Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 341 - 360 of 34,868 CVEs
CVE-2026-38717 CRITICAL - 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Published: Jun 18, 2026
Source: NVD
CVE-2026-38716 CRITICAL - 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Published: Jun 18, 2026
Source: NVD
CVE-2026-38715 CRITICAL - 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Published: Jun 18, 2026
Source: NVD
CVE-2026-38714 CRITICAL - 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Published: Jun 18, 2026
Source: NVD

Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.

Vendor: Grav
Product: grav-plugin-api
Published: Jun 18, 2026
Source: NVD

Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis, confirmed with the fix author, determined that the addressed defect does not apply to any released version of Zephyr: the affected code path exists only in unreleased development code, and no released ...

Published: Jun 18, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `MediaDurationBlock` will download and store the video in a temporary directory without deleting before all noded are done. `StepThroughItemsBlock` can be used ...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `AddAudioToVideoBlock` will download and store the video and audio in a temporary directory without deleting before all noded are done. `StepThroughItemsBlock` ...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, ScreenshotWebPageBlock will store the captured screenshots in a temporary directory. `StepThroughItemsBlock` can be used to iterate `ScreenshotWebPageBlock` mul...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepThroughItemsBlock` can iterate all the contents in a list and send them to `FileStoreBlock` for downloading one by one. Although `FileStoreBlock` has acces...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGPT's LoopVideoBLock allows users to input a video file and process the video, such as looping it 5 times or extending the time, and finally writing it...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the wor...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrar...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encod...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD
CVE-2026-11791 MEDIUM - 5.0

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload whi...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 18, 2026
Source: NVD

OpenFGA Improper Policy Enforcement

Vendor: go
Product: github.com/openfga/openfga
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55093 MEDIUM - 6.1

tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load

Vendor: rust
Product: tract-nnef
Published: Jun 18, 2026
Source: GitHub

PGHoard: Password written to debug log

Vendor: pip
Product: pghoard
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54695 HIGH - 7.5

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

Vendor: pip
Product: pipecat-ai
Published: Jun 18, 2026
Source: GitHub