CVE search

401,008 results
CVE-2026-51918—FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code ().EPSS —CVE-2026-51911—vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposeEPSS —CVE-2026-51917—FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.EPSS —CVE-2026-67989HIGHcrmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition EPSS —CVE-2026-51916HIGHTransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowEPSS —CVE-2026-51904—SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, crEPSS —CVE-2026-51906—In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write EPSS —CVE-2026-51899MEDIUMIn SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_scheduleEPSS —CVE-2026-51907HIGHIn TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write imaEPSS —CVE-2026-86345CRITICAL389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication resultEPSS 0.4%CVE-2026-103766HIGHClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete ParameterEPSS 0.4%CVE-2026-103765HIGHMooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata ServerEPSS 0.5%CVE-2026-103764CRITICALMooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP TransportEPSS 0.6%CVE-2026-103761HIGHMooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify QueueEPSS 0.4%CVE-2026-103760HIGHMooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response WriteEPSS 0.4%CVE-2025-71427HIGHOffice-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_imageEPSS 0.3%CVE-2026-18397CRITICALSConnect: Native Host Unauthenticated Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-86344HIGH389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeueEPSS 0.3%CVE-2026-27873MEDIUM- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: beforeEPSS 0.1%CVE-2026-64893HIGH- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issuEPSS 0.1%