Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-94544 — Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and …

Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regula…

next.js | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-94543 — Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications

Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental S…

next.js | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
2.3 LOW
CVE-2026-94486 — Next.js: Information disclosure in the Next.js development server's Model Context Protoco…

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting…

next.js | Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-94485 — Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicPa…

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricti…

next.js | Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-94484 — Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substit…

Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Stat…

next.js | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.3 HIGH
CVE-2026-94483 — Next.js: Server-Side Request Forgery in Image Optimization

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.…

next.js | Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-67989 — Ruby_llm Regular Expression Denial of Service

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51922 — AgentScope Code Injection Vulnerability

agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or comman…

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51918 — FinRobot Code Injection Vulnerability

FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code ().

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51917 — FinRobot CodingUtils Code Injection

FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51916 — SuperAGI Incorrect Access Control Vulnerability

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/d…

| Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51915 — SuperAGI Incorrect Access Control Vulnerability

TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a c…

| Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51914 — SuperAGI Agent Template Controller Incorrect Access Control

TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/c…

| Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51911 — Vanna Code Injection Vulnerability

vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code o…

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.1 HIGH
CVE-2026-51907 — TaskingAI QR Code Generator Plugin Path Traversal Vulnerability

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by…

Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51906 — TaskingAI Path Traversal Vulnerability

In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server file…

| Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51904 — SuperAGI Improper Access Control Vulnerability

SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/contr…

| Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51901 — SuperAGI Incorrect Access Control Vulnerability

SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule exi…

| Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51899 — SuperAGI Insecure Direct Object Reference Vulnerability

In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from…

| Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-51898 — Pandas-AI Code Injection Vulnerability

sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14939 Results