Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,481 - 5,500 of 34,868 CVEs
CVE-2026-47410 CRITICAL - 9.8

praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47405 HIGH - 8.8

PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47399 HIGH - 8.8

PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub

PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47408 MEDIUM - 6.5

praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-48169 HIGH - 8.8

PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub

PraisonAI has an Arbitrary File Write in Python API

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47391 CRITICAL - 9.8

PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub

PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47392 CRITICAL - 9.9

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

Vendor: pip
Product: praisonaiagents
Published: May 29, 2026
Source: GitHub
CVE-2026-47395 MEDIUM - 5.5

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

Vendor: pip
Product: praisonaiagents
Published: May 29, 2026
Source: GitHub
CVE-2026-47393 CRITICAL - 9.8

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47396 CRITICAL - 9.8

PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47390 MEDIUM - 5.5

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

Vendor: pip
Product: praisonaiagents
Published: May 29, 2026
Source: GitHub
CVE-2026-47398 HIGH - 8.1

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-9831 MEDIUM - 6.3

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue w...

Published: May 29, 2026
Source: NVD
CVE-2026-47268 MEDIUM - 6.4

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.10, an authenticated Nezha dashboard user can create or update a DDNS profile with provider webhook and configure an arbitrary webhook_url, HTTP method, reque...

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 29, 2026
Source: GitHub
CVE-2026-47233 MEDIUM - 6.5

Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` โ€” incomplete fix of #2024

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47234 MEDIUM - 4.4

Admidio writes session IDs and auto-login cookie values to application logs

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub
CVE-2026-47232 MEDIUM - 4.3

Admidio PKCS#12 private key export action lacks CSRF protection

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub