|
21
|
4.7 |
MEDIUM
Network
|
-
|
-
|
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and …
New
|
CWE-79 CWE-113
Cross-site Scripting HTTP Response Splitting
|
CVE-2026-54163
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
7.1 |
HIGH
Local
|
-
|
-
|
Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-52584
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
9.8 |
CRITICAL
Network
|
-
|
-
|
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
New
|
CWE-89
SQL Injection
|
CVE-2026-52348
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
7.5 |
HIGH
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose …
New
|
CWE-287
Improper Authentication
|
CVE-2026-48812
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST request to `/api/v4/mqtt/publi…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-47276
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
- |
|
-
|
-
|
Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session as fresh after verifying an OAuth account that bel…
New
|
CWE-287
Improper Authentication
|
CVE-2026-46715
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook…
New
|
CWE-22
Path Traversal
|
CVE-2026-46671
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
7.7 |
HIGH
Local
|
-
|
-
|
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0…
New
|
CWE-22 CWE-306 CWE-346
Path Traversal Missing Authentication for Critical Function Origin Validation Error
|
CVE-2026-46555
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
6.5 |
MEDIUM
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthe…
New
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-45295
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
5.4 |
MEDIUM
Network
|
-
|
-
|
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled dat…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44228
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|