5.3

CVSS4.0

CVE-2026-6616 - TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side reque…

A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/helper/webpage_extractor.py of the component WebScraperTool. Such manipulation leads to server-side request forge…

πŸ“… Published: April 20, 2026, 7:15 a.m. πŸ”„ Last Modified: April 20, 2026, 7:15 a.m.

4

CVSS3.1

CVE-2026-41282 -

ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step templates against untrusted targets (not the default configuration).

πŸ“… Published: April 20, 2026, 7:10 a.m. πŸ”„ Last Modified: April 20, 2026, 7:10 a.m.

6.9

CVSS4.0

CVE-2026-6615 - TransformerOptimus SuperAGI Multipart Upload resources.py upload path traversal

A weakness has been identified in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function Upload of the file superagi/controllers/resources.py of the component Multipart Upload Handler. This manipulation of the argument Name causes path traversal. It is possible to initiate…

πŸ“… Published: April 20, 2026, 7 a.m. πŸ”„ Last Modified: April 20, 2026, 7 a.m.

9.4

CVSS4.0

CVE-2026-6644 - A command injection vulnerability was found in the PPTP VPN Clients on the ADM

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied i…

πŸ“… Published: April 20, 2026, 6:54 a.m. πŸ”„ Last Modified: April 20, 2026, 6:54 a.m.

5.3

CVSS4.0

CVE-2026-6614 - TransformerOptimus SuperAGI project.py get_projects_organisation authorization

A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulation results in authorization bypass. The attack may be perfo…

πŸ“… Published: April 20, 2026, 6:45 a.m. πŸ”„ Last Modified: April 20, 2026, 6:45 a.m.

8.6

CVSS4.0

CVE-2026-6643 - A stack-based buffer overflow vulnerability in the VPN Clients on the ADM

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an authenticated remote attacker can exploit these to e…

πŸ“… Published: April 20, 2026, 6:34 a.m. πŸ”„ Last Modified: April 20, 2026, 6:34 a.m.

5.3

CVSS4.0

CVE-2026-6613 - TransformerOptimus SuperAGI agent.py get_schedule_data authorization

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of the file superagi/controllers/agent.py. The manipulation of the argument agent_id leads to authorization bypass. The attack is possible to be carried …

πŸ“… Published: April 20, 2026, 6:30 a.m. πŸ”„ Last Modified: April 20, 2026, 6:30 a.m.

5.3

CVSS4.0

CVE-2026-6612 - TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution auth…

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/agent_execution.py of the component Agent Execution Endpoint. Executing a manipulation of the argument agent_execution_id…

πŸ“… Published: April 20, 2026, 6:15 a.m. πŸ”„ Last Modified: April 20, 2026, 6:15 a.m.

2.3

CVSS4.0

CVE-2026-6611 - liangliangyy DjangoBlog File Upload Endpoint settings.py hard-coded key

A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulation of the argument SECRET_KEY results in use of hard-coded cryptographic key . Remote exploitation o…

πŸ“… Published: April 20, 2026, 6 a.m. πŸ”„ Last Modified: April 20, 2026, 6 a.m.

0.0

CVE-2024-7083 - Email Encoder < 2.3.4 - Admin+ Stored XSS

The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 20, 2026, 6 a.m. πŸ”„ Last Modified: April 20, 2026, 6 a.m.
Total resulsts: 345293
Page 9 of 34,530
Β« previous page Β» next page
Filters