VulnSea

CWE-1188

CVEs classified under CWE-1188, newest first.

52 CVEsRSS

CVE-2026-89139High· 8.7
today

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…

TwilightTemporal Technologies, Inc. · go.temporal.io/servervia NVD
GHSA-jgh3-fggc-mcpmHigh· 7.6
3d ago

Obot: Server-Side Request Forgery via remote MCP server URL

Obot: Server-Side Request Forgery via remote MCP server URL

Twilightobot-platform · github.com/obot-platform/obotvia OSV
CVE-2026-93338Medium· 5.3
3d ago

Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with…

Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with…

SunlitGrandstream Networks · GWN7660ELREPSS 0.31%via NVD
CVE-2026-54907Medium· 5.3
4d ago

Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates

Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauth…

Sunlitfuomag9 · caddy-proxy-managerEPSS 0.17%via NVD
CVE-2026-61793Medium· 6.9PoC
4d ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…

Twilightnuxt-modules · og-imageEPSS 0.46%via NVD
CVE-2026-57139Critical· 9.8PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication …

AbyssalMervinPraison · PraisonAIEPSS 0.42%via NVD
CVE-2026-53660High· 7.4
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and O…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-57148Critical· 9.8PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance …

AbyssalMervinPraison · PraisonAIEPSS 0.37%via NVD
CVE-2026-57147Critical· 9.8PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run whe…

AbyssalMervinPraison · PraisonAIEPSS 0.77%via NVD
CVE-2026-52824Critical· 9.1PoC
6d ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that …

Abyssalkimai · kimaiEPSS 2.1%via NVD
CVE-2026-46619Critical· 9.3
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.58%via NVD
CVE-2026-57127Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KE…

AbyssalMervinPraison · PraisonAIEPSS 0.90%via NVD
CVE-2026-49462Medium· 5.3
1w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped defau…

Sunlitnl-portal · nl.nl-portal:appEPSS 0.28%via NVD
CVE-2026-79394High· 7.5
1w ago

An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthentica…

An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthentica…

TwilightEPSS 0.43%via NVD
CVE-2026-87827Critical· 10.0
1w ago

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service ca…

MidnightKGUARD · KGUARD_firmwareEPSS 1.1%via NVD
CVE-2026-86464Critical· 9.9
1w ago

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

MidnightEclipse Foundation · Eclipse aeriOSEPSS 0.35%via NVD
CVE-2026-53507None
3w ago

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the OpenAPI spec by default (allow-external-r…

SunlitEPSS 0.29%via NVD
CVE-2026-77348High· 8.2
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling …

TwilightEPSS 0.25%via NVD
CVE-2026-55581High· 8.4
3w ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…

Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.34%via NVD
CVE-2026-77915Critical· 9.8
4w ago

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web…

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web…

MidnightEPSS 0.40%via NVD
CVE-2026-62388High· 7.5
1mo ago

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by e…

TwilightEPSS 0.46%via NVD
CVE-2026-33921Medium· 5.2
1mo ago

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user witho…

SunlitEPSS 0.10%via NVD
CVE-2026-16504Critical· 9.8
1mo ago

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

MidnightEPSS 0.35%via NVD
CVE-2026-16503Critical· 9.1
1mo ago

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres"

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, th…

MidnightEPSS 0.32%via NVD
CVE-2026-66066CriticalPoC
1mo ago

Action Pack is a framework for handling and responding to web requests

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload …

Abyssalactivestorage · activestorageEPSS 28%via NVD
CVE-2026-61439High· 7.5
2mo ago

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector promp…

TwilightEPSS 0.43%via NVD
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-54067Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-54158Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
CVE-2026-14474High· 8.8
2mo ago

A flaw was found in SSSD's LDAP sudo provider

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subt…

TwilightEPSS 0.57%via NVD
CWE-1188 vulnerabilities (CVEs) · VulnSea