Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 401 - 420 of 34,990 CVEs
CVE-2026-56078 HIGH - 8.8

PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite arbitrary files, enabling sensitive disclosure, denial of serv...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-56077 MEDIUM - 6.5

PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows attackers to access sensitive data by registering agents with duplicate IDs. Attackers can exploit the lack of agent ID uniqueness enforcement to share ledger instances and expose ...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-56076 HIGH - 8.1

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks authentication and hardcodes Access-Control-Allow-Origin: * headers, combined with Starlette's Con...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-56075 HIGH - 8.8

PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable. Authenticated attackers can instruct the LLM agent to execute arbitrary sh...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-56074 MEDIUM - 5.5

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentia...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 18, 2026
Source: NVD

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method ent...

Published: Jun 18, 2026
Source: NVD

Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standar...

Published: Jun 18, 2026
Source: NVD
CVE-2026-54130 CRITICAL - 9.8

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-49205 MEDIUM - 6.5

phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4 other write endpo...

Vendor: thorsten
Product: phpMyFAQ
Published: Jun 18, 2026
Source: NVD
CVE-2026-47647 CRITICAL - 9.9

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-47633 HIGH - 7.5

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-32174 HIGH - 7.7

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

Published: Jun 18, 2026
Source: NVD
CVE-2026-22674 MEDIUM - 4.8

Hashgraph Guardian through 3.5.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers...

Vendor: hashgraph
Product: guardian
Published: Jun 18, 2026
Source: NVD
CVE-2026-49454 CRITICAL - 9.1

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified before the library returned a successful authentication result. The XMLDSig trust boundary was inco...

Vendor: szTheory
Product: relyra
Published: Jun 18, 2026
Source: NVD
CVE-2026-49257 CRITICAL - 10.0

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including SQL query execution, schema creation, and ta...

Vendor: startreedata
Product: mcp-pinot
Published: Jun 18, 2026
Source: NVD
CVE-2026-49252 CRITICAL - 9.9

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write permission to any record...

Vendor: deepstreamIO
Product: deepstream.io
Published: Jun 18, 2026
Source: NVD

OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the target is an absolute path. A subsequent file entry in the same archive traverses the symlink, writing t...

Vendor: theonedev
Product: onedev
Published: Jun 18, 2026
Source: NVD
CVE-2026-46699 HIGH - 7.6

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to version 3.61.0, a vulnerability in the conda-forge automated webservices allowed unintended write access to feedstock repositories through GitHub userna...

Vendor: conda-forge
Product: conda-smithy
Published: Jun 18, 2026
Source: NVD

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The ht_undo_im...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Jun 18, 2026
Source: NVD