Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-47414 Vulnerability in praisonai-platform (CVE-2026-47414)
vulnerability in praisonai-platform (CVE-2026-47414). Data can be tampered with by attackers. Exploitable via `PATCH /workspaces/{workspace_id}/labels/{label_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47406 Vulnerability in praisonai-platform (CVE-2026-47406)
vulnerability in praisonai-platform (CVE-2026-47406). Confidential information can be exposed externally. Exploitable via `GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47405 Vulnerability in praisonai-platform (CVE-2026-47405)
vulnerability in praisonai-platform (CVE-2026-47405). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /workspaces/{workspace_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47399 Vulnerability in praisonai-platform (CVE-2026-47399)
vulnerability in praisonai-platform (CVE-2026-47399). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_attacker}/agents/{victim_agent_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-48169 Vulnerability in praisonai-platform (CVE-2026-48169)
vulnerability in praisonai-platform (CVE-2026-48169). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/workspaces/{workspace_id}/issues/{issue_id}`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47398 Code Injection in PraisonAI (CVE-2026-47398)
code injection in PraisonAI (CVE-2026-47398). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/recipes/run`. Mitigation: upgrade to `4.6.40` or later.
CVE-2026-47231 Vulnerability in admidio/admidio (CVE-2026-47231)
vulnerability in admidio/admidio (CVE-2026-47231). Confidential information can be exposed externally. Exploitable via `GET /modules/documents-files.php`. Mitigation: upgrade to `5.0.10` or later.
CVE-2026-47201 Vulnerability in goauthentik.io (CVE-2026-47201)
vulnerability in goauthentik.io (CVE-2026-47201). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.0-20260528144335-a370d76d23c7` or later.
CVE-2026-46527 Vulnerability in c (CVE-2026-46527)
vulnerability in c (CVE-2026-46527). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
CVE-2026-46599 Vulnerability in golang.org/x/image (CVE-2026-46599)
vulnerability in golang.org/x/image (CVE-2026-46599). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.0` or later.
CVE-2026-47123 Vulnerability in laravel (CVE-2026-47123)
vulnerability in laravel (CVE-2026-47123). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.220` or later.
CVE-2026-48555 SSRF (Server-Side Request Forgery) in spatie/laravel-medialibrary (CVE-2026-48555)
SSRF in spatie/laravel-medialibrary (CVE-2026-48555). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.23.0` or later.
CVE-2026-48557 Spatie Laravel Media Library contains a file upload restriction bypass
Spatie Laravel Media Library contains a file upload restriction bypass
CVE-2026-44285 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network prot...
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi...
CVE-2026-44420 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel b...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process...
CVE-2026-44421 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs....
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX...
CVE-2026-44422 Vulnerability in freerdp (CVE-2026-44422)
vulnerability in freerdp (CVE-2026-44422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-47260 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-47260)
SSRF in phanan/koel (CVE-2026-47260). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.3.5` or later.
CVE-2026-46702 Vulnerability in russh (CVE-2026-46702)
vulnerability in russh (CVE-2026-46702). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.1` or later.
CVE-2026-47255 Vulnerability in @agenticmail/api (CVE-2026-47255)
vulnerability in @agenticmail/api (CVE-2026-47255). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.32` or later.
CVE-2026-49372 In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49373 Vulnerability in jetbrains (CVE-2026-49373)
vulnerability in jetbrains (CVE-2026-49373). Confidential information can be exposed externally.
CVE-2026-49374 Vulnerability in jetbrains (CVE-2026-49374)
vulnerability in jetbrains (CVE-2026-49374). Confidential information can be exposed externally.
CVE-2026-49366 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-49367 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49368 In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
CVE-2026-49371 In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-47740 shopper/framework: Authorization bypass in multiple Livewire admin components
shopper/framework: Authorization bypass in multiple Livewire admin components
CVE-2026-42929 Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
CVE-2026-10107 SSRF (Server-Side Request Forgery) in CVE-2026-10107 (CVE-2026-10107)
SSRF in CVE-2026-10107 (CVE-2026-10107). Confidential information can be exposed externally.
CVE-2026-10108 Path Traversal in xiaomusic (CVE-2026-10108)
path traversal in xiaomusic (CVE-2026-10108). Confidential information can be exposed externally. Exploitable via `GET /music/{file_path`. Mitigation: upgrade to `0.5.8` or later.
CVE-2026-5768 Vulnerability in CVE-2026-5768 (CVE-2026-5768)
vulnerability in CVE-2026-5768 (CVE-2026-5768). Successful exploitation can lead to full system takeover.
CVE-2026-10105 SQL Injection in agno (CVE-2026-10105)
SQL injection in agno (CVE-2026-10105). Confidential information can be exposed externally.
CVE-2026-47139 Vulnerability in vm2 (CVE-2026-47139)
vulnerability in vm2 (CVE-2026-47139). Confidential information can be exposed externally. Exploitable via ``NodeVM``. Mitigation: upgrade to `3.11.4` or later.
CVE-2026-47209 Vulnerability in vm2 (CVE-2026-47209)
vulnerability in vm2 (CVE-2026-47209). Data can be tampered with by attackers. Exploitable via ``BaseHandler.set``. Mitigation: upgrade to `3.11.4` or later.
CVE-2026-47135 Vulnerability in vm2 (CVE-2026-47135)
vulnerability in vm2 (CVE-2026-47135). Confidential information can be exposed externally. Exploitable via ``Symbol.for``. Mitigation: upgrade to `3.11.4` or later.
CVE-2026-45742 Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742). Risk of unauthorized operations or information disclosure. Exploitable via ``downloadFrom``. Mitigation: upgrade to `8.33.0` or later.
CVE-2026-45741 Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741). Confidential information can be exposed externally.
CVE-2026-44829 Path Traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829)
path traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829). Data can be tampered with by attackers. Exploitable via ``filepath.Base``. Mitigation: upgrade to `8.33.0` or later.
CVE-2026-45662 OS Command Injection in CVE-2026-45662 (CVE-2026-45662)
OS command injection in CVE-2026-45662 (CVE-2026-45662). Successful exploitation can lead to full system takeover.
CVE-2026-35630 Vulnerability in openclaw (CVE-2026-35630)
vulnerability in openclaw (CVE-2026-35630). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
CVE-2026-35674 Authorization Flaw in openclaw (CVE-2026-35674)
vulnerability in openclaw (CVE-2026-35674). Successful exploitation can lead to full system takeover.
CVE-2026-39276 Path Traversal in path-traversal (CVE-2026-39276)
path traversal in path-traversal (CVE-2026-39276). Successful exploitation can lead to full system takeover.
CVE-2026-32905 Vulnerability in openclaw (CVE-2026-32905)
vulnerability in openclaw (CVE-2026-32905). Confidential information can be exposed externally.
CVE-2026-10065 Buffer Overflow in CVE-2026-10065 (CVE-2026-10065)
vulnerability in CVE-2026-10065 (CVE-2026-10065). Successful exploitation can lead to full system takeover.
CVE-2026-10066 Buffer Overflow in CVE-2026-10066 (CVE-2026-10066)
vulnerability in CVE-2026-10066 (CVE-2026-10066). Successful exploitation can lead to full system takeover.
CVE-2026-10067 Buffer Overflow in CVE-2026-10067 (CVE-2026-10067)
vulnerability in CVE-2026-10067 (CVE-2026-10067). Successful exploitation can lead to full system takeover.
CVE-2026-10068 SSRF (Server-Side Request Forgery) in CVE-2026-10068 (CVE-2026-10068)
SSRF in CVE-2026-10068 (CVE-2026-10068). Risk of unauthorized operations or information disclosure.
CVE-2026-10069 Vulnerability in CVE-2026-10069 (CVE-2026-10069)
vulnerability in CVE-2026-10069 (CVE-2026-10069). Risk of unauthorized operations or information disclosure.
CVE-2018-25403 SQL Injection in sqli (CVE-2018-25403)
SQL injection in sqli (CVE-2018-25403). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →