Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5734 |
|
Out-of-Bounds Write in mozilla (CVE-2026-5734)
out-of-bounds write in mozilla (CVE-2026-5734). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33816 |
|
CVE-2026-33816 in github.com/jackc/pgx
CVE-2026-33816 in github.com/jackc/pgx
|
| CVE-2026-28808 |
|
Authorization Flaw in erlang (CVE-2026-28808)
vulnerability in erlang (CVE-2026-28808). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35471 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35471)
path traversal in github.com/patrickhener/goshs (CVE-2026-35471). Successful exploitation can lead to full system takeover. Exploitable via ``deleteFile``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35392 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35392)
path traversal in github.com/patrickhener/goshs (CVE-2026-35392). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35393 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-35393)
path traversal in github.com/patrickhener/goshs (CVE-2026-35393). Successful exploitation can lead to full system takeover. Exploitable via ``req.URL.Path``. Mitigation: upgrade to `1.1.5-0.20260401172448-237f3af891a9` or later.
|
| CVE-2026-35459 |
|
SSRF (Server-Side Request Forgery) in pyload-ng (CVE-2026-35459)
SSRF in pyload-ng (CVE-2026-35459). Confidential information can be exposed externally. Exploitable via ``CURLOPT_REDIR_PROTOCOLS``.
|
| CVE-2026-35184 |
|
SQL Injection in sqli (CVE-2026-35184)
SQL injection in sqli (CVE-2026-35184). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.0` or later.
|
| CVE-2026-35178 |
|
Code Injection in forceworkbench (CVE-2026-35178)
code injection in forceworkbench (CVE-2026-35178). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `65.0.0` or later.
|
| CVE-2025-54328 |
|
Vulnerability in samsung (CVE-2025-54328)
vulnerability in samsung (CVE-2025-54328). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58349 |
|
Vulnerability in samsung (CVE-2025-58349)
vulnerability in samsung (CVE-2025-58349). Confidential information can be exposed externally.
|
| CVE-2026-35174 |
|
Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
|
| CVE-2026-35030 |
|
Authentication Bypass in litellm (CVE-2026-35030)
authentication bypass in litellm (CVE-2026-35030). Confidential information can be exposed externally. Mitigation: upgrade to `1.83.0` or later.
|
| CVE-2026-34977 |
|
OS Command Injection in c (CVE-2026-34977)
OS command injection in c (CVE-2026-34977). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-34444 |
|
Vulnerability in scoder (CVE-2026-34444)
vulnerability in scoder (CVE-2026-34444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31405 |
|
Out-of-Bounds Read in linux (CVE-2026-31405)
vulnerability in linux (CVE-2026-31405). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35616 KEV |
|
[KEV] Vulnerability in Fortinet forticlient-ems (CVE-2026-35616)
vulnerability in Fortinet forticlient-ems (CVE-2026-35616). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-25687 |
|
Path Traversal in wisdom (CVE-2019-25687)
path traversal in wisdom (CVE-2019-25687). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25254 |
|
Out-of-Bounds Write in nico-ftp-project (CVE-2018-25254)
out-of-bounds write in nico-ftp-project (CVE-2018-25254). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20052 |
|
Unrestricted File Upload in snewscms (CVE-2016-20052)
vulnerability in snewscms (CVE-2016-20052). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34938 |
|
Vulnerability in praisonaiagents (CVE-2026-34938)
vulnerability in praisonaiagents (CVE-2026-34938). Successful exploitation can lead to full system takeover. Exploitable via ``str``. Mitigation: upgrade to `1.5.90` or later.
|
| CVE-2026-34952 |
|
Vulnerability in praisonai (CVE-2026-34952)
vulnerability in praisonai (CVE-2026-34952). Confidential information can be exposed externally. Exploitable via ``GatewayConfig``. Mitigation: upgrade to `4.5.97` or later.
|
| CVE-2026-34953 |
|
Authorization Flaw in praisonai (CVE-2026-34953)
vulnerability in praisonai (CVE-2026-34953). Confidential information can be exposed externally. Exploitable via ``True``. Mitigation: upgrade to `4.5.97` or later.
|
| CVE-2026-34935 |
|
OS Command Injection in praisonai (CVE-2026-34935)
OS command injection in praisonai (CVE-2026-34935). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.69` or later.
|
| CVE-2026-34934 |
|
SQL Injection in praisonai (CVE-2026-34934)
SQL injection in praisonai (CVE-2026-34934). Successful exploitation can lead to full system takeover. Exploitable via ``get_all_user_threads``. Mitigation: upgrade to `4.5.90` or later.
|
| CVE-2026-34612 |
|
SQL Injection in sqli (CVE-2026-34612)
SQL injection in sqli (CVE-2026-34612). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/main/flows/search`.
|
| CVE-2021-4477 |
|
Vulnerability in CVE-2021-4477 (CVE-2021-4477)
vulnerability in CVE-2021-4477 (CVE-2021-4477). Confidential information can be exposed externally.
|
| CVE-2017-20234 |
|
Vulnerability in CVE-2017-20234 (CVE-2017-20234)
vulnerability in CVE-2017-20234 (CVE-2017-20234). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20235 |
|
Authentication Bypass in prosoft-technology (CVE-2017-20235)
authentication bypass in prosoft-technology (CVE-2017-20235). Confidential information can be exposed externally.
|
| CVE-2017-20236 |
|
OS Command Injection in prosoft-technology (CVE-2017-20236)
OS command injection in prosoft-technology (CVE-2017-20236). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25236 |
|
Authentication Bypass in CVE-2018-25236 (CVE-2018-25236)
authentication bypass in CVE-2018-25236 (CVE-2018-25236). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27634 |
|
SQL Injection in piwigo (CVE-2026-27634)
SQL injection in piwigo (CVE-2026-27634). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25237 |
|
Vulnerability in dos (CVE-2018-25237)
vulnerability in dos (CVE-2018-25237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28766 |
|
Vulnerability in mygardyn (CVE-2026-28766)
vulnerability in mygardyn (CVE-2026-28766). Confidential information can be exposed externally.
|
| CVE-2026-25197 |
|
Vulnerability in mygardyn (CVE-2026-25197)
vulnerability in mygardyn (CVE-2026-25197). Confidential information can be exposed externally.
|
| CVE-2017-20237 |
|
Authentication Bypass in CVE-2017-20237 (CVE-2017-20237)
authentication bypass in CVE-2017-20237 (CVE-2017-20237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28798 |
|
SSRF (Server-Side Request Forgery) in zimaspace (CVE-2026-28798)
SSRF in zimaspace (CVE-2026-28798). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31402 |
|
Out-of-Bounds Write in linux (CVE-2026-31402)
out-of-bounds write in linux (CVE-2026-31402). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32186 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32186)
SSRF in ssrf (CVE-2026-32186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0545 |
|
Vulnerability in mlflow (CVE-2026-0545)
vulnerability in mlflow (CVE-2026-0545). Confidential information can be exposed externally.
|
| CVE-2026-28373 |
|
Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35216 |
|
OS Command Injection in budibase (CVE-2026-35216)
OS command injection in budibase (CVE-2026-35216). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31818 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-31818)
SSRF in ssrf (CVE-2026-31818). Confidential information can be exposed externally.
|
| CVE-2026-23455 |
|
Out-of-Bounds Read in linux (CVE-2026-23455)
vulnerability in linux (CVE-2026-23455). Confidential information can be exposed externally.
|
| CVE-2026-23450 |
|
Use-After-Free in linux (CVE-2026-23450)
vulnerability in linux (CVE-2026-23450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35171 |
|
Code Injection in kedro (CVE-2026-35171)
code injection in kedro (CVE-2026-35171). Successful exploitation can lead to full system takeover. Exploitable via ``KEDRO_LOGGING_CONFIG``. Mitigation: upgrade to `1.3.0` or later.
|
| CVE-2026-33105 |
|
Vulnerability in microsoft (CVE-2026-33105)
vulnerability in microsoft (CVE-2026-33105). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33107 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-33107)
SSRF in ssrf (CVE-2026-33107). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26135 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-26135)
SSRF in ssrf (CVE-2026-26135). Confidential information can be exposed externally.
|
| CVE-2026-32211 |
|
Vulnerability in microsoft (CVE-2026-32211)
vulnerability in microsoft (CVE-2026-32211). Confidential information can be exposed externally.
|