|
121
|
2.6 |
LOW
Network
|
-
|
-
|
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5 client (including bridge m…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-47275
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
7.6 |
HIGH
Network
|
-
|
-
|
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty secret (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` at `bin/mcp-server.ts…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-46701
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
7.5 |
HIGH
Network
|
-
|
-
|
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the f…
New
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-45713
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
6.5 |
MEDIUM
Network
|
-
|
-
|
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on …
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-45139
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
5.3 |
MEDIUM
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does not affect the default con…
New
|
CWE-20 CWE-125
Improper Input Validation Out-of-bounds Read
|
CVE-2026-44978
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
8.8 |
HIGH
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote cli…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44178
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
8.2 |
HIGH
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VN…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41521
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
9.8 |
CRITICAL
Network
|
-
|
-
|
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-41252
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
7.1 |
HIGH
Adjacent
|
-
|
-
|
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 ar…
New
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2026-39879
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
- |
|
-
|
-
|
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 wi…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-39385
|
2026-07-21 02:17 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|