Vulnerabilities
Summary — last 7 days
New vulnerabilities2,758▼ 17 vs. last week
Critical / high1,269▼ 209 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 185 vs. last week
121 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2.1) | 0.38% | — | Nousresearch Hermes-agentAI | 7/4/2026 | 7/6/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may… | |
| Deferred | Low (1.3) | 0.37% | — | Nousresearch Hermes-agentAI | 7/3/2026 | 7/6/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Tag Filter. The manipulation leads to improper handling of case sensitivity. The… | |
| Deferred | Low (2.1) | 0.22% | — | Nousresearch Hermes-agentAI | 6/7/2026 | 7/23/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has… | |
| Deferred | Low (1.9) | 0.14% | — | Nousresearch Hermes-agentAI | 6/2/2026 | 7/22/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be… | |
| Deferred | Medium (5.5) | 0.37% | — | Nousresearch Hermes-agentAI | 6/1/2026 | 7/22/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The… | |
| Deferred | Low (2.1) | 0.23% | — | Nousresearch Hermes-agentAI | 6/1/2026 | 7/22/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The… | |
| Deferred | Low (2.9) | 0.27% | — | Nousresearch Hermes-agentAI | 6/1/2026 | 7/22/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch the attack remotely. The attack requires a high level of complexity. The… | |
| Deferred | Medium (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 6/1/2026 | 7/22/2026 | A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Deferred | Medium (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 6/1/2026 | 7/22/2026 | A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.… | |
| Deferred | Medium (5) | 0.41% | — | Learningcircuit Local Deep ResearchAI | 5/28/2026 | 6/17/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The main logic is to… | |
| Deferred | Medium (5) | 0.36% | — | Learningcircuit Local Deep ResearchAI | 5/28/2026 | 6/17/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title or research.query) and metadata key-value pairs — directly into an… | |
| Deferred | Low (1.9) | 0.32% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in incorrect comparison.… | |
| Deferred | Medium (5.5) | 0.64% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly… | |
| Deferred | Medium (5.5) | 3.2% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the component terminal_tool. This manipulation causes os command injection. It is possible to initiate the attack remotely. The… | |
| Deferred | Medium (5.5) | 0.52% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted… | |
| Deferred | Medium (5.5) | 0.57% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost Agent. The manipulation of the argument format_message results in escaping of output. The attack can be executed remotely. The exploit is now public and may be… | |
| Deferred | Medium (5.5) | 0.52% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Prompt Handler. The manipulation of the argument THREAT_PATTERNS leads to injection. Remote exploitation of the attack is… | |
| Deferred | Medium (5.5) | 0.48% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local.py of the component Messaging Gateway Handler. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit… | |
| Deferred | Medium (5.5) | 0.79% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the file tools/file_tools.py of the component read_file Tool. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been… | |
| Deferred | Medium (5.5) | 0.47% | — | Nousresearch Hermes-agentAI | 5/24/2026 | 7/23/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit is publicly available and might… | |
| Deferred | Low (1.9) | 0.17% | — | Nousresearch Hermes-agentAI | 4/29/2026 | 6/17/2026 | A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. Upgrading… | |
| Deferred | Medium (5.5) | 0.69% | — | Nousresearch Hermes-agentAI | 4/29/2026 | 6/17/2026 | A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Deferred | High (8.8) | 1.4% | — | Tubitak Bilgem Software Technologies Research Institute Pardus OS MY ComputerAI | 4/29/2026 | 6/17/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0. | |
| Deferred | Low (2.9) | 0.58% | — | Nousresearch Hermes-agentAI | 4/27/2026 | 6/17/2026 | A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be launched remotely. A… | |
| Deferred | Low (2.9) | 0.58% | — | Nousresearch Hermes-agentAI | 4/27/2026 | 6/17/2026 | A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. The complexity of… |