// psirt.com
PSIRT
Product Security Incident Response Team
Vulnerability intelligence and regulatory resources for security teams navigating NIS2, the Cyber Resilience Act, and coordinated disclosure.
View vulnerabilities →382,429CVEs indexed
1,018,937Security advisories
1,677CISA KEV entries
Vulnerabilities
CVE — Common Vulnerabilities
CVE — Common VulnerabilitiesBrowse all →
CVE-2026-79717MEDIUM 6.4
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace mana…CVE-2026-70551HIGH 8.5
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.CVE-2026-69104HIGH 7.6
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unautho…CVE-2026-55624NONE
MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blo…CVE-2026-55540HIGH 7.1
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the wo…CVE-2026-55541NONE
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app()…CVE-2026-55537HIGH 7.1
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.g…CVE-2026-55535MEDIUM 6.8
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind th…CVE-2026-55531MEDIUM 6.5
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize req…CVE-2026-55538HIGH 7.3
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authentic…CVE-2026-55534HIGH 8.6
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authent…CVE-2026-55527HIGH 7.1
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller su…CVE-2026-55528HIGH 8.2
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not chec…CVE-2026-55529MEDIUM 6.9
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so…CVE-2026-55530MEDIUM 6.1
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools…CVE-2026-55526HIGH 8.5
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_pag…CVE-2026-15310NONE
When decompressing crafted zip files using the bzip/LZMA/Zstandard
compressions, Python could use an attacker-controlled size to
pre-allocate memory, possi…CVE-2026-16599NONE
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line…CVE-2026-16286CRITICAL 9.8
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Sof…CVE-2026-79655HIGH 7.8
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By…
Advisories — OSV Database
Advisories — OSV DatabaseBrowse all →
CVE-2026-78683CRITICAL
NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle DeserializationCVE-2026-78682CRITICAL
NLTK before 3.10.3 SSRF Protection Bypass via ProxyCVE-2026-78681CRITICAL
NLTK before 3.10.3 Entity Expansion DoS via ElementTreeCVE-2026-78680CRITICAL
NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot BinaryCVE-2026-78679CRITICAL
GitPython before 3.1.59 Arbitrary File Read via TagReference.createCVE-2026-78678CRITICAL
GitPython before 3.1.59 Arbitrary File Read via Repo.blame()CVE-2026-78677CRITICAL
GitPython before 3.1.59 Path Traversal via separate-git-dirCVE-2026-78676CRITICAL
GitPython before 3.1.59 Remote Code Execution via Config InjectionCVE-2026-78675CRITICAL
GitPython before 3.1.59 Local File Content Disclosure via .gitmodulesCVE-2026-76846CRITICAL
Grav before 2.0.16 Information Disclosure via Twig SandboxCVE-2026-76839CRITICAL
Grav before 2.0.16 Information Disclosure via offsetGetCVE-2026-75575CRITICAL
Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor MethodCVE-2026-72702CRITICAL
Grav CMS before 2.0.16 Origin Validation Bypass via RefererCVE-2026-72701CRITICAL
Grav CMS before 2.0.16 Timing Attack via verifyNonceCVE-2026-72698CRITICAL
Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox BypassCVE-2026-72697CRITICAL
Grav CMS before 2.0.16 Path Traversal via media_directoryCVE-2026-72696CRITICAL
Grav CMS before 2.0.16 Symlink Following via createLockFileCVE-2026-72695CRITICAL
Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFileCVE-2026-56707CRITICAL
Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via ShortcodeCVE-2026-56706CRITICAL
Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking
KEV — Known Exploited Vulnerabilities
CISA
CVE-2026-21962EXPLOITED
Oracle — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (comp…CVE-2026-73570EXPLOITED
Synacor — A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp…CVE-2026-72529EXPLOITED
TrueConf — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.…CVE-2026-72530EXPLOITED
TrueConf — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.…CVE-2026-64849EXPLOITED
MLflow — MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior…CVE-2026-55040EXPLOITED
Microsoft — Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a…CVE-2026-59310EXPLOITED
Broadcom — VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access…CVE-2026-65400EXPLOITED
Apple — An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macO…CVE-2026-33824EXPLOITED
Microsoft — Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.CVE-2025-62593EXPLOITED
Ray-Project — Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploite…CVE-2026-20349EXPLOITED
Cisco — A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwa…CVE-2026-68820EXPLOITED
Microsoft — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc…CVE-2026-72898EXPLOITED
Metabase — Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint…CVE-2026-8037EXPLOITED
Progress — OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated att…CVE-2026-63077EXPLOITED
JetBrains — In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polli…Resources
CISA / USAKEV CatalogAuthoritative catalog of vulnerabilities actively exploited in the wild.NIST / USANVDNational Vulnerability Database — CVE enrichment with CVSS scores, CPE mapping, and CWE classification.EU RegulationCyber Resilience ActRegulation (EU) 2024/2847 — mandatory security requirements for products with digital elements.EU DirectiveNIS2 DirectiveDirective (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union.FIRSTPSIRT Services FrameworkReference framework for establishing and operating a Product Security Incident Response Team.MITRECVE ProgramCVE assignment, CNA ecosystem, and disclosure coordination.GitHubGHSACurated security advisories for open source — npm, PyPI, Maven, Go, Rust, NuGet and more.RSSLatest CVEsRSS feed of recently published CVEs with CVSS scores and enrichment.RSSCISA KEV FeedRSS feed of newly added Known Exploited Vulnerabilities from CISA.RSSLatest AdvisoriesRSS feed of recently published security advisories.PSIRT.COMCRA SummitPast research and events on the Cyber Resilience Act, with speakers from ENISA, Thales, Orange and others.
Mailing Lists
BugtraqEst. 1993
The original full-disclosure vulnerability mailing list. Bugtraq has been the primary channel for publishing detailed vulnerability information and exploit techniques for over three decades.
Subscribebugtraq@securityfocus.com
Archivessecurityfocus.com
SecurityFocusBID Database
Home of the Bugtraq ID (BID) vulnerability database - over 75,000 entries cross-referenced with CVEs, providing historical vulnerability intelligence dating back to 1999.
BID LookupExample: BID-21
Coverage75,921 BIDs mapped
CommunityOpen Security
Join the security research community. Discuss vulnerabilities, share advisories, and collaborate on coordinated disclosure through the Bugtraq mailing lists.
Contact
For research inquiries, partnerships, or PSIRT collaboration:
contact@psirt.com