|
101
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
rmnet_dellink() removes the endpoint from the hash table wit…
New
|
-
|
CVE-2026-64188
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
xfs: fail recovery on a committed log item with no regions
If the first op of a transaction is a bare transaction header
(len == …
New
|
-
|
CVE-2026-64187
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
5.4 |
MEDIUM
Network
|
-
|
-
|
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can by…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-63745
|
2026-07-21 02:18 |
2026-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
7.7 |
HIGH
Network
|
-
|
-
|
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the Surreal…
New
|
CWE-22
Path Traversal
|
CVE-2026-63739
|
2026-07-21 02:18 |
2026-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to p…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-63733
|
2026-07-21 02:18 |
2026-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
5.8 |
MEDIUM
Network
|
-
|
-
|
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim in `submission.…
New
|
CWE-20 CWE-915
Improper Input Validation Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-63428
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
5.4 |
MEDIUM
Network
|
-
|
-
|
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Us…
New
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-63102
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
6.5 |
MEDIUM
Network
|
-
|
-
|
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR b…
New
|
CWE-126 CWE-190
Buffer Over-read Integer Overflow or Wraparound
|
CVE-2026-63091
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
7.1 |
HIGH
Local
|
-
|
-
|
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `…
New
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-58484
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` u…
New
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2026-58414
|
2026-07-21 02:18 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|