CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,276 result(s) · page 160 of 164
CVE-2026-57136
HIGH

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delim...

CVSS 8.8 2026-09-15
CVE-2026-57135
HIGH

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only...

CVSS 7.6 2026-09-15
CVE-2026-57134
HIGH

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator on...

CVSS 8.2 2026-09-15
CVE-2026-57133
HIGH

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delim...

CVSS 8.8 2026-09-15
CVE-2026-57112
HIGH

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents...

CVSS 8.3 2026-09-15
CVE-2026-52828
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level...

CVSS 5.3 2026-09-15
CVE-2026-52827
HIGH

Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api...

CVSS 7.1 2026-09-15
CVE-2026-52826
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/a...

CVSS 5.3 2026-09-15
CVE-2026-52825
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead ma...

CVSS 5.3 2026-09-15
CVE-2026-52824
CRITICAL

Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and...

CVSS 9.1 2026-09-15
CVE-2026-52823
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an a...

CVSS 5.3 2026-09-15
CVE-2026-52822
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can der...

CVSS 5.3 2026-09-15
CVE-2026-52821
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only...

CVSS 5.3 2026-09-15
CVE-2026-52820
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through Timeshee...

CVSS 5.3 2026-09-15
CVE-2026-52819
MEDIUM

Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_...

CVSS 6.3 2026-09-15
CVE-2026-1759
MEDIUM

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.62551507...

CVSS 6.5 2026-09-15
CVE-2026-1758
HIGH

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11....

CVSS 8.3 2026-09-15
CVE-2026-91859
MEDIUM

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering...

CVSS 5.3 2026-09-15
CVE-2026-91857
MEDIUM

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPi...

CVSS 5.3 2026-09-15
CVE-2026-62379
CRITICAL

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose class...

CVSS 9.8 2026-09-15
1 158 159 160 161 162 164
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.