|
11
|
- |
|
-
|
-
|
ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under ce…
New
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-8169
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
7.5 |
HIGH
Network
|
-
|
-
|
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abor…
New
|
CWE-248
Uncaught Exception
|
CVE-2026-64612
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
8.6 |
HIGH
Network
|
-
|
-
|
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no se…
New
|
CWE-306 CWE-434
Missing Authentication for Critical Function Unrestricted Upload of File with Dangerous Type
|
CVE-2026-63429
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-…
New
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2026-58482
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks…
New
|
CWE-22 CWE-23
Path Traversal Relative Path Traversal
|
CVE-2026-58481
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` an…
New
|
CWE-22 CWE-23
Path Traversal Relative Path Traversal
|
CVE-2026-58413
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
5.3 |
MEDIUM
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Creat…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-55639
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
8.0 |
HIGH
Local
|
-
|
-
|
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with i…
New
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-55626
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
8.7 |
HIGH
Network
|
-
|
-
|
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe str…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-54498
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
3.7 |
LOW
Network
|
-
|
-
|
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and earlier, the _.merge(target, source) utility exported by @feathersjs/commons re…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-54335
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|