Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-19019 — poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence c…

A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component…

Remote | Misconfiguration
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.5 MEDIUM
CVE-2026-19011 — TinyAGI agents.ts buildSystemPrompt file inclusion

A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file incl…

Remote | Path Traversal
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-19010 — TinyAGI Message API Endpoint index.ts processMessage authorization

A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such manipulation l…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-19009 — TinyAGI Message API Endpoint response.ts collectFiles file inclusion

A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This manipulation cause…

Remote | Path Traversal
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-19008 — mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following

A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Suc…

openclaw-cn | Remote | Path Traversal
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.0 MEDIUM
CVE-2026-18915 — Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp…

Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp…

| Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-18649 — Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265de…

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmen…

enterprise_linux enterprise_linux | Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.5 HIGH
CVE-2026-18597 — Blind SSRF on Foxit PDF Services API

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirect…

pdf_services_api | Remote | Server-Side Request Forgery
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.4 MEDIUM
CVE-2026-0637 — Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the p…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
9.4 CRITICAL
CVE-2025-15039 — Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain aut…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
3.8 LOW
CVE-2025-14779 — Improper Access Control via Secret Type Management API in WSO2 Identity Server

The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, le…

identity_server | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.3 MEDIUM
CVE-2025-13909 — Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allo…

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequ…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
3.7 LOW
CVE-2025-13736 — Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Di…

When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.4 MEDIUM
CVE-2025-13394 — Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables…

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for th…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
2.4 LOW
CVE-2025-12627 — Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server…

The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impe…

identity_server | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.3 MEDIUM
CVE-2025-11850 — Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Iden…

When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness check…

identity_server | Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.9 MEDIUM
CVE-2024-8995 — Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unautho…

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reuse…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.9 MEDIUM
CVE-2024-6832 — Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Product…

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured use…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.0 MEDIUM
CVE-2024-10302 — Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Ma…

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then…

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-19007 — mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management

A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/auto-reply/reply/reply-elevated.ts. This manipulati…

openclaw-cn | Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 9871 Results