Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-90995 — Sssd: sssd: local denial of service due to null pointer dereference in pam responder

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted pro…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.0 MEDIUM
CVE-2026-90994 — Sssd: sssd: denial of service via malformed pam v1 requests

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX so…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.8 HIGH
CVE-2026-90947 — Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-boun…

enterprise_linux enterprise_linux | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.3 CRITICAL
CVE-2026-90943 — parallax filament-comments through 3.0.0 Stored XSS via Comment Body

parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers ca…

Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.0 MEDIUM
CVE-2026-90795 — itsourcecode Loan Management System navbar.php cross site scripting

A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead t…

Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-90794 — GPAC MP4Box vrml_tools.c gf_sg_script_load use after free

A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a manipulation results…

Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.4 MEDIUM
CVE-2026-90793 — GPAC MP4Box base_scenegraph.c gf_node_get_name use after free

A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after…

Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.0 MEDIUM
CVE-2026-90792 — GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereference

A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argumen…

gpac | Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.0 MEDIUM
CVE-2026-90463 — Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / …

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to ca…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.3 MEDIUM
CVE-2026-88819 — Siglet Refresh Token Issuer DID Proof of Possession Bypass

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.5 HIGH
CVE-2026-81301 — Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access

Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI …

file_manager | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.1 CRITICAL
CVE-2026-61534 — Yayson: Prototype pollution in the Store/LegacyStore deserialization

Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-o…

Remote | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.1 CRITICAL
CVE-2026-57145 — PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without trav…

praisonai | Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.2 HIGH
CVE-2026-57132 — PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables aut…

PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentica…

praisonai | Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-57131 — praisonai: Jobs API exposes agent-execution endpoints with no authentication

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorizatio…

praisonai | Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-57127 — praisonai: recipe serve auth middleware silently disables itself when no secret is set

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware f…

praisonai | Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-57124 — PraisonAI UI MCP connect endpoint allows unauthenticated local command execution

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args …

praisonai | Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.6 HIGH
CVE-2026-57122 — PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing…

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and …

praisonai | Remote | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-57119 — PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without…

praisonai | Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.3 HIGH
CVE-2026-56839 — PraisonAI Code agent tools fail open without a workspace boundary

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforc…

praisonai | Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12611 Results