// psirt.com
Product Security Incident Response Team
Vulnerability intelligence and regulatory resources for security teams navigating NIS2, the Cyber Resilience Act, and coordinated disclosure.
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace mana…
2026-08-25
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
2026-08-25
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unautho…
2026-08-25
MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blo…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the wo…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app()…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.g…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind th…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize req…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authentic…
2026-08-25
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authent…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller su…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not chec…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools…
2026-08-25
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_pag…
2026-08-25
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possi…
2026-08-25
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line…
2026-08-25
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Sof…
2026-08-25
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By…
2026-08-25
NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization
2026-08-25GHSA-rhp5-r9x4-f5g2
NLTK before 3.10.3 SSRF Protection Bypass via Proxy
2026-08-25GHSA-6ww7-3frv-cqxh
NLTK before 3.10.3 Entity Expansion DoS via ElementTree
2026-08-25GHSA-97qj-x29f-37w7
NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary
2026-08-25GHSA-6hwm-xvph-95vm
GitPython before 3.1.59 Arbitrary File Read via TagReference.create
2026-08-25GHSA-3wxw-xv34-2frg
GitPython before 3.1.59 Arbitrary File Read via Repo.blame()
2026-08-25GHSA-5xxx-qhh7-9287
GitPython before 3.1.59 Path Traversal via separate-git-dir
2026-08-25GHSA-8mcc-hrx5-hvxc
GitPython before 3.1.59 Remote Code Execution via Config Injection
2026-08-25GHSA-284h-m62q-gf8w
GitPython before 3.1.59 Local File Content Disclosure via .gitmodules
2026-08-25GHSA-7833-fr7j-v32q
Grav before 2.0.16 Information Disclosure via Twig Sandbox
2026-08-25GHSA-xjw5-q542-3vmr
Grav before 2.0.16 Information Disclosure via offsetGet
2026-08-25GHSA-3jhr-mxmx-38cx
Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method
2026-08-25GHSA-7c6v-m68v-v73r
Grav CMS before 2.0.16 Origin Validation Bypass via Referer
2026-08-25GHSA-9ccq-2jfg-qw33
Grav CMS before 2.0.16 Timing Attack via verifyNonce
2026-08-25GHSA-38p6-h87p-r4cg
Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass
2026-08-25GHSA-p597-crqc-m349
Grav CMS before 2.0.16 Path Traversal via media_directory
2026-08-25GHSA-47ch-6w46-6xm7
Grav CMS before 2.0.16 Symlink Following via createLockFile
2026-08-25GHSA-q8w8-6cq5-j4h2
Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile
2026-08-25GHSA-jq29-c7v8-rg55
Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode
2026-08-25GHSA-x929-528m-vx2m
Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking
2026-08-25GHSA-33j4-hc95-pggg
KEV — Known Exploited Vulnerabilities CISA
Oracle — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (comp…
Added 2026-08-24Due 2026-08-27
Synacor — A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp…
Added 2026-08-21Due 2026-08-24
TrueConf — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.…
Added 2026-08-20Due 2026-08-23
TrueConf — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.…
Added 2026-08-20Due 2026-09-03
MLflow — MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior…
Added 2026-08-19Due 2026-09-02
Microsoft — Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a…
Added 2026-08-18Due 2026-08-21
Broadcom — VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access…
Added 2026-08-18Due 2026-08-21
Apple — An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macO…
Added 2026-08-18Due 2026-08-21
Microsoft — Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Added 2026-08-18Due 2026-08-21
Ray-Project — Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploite…
Added 2026-08-17Due 2026-08-20
Cisco — A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwa…
Added 2026-08-11Due 2026-08-14
Microsoft — Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loc…
Added 2026-08-11Due 2026-08-25
Metabase — Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint…
Added 2026-08-11Due 2026-08-14
Progress — OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated att…
Added 2026-08-07Due 2026-08-10
JetBrains — In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polli…
Added 2026-08-05Due 2026-08-08
The original full-disclosure vulnerability mailing list. Bugtraq has been the primary channel for publishing detailed vulnerability information and exploit techniques for over three decades.
Home of the Bugtraq ID (BID) vulnerability database - over 75,000 entries cross-referenced with CVEs, providing historical vulnerability intelligence dating back to 1999.
Coverage75,921 BIDs mapped
CommunityOpen Security
Join the security research community. Discuss vulnerabilities, share advisories, and collaborate on coordinated disclosure through the Bugtraq mailing lists.