Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

33925
Total
2632
Critical
10022
High
10229
Medium
CVE ID Severity Score Description Published
CVE-2026-5987 MEDIUM 4.7 A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemarkerView.java of the component FreeMarker … Apr 09, 2026
CVE-2026-5986 MEDIUM 5.3 A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This manipulation of … Apr 09, 2026
CVE-2026-5985 HIGH 7.3 A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /crud.php. The … Apr 09, 2026
CVE-2026-5507 UNKNOWN When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can … Apr 09, 2026
CVE-2026-5504 UNKNOWN A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In … Apr 09, 2026
CVE-2026-5503 UNKNOWN In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This caused TLSX_UseSNI to attach the attacker-controlled publicName to the shared WOLFSSL_CTX … Apr 09, 2026
CVE-2026-5295 UNKNOWN A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/pkcs7.c. When processing a CMS EnvelopedData message containing an OtherRecipientInfo (ORI) … Apr 09, 2026
CVE-2026-34424 CRITICAL 9.8 Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated … Apr 09, 2026
CVE-2026-5984 HIGH 8.8 A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation … Apr 09, 2026
CVE-2026-5983 HIGH 8.8 A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing … Apr 09, 2026
CVE-2026-5982 HIGH 8.8 A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing … Apr 09, 2026
CVE-2026-5981 HIGH 8.8 A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such … Apr 09, 2026
CVE-2026-5778 UNKNOWN Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS … Apr 09, 2026
CVE-2026-5772 UNKNOWN A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard … Apr 09, 2026
CVE-2026-5264 UNKNOWN Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer … Apr 09, 2026
CVE-2026-5263 UNKNOWN URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf … Apr 09, 2026
CVE-2026-40154 CRITICAL 9.3 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or … Apr 09, 2026
CVE-2026-40153 HIGH 7.4 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing … Apr 09, 2026
CVE-2026-40152 MEDIUM 5.3 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via _validate_path(), but passes … Apr 09, 2026
CVE-2026-40151 MEDIUM 5.3 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent names, roles, and the … Apr 09, 2026
CVE-2026-40150 HIGH 7.7 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitrary URLs from AI agents with zero validation. No scheme … Apr 09, 2026
CVE-2026-40149 HIGH 7.9 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unauthenticated modification of the tool approval allowlist when no auth_token is … Apr 09, 2026
CVE-2026-40148 MEDIUM 6.5 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registry validates archive members against path traversal attacks but performs … Apr 09, 2026
CVE-2026-40117 MEDIUM 6.2 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path parameter. … Apr 09, 2026
CVE-2026-40116 HIGH 7.5 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from any client without authentication or … Apr 09, 2026