|
171
|
6.5 |
MEDIUM
Network
|
apache
|
airflow
|
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, a…
New
|
CWE-200
Information Exposure
|
CVE-2026-25219
|
2026-04-18 03:37 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
10.0 |
CRITICAL
Network
|
praison
|
praisonai
|
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL validation. When a submitted job completes (succe…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-40114
|
2026-04-18 03:36 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
7.5 |
HIGH
Network
|
praison
|
praisonai
|
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into memory based on the client-supplied Content-Length…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-40115
|
2026-04-18 03:34 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
7.5 |
HIGH
Network
|
praison
|
praisonai
|
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from any client without authentication or Twilio signatu…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-40116
|
2026-04-18 03:33 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
6.5 |
MEDIUM
Network
|
juniper
|
junos_os_evolved
|
A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privilege…
Update
|
CWE-686
Function Call With Incorrect Argument Type
|
CVE-2026-33783
|
2026-04-18 03:27 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
7.5 |
HIGH
Network
|
praison
|
praisonaiagents
|
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path paramet…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-40117
|
2026-04-18 03:23 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Update
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-33104
|
2026-04-18 03:20 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
8.1 |
HIGH
Network
|
-
|
-
|
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.6. This is due to insufficient file type …
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5718
|
2026-04-18 03:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
7.5 |
HIGH
Network
|
-
|
-
|
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to t…
New
|
CWE-22
Path Traversal
|
CVE-2026-5710
|
2026-04-18 03:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
- |
|
-
|
-
|
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rendered the rule parameter through Jinja2's default Template() constructor, silentl…
New
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40320
|
2026-04-18 03:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|