|
1121
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in modelscope agentscope up to 1.0.18. This affects the function _get_bytes_from_web_url of the file src/agentscope/_utils/_common.py of the component Internal Ser…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6605
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1122
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in modelscope agentscope up to 1.0.18. This vulnerability affects the function _process_audio_block of the file src/agentscope/agent/_agent_base.py. Executing a manipul…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6606
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1123
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate of the component Worker API Endpoint. The manipulation leads to resource consu…
Update
|
CWE-400 CWE-404
Uncontrolled Resource Consumption Improper Resource Shutdown or Release
|
CVE-2026-6607
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1124
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. T…
Update
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2026-6608
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1125
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper a…
Update
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-6609
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1126
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of the file superagi/controllers/agent.py. The manipu…
Update
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-6613
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1127
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file supera…
Update
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-6614
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1128
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipula…
Update
|
CWE-259 CWE-798
Use of Hard-coded Password Use of Hard-coded Credentials
|
CVE-2026-6610
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1129
|
3.1 |
LOW
Network
|
-
|
-
|
A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulatio…
Update
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-6611
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1130
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/agent_execution.py of…
Update
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-6612
|
2026-04-23 05:22 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|