Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51867 | UNKNOWN | — | agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access … | Sep 30, 2026 |
| CVE-2026-51866 | UNKNOWN | — | In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow. | Sep 30, 2026 |
| CVE-2026-51864 | UNKNOWN | — | DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended … | Sep 30, 2026 |
| CVE-2026-51862 | UNKNOWN | — | DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or … | Sep 30, 2026 |
| CVE-2026-51861 | UNKNOWN | — | bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py. | Sep 30, 2026 |
| CVE-2026-51860 | UNKNOWN | — | bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py. | Sep 30, 2026 |
| CVE-2026-51859 | UNKNOWN | — | bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290). | Sep 30, 2026 |
| CVE-2026-51858 | UNKNOWN | — | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary. | Sep 30, 2026 |
| CVE-2026-51857 | UNKNOWN | — | In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary. | Sep 30, 2026 |
| CVE-2026-51856 | UNKNOWN | — | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to … | Sep 30, 2026 |
| CVE-2026-51853 | UNKNOWN | — | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, … | Sep 30, 2026 |
| CVE-2026-51852 | UNKNOWN | — | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing … | Sep 30, 2026 |
| CVE-2026-51570 | HIGH | 8.1 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | Sep 30, 2026 |
| CVE-2026-51568 | HIGH | 8.1 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | Sep 30, 2026 |
| CVE-2026-103000 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py … | Sep 30, 2026 |
| CVE-2026-102999 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API … | Sep 30, 2026 |
| CVE-2026-102998 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to … | Sep 30, 2026 |
| CVE-2026-102997 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can … | Sep 30, 2026 |
| CVE-2026-102996 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an … | Sep 30, 2026 |
| CVE-2026-102995 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a … | Sep 30, 2026 |
| CVE-2026-102150 | HIGH | 7.2 | A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set … | Sep 30, 2026 |
| CVE-2026-102149 | CRITICAL | 9.4 | Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate … | Sep 30, 2026 |
| CVE-2026-102147 | CRITICAL | 9.3 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the … | Sep 30, 2026 |
| CVE-2026-102146 | MEDIUM | 6.5 | An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection … | Sep 30, 2026 |
| CVE-2026-102145 | MEDIUM | 6.6 | An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through … | Sep 30, 2026 |