VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18347 CVEsRSS

CVE-2026-91925High· 8.8PoC
2w ago

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 paylo…

▾ Midnightpolyaxon · polyaxonEPSS 0.78%via NVD
CVE-2026-91924High· 8.5PoC
2w ago

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapp…

▾ Midnightsosedoff · pgwebEPSS 0.42%via NVD
CVE-2026-91923High· 7.7
2w ago

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply ar…

▾ Twilightkubesphere · kubesphereEPSS 0.45%via NVD
CVE-2026-91922Medium· 6.1PoC
2w ago

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft mali…

▾ Twilightsteedos · steedos-platformEPSS 0.34%via NVD
CVE-2026-91786Medium· 6.1
2w ago

A flaw was found in GNOME Shell

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search pro…

▾ SunlitRed Hat · gnome-shellEPSS 0.13%via NVD
CVE-2026-86818Medium· 4.8
2w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved nam…

▾ Sunlitfast-uri · fast-uriEPSS 0.25%via NVD
CVE-2026-80489Medium· 5.9
2w ago

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

▾ SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-77117Medium· 5.9
2w ago

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

▾ SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-1759Medium· 6.5
2w ago

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

▾ SunlitSecomea · GateManagerEPSS 0.26%via NVD
CVE-2026-1758High· 8.3
2w ago

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

▾ TwilightSecomea · GateManagerEPSS 0.24%via NVD
CVE-2026-57141Critical· 9.8
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklis…

▾ MidnightMervinPraison · PraisonAIEPSS 0.74%via NVD
CVE-2026-57138Critical· 9.9
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blockl…

▾ MidnightMervinPraison · PraisonAIEPSS 0.73%via NVD
CVE-2026-57137High· 8.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped A…

▾ MidnightMervinPraison · PraisonAIEPSS 0.51%via NVD
CVE-2026-57135High· 7.6PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment…

▾ MidnightMervinPraison · PraisonAIEPSS 0.42%via NVD
CVE-2026-57134High· 8.2PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth …

▾ MidnightMervinPraison · PraisonAIEPSS 0.41%via NVD
CVE-2026-57139Critical· 9.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication …

▾ AbyssalMervinPraison · PraisonAIEPSS 0.75%via NVD
CVE-2026-57133High· 8.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the compl…

▾ MidnightMervinPraison · PraisonAIEPSS 0.80%via NVD
CVE-2026-86472Medium· 4.8
2w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the …

▾ Sunlitfast-uri · fast-uriEPSS 0.25%via NVD
CVE-2026-57140Critical· 9.4
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authe…

▾ MidnightMervinPraison · PraisonAIEPSS 0.64%via NVD
CVE-2026-57136High· 8.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExec…

▾ MidnightMervinPraison · PraisonAIEPSS 0.55%via NVD
CVE-2026-91859Medium· 5.3
2w ago

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a re…

▾ SunlitMISP · MISPEPSS 0.47%via NVD
CVE-2026-19515High· 7.0
2w ago

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary op…

▾ TwilightWSO2 · WSO2 Integrator: MI for Visual Studio CodeEPSS 0.14%via NVD
CVE-2025-5802Medium· 5.3
2w ago

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error messag…

▾ SunlitWSO2 · WSO2 API ManagerEPSS 0.25%via NVD
CVE-2025-13166Low· 3.7
2w ago

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

▾ SunlitWSO2 · WSO2 Identity ServerEPSS 0.22%via NVD
CVE-2026-91857Medium· 5.3
2w ago

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  …

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  …

▾ SunlitMISP · MISPEPSS 0.21%via NVD
CVE-2026-59341Medium· 4.2PoC
2w ago

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can a…

▾ TwilightBitnami · sealed-secretsEPSS 0.40%via NVD
CVE-2026-91851Medium· 5.3
2w ago

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one…

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one…

▾ SunlitMISP · MISPEPSS 0.35%via NVD
CVE-2026-91846High· 7.1
2w ago

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselv…

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselv…

▾ TwilightMISP · MISPEPSS 0.35%via NVD
CVE-2026-91826Medium· 4.4
2w ago

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

▾ SunlitSamsung Opensource · rLottieEPSS 0.14%via NVD
CVE-2026-91782Low· 3.3
2w ago

A vulnerability was detected in GNU Binutils 2.47

A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null poi…

▾ Sunlitgnu · binutilsEPSS 0.18%via NVD
CVEs tagged “cve.org” — page 303 · VulnSea