Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73974 |
|
Path Traversal in linuxfabrik-lib (CVE-2026-73974)
path traversal in linuxfabrik-lib (CVE-2026-73974). Confidential information can be exposed externally. Exploitable via ``nagios``. Mitigation: upgrade to `6.1.0` or later.
|
| CVE-2026-75858 |
|
Code Injection in CVE-2026-75858 (CVE-2026-75858)
code injection in CVE-2026-75858 (CVE-2026-75858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
|
| CVE-2026-71477 |
|
Vulnerability in CVE-2026-71477 (CVE-2026-71477)
vulnerability in CVE-2026-71477 (CVE-2026-71477). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68939 |
|
OS Command Injection in CVE-2026-68939 (CVE-2026-68939)
OS command injection in CVE-2026-68939 (CVE-2026-68939). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34398 |
|
Vulnerability in CVE-2026-34398 (CVE-2026-34398)
vulnerability in CVE-2026-34398 (CVE-2026-34398). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34399 |
|
Vulnerability in CVE-2026-34399 (CVE-2026-34399)
vulnerability in CVE-2026-34399 (CVE-2026-34399). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34789 |
|
Code Injection in cpp (CVE-2026-34789)
code injection in cpp (CVE-2026-34789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59893 |
|
Vulnerability in sqlparse (CVE-2026-59893)
vulnerability in sqlparse (CVE-2026-59893). Risk of unauthorized operations or information disclosure. Exploitable via ``SQL_REGEX``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-54284 |
|
Vulnerability in sqlparse (CVE-2026-54284)
vulnerability in sqlparse (CVE-2026-54284). Risk of unauthorized operations or information disclosure. Exploitable via ``sqlparse``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-71491 |
|
Vulnerability in sqlparse (CVE-2026-71491)
vulnerability in sqlparse (CVE-2026-71491). Risk of unauthorized operations or information disclosure. Exploitable via ``group_comments``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-59894 |
|
Code Injection in sqlparse (CVE-2026-59894)
code injection in sqlparse (CVE-2026-59894). Risk of unauthorized operations or information disclosure. Exploitable via ``EVOHUNT_OUTPUT_FORMAT_INJECTION_VERIFIED``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-74895 |
|
Vulnerability in CVE-2026-74895 (CVE-2026-74895)
vulnerability in CVE-2026-74895 (CVE-2026-74895). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74899 |
|
Vulnerability in jahlives (CVE-2026-74899)
vulnerability in jahlives (CVE-2026-74899). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74887 |
|
Vulnerability in CVE-2026-74887 (CVE-2026-74887)
vulnerability in CVE-2026-74887 (CVE-2026-74887). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74874 |
|
Vulnerability in CVE-2026-74874 (CVE-2026-74874)
vulnerability in CVE-2026-74874 (CVE-2026-74874). Confidential information can be exposed externally.
|
| CVE-2026-74764 |
|
Path Traversal in path-traversal (CVE-2026-74764)
path traversal in path-traversal (CVE-2026-74764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73678 |
|
Code Injection in c (CVE-2026-73678)
code injection in c (CVE-2026-73678). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/responses/`.
|
| CVE-2026-73555 |
|
Vulnerability in CVE-2026-73555 (CVE-2026-73555)
vulnerability in CVE-2026-73555 (CVE-2026-73555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73485 |
|
Code Injection in CVE-2026-73485 (CVE-2026-73485)
code injection in CVE-2026-73485 (CVE-2026-73485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73487 |
|
Code Injection in ssrf (CVE-2026-73487)
code injection in ssrf (CVE-2026-73487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73486 |
|
Code Injection in CVE-2026-73486 (CVE-2026-73486)
code injection in CVE-2026-73486 (CVE-2026-73486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73325 |
|
Unsafe Deserialization in deserialization (CVE-2026-73325)
vulnerability in deserialization (CVE-2026-73325). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73263 |
|
OS Command Injection in CVE-2026-73263 (CVE-2026-73263)
OS command injection in CVE-2026-73263 (CVE-2026-73263). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/providers/{id}/connection`.
|
| CVE-2026-19594 |
|
Path Traversal in path-traversal (CVE-2026-19594)
path traversal in path-traversal (CVE-2026-19594). Data can be tampered with by attackers. Exploitable via ``snowflake.core``.
|
| CVE-2026-73248 |
|
Code Injection in CVE-2026-73248 (CVE-2026-73248)
code injection in CVE-2026-73248 (CVE-2026-73248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73233 |
|
Code Injection in cpp (CVE-2026-73233)
code injection in cpp (CVE-2026-73233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73034 |
|
Path Traversal in path-traversal (CVE-2026-73034)
path traversal in path-traversal (CVE-2026-73034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73036 |
|
Vulnerability in CVE-2026-73036 (CVE-2026-73036)
vulnerability in CVE-2026-73036 (CVE-2026-73036). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72742 |
|
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field...
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field...
|
| CVE-2026-54981 |
|
Vulnerability in microsoft (CVE-2026-54981)
vulnerability in microsoft (CVE-2026-54981). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73217 |
|
Vulnerability in CVE-2026-73217 (CVE-2026-73217)
vulnerability in CVE-2026-73217 (CVE-2026-73217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12372 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12372)
SSRF in ssrf (CVE-2026-12372). Risk of unauthorized operations or information disclosure. Exploitable via ``ipaddress``.
|
| CVE-2026-10595 |
|
Vulnerability in path-traversal (CVE-2026-10595)
vulnerability in path-traversal (CVE-2026-10595). Confidential information can be exposed externally. Exploitable via ``pathlib``.
|
| CVE-2026-71870 |
|
Vulnerability in pypdf (CVE-2026-71870)
vulnerability in pypdf (CVE-2026-71870). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.15.0` or later.
|
| CVE-2026-71852 |
|
Vulnerability in pypdf (CVE-2026-71852)
vulnerability in pypdf (CVE-2026-71852). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.15.0` or later.
|
| CVE-2026-67422 |
|
Vulnerability in pymdown-extensions (CVE-2026-67422)
vulnerability in pymdown-extensions (CVE-2026-67422). Risk of unauthorized operations or information disclosure. Exploitable via ``caret``. Mitigation: upgrade to `10.16.1` or later.
|
| CVE-2026-71554 |
|
Vulnerability in h2 (CVE-2026-71554)
vulnerability in h2 (CVE-2026-71554). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `4.4.1` or later.
|
| CVE-2026-55522 |
|
Code Injection in praisonaiagents (CVE-2026-55522)
code injection in praisonaiagents (CVE-2026-55522). Successful exploitation can lead to full system takeover. Exploitable via ``tools.py``. Mitigation: upgrade to `1.6.58` or later.
|
| CVE-2026-9196 |
|
Code Injection in langflow (CVE-2026-9196)
code injection in langflow (CVE-2026-9196). Confidential information can be exposed externally.
|
| CVE-2026-9201 |
|
Vulnerability in langflow (CVE-2026-9201)
vulnerability in langflow (CVE-2026-9201). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8470 |
|
Vulnerability in langflow (CVE-2026-8470)
vulnerability in langflow (CVE-2026-8470). Data can be tampered with by attackers.
|
| CVE-2026-17632 |
|
Code Injection in langflow (CVE-2026-17632)
code injection in langflow (CVE-2026-17632). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71284 |
|
OS Command Injection in CVE-2026-71284 (CVE-2026-71284)
OS command injection in CVE-2026-71284 (CVE-2026-71284). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71283 |
|
Path Traversal in CVE-2026-71283 (CVE-2026-71283)
path traversal in CVE-2026-71283 (CVE-2026-71283). Data can be tampered with by attackers.
|
| CVE-2026-71259 |
|
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
|
| CVE-2026-70493 |
|
Vulnerability in open-webui (CVE-2026-70493)
vulnerability in open-webui (CVE-2026-70493). Risk of unauthorized operations or information disclosure. Exploitable via ``ENABLE_KB_EXEC``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70491 |
|
Information Disclosure in open-webui (CVE-2026-70491)
vulnerability in open-webui (CVE-2026-70491). Confidential information can be exposed externally. Exploitable via `GET /api/v1/tools/`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70477 |
|
Code Injection in flowise (CVE-2026-70477)
code injection in flowise (CVE-2026-70477). Risk of unauthorized operations or information disclosure. Exploitable via ``run``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69264 |
|
Code Injection in flowise (CVE-2026-69264)
code injection in flowise (CVE-2026-69264). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70470 |
|
Vulnerability in flowise (CVE-2026-70470)
vulnerability in flowise (CVE-2026-70470). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/{chatflowId}`. Mitigation: upgrade to `3.1.3` or later.
|