Busca de CVEs
390.614 resultadosCVE-2026-47410CRITICALpraisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unsetEPSS 0.6%CVE-2026-47409HIGHpraisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}EPSS 0.5%CVE-2026-47408MEDIUMpraisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownershipEPSS 0.4%CVE-2026-16451MEDIUMzsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted uploadEPSS 0.3%CVE-2026-15342MEDIUMCVE-2026-15342EPSS 0.4%CVE-2026-47407CRITICALPraisonAI Platform has a cross-workspace IDOR + member-role privilege escalationEPSS 0.4%CVE-2026-15432HIGHObservable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerificationEPSS 0.2%CVE-2026-15829HIGHSQL Injection and Security Boundary Bypass in googleapis/mcp-toolboxEPSS 0.2%CVE-2026-16454MEDIUMPrivilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware ExfiltrationEPSS 0.4%CVE-2026-47406HIGHpraisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOREPSS 0.4%CVE-2026-47405HIGHPraisonAI Platform missing role checks let any workspace member become owner and take over workspace membershipEPSS 0.5%CVE-2026-47399HIGHPraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object IDEPSS 0.5%CVE-2026-15793MEDIUMGit source checkout from a bundle file could lead to command injectionEPSS 0.2%CVE-2026-15792MEDIUMPossible panic when incorrect parameters sent from frontendEPSS 0.2%CVE-2026-15791LOWLLB file operation can be tricked to remove /tmp directory contentsEPSS 0.2%CVE-2026-15789MEDIUMMalicious client can bypass destination directory validation on local sources uploadEPSS 0.3%CVE-2026-24232MEDIUMNVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploEPSS 0.4%CVE-2026-44907HIGHA denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could leaEPSS 0.6%CVE-2026-47398HIGHPraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334EPSS 0.6%CVE-2026-47397HIGHPraisonAI has an Arbitrary File Write in Python APIEPSS 0.5%