A vulnerability was found in netease-youdao LobsterAI 2026.6.10. It has been classified as problematic. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-18995. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in NousResearch hermes-agent up to 0.16.0 and classified as critical. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls.
This vulnerability is identified as CVE-2026-18993. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability has been found in MervinPraison PraisonAI up to 4.6.39 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Claude GitHub Actions Workflow. The manipulation leads to command injection.
This vulnerability is referenced as CVE-2026-48168. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in IBM Langflow OSS up to 1.10.3. Affected is an unknown function. Executing a manipulation can lead to code injection.
The identification of this vulnerability is CVE-2026-8182. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.10.3. This impacts an unknown function. Performing a manipulation results in code injection.
This vulnerability was named CVE-2026-17633. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as critical was found in IBM Langflow OSS up to 1.10.3. This affects an unknown function. Such manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-17624. The attack can be launched remotely. No exploit exists.
A vulnerability classified as critical has been found in IBM Langflow OSS up to 1.10.3. The impacted element is an unknown function of the component Custom Component Validation. This manipulation causes use of weak hash.
This vulnerability is handled as CVE-2026-9201. The attack can be initiated remotely. There is not any exploit available.
A vulnerability described as critical has been identified in IBM Langflow OSS up to 1.10.3. The affected element is an unknown function of the component Agentic Assistant Validation. The manipulation results in code injection.
This vulnerability is known as CVE-2026-9196. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as critical has been reported in IBM Langflow OSS up to 1.10.3. Impacted is an unknown function of the component AST. The manipulation leads to code injection.
This vulnerability is traded as CVE-2026-17632. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as very critical has been found in NI NI-PAL up to 26.3.1. This issue affects some unknown processing of the component NI-PAL kernel driver. Executing a manipulation can lead to improper privilege management.
This vulnerability appears as CVE-2026-18485. The attack requires local access. There is no available exploit.
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
A vulnerability identified as critical has been detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2026-18992. The attack is possible to be carried out remotely. Moreover, an exploit is present.