// vulnerability intelligence · 14 entries
Vulnerabilities, explained
Vulnerability analysis and response guidance: scope, risk, how the attack works, and how to fix and detect it, with sources for every point.
| Vulnerability · | KEV | |||
|---|---|---|---|---|
CVE-2026-94127 F5 BIG-IP APM OAuth heap overflow | Critical | 9.8 | Listed | — |
CVE-2026-90553 vLLM LlavaOnevision2 ignores trust_remote_code | High | 7.8 | Not listed | 2026-07-11 |
CVE-2026-82021 Hermes Agent MCP catalog not pinned to a commit | Critical | 9.0 | Not listed | 2026-07-07 |
CVE-2026-50016 pnpm dependency alias path traversal | High | 8.8 | Not listed | — |
CVE-2026-48501 GitHub CLI verify commands leak token | Critical | 9.1 | Not listed | — |
CVE-2026-45321 TanStack npm release pipeline hijack | Critical | 9.6 | Listed | 2026-05-11 |
CVE-2026-45758 guardrails-ai malicious PyPI release | Critical | 9.6 | Not listed | 2026-05-11 |
No CVEGHSA-fw8c-xr5c-95f9 axios npm maintainer account takeover | N/A | — | Not listed | 2026-03-31 |
CVE-2026-33634 Trivy and trivy-action trojanized | High | 8.8 | Listed | 2026-03-19 |
CVE-2026-33017 Langflow public flow unauthenticated RCE | Critical | 9.8 | Listed | — |
CVE-2026-59822 LiteLLM MCP gateway auth bypass | High | 8.2 | Listed | 2026-02-07 |
CVE-2026-5241 Transformers LightGlue config overrides trust_remote_code | Critical | 9.6 | Not listed | 2025-07-25 |
CVE-2026-12537 Gemini CLI headless workspace trust | High | 7.8 | Not listed | 2025-06-25 |
CVE-2026-26030 Semantic Kernel filter runs as code | Critical | 9.9 | Not listed | 2025-06-25 |
Nothing we have published matches these conditions (that does not mean the product has no vulnerabilities).