Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51763
Total
4101
Critical
15352
High
15010
Medium
CVE ID Severity Score Description Published
CVE-2026-58481 MEDIUM 6.5 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks … Jul 20, 2026
CVE-2026-58414 MEDIUM 5.5 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/<env>` contains … Jul 20, 2026
CVE-2026-58413 MEDIUM 6.1 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this … Jul 20, 2026
CVE-2026-55645 MEDIUM 6.5 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection … Jul 20, 2026
CVE-2026-55238 MEDIUM 5.3 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the … Jul 20, 2026
CVE-2026-54538 HIGH 7.5 xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the … Jul 20, 2026
CVE-2026-54051 CRITICAL 9.9 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main … Jul 20, 2026
CVE-2026-50743 MEDIUM 5.4 A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted … Jul 20, 2026
CVE-2026-47276 MEDIUM 6.5 In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST … Jul 20, 2026
CVE-2026-47275 LOW 2.6 In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5 client (including … Jul 20, 2026
CVE-2026-46701 HIGH 7.6 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty secret (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` at `bin/mcp-server.ts:89`), which … Jul 20, 2026
CVE-2026-46555 HIGH 7.7 WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the … Jul 20, 2026
CVE-2026-44978 MEDIUM 5.3 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does … Jul 20, 2026
CVE-2026-44178 HIGH 8.8 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding … Jul 20, 2026
CVE-2026-42218 MEDIUM 5.3 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in … Jul 20, 2026
CVE-2026-42210 UNKNOWN — Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), … Jul 20, 2026
CVE-2026-41521 HIGH 8.2 xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection … Jul 20, 2026
CVE-2026-41252 CRITICAL 9.8 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when … Jul 20, 2026
CVE-2026-40187 UNKNOWN — In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to … Jul 20, 2026
CVE-2026-39879 HIGH 7.1 Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of … Jul 20, 2026
CVE-2026-39385 UNKNOWN — Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated … Jul 20, 2026
CVE-2026-35591 UNKNOWN — libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the … Jul 20, 2026
CVE-2026-35590 UNKNOWN — libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the … Jul 20, 2026
CVE-2026-35217 MEDIUM 6.5 NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker … Jul 20, 2026
CVE-2026-35048 CRITICAL 9.8 The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper … Jul 20, 2026