Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-47397 — PraisonAI has an Arbitrary File Write in Python API

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path…

praisonai | Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-44907 — React Server DOM Denial of Service Vulnerability

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages:…

| Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-24232 — NVIDIA Transformers4Rec Improper Deserialization Vulnerability

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data…

| Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-16454 — Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allo…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-16451 — zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.z…

zs-admin | Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.6 HIGH
CVE-2026-15829 — SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-…

mcp_toolbox_for_databases | Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.3 HIGH
CVE-2026-15793 — Git source checkout from a bundle file could lead to command injection

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command in…

buildkit | Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.3 MEDIUM
CVE-2026-15792 — Possible panic when incorrect parameters sent from frontend

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

buildkit | Remote | Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.3 LOW
CVE-2026-15791 — LLB file operation can be tricked to remove /tmp directory contents

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs …

buildkit | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.9 MEDIUM
CVE-2026-15789 — Malicious client can bypass destination directory validation on local sources upload

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the …

buildkit | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.7 HIGH
CVE-2026-15724 — Path traversal in Progress ShareFile Storage Zones Controller (SZC)

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the ser…

sharefile_storage_zones_controller | Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.2 HIGH
CVE-2026-15432 — Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side …

Remote | Cryptography
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-15342 — CVE-2026-15342

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace b…

plane | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2025-68640 — Apple Find My Unauthorized Device Removal Vulnerability

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account …

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.3 CRITICAL
CVE-2026-64825 — Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a craft…

Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.3 CRITICAL
CVE-2026-64824 — Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a c…

Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.7 MEDIUM
CVE-2026-64823 — Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI

Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb …

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56586 — HCL IEM was affected with X-Content-Type-Options Header Missing

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56585 — HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-47396 — PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion whe…

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured.…

praisonai | Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 8828 Results