Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-57129 — PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(fi…

| Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57126 — praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before s…

| Server-Side Request Forgery
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57120 — PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every b…

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to res…

| Information Disclosure
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-59570 — Android ZCC denial of service

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

client_connector | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57123 — PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validatio…

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the…

| Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-90791 — GPAC MP4Box base_scenegraph.c gf_node_unregister use after free

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation resu…

| Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.1 HIGH
CVE-2026-59569 — Android ZCC VPN API method privilege escalation

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

client_connector | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.1 HIGH
CVE-2026-25687 — ZCC race condition in ZPA tunnel handler

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary c…

client_connector | Remote | Race Condition
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-90790 — a2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch…

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of …

| Server-Side Request Forgery
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57130 — PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values di…

| Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57128 — PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handl…

| Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57115 — PraisonAI: SpiderTools redirect-target SSRF protection bypass

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a pub…

| Server-Side Request Forgery
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57125 — PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve f…

| Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-82427 — Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map …

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working …

| Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-82428 — Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical …

| Supply Chain
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.3 CRITICAL
CVE-2026-90961 — MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fa…

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.8 HIGH
CVE-2026-90949 — Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mi…

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size…

enterprise_linux enterprise_linux | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.8 HIGH
CVE-2026-90948 — Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png…

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads …

enterprise_linux enterprise_linux | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-90941 — novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid …

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.9 MEDIUM
CVE-2026-90940 — novel-plus through 5.3.3 Default Cache Management Password in the Front Portal

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying t…

Remote | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12501 Results