Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.2 MEDIUM
CVE-2026-82019 — TripleLift video-bundle.js DOM-based XSS via postMessage

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domai…

Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.6 HIGH
CVE-2026-7848 — SQL Injection in Alior Bank raty PrestaShop module

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectC…

Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-59570 — Android ZCC denial of service

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

client_connector | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.1 HIGH
CVE-2026-59569 — Android ZCC VPN API method privilege escalation

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

client_connector | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.1 HIGH
CVE-2026-57130 — PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values di…

praisonai | Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-57129 — PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(fi…

praisonai | Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-57128 — PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handl…

praisonai | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.5 HIGH
CVE-2026-57126 — praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before s…

praisonai | Remote | Server-Side Request Forgery
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-57125 — PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve f…

praisonai | Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-57123 — PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validatio…

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the…

praisonai | Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-57120 — PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every b…

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to res…

praisonai | Remote | Information Disclosure
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-57115 — PraisonAI: SpiderTools redirect-target SSRF protection bypass

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a pub…

praisonai | Remote | Server-Side Request Forgery
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.1 HIGH
CVE-2026-25687 — ZCC race condition in ZPA tunnel handler

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary c…

client_connector | Remote | Race Condition
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.6 HIGH
CVE-2026-15600 — SQL Injection in Alior Bank raty PrestaShop module

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQ…

Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.8 MEDIUM
CVE-2026-12985 — Mattermost DCR redirect URI allowlist bypass via improper URL component validation

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the r…

Remote | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.3 CRITICAL
CVE-2026-90961 — MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fa…

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.8 HIGH
CVE-2026-90949 — Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mi…

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size…

enterprise_linux enterprise_linux | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.8 HIGH
CVE-2026-90948 — Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png…

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads …

enterprise_linux enterprise_linux | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-90941 — novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid …

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.9 MEDIUM
CVE-2026-90940 — novel-plus through 5.3.3 Default Cache Management Password in the Front Portal

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying t…

Remote | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12609 Results