Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57401
Total
4583
Critical
17032
High
16919
Medium
CVE ID Severity Score Description Published
CVE-2026-90795 MEDIUM 4.3 A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of … Sep 14, 2026
CVE-2026-90794 MEDIUM 6.3 A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing … Sep 14, 2026
CVE-2026-90793 MEDIUM 5.4 A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation … Sep 14, 2026
CVE-2026-90792 MEDIUM 4.3 A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This … Sep 14, 2026
CVE-2026-90463 MEDIUM 4.0 A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to … Sep 14, 2026
CVE-2026-88819 UNKNOWN — In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID. Sep 14, 2026
CVE-2026-87087 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Sep 14, 2026
CVE-2026-81301 UNKNOWN — Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a … Sep 14, 2026
CVE-2026-61534 CRITICAL 9.1 Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and … Sep 14, 2026
CVE-2026-57145 CRITICAL 9.1 PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, … Sep 14, 2026
CVE-2026-57132 HIGH 8.2 PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use … Sep 14, 2026
CVE-2026-57131 CRITICAL 9.8 PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts … Sep 14, 2026
CVE-2026-57127 CRITICAL 9.8 PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each … Sep 14, 2026
CVE-2026-57124 CRITICAL 9.8 PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and … Sep 14, 2026
CVE-2026-57122 HIGH 8.6 PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is … Sep 14, 2026
CVE-2026-57119 HIGH 7.5 PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes … Sep 14, 2026
CVE-2026-56839 HIGH 7.3 PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers … Sep 14, 2026
CVE-2026-55795 UNKNOWN — Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number … Sep 14, 2026
CVE-2026-55236 MEDIUM 5.9 langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by … Sep 14, 2026
CVE-2026-55235 MEDIUM 5.9 langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target … Sep 14, 2026
CVE-2026-54542 LOW 3.7 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash … Sep 14, 2026
CVE-2026-54541 LOW 3.7 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash … Sep 14, 2026
CVE-2026-54529 MEDIUM 5.3 SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the … Sep 14, 2026
CVE-2026-53708 MEDIUM 6.6 ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to … Sep 14, 2026
CVE-2026-4103 MEDIUM 6.4 Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the … Sep 14, 2026