CVE Browser

Page 1 (more results available)

Vendor: 1Panel-dev Remove filter Clear all
CVE-2026-79919 MEDIUM

MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)

CVSS 6.3 EPSS 0.39% Sep 21, 2026
CVE-2026-79918 MEDIUM

MaxKB: Sandbox escape via unhooked fexecve

CVSS 6.3 EPSS 0.36% Sep 21, 2026
CVE-2026-77517 MEDIUM

MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base

CVSS 5.4 EPSS 0.23% Sep 21, 2026
CVE-2026-77521 CRITICAL

MaxKB: Prompt-injectable agent can lead to command execution

CVSS 10.0 EPSS 1.05% Sep 21, 2026
CVE-2026-77522 MEDIUM

MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)

CVSS 4.3 EPSS 0.30% Sep 21, 2026
CVE-2026-79917 MEDIUM

MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation

CVSS 6.5 EPSS 0.27% Sep 21, 2026
CVE-2026-77516 MEDIUM

MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path

CVSS 5.4 EPSS 0.24% Sep 21, 2026
CVE-2026-77523 HIGH

MaxKB: Cross-workspace model parameter form write

CVSS 7.4 EPSS 0.26% Sep 21, 2026
CVE-2026-77525 MEDIUM

MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id

CVSS 4.2 EPSS 0.19% Sep 21, 2026
CVE-2026-77518 MEDIUM

MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows

CVSS 5.0 EPSS 0.27% Sep 21, 2026
CVE-2026-79916 CRITICAL

MaxKB AWS Bedrock model credential injection leads to remote code execution

CVSS 9.1 EPSS 0.45% Sep 21, 2026
CVE-2026-77520 MEDIUM

MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application

CVSS 5.4 EPSS 0.23% Sep 21, 2026
CVE-2026-77519 MEDIUM

MaxKB: Expired application API keys remain usable on `/chat/api/mcp`

CVSS 5.4 EPSS 0.24% Sep 21, 2026
CVE-2026-76902 MEDIUM

CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}`

CVSS 5.0 EPSS 0.27% Sep 18, 2026
CVE-2026-63646 MEDIUM

CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users

CVSS 6.9 EPSS 0.66% Sep 18, 2026
CVE-2026-76899 MEDIUM

CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`

CVSS 5.7 EPSS 0.40% Sep 18, 2026
CVE-2026-76900 MEDIUM

CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime

CVSS 6.8 EPSS 0.50% Sep 18, 2026
CVE-2026-76901 MEDIUM

CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts

CVSS 5.8 EPSS 0.40% Sep 18, 2026
CVE-2026-63647 CRITICAL

CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`

CVSS 9.3 EPSS 0.50% Sep 18, 2026
CVE-2026-52745 MEDIUM

CordysCRM: Customer Public Pool Sorting Field SQL Injection

CVSS 5.3 EPSS 0.34% Sep 18, 2026
CVE-2026-65956 CRITICAL

KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF

CVSS 10.0 EPSS 0.64% Aug 26, 2026
CVE-2026-69129 MEDIUM

KubePi: Insufficient per-cluster authorization checks in cluster management APIs

CVSS 5.8 EPSS 0.41% Aug 26, 2026
CVE-2026-64870 MEDIUM

MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation

CVSS 5.3 EPSS 0.36% Jul 30, 2026
CVE-2026-16223 MEDIUM

1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java getSqlBotSrc server-side request forgery

CVSS 5.3 EPSS 0.37% Jul 19, 2026
CVE-2026-16222 MEDIUM

1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side request forgery

CVSS 5.3 EPSS 0.37% Jul 19, 2026

Showing 1 to 25 CVEs · page 1 (more available)