CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,643 result(s) · page 174 of 183
CVE-2026-7848
HIGH

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and...

CVSS 8.6 2026-09-14
CVE-2026-59570
HIGH

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

CVSS 7.5 2026-09-14
CVE-2026-59569
HIGH

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

CVSS 8.1 2026-09-14
CVE-2026-57130
HIGH

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, ...

CVSS 8.1 2026-09-14
CVE-2026-57129
HIGH

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative re...

CVSS 7.5 2026-09-14
CVE-2026-57126
HIGH

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve...

CVSS 8.5 2026-09-14
CVE-2026-57125
CRITICAL

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml...

CVSS 9.8 2026-09-14
CVE-2026-57123
CRITICAL

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes w...

CVSS 9.8 2026-09-14
CVE-2026-57120
MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or st...

CVSS 6.5 2026-09-14
CVE-2026-57115
MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects auto...

CVSS 6.5 2026-09-14
CVE-2026-25687
HIGH

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and pote...

CVSS 8.1 2026-09-14
CVE-2026-15600
HIGH

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST paramet...

CVSS 8.6 2026-09-14
CVE-2026-12985
MEDIUM

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob pat...

CVSS 6.8 2026-09-14
CVE-2026-90961
CRITICAL

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthen...

CVSS 9.3 2026-09-14
CVE-2026-90949
HIGH

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the al...

CVSS 7.8 2026-09-14
CVE-2026-90948
HIGH

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffe...

CVSS 7.8 2026-09-14
CVE-2026-90940
MEDIUM

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal ca...

CVSS 5.3 2026-09-14
CVE-2026-90939
MEDIUM

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retri...

CVSS 6.5 2026-09-14
CVE-2026-90787
HIGH

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebCont...

CVSS 7.3 2026-09-14
CVE-2026-90786
MEDIUM

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol...

CVSS 5.3 2026-09-14
1 172 173 174 175 176 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.