Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-55523 — PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it vali…

praisonai | Remote | Server-Side Request Forgery
Aug 05, 2026 Aug 06, 2026
Aug 05, 2026
Aug 06, 2026
7.8 HIGH
CVE-2026-55522 — PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe…

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution…

Aug 05, 2026 Aug 06, 2026
Aug 05, 2026
Aug 06, 2026
5.4 MEDIUM
CVE-2026-21766 — HCL Digital Experience and Digital Experience Compose insufficiently protects credentials

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive i…

Remote | Information Disclosure
Aug 05, 2026 Aug 28, 2026
Aug 05, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-18958 — imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection

A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknow…

student-management-system | Remote | Injection
Aug 05, 2026 Aug 12, 2026
Aug 05, 2026
Aug 12, 2026
5.7 MEDIUM
CVE-2026-18954 — Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MC…

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on th…

Aug 05, 2026 Aug 10, 2026
Aug 05, 2026
Aug 10, 2026
8.8 HIGH
CVE-2026-18953 — Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbi…

Aug 05, 2026 Aug 10, 2026
Aug 05, 2026
Aug 10, 2026
9.1 CRITICAL
CVE-2026-17556 — Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance s…

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user…

enterprise_server | Remote | Path Traversal
Aug 05, 2026 Aug 18, 2026
Aug 05, 2026
Aug 18, 2026
Showing 20 of 12787 Results