6.9

CVSS4.0

CVE-2026-4959 - OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Performing a manipulation of the argument interaction_id results in missing authentication. Remote exploi…

πŸ“… Published: March 27, 2026, 3:31 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

2.3

CVSS4.0

CVE-2026-4958 - OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization

A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/websockets/replayer.py of the component WebSocket Endpoint. Such manipulation of the argument interaction_id leads to authorization b…

πŸ“… Published: March 27, 2026, 3:31 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

5.3

CVSS4.0

CVE-2026-32984 - Heap buffer overflow in wazuh-authd

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low availability impact to the authe…

πŸ“… Published: March 27, 2026, 3:02 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

8.8

CVSS3.1

CVE-2026-5027 - Langflow - Path Traversal Arbitrary File Write via upload_user_file

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

πŸ“… Published: March 27, 2026, 2:54 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

5.1

CVSS4.0

CVE-2026-4957 - OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file

A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of the file XAgent/function_handler.py of the component API Key Handler. This manipulation of the argument api_key causes sensitive information in log files. The attack may be initia…

πŸ“… Published: March 27, 2026, 2:52 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

6.9

CVSS4.0

CVE-2026-4956 - Shenzhen Ruiming Technology Streamax Crocus Parameter DevicePrint.do sql injection

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePrint.do?Action=ReadTask of the component Parameter Handler. The manipulation of the argument State results in sql injection. The attack can be launched…

πŸ“… Published: March 27, 2026, 2:52 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

6.9

CVSS4.0

CVE-2026-4955 - Shenzhen Ruiming Technology Streamax Crocus OperateStatistic.do sql injection

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. The manipulation of the argument VehicleID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be…

πŸ“… Published: March 27, 2026, 2:51 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

6.3

CVSS3.1

CVE-2026-4980 - Improper Restriction of XML External Entity Reference in Inkscape

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

πŸ“… Published: March 27, 2026, 2:50 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

7

CVSS4.0

CVE-2026-5026 - Langflow - Stored XSS via Malicious SVG Upload

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content. Since SVG files can contain embedded JavaScript, an attacker can upload a malicious SVG that executes arbitrary JavaScript when viewed by other users, …

πŸ“… Published: March 27, 2026, 2:50 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

6.5

CVSS3.1

CVE-2026-5025 - Langflow - Application Logs Exposed to All Authenticated Users

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').

πŸ“… Published: March 27, 2026, 2:43 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.
Total resulsts: 341081
Page 24 of 34,109
Β« previous page Β» next page
Filters