Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

485 CVEs · Critical severity

CVEs (485)

Showing 276–300 of 485

CVE ID Severity Patch CVSS Published Description
CVE-2026-50755 CRITICAL 9.8 2026-07-21 An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
CVE-2026-59142 CRITICAL Patched 9.1 2026-07-21 Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_v…
CVE-2026-59141 CRITICAL Patched 9.1 2026-07-21 Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_…
CVE-2026-59140 CRITICAL Patched 9.1 2026-07-21 Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validat…
CVE-2026-59139 CRITICAL Patched 9.1 2026-07-21 Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator …
CVE-2016-20096 CRITICAL 9.8 2026-07-21 Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by…
CVE-2026-47416 CRITICAL 9.6 2026-07-21 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /wo…
CVE-2026-47413 CRITICAL 9.6 2026-07-21 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The…
CVE-2026-47410 CRITICAL 9.8 2026-07-21 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing sec…
CVE-2026-64825 CRITICAL Patched 9.3 2026-07-21 Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host file…
CVE-2026-47396 CRITICAL 9.8 2026-07-21 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVE…
CVE-2026-47393 CRITICAL 9.8 2026-07-21 PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_cod…
CVE-2026-47392 CRITICAL 9.9 2026-07-21 PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tool…
CVE-2026-47391 CRITICAL 9.8 2026-07-21 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers …
CVE-2026-28321 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and exe…
CVE-2026-28317 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator ac…
CVE-2026-28316 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability t…
CVE-2026-28314 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower i…
CVE-2026-28313 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact …
CVE-2026-28312 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The imp…
CVE-2026-28310 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The …
CVE-2026-28309 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Wi…
CVE-2026-28308 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. T…
CVE-2026-28307 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Win…
CVE-2026-28306 CRITICAL 9.1 2026-07-21 SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact i…