CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-18593MEDIUM | vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandboxA weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. The vendor was co… | CVSS6.3v4.0 | EPSS0.266% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58556MEDIUM | Generated title:Huawei EMUI and Harmony OS Bluetooth Module Permission Control VulnerabilityPermission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability. CWE-264Jul 15, 2026 | CVSS5.1v3.1 | EPSS0.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58555MEDIUM | Generated title:Huawei HarmonyOS Card Module Permission Bypass VulnerabilityPermission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability. CWE-264Jul 15, 2026 | CVSS6.6v3.1 | EPSS0.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14784MEDIUM | vxcontrol PentAGI Docker API client.go sandboxA vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance. | CVSS5.3v4.0 | EPSS0.228% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Huawei EMUI and HarmonyOS Service Notifications Permission Control VulnerabilityPermission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability. CWE-264Jun 9, 2026 | CVSS3.6v3.1 | EPSS0.074% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-9368MEDIUM | NousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandboxA vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS6.9v4.0 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:HarmonyOS App Management Module Permission Control VulnerabilityPermission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264May 15, 2026 | CVSS3.6v3.1 | EPSS0.077% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-6878MEDIUM | ByteDance verl grader.py math_equal sandboxA vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS6.3v4.0 | EPSS0.333% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6224MEDIUM | nocobase plugin-workflow-javascript Vm.js createSafeConsole sandboxA security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS6.9v4.0 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6117MEDIUM | AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandboxA vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component install-upload Endpoint. The manipulation of the argument File results in sandbox issue. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | CVSS5.3v4.0 | EPSS0.224% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20046HIGH | Cisco IOS XR Software CLI Privilege Escalation VulnerabilityA vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group–based checks. A successful exploit could allow … CWE-264Mar 11, 2026 | CVSS8.8v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28541MEDIUM | Generated title:Huawei HarmonyOS Cellular Data Module Permission Control VulnerabilityPermission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability. CWE-264Mar 5, 2026 | CVSS4.0v3.1 | EPSS0.087% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Huawei HarmonyOS Resource Scheduling Module Permission Control VulnerabilityPermission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity. CWE-264Mar 5, 2026 | CVSS3.3v3.1 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-24924MEDIUM | Generated title:HarmonyOS Print Module Improper Permission Control VulnerabilityVulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Feb 6, 2026 | CVSS6.1v3.1 | EPSS0.108% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24920MEDIUM | Generated title:Huawei EMUI and HarmonyOS AMS Module Permission Control VulnerabilityPermission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability. CWE-264Feb 6, 2026 | CVSS6.2v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24931MEDIUM | Generated title:Huawei HarmonyOS Card Module Improper Criterion Security Check VulnerabilityVulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Feb 6, 2026 | CVSS5.9v3.1 | EPSS0.102% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24923MEDIUM | Generated title:HarmonyOS HDC Module Permission Control VulnerabilityPermission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Feb 6, 2026 | CVSS6.3v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68967MEDIUM | Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Jan 14, 2026 | CVSS5.7v3.1 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66329MEDIUM | Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability. CWE-264Dec 8, 2025 | CVSS4.0v3.1 | EPSS0.085% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66325MEDIUM | Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Dec 8, 2025 | CVSS6.2v3.1 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58302HIGH | Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Nov 28, 2025 | CVSS8.4v3.1 | EPSS0.094% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58294MEDIUM | Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Nov 28, 2025 | CVSS6.2v3.1 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58315MEDIUM | Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CWE-264Nov 28, 2025 | CVSS5.5v3.1 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58312MEDIUM | Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability. CWE-264Nov 28, 2025 | CVSS5.1v3.1 | EPSS0.077% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-58309MEDIUM | Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. CWE-264Nov 28, 2025 | CVSS6.8v3.1 | EPSS0.088% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |