Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-47418 — praisonai-platform: Project endpoints accept any project_id without workspace ownership c…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELET…

Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47417 — praisonai-platform: Comment endpoints accept any issue_id without workspace ownership che…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{worksp…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.6 CRITICAL
CVE-2026-47416 — praisonai-platform: Any workspace member can promote themselves (or any other member) to …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/mem…

Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.3 HIGH
CVE-2026-47415 — praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE …

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.6 HIGH
CVE-2026-47414 — praisonai-platform: Label endpoints accept any label_id and any issue_id without workspac…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{works…

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.6 CRITICAL
CVE-2026-47413 — praisonai-platform: Any workspace member can add arbitrary user as owner via POST /worksp…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspa…

Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47412 — praisonai-platform: Any workspace member can delete the entire workspace via DELETE /work…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspa…

Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-47411 — praisonai-platform: Any workspace member can rewrite workspace name, description, and set…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH …

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-44880 — Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution…

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code…

Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.2 HIGH
CVE-2026-21579 — Atlassian Confluence Data Center Information Disclosure Vulnerability

This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Inf…

confluence_data_center | Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-21577 — Atlassian Confluence Data Center Denial of Service Vulnerability

This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial …

confluence_data_center | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-21575 — Atlassian Sourcetree Remote Code Execution Vulnerability

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, wit…

sourcetree | Remote | Authentication
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.8 HIGH
CVE-2026-16493 — Ansible-core: argument injection in ansible-galaxy collection install via git clone (inco…

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator be…

Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.8 MEDIUM
CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

openj9 | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.7 MEDIUM
CVE-2026-16243 — Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compa…

In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.

omr | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-47410 — praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowin…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcod…

praisonai | Remote | Cryptography
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47409 — praisonai-platform: Any workspace member can remove any other member (including the owner…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-47408 — praisonai-platform: list_issue_activity returns activity log for any issue regardless of …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issu…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.4 CRITICAL
CVE-2026-47407 — PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and pr…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47406 — praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 9602 Results