Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,994
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,821 - 1,840 of 3,443 CVEs
CVE-2026-34953 CRITICAL - 9.1

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access t...

Vendor: pip
Product: praisonai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34952 CRITICAL - 9.1

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their ...

Vendor: pip
Product: praisonai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34934 CRITICAL - 9.8

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with unescaped thread IDs fetched from the database. An attacker stores a malicious thread ID via update_thread. When the application loads the thread list, ...

Vendor: pip
Product: praisonai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34935 CRITICAL - 9.8

PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through the call chain to anyio.open_process() with no validation, allowlist check, or sanitization at any hop, allowing arbitrary OS comman...

Vendor: pip
Product: praisonai
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34938 CRITICAL - 10.0

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitr...

Vendor: pip
Product: praisonaiagents
Published: Apr 01, 2026
Source: GitHub
CVE-2026-34571 CRITICAL - 9.9

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34569 CRITICAL - 9.9

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34568 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a mali...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34567 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section....

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34566 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing ...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34565 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management ...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34564 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when adding Pages to navigation menus through the Menu Management ...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34563 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when handling backup uploads and processing backup metadata. An at...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34560 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged da...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34559 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog tags. An attacker can inject a malic...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 01, 2026
Source: NVD
CVE-2026-34873 CRITICAL - 9.1

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-34872 CRITICAL - 9.1

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory ...

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-34456 CRITICAL - 9.1

Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email add...

Vendor: reviactyl
Product: panel
Published: Apr 01, 2026
Source: NVD
CVE-2026-34875 CRITICAL - 9.8

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

Vendor: arm
Product: mbed_tls
Published: Apr 01, 2026
Source: NVD
CVE-2026-34751 CRITICAL - 9.1

Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset. This issue ha...

Vendor: payloadcms
Product: payload
Published: Apr 01, 2026
Source: NVD