Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-47408 — praisonai-platform: list_issue_activity returns activity log for any issue regardless of …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issu…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.4 CRITICAL
CVE-2026-47407 — PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and pr…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.1 HIGH
CVE-2026-47406 — praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-47405 — PraisonAI Platform missing role checks let any workspace member become owner and take ove…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege wo…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-47399 — PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that a…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.1 HIGH
CVE-2026-47398 — PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_ge…

PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.p…

Remote | Supply Chain
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.1 HIGH
CVE-2026-47397 — PraisonAI has an Arbitrary File Write in Python API

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path…

Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-44907 — React Server DOM Denial of Service Vulnerability

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages:…

| Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-24232 — NVIDIA Transformers4Rec Improper Deserialization Vulnerability

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data…

| Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-16454 — Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allo…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-16451 — zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.z…

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.6 HIGH
CVE-2026-15829 — SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-…

mcp_toolbox_for_databases | Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.3 HIGH
CVE-2026-15793 — Git source checkout from a bundle file could lead to command injection

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command in…

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.3 MEDIUM
CVE-2026-15792 — Possible panic when incorrect parameters sent from frontend

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

Remote | Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.3 LOW
CVE-2026-15791 — LLB file operation can be tricked to remove /tmp directory contents

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs …

| Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.9 MEDIUM
CVE-2026-15789 — Malicious client can bypass destination directory validation on local sources upload

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the …

| Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.7 HIGH
CVE-2026-15724 — Path traversal in Progress ShareFile Storage Zones Controller (SZC)

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the ser…

sharefile_storage_zones_controller | Remote | Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.2 HIGH
CVE-2026-15432 — Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side …

Remote | Cryptography
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-15342 — CVE-2026-15342

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace b…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2025-68640 — Apple Find My Unauthorized Device Removal Vulnerability

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account …

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 8476 Results