Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-61451 | CRITICAL | 9.6 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function … | Jul 15, 2026 |
| CVE-2026-61449 | MEDIUM | 6.5 | Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's … | Jul 15, 2026 |
| CVE-2026-61446 | HIGH | 8.4 | PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and … | Jul 15, 2026 |
| CVE-2026-61443 | HIGH | 8.1 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to … | Jul 15, 2026 |
| CVE-2026-61440 | MEDIUM | 6.5 | PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove … | Jul 15, 2026 |
| CVE-2026-61438 | HIGH | 7.3 | PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML … | Jul 15, 2026 |
| CVE-2026-61436 | HIGH | 8.6 | PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON … | Jul 15, 2026 |
| CVE-2026-61435 | HIGH | 8.2 | PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the … | Jul 15, 2026 |
| CVE-2026-61433 | HIGH | 7.8 | PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through … | Jul 15, 2026 |
| CVE-2026-61430 | HIGH | 8.5 | PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time … | Jul 15, 2026 |
| CVE-2026-61427 | HIGH | 7.3 | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer … | Jul 15, 2026 |
| CVE-2026-60087 | MEDIUM | 6.1 | PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can … | Jul 15, 2026 |
| CVE-2026-60085 | HIGH | 7.5 | PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely … | Jul 15, 2026 |
| CVE-2026-59259 | UNKNOWN | — | n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check … | Jul 15, 2026 |
| CVE-2026-59254 | UNKNOWN | — | n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can … | Jul 15, 2026 |
| CVE-2026-59236 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated … | Jul 15, 2026 |
| CVE-2026-58655 | HIGH | 8.8 | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin … | Jul 15, 2026 |
| CVE-2026-57996 | HIGH | 8.8 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with … | Jul 15, 2026 |
| CVE-2026-56764 | LOW | 3.7 | Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can … | Jul 15, 2026 |
| CVE-2026-56699 | CRITICAL | 10.0 | Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can … | Jul 15, 2026 |
| CVE-2026-56400 | HIGH | 8.3 | open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary … | Jul 15, 2026 |
| CVE-2026-56398 | HIGH | 7.3 | Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from … | Jul 15, 2026 |
| CVE-2026-56375 | LOW | 3.3 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources … | Jul 15, 2026 |
| CVE-2026-56353 | MEDIUM | 4.8 | n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, … | Jul 15, 2026 |
| CVE-2026-56352 | MEDIUM | 6.4 | n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the … | Jul 15, 2026 |