Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52841
Total
4211
Critical
15646
High
15361
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-61455 | MEDIUM | 6.5 | Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a … | Jul 10, 2026 |
| CVE-2026-61450 | MEDIUM | 6.5 | Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate … | Jul 10, 2026 |
| CVE-2026-61444 | CRITICAL | 9.1 | PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can … | Jul 10, 2026 |
| CVE-2026-61441 | MEDIUM | 6.5 | PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete … | Jul 10, 2026 |
| CVE-2026-61437 | HIGH | 7.8 | PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, … | Jul 10, 2026 |
| CVE-2026-61434 | HIGH | 8.8 | PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, … | Jul 10, 2026 |
| CVE-2026-61432 | MEDIUM | 5.7 | PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither … | Jul 10, 2026 |
| CVE-2026-61431 | MEDIUM | 5.5 | PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute … | Jul 10, 2026 |
| CVE-2026-60091 | HIGH | 7.2 | PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but … | Jul 10, 2026 |
| CVE-2026-60089 | MEDIUM | 5.5 | PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A … | Jul 10, 2026 |
| CVE-2026-60086 | MEDIUM | 5.3 | PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector … | Jul 10, 2026 |
| CVE-2026-59796 | HIGH | 8.1 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | Jul 10, 2026 |
| CVE-2026-59795 | HIGH | 8.1 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | Jul 10, 2026 |
| CVE-2026-59794 | HIGH | 7.3 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | Jul 10, 2026 |
| CVE-2026-59793 | HIGH | 8.8 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | Jul 10, 2026 |
| CVE-2026-59792 | CRITICAL | 9.6 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | Jul 10, 2026 |
| CVE-2026-59791 | LOW | 3.5 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | Jul 10, 2026 |
| CVE-2026-58661 | UNKNOWN | — | n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota … | Jul 10, 2026 |
| CVE-2026-57994 | MEDIUM | 5.3 | phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (draft or review-only) FAQ … | Jul 10, 2026 |
| CVE-2026-57961 | LOW | 2.7 | phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML … | Jul 10, 2026 |
| CVE-2026-56765 | CRITICAL | 9.8 | Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. … | Jul 10, 2026 |
| CVE-2026-56373 | LOW | 3.7 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability … | Jul 10, 2026 |
| CVE-2026-56366 | LOW | 3.3 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing … | Jul 10, 2026 |
| CVE-2026-56354 | MEDIUM | 4.1 | n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to … | Jul 10, 2026 |
| CVE-2026-56335 | MEDIUM | 6.5 | Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null … | Jul 10, 2026 |