Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-56076 — PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authenti…

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks au…

praisonai | Remote | Authentication
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.8 HIGH
CVE-2026-56075 — PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override

PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_…

praisonai | Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
6.8 MEDIUM
CVE-2026-56074 — PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit thi…

praisonai | Misconfiguration
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.9 CRITICAL
CVE-2026-47647 — Dynamics 365 Elevation of Privilege Vulnerability

None

dynamics_365 | Remote
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.8 CRITICAL
CVE-2026-54130 — M365 Copilot Information Disclosure Vulnerability

None

365_copilot | Remote
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.7 HIGH
CVE-2026-32174 — Azure Bot Service Elevation of Privilege Vulnerability

None

Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.5 HIGH
CVE-2026-47633 — Microsoft Cost Management Information Disclosure Vulnerability

None

Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
2.3 LOW
CVE-2026-8668 — Hardcoded credentials in embedded content

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been r…

Remote | Authentication
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.6 HIGH
CVE-2026-8100 — Chef 360 Unauthorized API Access Vulnerability

Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encod…

Remote | Authorization
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
6.5 MEDIUM
CVE-2026-49205 — phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete…

phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $th…

phpmyfaq | Remote | Authorization
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.7 HIGH
CVE-2026-54017 — Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does …

open_webui | Remote | Path Traversal
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.8 MEDIUM
CVE-2026-22674 — Hashgraph Guardian Stored XSS via branding companyName field

Hashgraph Guardian through 3.5.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scr…

guardian | Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
10.0 CRITICAL
CVE-2026-49257 — mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0…

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 …

Remote | Authentication
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.1 CRITICAL
CVE-2026-49454 — Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verifie…

Remote | Authentication
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.6 HIGH
CVE-2026-46699 — conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot…

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.61.0, a vulnerability in the conda-forge …

Remote | Supply Chain
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.3 HIGH
CVE-2026-45696 — OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000)…

openexr | Remote | Memory Corruption
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
6.1 MEDIUM
CVE-2026-44663 — OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl()…

openexr | Memory Corruption
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.3 HIGH
CVE-2025-15661 — libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle…

libssh2 | Remote | Information Disclosure
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.9 CRITICAL
CVE-2026-49252 — deepstream is vulnerable to prototype pollution

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can l…

Remote | Misconfiguration
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.3 HIGH
CVE-2026-49248 — OneDev: RCE through absolute-path symlink following allows low-privileged users to overwr…

OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the tar…

onedev onedev | Remote | Path Traversal
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
Showing 20 of 7563 Results