4.8

CVSS4.0

CVE-2026-7397 - NousResearch hermes-agent file_tools.py _check_sensitive_path symlink

A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public and may be used for…

πŸ“… Published: April 29, 2026, 6 p.m. πŸ”„ Last Modified: April 29, 2026, 6 p.m.

9

CVSS3.1

CVE-2026-30893 - Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execu…

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the i…

πŸ“… Published: April 29, 2026, 5:55 p.m. πŸ”„ Last Modified: April 29, 2026, 5:55 p.m.

6.5

CVSS3.1

CVE-2026-28221 - Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char …

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() in wazuh-remoted. The bug is triggered when formatting attacker-controlled bytes using sprintf(dst_bu…

πŸ“… Published: April 29, 2026, 5:53 p.m. πŸ”„ Last Modified: April 29, 2026, 5:53 p.m.

6.5

CVSS3.1

CVE-2026-26206 - Wazuh: API brute-force protection bypass via race condition in login attempt tracking

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security/user/authenticate can be bypassed by sending concurrent authentication requests. Although the confi…

πŸ“… Published: April 29, 2026, 5:49 p.m. πŸ”„ Last Modified: April 29, 2026, 5:49 p.m.

4.4

CVSS3.1

CVE-2026-26204 - Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 byte before the start of the buffer allocated by strdup. Due…

πŸ“… Published: April 29, 2026, 5:43 p.m. πŸ”„ Last Modified: April 29, 2026, 5:43 p.m.

10

CVSS4.0

CVE-2026-26015 - Unauthenticated RCE in DocsGPT MCP STDIO Configuration

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execution (RCE)…

πŸ“… Published: April 29, 2026, 5:37 p.m. πŸ”„ Last Modified: April 29, 2026, 5:37 p.m.

6.9

CVSS4.0

CVE-2026-7396 - NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The…

πŸ“… Published: April 29, 2026, 5:30 p.m. πŸ”„ Last Modified: April 29, 2026, 5:30 p.m.

8

CVSS3.1

CVE-2026-5712 - IdentityIQ Role Editor Incorrect Authorization Vulnerability

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

πŸ“… Published: April 29, 2026, 5:18 p.m. πŸ”„ Last Modified: April 29, 2026, 5:18 p.m.

5.1

CVSS4.0

CVE-2026-7394 - SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may b…

πŸ“… Published: April 29, 2026, 5:15 p.m. πŸ”„ Last Modified: April 29, 2026, 5:15 p.m.

5.1

CVSS4.0

CVE-2026-7393 - SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted …

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be ca…

πŸ“… Published: April 29, 2026, 5 p.m. πŸ”„ Last Modified: April 29, 2026, 5 p.m.
Total resulsts: 347741
Page 59 of 34,775
Β« previous page Β» next page
Filters