Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-61736 |
|
Vulnerability in lightrag-hku (CVE-2026-61736)
vulnerability in lightrag-hku (CVE-2026-61736). Confidential information can be exposed externally. Mitigation: upgrade to `1.5.4` or later.
|
| CVE-2026-61684 |
|
Vulnerability in CVE-2026-61684 (CVE-2026-61684)
vulnerability in CVE-2026-61684 (CVE-2026-61684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61646 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61646)
SSRF in ssrf (CVE-2026-61646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61644 |
|
Authorization Flaw in CVE-2026-61644 (CVE-2026-61644)
vulnerability in CVE-2026-61644 (CVE-2026-61644). Confidential information can be exposed externally. Exploitable via `POST /api/core/chat/record/getCollectionQuote`.
|
| CVE-2026-61613 |
|
Vulnerability in CVE-2026-61613 (CVE-2026-61613)
vulnerability in CVE-2026-61613 (CVE-2026-61613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54563 |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54563)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54563). Confidential information can be exposed externally. Exploitable via `GET /dav/`. Mitigation: upgrade to `4.0.0-20260606032813-26b6b1044b02` or later.
|
| CVE-2026-54562 |
|
SSRF (Server-Side Request Forgery) in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54562)
SSRF in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54562). Confidential information can be exposed externally. Exploitable via `POST /api/v4/workflow/download`. Mitigation: upgrade to `4.0.0-20260606025411-aaebf317a78f` or later.
|
| CVE-2026-54560 |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54560)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54560). Confidential information can be exposed externally. Exploitable via `POST /api/v4/session/oauth/token`. Mitigation: upgrade to `4.0.0-20260606015557-ed20843dc3df` or later.
|
| CVE-2026-33213 |
|
Open Redirect in redash (CVE-2026-33213)
vulnerability in redash (CVE-2026-33213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62175 |
|
Vulnerability in CVE-2026-62175 (CVE-2026-62175)
vulnerability in CVE-2026-62175 (CVE-2026-62175). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61871 |
|
Vulnerability in dos (CVE-2026-61871)
vulnerability in dos (CVE-2026-61871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61869 |
|
Vulnerability in dos (CVE-2026-61869)
vulnerability in dos (CVE-2026-61869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61873 |
|
Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
|
| CVE-2026-61867 |
|
Vulnerability in dos (CVE-2026-61867)
vulnerability in dos (CVE-2026-61867). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61872 |
|
Vulnerability in CVE-2026-61872 (CVE-2026-61872)
vulnerability in CVE-2026-61872 (CVE-2026-61872). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61868 |
|
Vulnerability in dos (CVE-2026-61868)
vulnerability in dos (CVE-2026-61868). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61864 |
|
Vulnerability in CVE-2026-61864 (CVE-2026-61864)
vulnerability in CVE-2026-61864 (CVE-2026-61864). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61865 |
|
Vulnerability in CVE-2026-61865 (CVE-2026-61865)
vulnerability in CVE-2026-61865 (CVE-2026-61865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61866 |
|
Vulnerability in imagemagick (CVE-2026-61866)
vulnerability in imagemagick (CVE-2026-61866). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61464 |
|
Vulnerability in dos (CVE-2026-61464)
vulnerability in dos (CVE-2026-61464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61452 |
|
Vulnerability in CVE-2026-61452 (CVE-2026-61452)
vulnerability in CVE-2026-61452 (CVE-2026-61452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61859 |
|
Vulnerability in imagemagick (CVE-2026-61859)
vulnerability in imagemagick (CVE-2026-61859). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61446 |
|
Code Injection in path-traversal (CVE-2026-61446)
code injection in path-traversal (CVE-2026-61446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61438 |
|
OS Command Injection in CVE-2026-61438 (CVE-2026-61438)
OS command injection in CVE-2026-61438 (CVE-2026-61438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61453 |
|
Cross-Site Scripting (XSS) in CVE-2026-61453 (CVE-2026-61453)
cross-site scripting in CVE-2026-61453 (CVE-2026-61453). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2026-61449 |
|
Vulnerability in CVE-2026-61449 (CVE-2026-61449)
vulnerability in CVE-2026-61449 (CVE-2026-61449). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2026-61443 |
|
Path Traversal in CVE-2026-61443 (CVE-2026-61443)
path traversal in CVE-2026-61443 (CVE-2026-61443). Confidential information can be exposed externally.
|
| CVE-2026-61440 |
|
Vulnerability in CVE-2026-61440 (CVE-2026-61440)
vulnerability in CVE-2026-61440 (CVE-2026-61440). Data can be tampered with by attackers.
|
| CVE-2026-61451 |
|
Open Redirect in CVE-2026-61451 (CVE-2026-61451)
vulnerability in CVE-2026-61451 (CVE-2026-61451). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/auth/forgot-password`.
|
| CVE-2026-61863 |
|
Vulnerability in imagemagick (CVE-2026-61863)
vulnerability in imagemagick (CVE-2026-61863). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61862 |
|
Out-of-Bounds Read in CVE-2026-61862 (CVE-2026-61862)
vulnerability in CVE-2026-61862 (CVE-2026-61862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61860 |
|
Use-After-Free in dos (CVE-2026-61860)
vulnerability in dos (CVE-2026-61860). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61457 |
|
Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59236 |
|
Vulnerability in CVE-2026-59236 (CVE-2026-59236)
vulnerability in CVE-2026-59236 (CVE-2026-59236). Risk of unauthorized operations or information disclosure. Exploitable via `POST /customer/import/excel/save`.
|
| CVE-2026-61435 |
|
Authentication Bypass in CVE-2026-61435 (CVE-2026-61435)
authentication bypass in CVE-2026-61435 (CVE-2026-61435). Data can be tampered with by attackers. Exploitable via `GET /api/v1/agents`.
|
| CVE-2026-61436 |
|
Authentication Bypass in CVE-2026-61436 (CVE-2026-61436)
authentication bypass in CVE-2026-61436 (CVE-2026-61436). Data can be tampered with by attackers.
|
| CVE-2026-61433 |
|
Code Injection in CVE-2026-61433 (CVE-2026-61433)
code injection in CVE-2026-61433 (CVE-2026-61433). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60085 |
|
Vulnerability in CVE-2026-60085 (CVE-2026-60085)
vulnerability in CVE-2026-60085 (CVE-2026-60085). Confidential information can be exposed externally.
|
| CVE-2026-59254 |
|
Vulnerability in n8n (CVE-2026-59254)
vulnerability in n8n (CVE-2026-59254). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.27.4` or later.
|
| CVE-2026-61430 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61430)
SSRF in ssrf (CVE-2026-61430). Confidential information can be exposed externally.
|
| CVE-2026-61427 |
|
Vulnerability in CVE-2026-61427 (CVE-2026-61427)
vulnerability in CVE-2026-61427 (CVE-2026-61427). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| CVE-2026-60087 |
|
Authorization Flaw in CVE-2026-60087 (CVE-2026-60087)
vulnerability in CVE-2026-60087 (CVE-2026-60087). Data can be tampered with by attackers.
|
| CVE-2026-59259 |
|
Vulnerability in n8n (CVE-2026-59259)
vulnerability in n8n (CVE-2026-59259). Confidential information can be exposed externally. Mitigation: upgrade to `2.27.4` or later.
|
| CVE-2026-57996 |
|
Privilege Escalation in privilege-escalation (CVE-2026-57996)
vulnerability in privilege-escalation (CVE-2026-57996). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/api/user/add`.
|
| CVE-2026-56339 |
|
Vulnerability in CVE-2026-56339 (CVE-2026-56339)
vulnerability in CVE-2026-56339 (CVE-2026-56339). Confidential information can be exposed externally.
|
| CVE-2026-58655 |
|
Code Injection in CVE-2026-58655 (CVE-2026-58655)
code injection in CVE-2026-58655 (CVE-2026-58655). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56764 |
|
Vulnerability in CVE-2026-56764 (CVE-2026-56764)
vulnerability in CVE-2026-56764 (CVE-2026-56764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56699 |
|
Vulnerability in CVE-2026-56699 (CVE-2026-56699)
vulnerability in CVE-2026-56699 (CVE-2026-56699). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56398 |
|
Vulnerability in openwebui (CVE-2026-56398)
vulnerability in openwebui (CVE-2026-56398). Confidential information can be exposed externally.
|
| CVE-2026-56400 |
|
Vulnerability in openwebui (CVE-2026-56400)
vulnerability in openwebui (CVE-2026-56400). Successful exploitation can lead to full system takeover.
|