|
1281
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. Th…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9305
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1282
|
3.7 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjou…
New
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-9306
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1283
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manip…
New
|
CWE-862 CWE-863
Missing Authorization Incorrect Authorization
|
CVE-2026-9350
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1284
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the file tools/file_tools.py of the component read_file…
New
|
CWE-22
Path Traversal
|
CVE-2026-9351
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1285
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local.py of the component Messaging Gateway H…
New
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-9352
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1286
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Pro…
New
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-9353
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1287
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost Agent. The manipulation of the argument …
New
|
CWE-74 CWE-116
Injection Improper Encoding or Escaping of Output
|
CVE-2026-9354
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1288
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection…
New
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-9366
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1289
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the com…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9367
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1290
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Hand…
New
|
CWE-264 CWE-265
Permissions, Privileges, and Access Controls Privilege Issues
|
CVE-2026-9368
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|