|
111
|
6.5 |
MEDIUM
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection sequence, the parser does not perform …
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-55645
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
5.3 |
MEDIUM
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did…
New
|
CWE-126
Buffer Over-read
|
CVE-2026-55238
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
7.5 |
HIGH
Network
|
-
|
-
|
xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protocol control header du…
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-54538
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
- |
|
-
|
-
|
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily la…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-54463
|
2026-07-21 02:17 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.…
New
|
CWE-78
OS Command
|
CVE-2026-54051
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without …
New
|
CWE-352
Origin Validation Error
|
CVE-2026-50743
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Update
|
CWE-94
Code Injection
|
CVE-2026-50650
|
2026-07-21 02:17 |
2026-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 windows_server_2022<…
|
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-58610
|
2026-07-21 02:17 |
2026-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
- |
|
-
|
-
|
systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) sourc…
Update
|
CWE-78
OS Command
|
CVE-2026-50289
|
2026-07-21 02:17 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/params.ts ships a runtime template copied into generated SDKs as params.gen.ts, a…
Update
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-48819
|
2026-07-21 02:17 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|