HIGH8.1CVE-2026-47412praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
HIGH8.3CVE-2026-47415praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
CRITICAL9.6CVE-2026-47413praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
MEDIUM6.5CVE-2026-47411praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
HIGH8.1CVE-2026-47417praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
HIGH8.1CVE-2026-47418praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
LOW3.1CVE-2026-45426EPSS 0.04%Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access
MEDIUM5.9CVE-2026-41017EPSS 0.02%Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy
MEDIUM6.5CVE-2026-45192EPSS 0.04%Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response
LOW3.3CVE-2026-10233EPSS 0.01%A security vulnerability has been detected in Assimp up to 6.0.4.
MEDIUM5.3CVE-2026-10232EPSS 0.01%A weakness has been identified in Assimp up to 6.0.4.
MEDIUM5.3CVE-2026-10231EPSS 0.01%A security flaw has been discovered in Assimp up to 6.0.4.
MEDIUM5.3CVE-2026-10230EPSS 0.01%A vulnerability was identified in Assimp up to 6.0.4.
MEDIUM5.3CVE-2026-10229EPSS 0.01%A vulnerability was determined in Assimp up to 6.0.4.
HIGH7.1CVE-2026-48827EPSS 0.10%Path traversal vulnerability in Apache MINA SSHD bundle sshd-git.
LOW3.3CVE-2026-10201EPSS 0.01%A vulnerability was determined in Assimp up to 6.0.4.
MEDIUM5.3CVE-2026-10200EPSS 0.01%A vulnerability was found in Assimp up to 6.0.4.
LOW3.3CVE-2026-10199EPSS 0.01%A vulnerability has been found in Assimp up to 6.0.4.
LOW3.3CVE-2026-10198EPSS 0.01%A flaw has been found in Assimp up to 6.0.4.
LOW3.3CVE-2026-10197EPSS 0.01%A vulnerability was detected in Assimp up to 6.0.4.
MEDIUM6.3CVE-2026-10194EPSS 0.04%A weakness has been identified in OFFIS DCMTK 3.7.0.
HIGH8.1CVE-2026-8796EPSS 0.01%Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input.
MEDIUM6.2CVE-2026-8594EPSS 0.00%Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters.
MEDIUM5.3CVE-2026-48840EPSS 0.03%Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memo…