| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-47688 🧪 | FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules | FOGProject | fogproject | High | 8.2 | 2026-07-21 20:40:31 | Deep Dive |
| CVE-2026-47687 🧪 | FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint | FOGProject | fogproject | High | 7.3 | 2026-07-21 20:39:01 | Deep Dive |
| CVE-2026-47685 🧪 | FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page | FOGProject | fogproject | High | 7.3 | 2026-07-21 20:37:32 | Deep Dive |
| CVE-2026-63764 🧪 | LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass | InternLM | lmdeploy | High | 8.6 | 2026-07-21 20:36:58 | Deep Dive |
| CVE-2026-63358 🧪 | FileGator privilege escalation | FileGator | FileGator | High | 7.3 | 2026-07-21 20:13:08 | Deep Dive |
| CVE-2026-47667 🧪 | CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Crafted NIfTI/Analyze Header | GreycLab | CImg | High | 7.5 | 2026-07-21 19:57:49 | Deep Dive |
| CVE-2026-55084 🧪 | SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read | dhis2 | dhis2-core | High | 8.8 | 2026-07-21 18:30:09 | Deep Dive |
| CVE-2026-47419 🧪 | praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR | MervinPraison | praisonai-platform | High | 8.3 | 2026-07-21 17:31:59 | Deep Dive |
| CVE-2026-47418 🧪 | praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR | MervinPraison | praisonai-platform | High | 8.1 | 2026-07-21 17:26:46 | Deep Dive |
| CVE-2026-47417 🧪 | praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR | MervinPraison | praisonai-platform | High | 8.1 | 2026-07-21 17:24:41 | Deep Dive |
| CVE-2026-47416 🧪 | praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id} | MervinPraison | praisonai-platform | Critical | 9.6 | 2026-07-21 17:19:12 | Deep Dive |
| CVE-2026-47415 🧪 | praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR | MervinPraison | praisonai-platform | High | 8.3 | 2026-07-21 17:13:08 | Deep Dive |
| CVE-2026-47414 🧪 | praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOR | MervinPraison | praisonai-platform | High | 7.6 | 2026-07-21 17:11:37 | Deep Dive |
| CVE-2026-47413 🧪 | praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members | MervinPraison | praisonai-platform | Critical | 9.6 | 2026-07-21 17:07:22 | Deep Dive |
| CVE-2026-47412 🧪 | praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id} | MervinPraison | praisonai-platform | High | 8.1 | 2026-07-21 17:04:47 | Deep Dive |
| CVE-2026-47410 🧪 | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset | MervinPraison | praisonai-platform | Critical | 9.8 | 2026-07-21 16:55:31 | Deep Dive |
| CVE-2026-47409 🧪 | praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id} | MervinPraison | praisonai-platform | High | 8.1 | 2026-07-21 16:53:18 | Deep Dive |
| CVE-2026-47406 🧪 | praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR | MervinPraison | praisonai-platform | High | 8.1 | 2026-07-21 16:37:13 | Deep Dive |
| CVE-2026-47405 🧪 | PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership | MervinPraison | praisonai-platform | High | 8.8 | 2026-07-21 16:18:28 | Deep Dive |
| CVE-2026-47399 🧪 | PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID | MervinPraison | praisonai-platform | High | 8.8 | 2026-07-21 16:15:10 | Deep Dive |