Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 161 - 180 of 36,689 CVEs
CVE-2026-56823 MEDIUM - 5.4

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the webhook belongs to the aut...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD
CVE-2026-56663 HIGH - 8.5

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services. _is_ip_blocked() in backend/backe...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD
CVE-2026-55677 HIGH - 7.5

Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows...

Vendor: labstack
Product: echo
Published: Jun 26, 2026
Source: NVD
CVE-2026-54636 CRITICAL - 9.9

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the Docker container and ...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-45408 CRITICAL - 9.0

Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (&l...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-45407 MEDIUM - 5.5

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creation defeats the netrc binary's built-in 0600 permission setting, leaving git credentials readable by any local...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-45406 HIGH - 8.8

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename cont...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-45405 HIGH - 8.8

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks during extraction and follows them for subsequent e...

Vendor: dokku
Product: dokku
Published: Jun 26, 2026
Source: NVD
CVE-2026-28385 MEDIUM - 5.0

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network infrastructure via the /images endpoint. When importing an image from a...

Vendor: Canonical
Product: lxd
Published: Jun 26, 2026
Source: NVD
CVE-2026-13434 MEDIUM - 4.9

A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation ...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 26, 2026
Source: NVD

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

Vendor: PayloadCMS
Product: PayloadCMS
Published: Jun 26, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, th...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the serv...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 26, 2026
Source: NVD

fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`

Vendor: rubygems
Product: fluent-plugin-s3
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44161 HIGH - 7.2

Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44160 HIGH - 7.5

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44025 HIGH - 7.5

Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-44024 CRITICAL - 9.8

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Vendor: rubygems
Product: fluentd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-9640 HIGH - 7.2

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project operator in a restricted multi-tenant environment can bypass policy restr...

Published: Jun 26, 2026
Source: NVD
CVE-2026-9639 MEDIUM - 6.5

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that omits the expires_at snapshot field.

Published: Jun 26, 2026
Source: NVD