2026-07-10
2026-07-10 20:16Z
HIGH

CVE-2026-55377 — Logto: Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55377

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A WebAuthn registration verification record for binding a new passkey could be created and verified with only an existing Account API bearer token, then sent in the logto-verification-id header and treated as identityVerified=true by Account Center CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDLogtoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 19:17Z
HIGH

CVE-2026-6212 — Authorization: bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6212

Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue affects TeraMIS: from V03.26.01.14 through 30.04.2026. CVSSv3.1 8.8 (HIGH)

CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 19:17Z
HIGH

CVE-2026-61461 — Dify: before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61461

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDifyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 19:17Z
HIGH

CVE-2026-61460 — Krayin: CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61460

Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users. Attackers can modify CRM records and reassign ownership by exploiting missing record-level ownership validation in edit, update, and destroy methods. CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDKrayinTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 19:17Z
CRIT

CVE-2026-61459 — MCP: Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61459

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cl CVSSv3.1 9.8 (CRITICAL)

CWECWE 88VNDMcpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 19:17Z
CRIT

CVE-2026-5801 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5801

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects SEM-PMP: through 23042026. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 19:17Z
CRIT

CVE-2026-59151 — Prowler: Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59151

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-contro CVSSv3.1 9.6 (CRITICAL)

CWECWE 287VNDProwlerTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-10
2026-07-10 19:17Z
HIGH

CVE-2026-54329 — Snipe: Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54329

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass assignable, allowing a low-privileged authenticated user in one company to create accessory records under another company when Full Multiple Companies Support is enabled. This issue is fixed in version 8.6.2. CVSSv3.1 8.5 (HIGH)

CWECWE 862VNDSnipeTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-10
2026-07-10 19:17Z
HIGH

CVE-2025-30007 — HestiaCP: before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-30007

HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in is_dns_record_format_valid() combined with unsafe eval-based parsing in update_domain_zone() to prematurely close a variable assignment string and achieve full root code execution on th CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDHestiacpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 18:16Z
HIGH

CVE-2026-56668 — ZITADEL: Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56668

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requested scopes remain within the original token's scopes, allowing a low-privilege token to be exchanged for elevated permissions at another application. This issue is fixed in version 4.15.3. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDZitadelTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 18:16Z
CRIT

CVE-2026-2397 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2397

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-10
2026-07-10 17:17Z
HIGH

CVE-2026-56675 — Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56675

9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify external requests as local. A remote unauthenticated attacker can access /v1 APIs such as /v1/models and may abuse configured upstream provider credentials through /v1 proxy endpoints depending on enabl CVSSv3.1 8.3 (HIGH)

CWECWE 306CWECWE 287CWECWE 290CWECWE 441TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-10
2026-07-10 17:16Z
HIGH

CVE-2026-55641 — Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55641

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default configuration, this exposes the /v1 proxy to upstream provider calls using stored provider credentials and allows /v1/search with the searxng provider_options.baseUrl parameter to drive server-side requ CVSSv3.1 8.2 (HIGH)

CWECWE 918CWECWE 290CWECWE 1327CWECWE 348TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 17:16Z
HIGH

CVE-2026-55638 — A remote unauthenticated attacker can send requests to /codex/* to bypass the API-key gate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55638

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A remote unauthenticated attacker can send requests to /codex/* to bypass the API-key gate and cause the server to make upstream provider calls using operator-stored LLM provider credentials. This issue is fixed in version 0.5.2. CVSSv3.1 8.6 (HIGH)

CWECWE 862CWECWE 863TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-10
2026-07-10 17:16Z
HIGH

CVE-2026-53657 — Lima: Prior to 2.1.3, on an instance of Lima running with the qemu driver, an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53657

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root privileges in the VM because the guest agent socket provides tunneling for arbitrary addresses, including Unix socket addresses for privileged daemons like D-Bus. This is CVSSv3.1 8.2 (HIGH)

CWECWE 668CWECWE 276VNDLimaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 17:16Z
CRIT

CVE-2026-51119 — Invixium: An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51119

An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components CVSSv3.1 9.1 (CRITICAL)

CWECWE 269VNDInvixiumTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 17:16Z
HIGH

CVE-2026-2398 — Authorization: bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-2398

Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 639TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 16:16Z
CRIT

CVE-2026-55500 — Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55500

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the ALWAYS_PROTECTED middleware check, which only validates JWT or CLI token. This issue is fixed in version 0.4.80. CVSSv3.1 9.9 (CRITICAL)

CWECWE 200TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-10
2026-07-10 16:16Z
HIGH

CVE-2026-54149 — MaxKB: Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54149

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/base_chat_step.py do not consistently validate MCP transport type, allowing an authenticated user to import a .tool file containing stdio transport with malicious commands and trigger the configuration through an AI Chat node so MultiServerMCPClient executes ar CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDMaxkbTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 16:16Z
CRIT

CVE-2026-15143 — This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15143

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services. CVSSv3.1 9.3 (CRITICAL)

CWECWE 918TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-10
2026-07-10 15:16Z
CRIT

CVE-2026-61444 — PraisonAI: versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61444

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen(). CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDPraisonaiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-61434 — PraisonAI: versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61434

PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-59796 — JetBrains: In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59796

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-59795 — JetBrains: In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59795

In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-10
2026-07-10 15:16Z
HIGH

CVE-2026-59793 — JetBrains: In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59793

In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration CVSSv3.1 8.8 (HIGH)

CWECWE 73VNDJetbrainsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score