🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-51922 agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attack... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51907 In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files t... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51906 In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51904 SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51918 FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51917 FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code. | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51916 TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py.... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51915 TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and updat... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51914 TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_age... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51911 vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, a... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51901 SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenti... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51899 In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/age... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51898 sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104846 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deser... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104845 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray i... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104844 PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can r... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103648 Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside t... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103631 Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103630 Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted ... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103629 Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromiu... | MEDIUM | ????? | ????? | NVD | 4 days ago |