Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52113
Total
4140
Critical
15446
High
15158
Medium
CVE ID Severity Score Description Published
CVE-2026-61451 CRITICAL 9.6 The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function … Jul 15, 2026
CVE-2026-61449 MEDIUM 6.5 Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's … Jul 15, 2026
CVE-2026-61446 HIGH 8.4 PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and … Jul 15, 2026
CVE-2026-61443 HIGH 8.1 PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to … Jul 15, 2026
CVE-2026-61440 MEDIUM 6.5 PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove … Jul 15, 2026
CVE-2026-61438 HIGH 7.3 PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML … Jul 15, 2026
CVE-2026-61436 HIGH 8.6 PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON … Jul 15, 2026
CVE-2026-61435 HIGH 8.2 PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the … Jul 15, 2026
CVE-2026-61433 HIGH 7.8 PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through … Jul 15, 2026
CVE-2026-61430 HIGH 8.5 PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time … Jul 15, 2026
CVE-2026-61427 HIGH 7.3 PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer … Jul 15, 2026
CVE-2026-60087 MEDIUM 6.1 PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can … Jul 15, 2026
CVE-2026-60085 HIGH 7.5 PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely … Jul 15, 2026
CVE-2026-59259 UNKNOWN — n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check … Jul 15, 2026
CVE-2026-59254 UNKNOWN — n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can … Jul 15, 2026
CVE-2026-59236 UNKNOWN — Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated … Jul 15, 2026
CVE-2026-58655 HIGH 8.8 The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin … Jul 15, 2026
CVE-2026-57996 HIGH 8.8 phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with … Jul 15, 2026
CVE-2026-56764 LOW 3.7 Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can … Jul 15, 2026
CVE-2026-56699 CRITICAL 10.0 Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can … Jul 15, 2026
CVE-2026-56400 HIGH 8.3 open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary … Jul 15, 2026
CVE-2026-56398 HIGH 7.3 Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from … Jul 15, 2026
CVE-2026-56375 LOW 3.3 ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources … Jul 15, 2026
CVE-2026-56353 MEDIUM 4.8 n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, … Jul 15, 2026
CVE-2026-56352 MEDIUM 6.4 n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the … Jul 15, 2026