Vulnerabilities

Summary — last 7 days

New vulnerabilities2,685▼ 177 vs. last week
Critical / high1,223▼ 305 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
–

121 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.36%—4TU Researchdata DjehutyAI10/1/202610/2/2026
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows:…
DeferredHigh (8.4)0.30%—4tu.researchdata DjehutyAI10/1/202610/6/2026
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.…
DeferredMedium (5.3)0.51%—Nousresearch Hermes-agentAIElectronAI9/3/20269/3/2026
A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely.…
DeferredMedium (5.3)0.35%—Nousresearch Hermes-agentAI9/3/20269/5/2026
A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The…
DeferredMedium (6.9)0.50%—Nousresearch Hermes-agentAI9/3/20269/3/2026
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argument session_id causes authorization bypass. The attack can be initiated remotely. The vendor was contacted early about…
DeferredLow (2.1)0.47%—Nousresearch Hermes-agentAI9/1/20269/2/2026
A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulation results in uncontrolled memory allocation. It is possible to initiate the attack remotely. The exploit has been made…
DeferredLow (2.1)0.47%—Nousresearch Hermes-agentAI9/1/20269/2/2026
A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the…
DeferredLow (2.1)0.52%—Nousresearch Hermes-agentAI9/1/20269/4/2026
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been…
DeferredCritical (9.8)0.89%—Gpt-researcherAI8/27/20269/9/2026
A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.
DeferredHigh (8.4)0.40%—Fujitsu Research OnecompressionAI8/12/20269/24/2026
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking…
DeferredLow (2.1)0.37%—Nousresearch Hermes-agentAI8/6/20268/12/2026
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and…
DeferredLow (2.1)0.37%—Nousresearch Hermes-agentAI8/6/20268/12/2026
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been…
DeferredLow (2.1)0.38%—Nousresearch Hermes-agentAI8/4/20268/12/2026
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been…
DeferredLow (2.1)0.35%—Nousresearch Hermes-agentAI8/4/20268/12/2026
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published…
DeferredLow (2.1)0.35%—Nousresearch Hermes-agentAI8/4/20268/12/2026
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and…
DeferredLow (1.3)0.36%—Nousresearch Hermes-agentAI7/26/20267/27/2026
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls.…
DeferredHigh (8.3)0.41%—Mcp-webresearchAI7/21/20267/23/2026
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers…
Awaiting AnalysisCritical (9.8)0.72%—Open Source GPT Researcher GPT ResearcherAI7/15/202610/6/2026
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.
DeferredMedium (6.4)0.26%—Buddyholis TablesearchAI7/10/20267/10/2026
The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
DeferredLow (2)0.36%—Nousresearch Hermes-agentAI7/10/20267/10/2026
A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The…
Awaiting AnalysisHigh (7.1)0.57%—Amazon Research AND Engineering StudioAI7/7/20267/8/2026
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read…
DeferredLow (2.1)0.48%—Nousresearch Hermes-agentAI7/6/20267/6/2026
A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be…
DeferredMedium (5.5)0.77%💥 PoCNousresearch Hermes-agentAI7/4/20267/6/2026
A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may…
DeferredLow (2.9)0.55%—Nousresearch Hermes-agentAI7/4/20267/6/2026
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such manipulation leads to improper authentication. The attack can be launched…
DeferredLow (2.1)0.47%—Nousresearch Hermes-agentAI7/4/20267/7/2026
A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be initiated remotely. The exploit has been…
Orbitaley — Vulnerabilities