5.3

CVSS4.0

CVE-2026-6618 - langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-s…

A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-side request forgery. …

📅 Published: April 20, 2026, 7:45 a.m. 🔄 Last Modified: April 20, 2026, 7:45 a.m.

8.7

CVSS4.0

CVE-2026-5967 - TeamT5|ThreatSonar Anti-Ransomware - Privilege Escalation

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges.

📅 Published: April 20, 2026, 7:44 a.m. 🔄 Last Modified: April 20, 2026, 7:44 a.m.

7.2

CVSS4.0

CVE-2026-5966 - TeamT5|ThreatSonar Anti-Ransomware - Arbitrary File Deletion

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.

📅 Published: April 20, 2026, 7:40 a.m. 🔄 Last Modified: April 20, 2026, 7:40 a.m.

9.3

CVSS4.0

CVE-2026-5964 - Digiwin|EasyFlow .NET - SQL Injection

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

📅 Published: April 20, 2026, 7:36 a.m. 🔄 Last Modified: April 20, 2026, 7:36 a.m.

9.3

CVSS4.0

CVE-2026-5963 - Digiwin|EasyFlow .NET - SQL Injection

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

📅 Published: April 20, 2026, 7:32 a.m. 🔄 Last Modified: April 20, 2026, 7:33 a.m.

5.3

CVSS4.0

CVE-2026-6617 - langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schem…

A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Performing a manipulation of the argument url results in server-…

📅 Published: April 20, 2026, 7:30 a.m. 🔄 Last Modified: April 20, 2026, 7:30 a.m.

5.3

CVSS4.0

CVE-2026-6616 - TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side reque…

A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/helper/webpage_extractor.py of the component WebScraperTool. Such manipulation leads to server-side request forge…

📅 Published: April 20, 2026, 7:15 a.m. 🔄 Last Modified: April 20, 2026, 7:15 a.m.

4

CVSS3.1

CVE-2026-41282 -

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

📅 Published: April 20, 2026, 7:10 a.m. 🔄 Last Modified: April 20, 2026, 7:10 a.m.

6.9

CVSS4.0

CVE-2026-6615 - TransformerOptimus SuperAGI Multipart Upload resources.py upload path traversal

A weakness has been identified in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function Upload of the file superagi/controllers/resources.py of the component Multipart Upload Handler. This manipulation of the argument Name causes path traversal. It is possible to initiate…

📅 Published: April 20, 2026, 7 a.m. 🔄 Last Modified: April 20, 2026, 7 a.m.

9.4

CVSS4.0

CVE-2026-6644 - A command injection vulnerability was found in the PPTP VPN Clients on the ADM

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied i…

📅 Published: April 20, 2026, 6:54 a.m. 🔄 Last Modified: April 20, 2026, 6:54 a.m.
Total resulsts: 345359
Page 14 of 34,536
« previous page » next page
Filters