Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-20074 |
|
Vulnerability in Cisco dos (CVE-2026-20074)
vulnerability in Cisco dos (CVE-2026-20074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5190 |
|
Out-of-Bounds Write in Amazon aws (CVE-2026-5190)
out-of-bounds write in Amazon aws (CVE-2026-5190). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3828 |
|
OS Command Injection in CVE-2026-3828 (CVE-2026-3828)
OS command injection in CVE-2026-3828 (CVE-2026-3828). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42311 |
|
Vulnerability in pillow (CVE-2026-42311)
vulnerability in pillow (CVE-2026-42311). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `12.2.0` or later.
|
| CVE-2026-42461 |
|
Vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-42461)
vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-42461). Confidential information can be exposed externally. Exploitable via `GET /api/templates`. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-42301 |
|
Vulnerability in pyp2spec (CVE-2026-42301)
vulnerability in pyp2spec (CVE-2026-42301). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.14.1` or later.
|
| CVE-2026-42296 |
|
Authorization Flaw in argo-workflows (CVE-2026-42296)
vulnerability in argo-workflows (CVE-2026-42296). Confidential information can be exposed externally. Mitigation: upgrade to `3.7.14, 4.0.5` or later.
|
| CVE-2026-42297 |
|
Vulnerability in argo-workflows (CVE-2026-42297)
vulnerability in argo-workflows (CVE-2026-42297). Data can be tampered with by attackers. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-42294 |
|
Vulnerability in argo-workflows (CVE-2026-42294)
vulnerability in argo-workflows (CVE-2026-42294). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.14, 4.0.5` or later.
|
| CVE-2026-41163 |
|
Privilege Escalation in CVE-2026-41163 (CVE-2026-41163)
vulnerability in CVE-2026-41163 (CVE-2026-41163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41311 |
|
Vulnerability in liquidjs (CVE-2026-41311)
vulnerability in liquidjs (CVE-2026-41311). Risk of unauthorized operations or information disclosure. Exploitable via ``getBlockRender``. Mitigation: upgrade to `10.25.7` or later.
|
| CVE-2026-6665 |
|
Vulnerability in pgbouncer (CVE-2026-6665)
vulnerability in pgbouncer (CVE-2026-6665). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2026-41705 |
|
Vulnerability in org.springframework.ai:spring-ai-milvus-store (CVE-2026-41705)
vulnerability in org.springframework.ai:spring-ai-milvus-store (CVE-2026-41705). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.6` or later.
|
| CVE-2026-6664 |
|
Vulnerability in pgbouncer (CVE-2026-6664)
vulnerability in pgbouncer (CVE-2026-6664). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2026-44966 |
|
Vulnerability in velocityjs (CVE-2026-44966)
vulnerability in velocityjs (CVE-2026-44966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44983 |
|
Vulnerability in smallbitvec (CVE-2026-44983)
vulnerability in smallbitvec (CVE-2026-44983). Risk of unauthorized operations or information disclosure. Exploitable via ``smallbitvec``.
|
| CVE-2026-44900 |
|
Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.1` or later.
|
| CVE-2026-42556 |
|
Cross-Site Scripting (XSS) in gitroom (CVE-2026-42556)
cross-site scripting in gitroom (CVE-2026-42556). Confidential information can be exposed externally.
|
| CVE-2026-42351 |
|
Path Traversal in pygeoapi (CVE-2026-42351)
path traversal in pygeoapi (CVE-2026-42351). Confidential information can be exposed externally. Mitigation: upgrade to `0.23.3` or later.
|
| CVE-2026-42352 |
|
SSRF (Server-Side Request Forgery) in pygeoapi (CVE-2026-42352)
SSRF in pygeoapi (CVE-2026-42352). Confidential information can be exposed externally. Exploitable via ``subscriber``. Mitigation: upgrade to `0.23.3` or later.
|
| CVE-2026-42452 |
|
Vulnerability in CVE-2026-42452 (CVE-2026-42452)
vulnerability in CVE-2026-42452 (CVE-2026-42452). Confidential information can be exposed externally.
|
| CVE-2026-42345 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42345 (CVE-2026-42345)
SSRF in CVE-2026-42345 (CVE-2026-42345). Confidential information can be exposed externally.
|
| CVE-2026-42339 |
|
SSRF (Server-Side Request Forgery) in github.com/QuantumNous/new-api (CVE-2026-42339)
SSRF in github.com/QuantumNous/new-api (CVE-2026-42339). Data can be tampered with by attackers. Exploitable via `POST /v1/chat/completions`. Mitigation: upgrade to `0.9.0.5` or later.
|
| CVE-2026-41432 |
|
Vulnerability in github.com/QuantumNous/new-api (CVE-2026-41432)
vulnerability in github.com/QuantumNous/new-api (CVE-2026-41432). Data can be tampered with by attackers. Exploitable via `POST /api/user/pay`. Mitigation: upgrade to `0.12.10` or later.
|
| CVE-2026-42224 |
|
Cross-Site Scripting (XSS) in ipl/web (CVE-2026-42224)
cross-site scripting in ipl/web (CVE-2026-42224). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.10.3` or later.
|
| CVE-2026-41520 |
|
Information Disclosure in cilium (CVE-2026-41520)
vulnerability in cilium (CVE-2026-41520). Confidential information can be exposed externally. Mitigation: upgrade to `1.17.15, 1.18.9, 1.19.3` or later.
|
| CVE-2026-44843 |
|
Unsafe Deserialization in langchain-core (CVE-2026-44843)
vulnerability in langchain-core (CVE-2026-44843). Confidential information can be exposed externally. Exploitable via ``RunnableWithMessageHistory``. Mitigation: upgrade to `0.3.85` or later.
|
| CVE-2026-44328 |
|
Vulnerability in github.com/free5gc/smf (CVE-2026-44328)
vulnerability in github.com/free5gc/smf (CVE-2026-44328). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /upi/v1/upNodesLinks/{upNodeRef}`. Mitigation: upgrade to `1.4.3` or later.
|
| CVE-2026-44325 |
|
Vulnerability in github.com/free5gc/nrf (CVE-2026-44325)
vulnerability in github.com/free5gc/nrf (CVE-2026-44325). Risk of unauthorized operations or information disclosure. Exploitable via `POST /oauth2/token`. Mitigation: upgrade to `1.4.3` or later.
|
| CVE-2026-44322 |
|
Vulnerability in github.com/free5gc/nef (CVE-2026-44322)
vulnerability in github.com/free5gc/nef (CVE-2026-44322). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId}`. Mitigation: upgrade to `1.2.3` or later.
|
| CVE-2026-44321 |
|
Vulnerability in github.com/free5gc/smf (CVE-2026-44321)
vulnerability in github.com/free5gc/smf (CVE-2026-44321). Risk of unauthorized operations or information disclosure. Exploitable via `POST /upi/v1/upNodesLinks`.
|
| CVE-2026-44320 |
|
Vulnerability in github.com/free5gc/nef (CVE-2026-44320)
vulnerability in github.com/free5gc/nef (CVE-2026-44320). Risk of unauthorized operations or information disclosure. Exploitable via ``NotifId``.
|
| CVE-2026-44319 |
|
Vulnerability in github.com/free5gc/nef (CVE-2026-44319)
vulnerability in github.com/free5gc/nef (CVE-2026-44319). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.2.3` or later.
|
| CVE-2026-44316 |
|
Vulnerability in github.com/free5gc/pcf (CVE-2026-44316)
vulnerability in github.com/free5gc/pcf (CVE-2026-44316). Risk of unauthorized operations or information disclosure. Exploitable via `POST /npcf-smpolicycontrol/v1/sm-policies`. Mitigation: upgrade to `1.4.2` or later.
|
| CVE-2026-44566 |
|
Path Traversal in open-webui (CVE-2026-44566)
path traversal in open-webui (CVE-2026-44566). Risk of unauthorized operations or information disclosure. Exploitable via ``file``. Mitigation: upgrade to `0.1.124` or later.
|
| CVE-2026-44567 |
|
Vulnerability in open-webui (CVE-2026-44567)
vulnerability in open-webui (CVE-2026-44567). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/auths/signup`. Mitigation: upgrade to `0.1.124` or later.
|
| CVE-2026-44549 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-44549)
cross-site scripting in open-webui (CVE-2026-44549). Confidential information can be exposed externally. Exploitable via ``XLSX.utils.sheet_to_html``. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-44832 |
|
Vulnerability in snipe/snipe-it (CVE-2026-44832)
vulnerability in snipe/snipe-it (CVE-2026-44832). Successful exploitation can lead to full system takeover. Exploitable via ``users.edit``. Mitigation: upgrade to `8.4.1` or later.
|
| CVE-2026-42205 |
|
Vulnerability in avo (CVE-2026-42205)
vulnerability in avo (CVE-2026-42205). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/resources/posts/actions`. Mitigation: upgrade to `3.31.2` or later.
|
| CVE-2026-41486 |
|
Code Injection in ray (CVE-2026-41486)
code injection in ray (CVE-2026-41486). Successful exploitation can lead to full system takeover. Exploitable via ``ray.data.arrow_tensor``. Mitigation: upgrade to `2.55.0` or later.
|
| CVE-2026-44400 |
|
Vulnerability in mailenable (CVE-2026-44400)
vulnerability in mailenable (CVE-2026-44400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44209 |
|
Vulnerability in banks (CVE-2026-44209)
vulnerability in banks (CVE-2026-44209). Successful exploitation can lead to full system takeover. Exploitable via ``banks``. Mitigation: upgrade to `2.4.2` or later.
|
| CVE-2026-44728 |
|
Code Injection in @babel/plugin-transform-modules-systemjs (CVE-2026-44728)
code injection in @babel/plugin-transform-modules-systemjs (CVE-2026-44728). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.0-alpha.13` or later.
|
| CVE-2026-7807 |
|
Path Traversal in smartertools (CVE-2026-7807)
path traversal in smartertools (CVE-2026-7807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42189 |
|
Vulnerability in russh (CVE-2026-42189)
vulnerability in russh (CVE-2026-42189). Risk of unauthorized operations or information disclosure. Exploitable via ``read_userauth_info_response``. Mitigation: upgrade to `0.60.1` or later.
|
| CVE-2026-44554 |
|
Vulnerability in open-webui (CVE-2026-44554)
vulnerability in open-webui (CVE-2026-44554). Data can be tampered with by attackers. Exploitable via `POST /api/v1/retrieval/process/web`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44556 |
|
Vulnerability in open-webui (CVE-2026-44556)
vulnerability in open-webui (CVE-2026-44556). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44555 |
|
Vulnerability in open-webui (CVE-2026-44555)
vulnerability in open-webui (CVE-2026-44555). Confidential information can be exposed externally. Exploitable via `POST /api/v1/models/create`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44552 |
|
Vulnerability in open-webui (CVE-2026-44552)
vulnerability in open-webui (CVE-2026-44552). Confidential information can be exposed externally. Exploitable via ``REDIS_KEY_PREFIX``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44553 |
|
Vulnerability in open-webui (CVE-2026-44553)
vulnerability in open-webui (CVE-2026-44553). Confidential information can be exposed externally. Exploitable via `POST /api/v1/users/{B_id}/update`. Mitigation: upgrade to `0.9.0` or later.
|