|
101
|
- |
|
-
|
-
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Mali…
New
|
CWE-405 CWE-770
Asymmetric Resource Consumption (Amplification) Allocation of Resources Without Limits or Throttling
|
CVE-2025-32394
|
2026-06-27 03:13 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
- |
|
-
|
-
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-32423
|
2026-06-27 03:13 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
8.5 |
HIGH
Network
|
-
|
-
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP prot…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-56663
|
2026-06-27 03:13 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
5.4 |
MEDIUM
Network
|
-
|
-
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint …
New
|
CWE-284 CWE-639
Improper Access Control Authorization Bypass Through User-Controlled Key
|
CVE-2026-56823
|
2026-06-27 03:13 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership…
New
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-55686
|
2026-06-27 03:13 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
7.5 |
HIGH
Network
|
-
|
-
|
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that v…
New
|
CWE-200 CWE-668
Information Exposure Exposure of Resource to Wrong Sphere
|
CVE-2026-57231
|
2026-06-27 03:13 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
9.1 |
CRITICAL
Network
|
deno
|
deno
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext …
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-44726
|
2026-06-27 03:11 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticat…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-5309
|
2026-06-27 03:05 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
8.1 |
HIGH
Network
|
caddyserver
|
caddy
|
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/…
New
|
CWE-20 CWE-176 CWE-178
Improper Input Validation Improper Handling of Unicode Encoding Improper Handling of Case Sensitivity
|
CVE-2026-45135
|
2026-06-27 03:04 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
3.8 |
LOW
Network
|
caddyserver
|
caddy
|
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In th…
New
|
CWE-187 CWE-863
Partial String Comparison Incorrect Authorization
|
CVE-2026-45692
|
2026-06-27 03:01 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|