Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
GHSA-mf8r-wm2w-f8c5 Information Disclosure in thorsten/phpmyfaq (GHSA-mf8r-wm2w-f8c5)
vulnerability in thorsten/phpmyfaq (GHSA-mf8r-wm2w-f8c5). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4.0/faqs/tags/{tagId}`. Mitigation: upgrade to `4.1.5` or later.
GHSA-88g4-74f3-63x9 Path Traversal in thorsten/phpmyfaq (GHSA-88g4-74f3-63x9)
path traversal in thorsten/phpmyfaq (GHSA-88g4-74f3-63x9). Risk of unauthorized operations or information disclosure. Exploitable via ``false``. Mitigation: upgrade to `4.1.5` or later.
CVE-2026-59189 Out-of-Bounds Read in CVE-2026-59189 (CVE-2026-59189)
vulnerability in CVE-2026-59189 (CVE-2026-59189). Risk of unauthorized operations or information disclosure.
CVE-2026-59187 Vulnerability in CVE-2026-59187 (CVE-2026-59187)
vulnerability in CVE-2026-59187 (CVE-2026-59187). Risk of unauthorized operations or information disclosure.
CVE-2026-59186 Vulnerability in CVE-2026-59186 (CVE-2026-59186)
vulnerability in CVE-2026-59186 (CVE-2026-59186). Risk of unauthorized operations or information disclosure.
CVE-2026-59184 Use-After-Free in CVE-2026-59184 (CVE-2026-59184)
vulnerability in CVE-2026-59184 (CVE-2026-59184). Risk of unauthorized operations or information disclosure.
CVE-2026-13478 Out-of-Bounds Read in c (CVE-2026-13478)
vulnerability in c (CVE-2026-13478). Risk of unauthorized operations or information disclosure.
CVE-2026-13217 Vulnerability in c (CVE-2026-13217)
vulnerability in c (CVE-2026-13217). Risk of unauthorized operations or information disclosure.
CVE-2026-13216 Out-of-Bounds Write in c (CVE-2026-13216)
out-of-bounds write in c (CVE-2026-13216). Data can be tampered with by attackers.
CVE-2026-55557 Path Traversal in browse-mcp (CVE-2026-55557)
path traversal in browse-mcp (CVE-2026-55557). Risk of unauthorized operations or information disclosure. Exploitable via ``browser_download``. Mitigation: upgrade to `0.8.2` or later.
CVE-2026-55585 Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
CVE-2026-55553 Information Disclosure in urllib (CVE-2026-55553)
vulnerability in urllib (CVE-2026-55553). Confidential information can be exposed externally. Exploitable via `Cookie header`. Mitigation: upgrade to `2.44.1` or later.
CVE-2026-55571 Vulnerability in djust (CVE-2026-55571)
vulnerability in djust (CVE-2026-55571). Data can be tampered with by attackers. Exploitable via ``LiveViewConsumer``. Mitigation: upgrade to `1.0.4` or later.
CVE-2026-55640 Vulnerability in nextcloud-mcp-server (CVE-2026-55640)
vulnerability in nextcloud-mcp-server (CVE-2026-55640). Data can be tampered with by attackers. Exploitable via `POST /webhooks/nextcloud`. Mitigation: upgrade to `0.117.2` or later.
GHSA-8qx3-8gm5-9cj2 Vulnerability in pickem (GHSA-8qx3-8gm5-9cj2)
vulnerability in pickem (GHSA-8qx3-8gm5-9cj2). Risk of unauthorized operations or information disclosure. Exploitable via ``chrome.row``. Mitigation: upgrade to `1.0.7` or later.
GHSA-8cp3-qxj6-px34 SSRF (Server-Side Request Forgery) in utcp-http (GHSA-8cp3-qxj6-px34)
SSRF in utcp-http (GHSA-8cp3-qxj6-px34). Risk of unauthorized operations or information disclosure. Exploitable via ``tokenUrl``. Mitigation: upgrade to `1.1.4` or later.
GHSA-ppx3-28rw-8fpf SSRF (Server-Side Request Forgery) in utcp-gql (GHSA-ppx3-28rw-8fpf)
SSRF in utcp-gql (GHSA-ppx3-28rw-8fpf). Risk of unauthorized operations or information disclosure. Exploitable via ``startswith``. Mitigation: upgrade to `1.1.1` or later.
GHSA-9qhg-99ww-9mqc SSRF (Server-Side Request Forgery) in utcp-http (GHSA-9qhg-99ww-9mqc)
SSRF in utcp-http (GHSA-9qhg-99ww-9mqc). Risk of unauthorized operations or information disclosure. Exploitable via ``HttpCommunicationProtocol.call_tool``. Mitigation: upgrade to `1.1.4` or later.
CVE-2026-55580 OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55580)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55580). Risk of unauthorized operations or information disclosure. Exploitable via ``config.go``. Mitigation: upgrade to `0.6.0` or later.
CVE-2026-55581 OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55581)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55581). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
CVE-2026-55582 OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55582)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55582). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
CVE-2026-79717 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-79717)
SSRF in ssrf (CVE-2026-79717). Risk of unauthorized operations or information disclosure.
CVE-2026-16599 Vulnerability in dos (CVE-2026-16599)
vulnerability in dos (CVE-2026-16599). Risk of unauthorized operations or information disclosure.
CVE-2026-70551 SSRF (Server-Side Request Forgery) in CVE-2026-70551 (CVE-2026-70551)
SSRF in CVE-2026-70551 (CVE-2026-70551). Confidential information can be exposed externally.
CVE-2026-16286 Unrestricted File Upload in CVE-2026-16286 (CVE-2026-16286)
vulnerability in CVE-2026-16286 (CVE-2026-16286). Successful exploitation can lead to full system takeover.
CVE-2026-69104 Vulnerability in CVE-2026-69104 (CVE-2026-69104)
vulnerability in CVE-2026-69104 (CVE-2026-69104). Risk of unauthorized operations or information disclosure.
CVE-2026-15310 Vulnerability in CVE-2026-15310 (CVE-2026-15310)
vulnerability in CVE-2026-15310 (CVE-2026-15310). Risk of unauthorized operations or information disclosure.
CVE-2026-79622 Path Traversal in path-traversal (CVE-2026-79622)
path traversal in path-traversal (CVE-2026-79622). Risk of unauthorized operations or information disclosure.
CVE-2026-79623 Command Injection in CVE-2026-79623 (CVE-2026-79623)
command injection in CVE-2026-79623 (CVE-2026-79623). Risk of unauthorized operations or information disclosure.
CVE-2026-75803 Vulnerability in CVE-2026-75803 (CVE-2026-75803)
vulnerability in CVE-2026-75803 (CVE-2026-75803). Risk of unauthorized operations or information disclosure.
CVE-2026-78885 Authentication Bypass in CVE-2026-78885 (CVE-2026-78885)
authentication bypass in CVE-2026-78885 (CVE-2026-78885). Risk of unauthorized operations or information disclosure.
CVE-2026-78887 Vulnerability in CVE-2026-78887 (CVE-2026-78887)
vulnerability in CVE-2026-78887 (CVE-2026-78887). Risk of unauthorized operations or information disclosure.
CVE-2026-79406 Vulnerability in CVE-2026-79406 (CVE-2026-79406)
vulnerability in CVE-2026-79406 (CVE-2026-79406). Risk of unauthorized operations or information disclosure.
CVE-2026-79655 Vulnerability in path-traversal (CVE-2026-79655)
vulnerability in path-traversal (CVE-2026-79655). Successful exploitation can lead to full system takeover.
CVE-2026-57863 Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
CVE-2026-63076 Vulnerability in dos (CVE-2026-63076)
vulnerability in dos (CVE-2026-63076). Risk of unauthorized operations or information disclosure.
CVE-2026-63074 Vulnerability in dos (CVE-2026-63074)
vulnerability in dos (CVE-2026-63074). Risk of unauthorized operations or information disclosure.
CVE-2026-14457 Vulnerability in dos (CVE-2026-14457)
vulnerability in dos (CVE-2026-14457). Risk of unauthorized operations or information disclosure.
CVE-2026-77998 Vulnerability in CVE-2026-77998 (CVE-2026-77998)
vulnerability in CVE-2026-77998 (CVE-2026-77998). Risk of unauthorized operations or information disclosure.
CVE-2026-63073 Vulnerability in dos (CVE-2026-63073)
vulnerability in dos (CVE-2026-63073). Risk of unauthorized operations or information disclosure.
CVE-2026-63075 Vulnerability in dos (CVE-2026-63075)
vulnerability in dos (CVE-2026-63075). Risk of unauthorized operations or information disclosure.
CVE-2026-78886 Path Traversal in path-traversal (CVE-2026-78886)
path traversal in path-traversal (CVE-2026-78886). Risk of unauthorized operations or information disclosure.
CVE-2026-78581 Vulnerability in CVE-2026-78581 (CVE-2026-78581)
vulnerability in CVE-2026-78581 (CVE-2026-78581). Risk of unauthorized operations or information disclosure.
CVE-2026-54874 Vulnerability in dos (CVE-2026-54874)
vulnerability in dos (CVE-2026-54874). Risk of unauthorized operations or information disclosure.
CVE-2026-18798 Vulnerability in dos (CVE-2026-18798)
vulnerability in dos (CVE-2026-18798). Risk of unauthorized operations or information disclosure.
CVE-2026-63072 Out-of-Bounds Write in dos (CVE-2026-63072)
out-of-bounds write in dos (CVE-2026-63072). Risk of unauthorized operations or information disclosure.
CVE-2026-55546 Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
CVE-2026-55536 Vulnerability in PraisonAI (CVE-2026-55536)
vulnerability in PraisonAI (CVE-2026-55536). Confidential information can be exposed externally. Exploitable via ``start_session``. Mitigation: upgrade to `4.6.58` or later.
CVE-2026-55532 Vulnerability in PraisonAI (CVE-2026-55532)
vulnerability in PraisonAI (CVE-2026-55532). Data can be tampered with by attackers. Exploitable via `Host header`. Mitigation: upgrade to `4.6.58` or later.
CVE-2026-55624 Vulnerability in CVE-2026-55624 (CVE-2026-55624)
vulnerability in CVE-2026-55624 (CVE-2026-55624). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →