Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Deepcode HIGH 7.5
CVE-2026-32847

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthentica…

Fix: after 1.2.0
Fix from $1,950 2026-05-28
Openharness HIGH 8.8
CVE-2026-7551

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to…

Fix: 2026-04-27+
Fix from $1,950 2026-04-30
Openharness HIGH 8.2
CVE-2026-6823

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["…

Fix: 0.1.7+
Fix from $1,950 2026-04-21
Openharness HIGH 8.8
CVE-2026-6819

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /rel…

Fix: 0.1.7+
Fix from $1,950 2026-04-21
Openharness HIGH 7.6
CVE-2026-6729

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats…

Fix: 0.1.7+
Fix from $1,950 2026-04-20
Openharness MEDIUM 6.3
CVE-2026-40516

OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to…

Fix: 2026-04-11+
Fix from $1,600 2026-04-17
Openharness MEDIUM 5.5
CVE-2026-40515

OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete p…

Fix: 2026-04-11+
Fix from $1,600 2026-04-17
Openharness HIGH 8.8
CVE-2026-40502

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive …

Fix: 2026-04-13+
Fix from $1,950 2026-04-16
Openharness MEDIUM 6.5
CVE-2026-40503

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files…

Fix: 2026-04-13+
Fix from $1,600 2026-04-16
Lightrag MEDIUM 6.5
CVE-2026-39413

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack…

Fix: 1.4.14+
Fix from $1,600 2026-04-08