Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.6 CVE-2026-46699

conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repository_CVE-2026-46699

conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a single repository. Prior to...

conda-forge conda-smithy < 3.61.0 CVE
HIGH 8.3 CVE-2026-45696

OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)_CVE-2026-45696

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 t...

AcademySoftwareFoundation openexr >= 3.4.0, < 3.4.11 CVE
HIGH 8.6 CVE-2026-8100

CVE-2026-8100_CVE-2026-8100

Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions....

Progress Chef Chef360 CVE
HIGH 7.7 CVE-2026-54017

Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal_CVE-2026-54017

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse prox...

open-webui open-webui < 0.9.6 CVE
HIGH 7.5 CVE-2026-47633

Microsoft Cost Management Information Disclosure Vulnerability_CVE-2026-47633

{“lastseen”:””,”description”:””,”published”:”2026-06-18T21:37:36.850Z”,&#82...

Microsoft Microsoft Cost Management - CVE
HIGH 7.7 CVE-2026-32174

Azure Bot Service Elevation of Privilege Vulnerability_CVE-2026-32174

{“lastseen”:””,”description”:””,”published”:”2026-06-18T21:39:17.817Z”,&#82...

Microsoft Azure AI Bot Service - CVE
HIGH 8.7 CVE-2026-56078

PraisonAI – Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor_CVE-2026-56078

PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. At...

PraisonAI PraisonAI CVE
HIGH 7.1 CVE-2026-56077

PraisonAI – Information Disclosure via Shared MultiAgentLedger State_CVE-2026-56077

PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows attackers to access sensiti...

PraisonAI PraisonAI CVE
HIGH 8.6 CVE-2026-56076

PraisonAI – Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint_CVE-2026-56076

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitra...

PraisonAI PraisonAI CVE
HIGH 8.7 CVE-2026-56075

PraisonAI – Arbitrary Shell Command Execution via Hardcoded Approval Mode Override_CVE-2026-56075

PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overridin...

PraisonAI PraisonAI CVE