Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-51861 — Bisheng Code Injection Vulnerability

bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.

| Injection
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51860 — Bisheng Directory Traversal Vulnerability

bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.

| Path Traversal
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51859 — Bisheng Directory Traversal Vulnerability

bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).

| Path Traversal
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51858 — CAMEL TerminalToolkit Shell Command Injection Vulnerability

In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.

| Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51857 — Camel-AI CodeExecutionToolkit Arbitrary Code Execution Vulnerability

In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.

| Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51856 — AgentScope RealtimeAgent Arbitrary Code Execution Vulnerability

In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python…

| Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51853 — Agent-Zero Directory Traversal Vulnerability

agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the w…

| Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51852 — Agent-Zero Directory Traversal

agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths withou…

| Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.1 HIGH
CVE-2026-51570 — ModelScope AgentScope Path Traversal Vulnerability

modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.

Remote | Path Traversal
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.1 HIGH
CVE-2026-51568 — ModelScope AgentScope Path Traversal Vulnerability

modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.

Remote | Path Traversal
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-103000 — pypdf: Possible large memory usage when retrieving alphabetical page labels

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-102999 — pypdf: Possible long runtimes with large amount of embedded files

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to repars…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-102998 — pypdf: Possible long runtimes when generating appearance streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat inv…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-102997 — pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use ineffic…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-102996 — pypdf: Possible large memory usage when parsing font data

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font.…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-102995 — pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-102150 — Kiteworks Secure Data Forms Missing Authentication for Critical Function

A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operatio…

kiteworks | Remote | Authentication
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
9.4 CRITICAL
CVE-2026-102149 — Kiteworks Email Protection Gateway Improper Access Control

Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account,…

kiteworks | Remote | Authentication
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
9.3 CRITICAL
CVE-2026-102147 — Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS)

A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session o…

kiteworks | Remote | Cross-Site Scripting
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-102146 — Kiteworks Email Protection Gateway Arbitrary File Write through Server-Side Template Inje…

An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email P…

kiteworks | Remote | Misconfiguration
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
Showing 20 of 14971 Results