Export limit exceeded: 404419 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404419 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108581 | 1 Tencentcloud | 1 Octop | 2026-10-11 | 6.5 Medium |
| TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provider API keys via GET /api/providers and GET /api/voice/providers. Attackers can query these endpoints, which only validate the JWT, to obtain plaintext LLM and voice provider API keys and abuse the upstream provider accounts. | ||||
| CVE-2026-108582 | 1 Genspark-ai | 1 Genoffice | 2026-10-11 | 5.5 Medium |
| GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-http directory under the system temporary directory to read client uploads and converted outputs, bypassing the HTTP bearer token. | ||||
| CVE-2026-108586 | 1 1mcp-app | 1 Agent | 2026-10-11 | 5.4 Medium |
| 1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes. | ||||
| CVE-2026-108595 | 1 Pulseaiclub | 1 Phi | 2026-10-11 | 5.3 Medium |
| Phi 0.3.0 through 0.28.4 contains a permission bypass vulnerability that allows spawned sub-agents to escape workspace_only_writes and readonly mode by supplying an unchecked workdir to agent_spawn. Attackers can plant prompt-injected instructions in processed content so the agent spawns a worker rooted elsewhere, causing unapproved file writes anywhere the user can write. | ||||
| CVE-2026-108597 | 1 Cohere-ai | 1 Cohere-python | 2026-10-11 | 4.8 Medium |
| Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host. | ||||
| CVE-2026-108598 | 1 Floci-io | 1 Floci | 2026-10-11 | 9.8 Critical |
| Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM. | ||||
| CVE-2026-108599 | 1 Pulseaiclub | 1 Phi | 2026-10-11 | 4.7 Medium |
| phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to bypass workspace_only_writes by exploiting lexical-only path checks in the permission gate. Attackers can commit symlinks pointing outside the workspace and use prompt injection to make the write tool write attacker-influenced content to external files without approval. | ||||
| CVE-2026-108600 | 1 Open-multi-agent | 1 Open-multi-agent | 2026-10-11 | 4.7 Medium |
| open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file_write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write. | ||||
| CVE-2026-108603 | 1 Addsumtech | 1 Slide-maker | 2026-10-11 | 3.3 Low |
| slide-maker through 5.8.0 contains a path traversal vulnerability in generate_images_openai.py that allows attackers to write image files outside the output directory via manifest-supplied filenames. Attackers can influence deck source material so the image prompt manifest contains ../ or symlinked filenames, creating directories and overwriting existing files at arbitrary paths. | ||||
| CVE-2026-108604 | 1 Tabularisdb | 1 Tabularis | 2026-10-11 | 6.3 Medium |
| Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run_query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, or PostgreSQL query_to_xml with embedded DELETE to modify data without approval prompts. | ||||
| CVE-2026-108689 | 1 Wukongopensource | 1 Wukong Aicrm | 2026-10-11 | 5.4 Medium |
| Wukong AICRM through 20260610 contains a missing authorization vulnerability that allows authenticated users to write into other users' AI chat sessions by supplying an arbitrary sessionId to POST /chat/send. Attackers can append messages to a victim's conversation and receive streamed assistant replies built from the victim's last 20 messages, disclosing conversation content. | ||||
| CVE-2026-108707 | 1 Wukongopensource | 1 Wukong Hrm | 2026-10-11 | 9.8 Critical |
| Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records. | ||||
| CVE-2026-108708 | 1 Wukongopensource | 1 Wukong Hrm | 2026-10-11 | 8.8 High |
| Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and EmployeeUtil data-scope checks return all employees. Any authenticated low-privileged employee can read payslips, salary records, bank cards and personal data, edit bank cards, and delete employees, departments and contracts company-wide. | ||||
| CVE-2026-108695 | 2 Multivendorx, Wordpress-extensions | 2 Multivendorx, Multivendorx | 2026-10-11 | 7.1 High |
| MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings via the settings REST endpoint. Attackers with the store_owner role can send POST requests to /wp-json/multivendorx/v1/settings, gated only by edit_stores, to overwrite commission, payout, and onboarding settings. | ||||
| CVE-2026-108760 | 2026-10-11 | 7.6 High | ||
| LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects. | ||||
| CVE-2026-108758 | 1 Easyappointments | 1 Easyappointments | 2026-10-11 | 8.2 High |
| Easy!Appointments through 1.6.0 contains an authorization bypass vulnerability in Booking::register() that allows unauthenticated attackers to modify any appointment by supplying an appointment id without its hash. Attackers can enumerate sequential appointment ids with a self-asserted manage_mode flag to rewrite appointment details, rebind them to attacker-controlled customers, and obtain management hashes for rescheduling or cancellation. | ||||
| CVE-2026-108757 | 2026-10-11 | 6.5 Medium | ||
| Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated attackers reaching port 18790, which binds all interfaces by default, can inject blind prompts into the user's main OpenClaw agent session as user instructions. | ||||
| CVE-2026-108756 | 1 Trinity Project | 1 Trinity | 2026-10-11 | 5.4 Medium |
| Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers controlling an agent, typically via prompt injection, can send messages through the owner's bot token, replace the binding with their own token, or delete it. | ||||
| CVE-2026-108755 | 1 Hatchet | 1 Hatchet | 2026-10-11 | 5.3 Medium |
| Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arbitrarily large or concurrent request bodies to POST /api/v1/sns/{tenant}/{event} with any UUID, which the SnsUpdate handler buffers before signature verification, degrading availability. | ||||
| CVE-2026-108754 | 2026-10-11 | 3.3 Low | ||
| GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group. | ||||