Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.6 HIGH
CVE-2026-46701 — Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an empty secret (`process.env['NETWORK_AI_MCP_SECRET'] ?? ''` at `bin/mcp-server.ts…

Remote | Authentication
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.7 HIGH
CVE-2026-46555 — WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfilt…

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0…

| Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.3 MEDIUM
CVE-2026-44978 — xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds re…

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. This vulnerability does not affect the default con…

xrdp | Remote | Memory Corruption
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-44178 — xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote cli…

xrdp | Remote | Memory Corruption
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
5.3 MEDIUM
CVE-2026-42218 — XRDP is vulnerable to a server timing attack, leading to user enumeration

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker c…

xrdp | Remote | Information Disclosure
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
5.3 MEDIUM
CVE-2026-42210 — Webmin 2FA requirement bypass

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with know…

webmin | Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.2 HIGH
CVE-2026-41521 — xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass

xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VN…

xrdp | Remote | Memory Corruption
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-41252 — xrdp: lib_palette_update Heap Buffer Overflow & RCE

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during …

xrdp | Remote | Memory Corruption
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
8.6 HIGH
CVE-2026-40187 — Authenticated RCE via Malicious eTemplate Upload in EGroupware

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS `/etemplates` m…

egroupware | Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.1 HIGH
CVE-2026-39879 — SQL injection in syslog-ng SQL destionation driver

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 ar…

| Injection
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.1 HIGH
CVE-2026-39385 — Frappe LMS enrollment bypass in paid courses via unrelated batch

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 wi…

learning | Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.0 HIGH
CVE-2026-35591 — Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile

libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG…

libvips | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.8 MEDIUM
CVE-2026-35590 — Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing da…

libvips | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-35217 — NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectabl…

NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker may still accept the malfor…

nanomq | Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
9.8 CRITICAL
CVE-2026-35048 — Piwigo RCE via PHP Code Injection into Config File in Installer

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, t…

piwigo | Remote | Injection
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
6.8 MEDIUM
CVE-2026-33328 — Possible integer overflow on 32-bit systems when reading GIF images

libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to …

libvips | Memory Corruption
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.0 HIGH
CVE-2026-33327 — Possible integer overflow leading to potential heap-based buffer overflow

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer o…

libvips | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.3 HIGH
CVE-2026-32825 — dataCycle No Brute-Force Protection On Web And API Login Endpoints

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authentication
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.3 HIGH
CVE-2026-32824 — dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redir…

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-32823 — dataCycle State-Changing GET Endpoints Enable CSRF

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Cross-Site Request Forgery
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
Showing 20 of 8502 Results