Known Vulnerabilities for User Files by Scriptonite
Listed below are 10 of the newest known vulnerabilities associated with "User Files" by "Scriptonite".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64624 json | FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire... | Not Provided | 2026-07-20 | 2026-07-23 |
| CVE-2026-63454 json | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attac... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63429 json | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no globa... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-62843 json | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-62685 json | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified... | Not Provided | 2026-07-15 | 2026-07-20 |
| CVE-2026-61835 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Dire... | Not Provided | 2026-07-15 | 2026-07-21 |
| CVE-2026-61684 json | FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /ap... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61446 json | PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads a... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-60089 json | PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.tom... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-59924 json | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-sup... | Not Provided | 2026-07-08 | 2026-07-08 |