Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-mf8r-wm2w-f8c5 |
|
Information Disclosure in thorsten/phpmyfaq (GHSA-mf8r-wm2w-f8c5)
vulnerability in thorsten/phpmyfaq (GHSA-mf8r-wm2w-f8c5). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4.0/faqs/tags/{tagId}`. Mitigation: upgrade to `4.1.5` or later.
|
| GHSA-88g4-74f3-63x9 |
|
Path Traversal in thorsten/phpmyfaq (GHSA-88g4-74f3-63x9)
path traversal in thorsten/phpmyfaq (GHSA-88g4-74f3-63x9). Risk of unauthorized operations or information disclosure. Exploitable via ``false``. Mitigation: upgrade to `4.1.5` or later.
|
| CVE-2026-59189 |
|
Out-of-Bounds Read in CVE-2026-59189 (CVE-2026-59189)
vulnerability in CVE-2026-59189 (CVE-2026-59189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59187 |
|
Vulnerability in CVE-2026-59187 (CVE-2026-59187)
vulnerability in CVE-2026-59187 (CVE-2026-59187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59186 |
|
Vulnerability in CVE-2026-59186 (CVE-2026-59186)
vulnerability in CVE-2026-59186 (CVE-2026-59186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59184 |
|
Use-After-Free in CVE-2026-59184 (CVE-2026-59184)
vulnerability in CVE-2026-59184 (CVE-2026-59184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13478 |
|
Out-of-Bounds Read in c (CVE-2026-13478)
vulnerability in c (CVE-2026-13478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13217 |
|
Vulnerability in c (CVE-2026-13217)
vulnerability in c (CVE-2026-13217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13216 |
|
Out-of-Bounds Write in c (CVE-2026-13216)
out-of-bounds write in c (CVE-2026-13216). Data can be tampered with by attackers.
|
| CVE-2026-55557 |
|
Path Traversal in browse-mcp (CVE-2026-55557)
path traversal in browse-mcp (CVE-2026-55557). Risk of unauthorized operations or information disclosure. Exploitable via ``browser_download``. Mitigation: upgrade to `0.8.2` or later.
|
| CVE-2026-55585 |
|
Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-55553 |
|
Information Disclosure in urllib (CVE-2026-55553)
vulnerability in urllib (CVE-2026-55553). Confidential information can be exposed externally. Exploitable via `Cookie header`. Mitigation: upgrade to `2.44.1` or later.
|
| CVE-2026-55571 |
|
Vulnerability in djust (CVE-2026-55571)
vulnerability in djust (CVE-2026-55571). Data can be tampered with by attackers. Exploitable via ``LiveViewConsumer``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2026-55640 |
|
Vulnerability in nextcloud-mcp-server (CVE-2026-55640)
vulnerability in nextcloud-mcp-server (CVE-2026-55640). Data can be tampered with by attackers. Exploitable via `POST /webhooks/nextcloud`. Mitigation: upgrade to `0.117.2` or later.
|
| GHSA-8qx3-8gm5-9cj2 |
|
Vulnerability in pickem (GHSA-8qx3-8gm5-9cj2)
vulnerability in pickem (GHSA-8qx3-8gm5-9cj2). Risk of unauthorized operations or information disclosure. Exploitable via ``chrome.row``. Mitigation: upgrade to `1.0.7` or later.
|
| GHSA-8cp3-qxj6-px34 |
|
SSRF (Server-Side Request Forgery) in utcp-http (GHSA-8cp3-qxj6-px34)
SSRF in utcp-http (GHSA-8cp3-qxj6-px34). Risk of unauthorized operations or information disclosure. Exploitable via ``tokenUrl``. Mitigation: upgrade to `1.1.4` or later.
|
| GHSA-ppx3-28rw-8fpf |
|
SSRF (Server-Side Request Forgery) in utcp-gql (GHSA-ppx3-28rw-8fpf)
SSRF in utcp-gql (GHSA-ppx3-28rw-8fpf). Risk of unauthorized operations or information disclosure. Exploitable via ``startswith``. Mitigation: upgrade to `1.1.1` or later.
|
| GHSA-9qhg-99ww-9mqc |
|
SSRF (Server-Side Request Forgery) in utcp-http (GHSA-9qhg-99ww-9mqc)
SSRF in utcp-http (GHSA-9qhg-99ww-9mqc). Risk of unauthorized operations or information disclosure. Exploitable via ``HttpCommunicationProtocol.call_tool``. Mitigation: upgrade to `1.1.4` or later.
|
| CVE-2026-55580 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55580)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55580). Risk of unauthorized operations or information disclosure. Exploitable via ``config.go``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-55581 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55581)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55581). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-55582 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55582)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55582). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-79717 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-79717)
SSRF in ssrf (CVE-2026-79717). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16599 |
|
Vulnerability in dos (CVE-2026-16599)
vulnerability in dos (CVE-2026-16599). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70551 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-70551 (CVE-2026-70551)
SSRF in CVE-2026-70551 (CVE-2026-70551). Confidential information can be exposed externally.
|
| CVE-2026-16286 |
|
Unrestricted File Upload in CVE-2026-16286 (CVE-2026-16286)
vulnerability in CVE-2026-16286 (CVE-2026-16286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69104 |
|
Vulnerability in CVE-2026-69104 (CVE-2026-69104)
vulnerability in CVE-2026-69104 (CVE-2026-69104). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15310 |
|
Vulnerability in CVE-2026-15310 (CVE-2026-15310)
vulnerability in CVE-2026-15310 (CVE-2026-15310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79622 |
|
Path Traversal in path-traversal (CVE-2026-79622)
path traversal in path-traversal (CVE-2026-79622). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79623 |
|
Command Injection in CVE-2026-79623 (CVE-2026-79623)
command injection in CVE-2026-79623 (CVE-2026-79623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75803 |
|
Vulnerability in CVE-2026-75803 (CVE-2026-75803)
vulnerability in CVE-2026-75803 (CVE-2026-75803). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78885 |
|
Authentication Bypass in CVE-2026-78885 (CVE-2026-78885)
authentication bypass in CVE-2026-78885 (CVE-2026-78885). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78887 |
|
Vulnerability in CVE-2026-78887 (CVE-2026-78887)
vulnerability in CVE-2026-78887 (CVE-2026-78887). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79406 |
|
Vulnerability in CVE-2026-79406 (CVE-2026-79406)
vulnerability in CVE-2026-79406 (CVE-2026-79406). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79655 |
|
Vulnerability in path-traversal (CVE-2026-79655)
vulnerability in path-traversal (CVE-2026-79655). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57863 |
|
Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63076 |
|
Vulnerability in dos (CVE-2026-63076)
vulnerability in dos (CVE-2026-63076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63074 |
|
Vulnerability in dos (CVE-2026-63074)
vulnerability in dos (CVE-2026-63074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14457 |
|
Vulnerability in dos (CVE-2026-14457)
vulnerability in dos (CVE-2026-14457). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77998 |
|
Vulnerability in CVE-2026-77998 (CVE-2026-77998)
vulnerability in CVE-2026-77998 (CVE-2026-77998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63073 |
|
Vulnerability in dos (CVE-2026-63073)
vulnerability in dos (CVE-2026-63073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63075 |
|
Vulnerability in dos (CVE-2026-63075)
vulnerability in dos (CVE-2026-63075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78886 |
|
Path Traversal in path-traversal (CVE-2026-78886)
path traversal in path-traversal (CVE-2026-78886). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78581 |
|
Vulnerability in CVE-2026-78581 (CVE-2026-78581)
vulnerability in CVE-2026-78581 (CVE-2026-78581). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54874 |
|
Vulnerability in dos (CVE-2026-54874)
vulnerability in dos (CVE-2026-54874). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18798 |
|
Vulnerability in dos (CVE-2026-18798)
vulnerability in dos (CVE-2026-18798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63072 |
|
Out-of-Bounds Write in dos (CVE-2026-63072)
out-of-bounds write in dos (CVE-2026-63072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55546 |
|
Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
|
| CVE-2026-55536 |
|
Vulnerability in PraisonAI (CVE-2026-55536)
vulnerability in PraisonAI (CVE-2026-55536). Confidential information can be exposed externally. Exploitable via ``start_session``. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-55532 |
|
Vulnerability in PraisonAI (CVE-2026-55532)
vulnerability in PraisonAI (CVE-2026-55532). Data can be tampered with by attackers. Exploitable via `Host header`. Mitigation: upgrade to `4.6.58` or later.
|
| CVE-2026-55624 |
|
Vulnerability in CVE-2026-55624 (CVE-2026-55624)
vulnerability in CVE-2026-55624 (CVE-2026-55624). Risk of unauthorized operations or information disclosure.
|