6.9

CVSS4.0

CVE-2026-6110 - FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit is p…

πŸ“… Published: April 12, 2026, 2 a.m. πŸ”„ Last Modified: April 13, 2026, 5:48 p.m.

5.3

CVSS4.0

CVE-2026-6109 - FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manipulation can lead to cross-site request forgery. The attack m…

πŸ“… Published: April 12, 2026, 1:30 a.m. πŸ”„ Last Modified: April 14, 2026, 4:33 p.m.

5.3

CVSS4.0

CVE-2026-6108 - 1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection

A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Model Context Protocol Node. Performing a manipulation results in os command injection. The attack is p…

πŸ“… Published: April 12, 2026, 1 a.m. πŸ”„ Last Modified: April 14, 2026, 2 p.m.

5.1

CVSS4.0

CVE-2026-6107 - 1Panel-dev MaxKB ChatHeadersMiddleware chat_headers_middleware.py cross site scripting

A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/common/middleware/chat_headers_middleware.py of the component ChatHeadersMiddleware. This manipulation of the argument Name causes cross site scripting. Remote exploitation of the atta…

πŸ“… Published: April 12, 2026, 12:45 a.m. πŸ”„ Last Modified: April 15, 2026, 3:16 p.m.

0.0

CVE-2026-31413 - bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR maybe_fork_scalars() is called for both BPF_AND and BPF_OR when the source operand is a constant. When dst has signed range [-1, 0], it forks the verifier state:…

πŸ“… Published: April 12, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 3:01 p.m.

5.1

CVSS4.0

CVE-2026-6106 - 1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site script…

A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/static_headers_middleware.py of the component Public Chat Interface. The manipulation of the argument Name results in cross site scripting…

πŸ“… Published: April 11, 2026, 10:15 p.m. πŸ”„ Last Modified: April 13, 2026, 3:01 p.m.

6.9

CVSS4.0

CVE-2026-6105 - perfree go-fastdfs-web doInstall InstallController.java improper authorization

A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.java of the component doInstall Interface. The manipulation leads to improper authorization. The attack may be initiated …

πŸ“… Published: April 11, 2026, 10 p.m. πŸ”„ Last Modified: April 13, 2026, 5:41 p.m.

9.3

CVSS4.0

CVE-2026-31845 - Reflected XSS in Rukovoditel CRM Zadarma API permits session hijacking

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response without proper sanitiz…

πŸ“… Published: April 11, 2026, 6:26 p.m. πŸ”„ Last Modified: April 13, 2026, 5:44 p.m.

8.3

CVSS4.0

CVE-2026-32146 - Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement t…

πŸ“… Published: April 11, 2026, 12:59 p.m. πŸ”„ Last Modified: April 22, 2026, 4:03 p.m.

6.5

CVSS3.1

CVE-2026-23900 - Extension - phoca.cz - Stored XSS vectors in Phoca Maps component 5.0.0 - 6.0.2 for Joomla

Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.

πŸ“… Published: April 11, 2026, 12:52 p.m. πŸ”„ Last Modified: April 17, 2026, 4:15 p.m.
Total resulsts: 346099
Page 215 of 34,610
Β« previous page Β» next page
Filters