Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-47405 — PraisonAI Platform missing role checks let any workspace member become owner and take ove…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege wo…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.3 CRITICAL
CVE-2026-64825 — Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a craft…

Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.3 CRITICAL
CVE-2026-64824 — Home Assistant Core < 2026.6.0 Symlink Path Traversal RCE via backup-restore

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a c…

Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.7 MEDIUM
CVE-2026-64823 — Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI

Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb …

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56586 — HCL IEM was affected with X-Content-Type-Options Header Missing

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56585 — HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-47396 — PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion whe…

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured.…

Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
5.5 MEDIUM
CVE-2026-47395 — PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback U…

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expands `@url:` mentions…

| Server-Side Request Forgery
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.7 HIGH
CVE-2026-47394 — PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workfl…

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vulnerable handlers in `…

Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-47393 — PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API …

Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.9 CRITICAL
CVE-2026-47392 — PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `exec…

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37…

Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-47391 — PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool …

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` t…

Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
5.5 MEDIUM
CVE-2026-47390 — PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL validation can be bypassed using alternate loopba…

| Server-Side Request Forgery
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28321 — SolarWinds Serv-U Broken Access Control Vulnerability

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain…

serv-u | Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28317 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower i…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28316 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the r…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.2 MEDIUM
CVE-2026-28315 — SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

serv-u | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28314 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.

serv-u | Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28313 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deploym…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28312 — SolarWinds Serv-U Privilege Escalation Vulnerability

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows dep…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 8392 Results