Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-58481 | MEDIUM | 6.5 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks … | Jul 20, 2026 |
| CVE-2026-58414 | MEDIUM | 5.5 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/<env>` contains … | Jul 20, 2026 |
| CVE-2026-58413 | MEDIUM | 6.1 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this … | Jul 20, 2026 |
| CVE-2026-55645 | MEDIUM | 6.5 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection … | Jul 20, 2026 |
| CVE-2026-55238 | MEDIUM | 5.3 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the … | Jul 20, 2026 |
| CVE-2026-54538 | HIGH | 7.5 | xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the … | Jul 20, 2026 |
| CVE-2026-54051 | CRITICAL | 9.9 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main … | Jul 20, 2026 |
| CVE-2026-50743 | MEDIUM | 5.4 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted … | Jul 20, 2026 |
| CVE-2026-47276 | MEDIUM | 6.5 | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST … | Jul 20, 2026 |
| CVE-2026-47275 | LOW | 2.6 | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5 client (including … | Jul 20, 2026 |
| CVE-2026-46701 | HIGH | 7.6 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty secret (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` at `bin/mcp-server.ts:89`), which … | Jul 20, 2026 |
| CVE-2026-46555 | HIGH | 7.7 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the … | Jul 20, 2026 |
| CVE-2026-44978 | MEDIUM | 5.3 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does … | Jul 20, 2026 |
| CVE-2026-44178 | HIGH | 8.8 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding … | Jul 20, 2026 |
| CVE-2026-42218 | MEDIUM | 5.3 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in … | Jul 20, 2026 |
| CVE-2026-42210 | UNKNOWN | — | Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), … | Jul 20, 2026 |
| CVE-2026-41521 | HIGH | 8.2 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection … | Jul 20, 2026 |
| CVE-2026-41252 | CRITICAL | 9.8 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when … | Jul 20, 2026 |
| CVE-2026-40187 | UNKNOWN | — | In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to … | Jul 20, 2026 |
| CVE-2026-39879 | HIGH | 7.1 | Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of … | Jul 20, 2026 |
| CVE-2026-39385 | UNKNOWN | — | Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated … | Jul 20, 2026 |
| CVE-2026-35591 | UNKNOWN | — | libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the … | Jul 20, 2026 |
| CVE-2026-35590 | UNKNOWN | — | libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the … | Jul 20, 2026 |
| CVE-2026-35217 | MEDIUM | 6.5 | NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker … | Jul 20, 2026 |
| CVE-2026-35048 | CRITICAL | 9.8 | The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper … | Jul 20, 2026 |