Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 601 - 620 of 35,119 CVEs

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepThroughItemsBlock` can iterate all the contents in a list and send them to `FileStoreBlock` for downloading one by one. Although `FileStoreBlock` has acces...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGPT's LoopVideoBLock allows users to input a video file and process the video, such as looping it 5 times or extending the time, and finally writing it...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD
CVE-2026-46580 HIGH - 8.8

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the wor...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD
CVE-2026-44691 HIGH - 8.8

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrar...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD
CVE-2026-44688 HIGH - 8.8

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD
CVE-2026-22551 MEDIUM - 6.5

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encod...

Vendor: Eclipse Foundation
Product: Eclipse Theia
Published: Jun 18, 2026
Source: NVD
CVE-2026-11791 MEDIUM - 5.0

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload whi...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 18, 2026
Source: NVD

OpenFGA Improper Policy Enforcement

Vendor: go
Product: github.com/openfga/openfga
Published: Jun 18, 2026
Source: GitHub
CVE-2026-55093 MEDIUM - 6.1

tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load

Vendor: rust
Product: tract-nnef
Published: Jun 18, 2026
Source: GitHub

PGHoard: Password written to debug log

Vendor: pip
Product: pghoard
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54695 HIGH - 7.5

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

Vendor: pip
Product: pipecat-ai
Published: Jun 18, 2026
Source: GitHub

opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Access to files of top-level drafts is not protected by permissions

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Request header injection in `Http\Remote`

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: Self cross-site scripting (self-XSS) in the writer field

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Vendor: composer
Product: getkirby/cms
Published: Jun 18, 2026
Source: GitHub
CVE-2026-47256 MEDIUM - 5.3

opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token

Vendor: go
Product: github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
Published: Jun 18, 2026
Source: GitHub