Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2025-32424

AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock_CVE-2025-32424

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, Screens...

Significant-Gravitas AutoGPT < 0.6.63 CVE
HIGH 8.7 CVE-2025-32422

AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock_CVE-2025-32422

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepTh...

Significant-Gravitas AutoGPT < 0.6.63 CVE
HIGH 8.7 CVE-2025-32392

AutoGPT has a DoS vulnerability in LoopVideoBlock_CVE-2025-32392

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGPT...

Significant-Gravitas AutoGPT < 0.6.63 CVE
HIGH 7.5 PACKETSTORM:223805

📄 WordPress Contest Gallery 28.1.4 SQL Injection_PACKETSTORM:223805

WordPress Contest Gallery plugin version 28.1.4 unauthenticated blind SQL Injection exploit written in Python3...

N/A N/A PACKETSTORM
HIGH 8.4 CVE-2026-12390

Access of resource using incompatible type (‘type confusion’) in AzeoTech DAQFactory_CVE-2026-12390

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files w...

AzeoTech DAQFactory CVE
HIGH 8.7 CVE-2026-48716

nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write_CVE-2026-48716

nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path u...

HKUDS nanobot <= 0.1.5.post3 CVE
HIGH 8.5 CVE-2026-25865

Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec_CVE-2026-25865

Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by ex...

Yandex Punto Switcher CVE
HIGH 8.3 CVE-2026-49248

OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar_CVE-2026-49248

OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR en...

theonedev onedev < 15.0.7 CVE
HIGH 8.1 CVE-2026-43994

Coturn: Stack buffer overflow in decode_oauth_token_gcm()_CVE-2026-43994

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token...

coturn coturn < 4.10.0 CVE
HIGH 8.3 CVE-2025-15661

libssh2 – Heap Buffer Over-read via sftp_symlink() in sftp.c_CVE-2025-15661

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c tha...

libssh2 libssh2 CVE