CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,643 result(s) · page 172 of 183
CVE-2026-53496
MEDIUM

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the...

CVSS 5.3 2026-09-14
CVE-2026-20353
CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducte...

CVSS 9.8 2026-09-14
CVE-2026-90995
MEDIUM

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a sp...

CVSS 5.5 2026-09-14
CVE-2026-90947
HIGH

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lea...

CVSS 7.8 2026-09-14
CVE-2026-90943
HIGH

parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious sc...

CVSS 8.7 2026-09-14
CVE-2026-90794
MEDIUM

A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a m...

CVSS 6.3 2026-09-14
CVE-2026-90793
MEDIUM

A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation...

CVSS 5.4 2026-09-14
CVE-2026-88819
MEDIUM

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

CVSS 6.3 2026-09-14
CVE-2026-81301
HIGH

Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the cal...

CVSS 8.5 2026-09-14
CVE-2026-61534
CRITICAL

Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names...

CVSS 9.1 2026-09-14
CVE-2026-57145
CRITICAL

PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and w...

CVSS 9.1 2026-09-14
CVE-2026-57132
HIGH

PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERV...

CVSS 8.2 2026-09-14
CVE-2026-57131
CRITICAL

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or p...

CVSS 9.8 2026-09-14
CVE-2026-57127
CRITICAL

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, bu...

CVSS 9.8 2026-09-14
CVE-2026-57124
CRITICAL

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlle...

CVSS 9.8 2026-09-14
CVE-2026-57122
HIGH

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET...

CVSS 8.6 2026-09-14
CVE-2026-57119
HIGH

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the j...

CVSS 7.5 2026-09-14
CVE-2026-56839
HIGH

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff ...

CVSS 7.3 2026-09-14
CVE-2026-55795
MEDIUM

Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when t...

CVSS 6.9 2026-09-14
CVE-2026-55236
MEDIUM

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by dis...

CVSS 5.9 2026-09-14
1 170 171 172 173 174 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.