Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34125
Total
2661
Critical
10081
High
10307
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34772 | MEDIUM | 5.8 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow … | Apr 04, 2026 |
| CVE-2026-34771 | HIGH | 7.5 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register … | Apr 04, 2026 |
| CVE-2026-34770 | HIGH | 7.0 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use … | Apr 04, 2026 |
| CVE-2026-34769 | HIGH | 7.7 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches … | Apr 04, 2026 |
| CVE-2026-34768 | LOW | 3.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: … | Apr 04, 2026 |
| CVE-2026-34767 | MEDIUM | 5.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register … | Apr 04, 2026 |
| CVE-2026-34766 | LOW | 3.3 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event … | Apr 04, 2026 |
| CVE-2026-35468 | MEDIUM | 5.3 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus request handlers … | Apr 03, 2026 |
| CVE-2026-34954 | HIGH | 8.6 | PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, … | Apr 03, 2026 |
| CVE-2026-34953 | CRITICAL | 9.1 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty … | Apr 03, 2026 |
| CVE-2026-34952 | CRITICAL | 9.1 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info … | Apr 03, 2026 |
| CVE-2026-34939 | MEDIUM | 6.5 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, … | Apr 03, 2026 |
| CVE-2026-34938 | CRITICAL | 10.0 | PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed … | Apr 03, 2026 |
| CVE-2026-34937 | HIGH | 7.8 | PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-controlled code into python3 -c … | Apr 03, 2026 |
| CVE-2026-34936 | HIGH | 7.7 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a caller-controlled api_base parameter that is concatenated with endpoint … | Apr 03, 2026 |
| CVE-2026-34935 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through … | Apr 03, 2026 |
| CVE-2026-34934 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with unescaped thread IDs fetched from … | Apr 03, 2026 |
| CVE-2026-34933 | MEDIUM | 5.5 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user … | Apr 03, 2026 |
| CVE-2026-34824 | HIGH | 7.5 | Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability … | Apr 03, 2026 |
| CVE-2026-34788 | MEDIUM | 6.5 | Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at line 168. The updateTagName() … | Apr 03, 2026 |
| CVE-2026-34787 | MEDIUM | 6.5 | Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php at line 80. … | Apr 03, 2026 |
| CVE-2026-34612 | CRITICAL | 9.9 | Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code … | Apr 03, 2026 |
| CVE-2026-34607 | HIGH | 7.2 | Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting … | Apr 03, 2026 |
| CVE-2026-34229 | MEDIUM | 6.1 | Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment module via … | Apr 03, 2026 |
| CVE-2026-34228 | UNKNOWN | — | Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parameters. … | Apr 03, 2026 |