Export limit exceeded: 101822 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (101822 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-57132 | 1 Mervinpraison | 1 Praisonai | 2026-09-16 | 8.2 High |
| PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.6.62. | ||||
| CVE-2026-57119 | 1 Mervinpraison | 1 Praisonai | 2026-09-16 | 7.5 High |
| PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59. | ||||
| CVE-2026-54567 | 1 Jugmac00 | 1 Flask-reuploaded | 2026-09-16 | 7.5 High |
| Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept denylist. An attacker who controls the name override can use a mixed-case dangerous extension to bypass a lowercase denylist and store the file in the served upload directory. Exploitation requires a denylist configuration, a user-influenced name override, and a deployment that resolves or executes extensions case-insensitively; pure allowlists remain protected and path containment is not bypassed. On an execution-capable upload directory, the stored file can execute with the web server's privileges and affect confidentiality, integrity, and availability. This issue is fixed in version 1.6.0. | ||||
| CVE-2026-27557 | 3 Carlo Gavazzi, Pepperl Fuchs, Phoenix Contact | 8 Yl212cei8m1io Firmware, Yl212cpn8m1io Firmware, Yn115cei8rpio Firmware and 5 more | 2026-09-16 | 7.5 High |
| An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read. | ||||
| CVE-2026-88053 | 2 Tesseract-ocr, Tesseract Project | 2 Tesseract Ocr, Tesseract | 2026-09-16 | 7.8 High |
| Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .traineddata file and uses those values as loop bounds without validating them against MAX_NUM_CLASS_PRUNERS, MAX_NUM_CLASSES, and MAX_NUM_PROTO_SETS. The loops store heap pointers into fixed-capacity ClassPruners and ProtoSets arrays in INT_TEMPLATES_STRUCT and INT_CLASS_STRUCT, so an oversized count causes heap out-of-bounds pointer writes during legacy-classifier initialization before OCR begins, resulting in heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review. | ||||
| CVE-2026-69503 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-16 | 8 High |
| Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69423 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-16 | 8 High |
| Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69422 | 1 Microsoft | 8 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 5 more | 2026-09-16 | 7 High |
| Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-87088 | 1 Tanium | 1 Enforce | 2026-09-16 | 7 High |
| Tanium addressed an unauthorized code execution vulnerability in Enforce. | ||||
| CVE-2026-87084 | 1 Tanium | 1 Enforce | 2026-09-16 | 7.7 High |
| Tanium addressed a server-side request forgery vulnerability in Enforce. | ||||
| CVE-2026-87075 | 1 Tanium | 1 Comply | 2026-09-16 | 8.1 High |
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87072 | 1 Tanium | 1 Comply | 2026-09-16 | 7.1 High |
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87030 | 1 Tanium | 1 Comply | 2026-09-16 | 8.5 High |
| Tanium addressed a path traversal vulnerability in Comply. | ||||
| CVE-2026-87817 | 2 Gitpython-developers, Gitpython Project | 2 Gitpython, Gitpython | 2026-09-16 | 8.8 High |
| GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository. | ||||
| CVE-2026-87023 | 1 Tanium | 1 Comply | 2026-09-16 | 8.5 High |
| Tanium addressed a path traversal vulnerability in Comply. | ||||
| CVE-2026-87021 | 1 Tanium | 1 Comply | 2026-09-16 | 7.2 High |
| Tanium addressed an unauthorized code execution vulnerability in Comply. | ||||
| CVE-2026-69413 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-16 | 7 High |
| Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-87036 | 1 Tanium | 1 Comply | 2026-09-16 | 8.1 High |
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87034 | 1 Tanium | 1 Comply | 2026-09-16 | 8.3 High |
| Tanium addressed a SQL injection vulnerability in Comply. | ||||
| CVE-2026-90932 | 1 Laradashboard | 1 Lara Dashboard | 2026-09-16 | 7.2 High |
| LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains inside storage/app/core-backups; the corresponding form requests only validate the value as a bounded string. An authenticated user holding only the delegated settings.edit permission (not Superadmin) can supply ../ traversal sequences to delete arbitrary files reachable on the host filesystem, including outside the application tree, or to restore a ZIP archive from an arbitrary on-disk location, writing arbitrary files into the application directories and achieving remote code execution. Note: the advisory states the vulnerable concatenation was introduced in the v0.9.7 release line. No patched version was available at the time of publication. | ||||