8.6

CVSS3.1

CVE-2026-25580 - Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, at…

📅 Published: Feb. 6, 2026, 9:01 p.m. 🔄 Last Modified: April 17, 2026, 10:30 p.m.

5.4

CVSS3.1

CVE-2026-25581 - SCEditor affected by DOM XSS via emoticon URL/HTML injection

SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration option…

📅 Published: Feb. 6, 2026, 8:58 p.m. 🔄 Last Modified: April 17, 2026, 10:30 p.m.

8.4

CVSS3.1

CVE-2026-25593 - OpenClaw Affected by Unauthenticated Local RCE via WebSocket config.apply

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command injection as the gateway user. This vulnerability …

📅 Published: Feb. 6, 2026, 8:56 p.m. 🔄 Last Modified: April 17, 2026, 10:30 p.m.

5.3

CVSS3.1

CVE-2026-25597 - PrestaShop has a time based enumeration in FO login form

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measu…

📅 Published: Feb. 6, 2026, 8:47 p.m. 🔄 Last Modified: April 18, 2026, 1:30 p.m.

8.6

CVSS3.1

CVE-2026-25628 - Qdrant affected by arbitrary file write via `/logger` endpoint

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.…

📅 Published: Feb. 6, 2026, 8:44 p.m. 🔄 Last Modified: April 17, 2026, 10:30 p.m.

10

CVSS3.1

CVE-2026-25592 - Semantic Kernel has an Arbitrary File Write via AI Agent Function Calling in .NET SDK

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. The problem has been fixed in Microso…

📅 Published: Feb. 6, 2026, 8:38 p.m. 🔄 Last Modified: April 17, 2026, 10:30 p.m.

5.3

CVSS4.0

CVE-2026-25631 - Domain allowlist bypass enables credential exfiltration

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domains, potentially leading to credential exfiltration. This only…

📅 Published: Feb. 6, 2026, 8:34 p.m. 🔄 Last Modified: April 18, 2026, 1:30 p.m.

8.7

CVSS4.0

CVE-2026-2066 - UTT 进取 520W formIpGroupConfig strcpy buffer overflow

A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpGroupConfig. Executing a manipulation of the argument groupName can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public …

📅 Published: Feb. 6, 2026, 8:32 p.m. 🔄 Last Modified: April 18, 2026, 6:30 p.m.

2.1

CVSS4.0

CVE-2026-25729 - DeepAudit Affected by User Enumeration via Broken Access Control

DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /api/v1/users/ endpoint allows any authenticated user to enumerate all users in the system and retrieve sensitive information including email addresses,…

📅 Published: Feb. 6, 2026, 8:30 p.m. 🔄 Last Modified: April 18, 2026, 1:30 p.m.

10

CVSS3.1

CVE-2026-25632 - EPyT-Flow has unsafe JSON deserialization (__type__)

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field…

📅 Published: Feb. 6, 2026, 8:24 p.m. 🔄 Last Modified: April 17, 2026, 10:30 p.m.
Total resulsts: 349182
Page 1765 of 34,919
« previous page » next page
Filters