2026-07-21
2026-07-21 20:17Z
CRIT

CVE-2026-59147 — Data: Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59147

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. dsu_find walks and path-compresses parent[x] with x a raw file-stored index never bounded against the node count, so both the read and the compression write-back land out CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 125CWECWE 787TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 20:17Z
CRIT

CVE-2026-59145 — Data: Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59145

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough about the header and layout (magic, version, section offsets, total_size, count and arena_used) but does not validate the three arrays it then trusts. Every lookup in si_idx_find walks a triple indirection read straight from the mmap'd segment, arena[reverse[slots[i].id]], with CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 20:17Z
CRIT

CVE-2026-59144 — Data: Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59144

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination size. ring_read_seq does memcpy(out, ring_slot(h, seq), elem_size) with elem_size read raw from the mmap'd segment, copying into a fixed 8-byte destination scalar. An elem_size larg CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 20:17Z
HIGH

CVE-2026-50758 — Site: Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50758

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter CVSSv3.1 8.1 (HIGH)

CWECWE 79TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 20:17Z
CRIT

CVE-2026-50755 — DayuanJiang: An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50755

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value CVSSv3.1 9.8 (CRITICAL)

CWECWE 290VNDDayuanjiangTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 19:17Z
CRIT

CVE-2026-64877 — An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64877

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-21
2026-07-21 19:17Z
CRIT

CVE-2026-59142 — Data: Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59142

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. shm_str_copy does memcpy(dst, arena + off, len) with off and len read raw from the mmap'd segment and unbounded, on the each, keys, values, pop, shift, take, swap, drain CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-21
2026-07-21 19:17Z
CRIT

CVE-2026-59141 — Data: Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59141

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts. rdx_find_locked indexes nodes[cur].children[k] and reads each node's label_off and label_len raw from the mmap'd segment, none bounded against the node count or the arena CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 19:17Z
CRIT

CVE-2026-59140 — Data: Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59140

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries then follow children[], leftmost and rightmost node indices read raw from the mmap'd segment without bounding them against node_capacity. A full structural check (ss_validate_tree CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 19:17Z
CRIT

CVE-2026-59139 — Data: Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59139

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. reqrep_recv_locked does memcpy(copy_buf, req_arena + arena_off, len) with arena_off and len read raw from the mmap'd segment and never bounded against the arena CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 19:17Z
HIGH

CVE-2026-55084 — DHIS2: A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55084

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the `/api/sqlViews/{viewId}/data.json` endpoint. An authenticated user with access to a SqlView can inject arbitrary SQL queries inside the `filter` parameter by abusing an expression executed by PostgreSQL and its output is reflected ins CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDhis2TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 19:17Z
CRIT

CVE-2026-16441 — Eclipse Openj9: In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16441

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method. CVSSv3.1 9.6 (CRITICAL) · EPSS 22th percentile

CWECWE 758VNDEclipseTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-21
2026-07-21 19:17Z
CRIT

CVE-2016-20096 — Linknat: VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2016-20096

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDLinknatTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-21
2026-07-21 18:17Z
HIGH

CVE-2026-47419 — PraisonAI: Versions prior to 0.1.4 have an* Insecure Direct Object Reference.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47419

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agent_id}`) gate access on `require_workspace_member(workspace_id)` only, then resolve `agent_id` through `AgentService.get(agent_id)` which is a primary-key lookup with no workspace constraint. A user who is a member of any workspace `W1` can r CVSSv3.1 8.3 (HIGH)

CWECWE 639VNDPraisonaiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-21
2026-07-21 18:17Z
HIGH

CVE-2026-47418 — PraisonAI: Versions prior to 0.1.4 have an Insecure Direct Object Reference.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47418

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/projects/{project_id}` and `GET .../{project_id}/stats`) gate access on `require_workspace_member(workspace_id)` only, then resolve `project_id` through `ProjectService.get(project_id)` / `update(project_id, ...)` / `delete(project_id)` / `get_stats(pr CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 18:17Z
HIGH

CVE-2026-47417 — PraisonAI: Versions prior to 0.1.4 have an Insecure Direct Object Reference.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47417

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and `GET .../comments`) gate access on `require_workspace_member(workspace_id)` only, then call `CommentService.create(issue_id=issue_id, ...)` and `CommentService.list_for_issue(issue_id)` without verifying that `issue_id` belongs to `workspace CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 18:17Z
CRIT

CVE-2026-47416 — PraisonAI: Versions prior to 0.1.4 are vulnerable to vertical privilege escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47416

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the route. The handler then calls `MemberService.update_role(workspace_id, user_id, body.role)` which sets the target member's role to wh CVSSv3.1 9.6 (CRITICAL)

CWECWE 862CWECWE 269VNDPraisonaiTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-21
2026-07-21 18:17Z
HIGH

CVE-2026-47415 — PraisonAI: Versions prior to 0.1.4 have an Insecure Direct Object Reference.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47415

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/issues/{issue_id}`) gate access on `require_workspace_member(workspace_id)` only, then resolve `issue_id` through `IssueService.get(issue_id)` which is a primary-key lookup with no workspace constraint. A user who is a member of any workspace `W1` can re CVSSv3.1 8.3 (HIGH)

CWECWE 639VNDPraisonaiTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-21
2026-07-21 18:17Z
CRIT

CVE-2026-47413 — PraisonAI: Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47413

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`) and forwards the request body's `user_id` and `role` straight into `MemberService.add(workspace_id, user_id, role)`, which has no caller-permission check. A user with t CVSSv3.1 9.6 (CRITICAL)

CWECWE 862CWECWE 269VNDPraisonaiTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-21
2026-07-21 18:16Z
HIGH

CVE-2026-47412 — PraisonAI: Versions prior to 0.1.4 have an authorization bypass enabling destructive action.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47412

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member of the workspace can issue a single DELETE to wipe the entire workspace, including every project, issue, comment, agent, label, and member record (cascading via the CVSSv3.1 8.1 (HIGH)

CWECWE 862CWECWE 269VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-21
2026-07-21 18:16Z
HIGH

CVE-2026-44880 — A buffer overflow vulnerability was found in the command line interface of AOS-CX.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44880

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-21
2026-07-21 18:16Z
HIGH

CVE-2026-21575 — Atlassian Sourcetree: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21575

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Win CVSSv3.1 8.0 (HIGH) · EPSS 23th percentile

CWECWE 94VNDAtlassianVNDHighTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-21
2026-07-21 18:16Z
CRIT

CVE-2026-16439 — Eclipse Openj9: In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16439

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. CVSSv3.1 9.1 (CRITICAL) · EPSS 11th percentile

CWECWE 124VNDEclipseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-21
2026-07-21 17:47Z
HIGH

Why Exposure Management Is Replacing Vulnerability Management

Horizon3.ai·horizon3.ai

Horizon3.ai argues that traditional vulnerability management—focused on identifying and patching individual CVEs—is insufficient for modern threat landscapes. The article advocates for Exposure Management and Gartner's CTEM framework, which evaluate how weaknesses chain together across identities, permissions, and systems to create exploitable attack paths rather than treating vulnerabilities in isolation.

SRFApplicationTACTA0004TACTA0005TACTA0001SRFIdentityTACTA0003SRFCloudTYPResearch
62
Edit Score
2026-07-21
2026-07-21 17:17Z
CRIT

CVE-2026-47410 — PraisonAI: Versions prior to 0.1.4 have an insecure default cryptographic key.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47410

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but only fires when `PLATFORM_ENV != "dev"`; the default value of `PLATFORM_ENV` is `"dev"`, so the check is silently bypassed in any deployment that does not explicitly opt out. The att CVSSv3.1 9.8 (CRITICAL)

CWECWE 798CWECWE 321VNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score