|
361
|
3.1 |
LOW
Network
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandbox result validation and spoof tool execution results by exploiting Python fram…
Update
|
CWE-74 CWE-290 CWE-693
Injection Authentication Bypass by Spoofing Protection Mechanism Failure
|
CVE-2026-39419
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362
|
- |
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability that allows authenticated users to inject arbitrary HTML and Ja…
Update
|
CWE-80
Basic XSS
|
CVE-2026-39425
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363
|
- |
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom <if…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-39426
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
364
|
- |
|
-
|
-
|
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability in runtime/template…
Update
|
CWE-200
Information Exposure
|
CVE-2026-34984
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
365
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37589
|
2026-04-18 00:25 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
366
|
8.4 |
HIGH
Local
|
-
|
-
|
PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working direct…
Update
|
CWE-94 CWE-426
Code Injection Untrusted Search Path
|
CVE-2026-40287
|
2026-04-18 00:24 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
367
|
9.8 |
CRITICAL
Network
|
-
|
-
|
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untru…
Update
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-40288
|
2026-04-18 00:24 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
368
|
9.1 |
CRITICAL
Network
|
-
|
-
|
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote se…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-40289
|
2026-04-18 00:24 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
369
|
- |
|
-
|
-
|
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the n…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-13822
|
2026-04-18 00:24 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
370
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-pr…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-24069
|
2026-04-18 00:24 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|