VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30012 CVEsRSS

CVE-2026-54178High· 8.1
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDi…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.56%via NVD
CVE-2026-54180High· 7.6
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder …

▾ TwilightLaravel-Backpack · CRUDEPSS 0.46%via NVD
CVE-2026-54181Medium· 5.4
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.31%via NVD
CVE-2026-54182High· 8.1
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::mak…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.78%via NVD
CVE-2026-57570Medium· 6.5
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling t…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.44%via NVD
CVE-2026-55244Medium· 5.0PoC
2w ago

ASTEVAL is an evaluator of Python expressions and statements

ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), …

▾ Twilightlmfit · astevalEPSS 0.18%via NVD
CVE-2026-55253High· 7.7
2w ago

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search()…

▾ Twilightlangchain-ai · langchain-mongodbEPSS 0.53%via NVD
CVE-2026-55236Medium· 5.9
2w ago

langgraph-api implements the LangGraph API for rapid development and testing

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by dispatching assistants.search with an incomplete value inste…

▾ Sunlitlangchain-ai · langgraph-apiEPSS 0.26%via NVD
CVE-2026-55235Medium· 5.9
2w ago

langgraph-api implements the LangGraph API for rapid development and testing

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the a…

▾ Sunlitlanggraph-api · langgraph-apiEPSS 0.36%via NVD
CVE-2026-54723Medium· 6.5
2w ago

devpi is a Python package index staging server and packaging, testing, and release tool

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +…

▾ Sunlitdevpi · devpiEPSS 0.43%via NVD
CVE-2026-55209Critical· 9.8
2w ago

resdata is software for reading and writing result files from the Eclipse reservoir simulator

resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRD…

▾ Midnightequinor · resdataEPSS 0.78%via NVD
CVE-2026-53659High· 7.5
2w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompress…

▾ Twilighthttp4k · http4kEPSS 0.63%via NVD
CVE-2026-53752High· 7.5
2w ago

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn sty…

▾ Twilightplutext · docx4jEPSS 0.63%via NVD
CVE-2026-53708Medium· 6.6PoC
2w ago

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…

▾ TwilightIBM · mcp-context-forgeEPSS 0.35%via NVD
CVE-2026-55102Medium· 5.8
2w ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosEr…

▾ Sunlitkyndryl-open-source · hashi-vault-jsEPSS 0.16%via NVD
CVE-2026-55072High· 8.5PoC
2w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…

▾ Midnightpimcore · pimcoreEPSS 0.41%via NVD
CVE-2026-54632High· 7.5
2w ago

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted b…

▾ Twilightsipsorcery-org · sipsorceryEPSS 0.72%via NVD
CVE-2026-57497Medium· 5.3
2w ago

webtransport-go is an implementation of the WebTransport protocol

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, …

▾ Sunlitquic-go · webtransport-goEPSS 0.52%via NVD
CVE-2026-57122High· 8.6
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned …

▾ TwilightMervinPraison · PraisonAIEPSS 0.19%via NVD
CVE-2026-57123Critical· 9.8
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authenticati…

▾ MidnightMervinPraison · praisonaiagentsEPSS 0.90%via NVD
CVE-2026-57126High· 8.5PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extr…

▾ MidnightMervinPraison · PraisonAIEPSS 0.38%via NVD
CVE-2026-57120Medium· 6.5PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level att…

▾ TwilightMervinPraison · praisonaiagentsEPSS 0.56%via NVD
CVE-2026-57124Critical· 9.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to Stdi…

▾ AbyssalMervinPraison · PraisonAIEPSS 1.0%via NVD
CVE-2026-57119High· 7.5PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary che…

▾ MidnightMervinPraison · PraisonAIEPSS 0.53%via NVD
CVE-2026-57127Critical· 9.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KE…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.90%via NVD
CVE-2026-56839High· 7.3PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy w…

▾ MidnightMervinPraison · PraisonAIEPSS 0.38%via NVD
CVE-2026-57131Critical· 9.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.97%via NVD
CVE-2026-57130High· 8.1PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteri…

▾ MidnightMervinPraison · praisonaiagentsEPSS 0.46%via NVD
CVE-2026-57132High· 8.2PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the applica…

▾ MidnightMervinPraison · PraisonAIEPSS 0.51%via NVD
CVE-2026-57115Medium· 6.5
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loop…

▾ SunlitMervinPraison · PraisonAIEPSS 0.43%via NVD
CVEs tagged “nvd” — page 339 · VulnSea