2026-47406)
vulnerability in praisonai-platform (CVE-2026-47406). Confidential information can be exposed externally. Exploitable via `GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47405 |
|
Vulnerability in praisonai-platform (CVE-2026-47405)
vulnerability in praisonai-platform (CVE-2026-47405). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /workspaces/{workspace_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47399 |
|
Vulnerability in praisonai-platform (CVE-2026-47399)
vulnerability in praisonai-platform (CVE-2026-47399). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_attacker}/agents/{victim_agent_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-48169 |
|
Vulnerability in praisonai-platform (CVE-2026-48169)
vulnerability in praisonai-platform (CVE-2026-48169). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_id}/issues/{issue_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47398 |
|
Code Injection in PraisonAI (CVE-2026-47398)
code injection in PraisonAI (CVE-2026-47398). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/recipes/run`. Mitigation: upgrade to `4.6.40` or later.
|
| CVE-2026-47231 |
|
Vulnerability in admidio/admidio (CVE-2026-47231)
vulnerability in admidio/admidio (CVE-2026-47231). Confidential information can be exposed externally. Exploitable via `GET /modules/documents-files.php`. Mitigation: upgrade to `5.0.10` or later.
|
| CVE-2026-47201 |
|
Vulnerability in goauthentik.io (CVE-2026-47201)
vulnerability in goauthentik.io (CVE-2026-47201). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.0-20260528144335-a370d76d23c7` or later.
|
| CVE-2026-46527 |
|
Vulnerability in c (CVE-2026-46527)
vulnerability in c (CVE-2026-46527). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
|
| CVE-2026-46599 |
|
Vulnerability in golang.org/x/image (CVE-2026-46599)
vulnerability in golang.org/x/image (CVE-2026-46599). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.0` or later.
|
| CVE-2026-47123 |
|
Vulnerability in laravel (CVE-2026-47123)
vulnerability in laravel (CVE-2026-47123). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.220` or later.
|
| CVE-2026-48555 |
|
SSRF (Server-Side Request Forgery) in spatie/laravel-medialibrary (CVE-2026-48555)
SSRF in spatie/laravel-medialibrary (CVE-2026-48555). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.23.0` or later.
|
| CVE-2026-48557 |
|
Spatie Laravel Media Library contains a file upload restriction bypass
Spatie Laravel Media Library contains a file upload restriction bypass
|
| CVE-2026-44285 |
|
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network prot...
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi...
|
| CVE-2026-44420 |
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel b...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process...
|
| CVE-2026-44421 |
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs....
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX...
|
| CVE-2026-44422 |
|
Vulnerability in freerdp (CVE-2026-44422)
vulnerability in freerdp (CVE-2026-44422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-47260 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-47260)
SSRF in phanan/koel (CVE-2026-47260). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.3.5` or later.
|
| CVE-2026-46702 |
|
Vulnerability in russh (CVE-2026-46702)
vulnerability in russh (CVE-2026-46702). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.1` or later.
|
| CVE-2026-47255 |
|
Vulnerability in @agenticmail/api (CVE-2026-47255)
vulnerability in @agenticmail/api (CVE-2026-47255). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.32` or later.
|
| CVE-2026-49372 |
|
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
|
| CVE-2026-49373 |
|
Vulnerability in jetbrains (CVE-2026-49373)
vulnerability in jetbrains (CVE-2026-49373). Confidential information can be exposed externally.
|
| CVE-2026-49374 |
|
Vulnerability in jetbrains (CVE-2026-49374)
vulnerability in jetbrains (CVE-2026-49374). Confidential information can be exposed externally.
|
| CVE-2026-49366 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
|
| CVE-2026-49367 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
|
| CVE-2026-49368 |
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
|
| CVE-2026-49371 |
|
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
|
| CVE-2026-47740 |
|
shopper/framework: Authorization bypass in multiple Livewire admin components
shopper/framework: Authorization bypass in multiple Livewire admin components
|
| CVE-2026-42929 |
|
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
|
| CVE-2026-10107 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-10107 (CVE-2026-10107)
SSRF in CVE-2026-10107 (CVE-2026-10107). Confidential information can be exposed externally.
|
| CVE-2026-10108 |
|
Path Traversal in xiaomusic (CVE-2026-10108)
path traversal in xiaomusic (CVE-2026-10108). Confidential information can be exposed externally. Exploitable via `GET /music/{file_path`. Mitigation: upgrade to `0.5.8` or later.
|
| CVE-2026-5768 |
|
Vulnerability in CVE-2026-5768 (CVE-2026-5768)
vulnerability in CVE-2026-5768 (CVE-2026-5768). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10105 |
|
SQL Injection in agno (CVE-2026-10105)
SQL injection in agno (CVE-2026-10105). Confidential information can be exposed externally.
|
| CVE-2026-47139 |
|
Vulnerability in vm2 (CVE-2026-47139)
vulnerability in vm2 (CVE-2026-47139). Confidential information can be exposed externally. Exploitable via ``NodeVM``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47209 |
|
Vulnerability in vm2 (CVE-2026-47209)
vulnerability in vm2 (CVE-2026-47209). Data can be tampered with by attackers. Exploitable via ``BaseHandler.set``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47135 |
|
Vulnerability in vm2 (CVE-2026-47135)
vulnerability in vm2 (CVE-2026-47135). Confidential information can be exposed externally. Exploitable via ``Symbol.for``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-45742 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742). Risk of unauthorized operations or information disclosure. Exploitable via ``downloadFrom``. Mitigation: upgrade to `8.33.0` or later.
|
| CVE-2026-45741 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741). Confidential information can be exposed externally.
|
| CVE-2026-44829 |
|
Path Traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829)
path traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829). Data can be tampered with by attackers. Exploitable via ``filepath.Base``. Mitigation: upgrade to `8.33.0` or later.
|
| CVE-2026-45662 |
|
OS Command Injection in CVE-2026-45662 (CVE-2026-45662)
OS command injection in CVE-2026-45662 (CVE-2026-45662). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35630 |
|
Vulnerability in openclaw (CVE-2026-35630)
vulnerability in openclaw (CVE-2026-35630). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-35674 |
|
Authorization Flaw in openclaw (CVE-2026-35674)
vulnerability in openclaw (CVE-2026-35674). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39276 |
|
Path Traversal in path-traversal (CVE-2026-39276)
path traversal in path-traversal (CVE-2026-39276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32905 |
|
Vulnerability in openclaw (CVE-2026-32905)
vulnerability in openclaw (CVE-2026-32905). Confidential information can be exposed externally.
|
| CVE-2026-10065 |
|
Buffer Overflow in CVE-2026-10065 (CVE-2026-10065)
vulnerability in CVE-2026-10065 (CVE-2026-10065). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10066 |
|
Buffer Overflow in CVE-2026-10066 (CVE-2026-10066)
vulnerability in CVE-2026-10066 (CVE-2026-10066). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10067 |
|
Buffer Overflow in CVE-2026-10067 (CVE-2026-10067)
vulnerability in CVE-2026-10067 (CVE-2026-10067). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10068 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-10068 (CVE-2026-10068)
SSRF in CVE-2026-10068 (CVE-2026-10068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10069 |
|
Vulnerability in CVE-2026-10069 (CVE-2026-10069)
vulnerability in CVE-2026-10069 (CVE-2026-10069). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25403 |
|
SQL Injection in sqli (CVE-2018-25403)
SQL injection in sqli (CVE-2018-25403). Confidential information can be exposed externally.
|