5.3

CVSS4.0

CVE-2026-6613 - TransformerOptimus SuperAGI agent.py get_schedule_data authorization

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of the file superagi/controllers/agent.py. The manipulation of the argument agent_id leads to authorization bypass. The attack is possible to be carried …

πŸ“… Published: April 20, 2026, 6:30 a.m. πŸ”„ Last Modified: April 20, 2026, 6:30 a.m.

5.3

CVSS4.0

CVE-2026-6612 - TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution auth…

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/agent_execution.py of the component Agent Execution Endpoint. Executing a manipulation of the argument agent_execution_id…

πŸ“… Published: April 20, 2026, 6:15 a.m. πŸ”„ Last Modified: April 20, 2026, 6:15 a.m.

2.3

CVSS4.0

CVE-2026-6611 - liangliangyy DjangoBlog File Upload Endpoint settings.py hard-coded key

A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulation of the argument SECRET_KEY results in use of hard-coded cryptographic key . Remote exploitation o…

πŸ“… Published: April 20, 2026, 6 a.m. πŸ”„ Last Modified: April 20, 2026, 6 a.m.

0.0

CVE-2024-7083 - Email Encoder < 2.3.4 - Admin+ Stored XSS

The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 20, 2026, 6 a.m. πŸ”„ Last Modified: April 20, 2026, 6 a.m.

6.3

CVSS4.0

CVE-2026-6610 - liangliangyy DjangoBlog Setting settings.py hard-coded credentials

A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads to hard-coded credentials. The attack may be launched remot…

πŸ“… Published: April 20, 2026, 5:45 a.m. πŸ”„ Last Modified: April 20, 2026, 5:45 a.m.

5.3

CVSS4.0

CVE-2026-6609 - liangliangyy DjangoBlog views.py form_valid improper authorization

A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. …

πŸ“… Published: April 20, 2026, 5:30 a.m. πŸ”„ Last Modified: April 20, 2026, 5:30 a.m.

6.9

CVSS4.0

CVE-2026-6608 - lm-sys fastchat Arena Side-by-Side View add_text control flow

A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fi…

πŸ“… Published: April 20, 2026, 5:15 a.m. πŸ”„ Last Modified: April 20, 2026, 5:15 a.m.

6.9

CVSS4.0

CVE-2026-6607 - lm-sys fastchat Worker API Endpoint api_generate resource consumption

A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate of the component Worker API Endpoint. The manipulation leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed publicly and may be use…

πŸ“… Published: April 20, 2026, 5 a.m. πŸ”„ Last Modified: April 20, 2026, 5 a.m.

6.9

CVSS4.0

CVE-2026-6606 - modelscope agentscope _agent_base.py _process_audio_block server-side request forgery

A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the atta…

πŸ“… Published: April 20, 2026, 4:45 a.m. πŸ”„ Last Modified: April 20, 2026, 4:45 a.m.

6.9

CVSS4.0

CVE-2026-6605 - modelscope agentscope Internal Service _common.py _get_bytes_from_web_url server-side request forge…

A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Service. Performing a manipulation results in server-side request forgery. It is possible to initiate t…

πŸ“… Published: April 20, 2026, 4:30 a.m. πŸ”„ Last Modified: April 20, 2026, 4:30 a.m.
Total resulsts: 345229
Page 4 of 34,523
Β« previous page Β» next page
Filters