5.3

CVSS4.0

CVE-2026-6587 - vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argu…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 20, 2026, midnight

5.3

CVSS4.0

CVE-2026-6586 - TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. T…

📅 Published: April 19, 2026, 11:45 p.m. 🔄 Last Modified: April 19, 2026, 11:45 p.m.

5.3

CVSS4.0

CVE-2026-6585 - TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation author…

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Organisation Update Endpoint. This manipulation of the argument organisation_id causes authorization bypa…

📅 Published: April 19, 2026, 11:30 p.m. 🔄 Last Modified: April 19, 2026, 11:30 p.m.

5.3

CVSS4.0

CVE-2026-6584 - TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/controllers/user.py of the component User Update Endpoint. The manipulation of the argument user_id results in authorization bypass. The attack may be perf…

📅 Published: April 19, 2026, 11:15 p.m. 🔄 Last Modified: April 19, 2026, 11:15 p.m.

5.3

CVSS4.0

CVE-2026-6583 - TransformerOptimus SuperAGI API Key Management Endpoint api_key.py edit_api_key authorization

A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edit_api_key of the file superagi/controllers/api_key.py of the component API Key Management Endpoint. The manipulation leads to authorization bypass. The attack is possible to be ca…

📅 Published: April 19, 2026, 11 p.m. 🔄 Last Modified: April 19, 2026, 11 p.m.

6.9

CVSS4.0

CVE-2026-6582 - TransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details…

A flaw has been found in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function get_vector_db_details of the file superagi/controllers/vector_dbs.py of the component Vector Database Management Endpoint. Executing a manipulation can lead to missing authentication. The attac…

📅 Published: April 19, 2026, 10:45 p.m. 🔄 Last Modified: April 19, 2026, 10:45 p.m.

8.7

CVSS4.0

CVE-2026-6581 - H3C Magic B1 aspForm SetMobileAPInfoById buffer overflow

A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now p…

📅 Published: April 19, 2026, 10:30 p.m. 🔄 Last Modified: April 19, 2026, 10:30 p.m.

6.9

CVSS4.0

CVE-2026-6580 - liangliangyy DjangoBlog Amap API Call views.py hard-coded key

A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipulation of the argument key leads to use of hard-coded cryptographic key . The attack may be launche…

📅 Published: April 19, 2026, 10:15 p.m. 🔄 Last Modified: April 19, 2026, 10:15 p.m.

6.9

CVSS4.0

CVE-2026-6579 - liangliangyy DjangoBlog Clean Endpoint views.py missing authentication

A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the publ…

📅 Published: April 19, 2026, 10 p.m. 🔄 Last Modified: April 19, 2026, 10 p.m.

6.3

CVSS4.0

CVE-2026-6578 - liangliangyy DjangoBlog Setting settings.py hard-coded credentials

A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard-coded credentials. The attack can be launched remotely. The…

📅 Published: April 19, 2026, 9:15 p.m. 🔄 Last Modified: April 19, 2026, 9:15 p.m.
Total resulsts: 345171
Page 2 of 34,518
« previous page » next page
Filters