| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-55536 | Cri | 0.52 | 9.1 | 0.01 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(),… | ||
| CVE-2026-55533 | Hig | 0.46 | 8.2 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST… | ||
| CVE-2026-55532 | Hig | 0.42 | 7.6 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type:… | ||
| CVE-2025-71407 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2025-71406 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2025-71346 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2024-58378 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2024-58377 | Med | 0.29 | 5.5 | 0.00 | Aug 25, 2026 | Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not… | ||
| CVE-2023-54354 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2022-51000 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2022-50999 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2022-50998 | 0.00 | — | 0.00 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2021-47996 | 0.00 | — | 0.01 | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. | |||
| CVE-2026-79717 | Med | 0.42 | 6.4 | 0.00 | Aug 25, 2026 | A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or… | ||
| CVE-2026-70551 | Hig | 0.55 | 8.5 | 0.00 | Aug 25, 2026 | A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL. | ||
| CVE-2026-69104 | Hig | 0.49 | 7.6 | 0.00 | Aug 25, 2026 | An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue. | ||
| CVE-2026-55624 | Med | 0.27 | — | 0.00 | Aug 25, 2026 | MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42d6b3f8 fixes the issue. | ||
| CVE-2026-55541 | — | Hig | 0.50 | — | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app() and _create_unified_app() do not install a credential check. Unauthenticated callers can reach POST /agents and POST… | |
| CVE-2026-55540 | — | Hig | 0.39 | 7.1 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other… | |
| CVE-2026-55538 | — | Hig | 0.40 | 7.3 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or incorrect bearer and X-API-Key values still reach agent… | |
| CVE-2026-55537 | — | Hig | 0.39 | 7.1 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh… | |
| CVE-2026-55535 | — | Med | 0.37 | 6.8 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or… | |
| CVE-2026-55534 | — | Hig | 0.49 | 8.6 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even… | |
| CVE-2026-55531 | Med | 0.35 | 6.5 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize request but does not call _cleanup_sessions or enforce a maximum. An unauthenticated caller can exhaust memory. The fix… | ||
| CVE-2026-55530 | — | Med | 0.33 | 6.1 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call can pass --update-all and a broad path to rewrite matching files without… | |
| CVE-2026-55529 | Med | 0.38 | 6.9 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-controlled localhost.evil.example HTTP origin matches the localhost allowlist. Without an API key, a… | ||
| CVE-2026-55528 | Hig | 0.46 | 8.2 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or… | ||
| CVE-2026-55527 | — | Hig | 0.39 | 7.1 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable… | |
| CVE-2026-55526 | — | Hig | 0.48 | 8.5 | 0.00 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP… | |
| CVE-2026-16599 | Med | 0.26 | — | 0.00 | Aug 25, 2026 | GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server… | ||
| CVE-2026-16286 | Cri | 0.64 | 9.8 | 0.00 | Aug 25, 2026 | Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository… | ||
| CVE-2026-15310 | Low | 0.07 | — | 0.01 | Aug 25, 2026 | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. | ||
| CVE-2026-2035364 | imp | 0.53 | 8.1 | — | Aug 25, 2026 | keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints | ||
| CVE-2026-2035366 | imp | 0.46 | 7.1 | — | Aug 25, 2026 | keystone: keystone: Application credential tokens can escape project scope via token-method reauthentication | ||
| CVE-2026-79655 | Hig | 0.44 | 7.8 | 0.00 | Aug 25, 2026 | A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink… | ||
| CVE-2026-79623 | Med | 0.41 | 6.3 | 0.02 | Aug 25, 2026 | A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the component Default Local Worker Backend. The manipulation leads to os command injection. The attack can be initiated… | ||
| CVE-2026-79622 | Hig | 0.47 | 7.3 | 0.01 | Aug 25, 2026 | A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is… | ||
| CVE-2026-55525 | Hig | 0.42 | 7.5 | 0.01 | Aug 25, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target… | ||
| CVE-2026-78360 | imp | 0.46 | 7.1 | — | Aug 25, 2026 | anitya: anitya: missing authorization check in delete_user allows any authenticated user to delete arbitrary users | ||
| CVE-2026-79406 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2026 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated… | ||
| CVE-2026-78887 | Low | 0.24 | 3.7 | 0.00 | Aug 25, 2026 | A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is… | ||
| CVE-2026-78886 | Low | 0.17 | 3.7 | 0.01 | Aug 25, 2026 | A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal. The attack can… | ||
| CVE-2026-78885 | Med | 0.29 | 5.6 | 0.01 | Aug 25, 2026 | A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the… | ||
| CVE-2026-78581 | Med | 0.27 | 4.2 | 0.00 | Aug 25, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant… | ||
| CVE-2026-77998 | Cri | 0.65 | — | 0.01 | Aug 25, 2026 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the… | ||
| CVE-2026-75803 | Cri | 0.52 | 9.1 | 0.00 | Aug 25, 2026 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an… | ||
| CVE-2026-63076 | Hig | 0.42 | 7.5 | 0.02 | Aug 25, 2026 | Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced… | ||
| CVE-2026-63075 | Hig | 0.42 | 7.5 | 0.01 | Aug 25, 2026 | Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can… | ||
| CVE-2026-63074 | Med | 0.31 | 5.9 | 0.01 | Aug 25, 2026 | Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow… | ||
| CVE-2026-63073 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a… |
- risk 0.52cvss 9.1epss 0.01
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(),…
- risk 0.46cvss 8.2epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST…
- risk 0.42cvss 7.6epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type:…
- CVE-2025-71407Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- CVE-2025-71406Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- CVE-2025-71346Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- CVE-2024-58378Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- risk 0.29cvss 5.5epss 0.00
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not…
- CVE-2023-54354Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- CVE-2022-51000Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- CVE-2022-50999Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- CVE-2022-50998Aug 25, 2026risk 0.00cvss —epss 0.00
Rejected reason: This CVE ID has been rejected as a duplicate.
- CVE-2021-47996Aug 25, 2026risk 0.00cvss —epss 0.01
Rejected reason: This CVE ID has been rejected as a duplicate.
- risk 0.42cvss 6.4epss 0.00
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or…
- risk 0.55cvss 8.5epss 0.00
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
- risk 0.49cvss 7.6epss 0.00
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
- risk 0.27cvss —epss 0.00
MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42d6b3f8 fixes the issue.
- risk 0.50cvss —epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app() and _create_unified_app() do not install a credential check. Unauthenticated callers can reach POST /agents and POST…
- risk 0.39cvss 7.1epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other…
- risk 0.40cvss 7.3epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or incorrect bearer and X-API-Key values still reach agent…
- risk 0.39cvss 7.1epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh…
- risk 0.37cvss 6.8epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or…
- risk 0.49cvss 8.6epss 0.00
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even…
- risk 0.35cvss 6.5epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize request but does not call _cleanup_sessions or enforce a maximum. An unauthenticated caller can exhaust memory. The fix…
- risk 0.33cvss 6.1epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call can pass --update-all and a broad path to rewrite matching files without…
- risk 0.38cvss 6.9epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-controlled localhost.evil.example HTTP origin matches the localhost allowlist. Without an API key, a…
- risk 0.46cvss 8.2epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or…
- risk 0.39cvss 7.1epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable…
- risk 0.48cvss 8.5epss 0.00
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP…
- risk 0.26cvss —epss 0.00
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server…
- risk 0.64cvss 9.8epss 0.00
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository…
- risk 0.07cvss —epss 0.01
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
- risk 0.53cvss 8.1epss —
keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints
- risk 0.46cvss 7.1epss —
keystone: keystone: Application credential tokens can escape project scope via token-method reauthentication
- risk 0.44cvss 7.8epss 0.00
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink…
- risk 0.41cvss 6.3epss 0.02
A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the component Default Local Worker Backend. The manipulation leads to os command injection. The attack can be initiated…
- risk 0.47cvss 7.3epss 0.01
A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is…
- risk 0.42cvss 7.5epss 0.01
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target…
- risk 0.46cvss 7.1epss —
anitya: anitya: missing authorization check in delete_user allows any authenticated user to delete arbitrary users
- risk 0.28cvss 4.3epss 0.00
A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated…
- risk 0.24cvss 3.7epss 0.00
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is…
- risk 0.17cvss 3.7epss 0.01
A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal. The attack can…
- risk 0.29cvss 5.6epss 0.01
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the…
- risk 0.27cvss 4.2epss 0.00
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant…
- risk 0.65cvss —epss 0.01
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the…
- risk 0.52cvss 9.1epss 0.00
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an…
- risk 0.42cvss 7.5epss 0.02
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced…
- risk 0.42cvss 7.5epss 0.01
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can…
- risk 0.31cvss 5.9epss 0.01
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow…
- risk 0.57cvss 9.8epss 0.01
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a…