CVE Vulnerability Database
Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47407 | CRITICAL | 9.4 | 0.2% | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platfor... |
| CVE-2026-47406 | HIGH | 8.1 | — | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins... |
| CVE-2026-47405 | HIGH | 8.8 | — | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a brok... |
| CVE-2026-47399 | HIGH | 8.8 | 0.5% | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspa... |
| CVE-2026-47398 | HIGH | 8.1 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-... |
| CVE-2026-47397 | HIGH | 7.1 | 0.4% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents t... |
| CVE-2026-44907 | HIGH | 7.5 | — | Jul 21, 2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo... |
| CVE-2026-24232 | MEDIUM | 4.3 | — | Jul 21, 2026 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data... |
| CVE-2026-16454 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie... |
| CVE-2026-16451 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts... |
| CVE-2026-15829 | HIGH | 8.6 | — | Jul 21, 2026 | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecastin... |
| CVE-2026-15793 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git s... |
| CVE-2026-15792 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. |
| CVE-2026-15791 | HIGH | 7.5 | 0.1% | Jul 21, 2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The acti... |
| CVE-2026-15789 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-contro... |
| CVE-2026-15724 | HIGH | 8.7 | 0.5% | Jul 21, 2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user ... |
| CVE-2026-15432 | HIGH | 8.2 | — | Jul 21, 2026 | When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time compar... |
| CVE-2026-15342 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo... |
| CVE-2025-68640 | MEDIUM | 5.3 | 0.3% | Jul 21, 2026 | The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T... |
| CVE-2026-64825 | CRITICAL | 9.3 | — | Jul 21, 2026 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to wri... |
| CVE-2026-64824 | CRITICAL | 9.3 | — | Jul 21, 2026 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a... |
| CVE-2026-64823 | MEDIUM | 4.7 | 0.2% | Jul 21, 2026 | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_... |
| CVE-2026-56586 | MEDIUM | 4.2 | 0.1% | Jul 21, 2026 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man... |
| CVE-2026-56585 | MEDIUM | 4.3 | 0.1% | Jul 21, 2026 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli... |
| CVE-2026-47396 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent... |
