CVE Watchtower

Advanced Threat Data Export

Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.

Data export is locked. Upgrade your package to enable filtering and downloading.

πŸ”” Premium Features
πŸ” Filter Threats
Title
SeverityEPSS (30-Day)
PoCActively ExploitedSourceDate
CVE-2026-10111
A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulati...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-10110
A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performi...
HIGHπŸ”’ LOCKED??????????NVD5 days ago
???-????-????
??????????????????????????????????
??????????????????????????????????
HIGHπŸ”’ LOCKED??????????SA5 days ago
CVE-2026-48840
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values t...
MEDIUMπŸ”’ LOCKED??????????NVD5 days ago
CVE-2026-47416
## Summary **Type:** Vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_...
CRITICALπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47409
## Summary **Type:** Authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated only by...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47414
## Summary **Type:** Insecure Direct Object Reference. Five label endpoints β€” `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .../lab...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47406
## Summary **Type:** Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies`...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47410
## Summary **Type:** Insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` ...
CRITICALπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47405
### Summary PraisonAI Platform has a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate th...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47399
### Summary PraisonAI Platform's workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated us...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47407
## Summary The Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_member(wor...
CRITICALπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47408
## Summary **Type:** Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `require_...
MEDIUMπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-48169
### Summary The PraisonAI Platform API has two authorization failures that together break workspace isolation. The service layer for issues and proje...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47397
# Bug Report: Arbitrary File Write in Python API ## Summary Hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled conten...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47391
## Summary The first-party PraisonAI A2A server example combines three behaviors into a remotely exploitable Critical chain: 1. The example exposes ...
CRITICALπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47394
## Summary The fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vulnerable handlers in `mcp_s...
HIGHπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47392
## Summary `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__...
CRITICALπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47395
### Summary PraisonAI's direct-prompt CLI automatically expands `@url:` mentions in raw prompt text before agent execution begins. If a prompt ...
MEDIUMπŸ”’ LOCKED??????????NVD6 days ago
CVE-2026-47393
### Summary CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) th...
CRITICALπŸ”’ LOCKED??????????NVD6 days ago