Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-64624 — FreeRDP RDP File Parser Remote Code Execution via CLI Options

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP …

| Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.3 MEDIUM
CVE-2026-57852 — Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic…

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.2 HIGH
CVE-2026-57495 — AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operat…

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version …

Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.1 HIGH
CVE-2026-57494 — AgenticMail: Cross-agent task authorization bypass in AgenticMail API

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending…

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.1 HIGH
CVE-2026-55550 — NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify t…

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, u…

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.6 HIGH
CVE-2026-55544 — NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure an…

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Beare…

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-52656 — SJCAM AllWinner Tech Arbitrary Code Execution Vulnerability

An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file

| Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.9 MEDIUM
CVE-2026-51385 — GRAPHIFY Remote Code Execution

An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binar…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-51031 — FlareSolverr Server-Side Request Forgery

FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information

| Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-51025 — Fuint Member Marketing System Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file

| Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.2 HIGH
CVE-2026-47255 — AgenticMail API/storage and outbound relay hardening

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and b…

Remote | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.5 MEDIUM
CVE-2026-47144 — Shamefile has an arbitrary file read via shamefile.yaml in shame next

Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose contents of f…

| Path Traversal
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.9 MEDIUM
CVE-2026-47134 — ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local…

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Library/Application Support/clea…

clearancekit | Cryptography
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.9 MEDIUM
CVE-2026-47133 — ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legi…

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-disk SQLite policy store (`/Library/Application Supp…

clearancekit | Cryptography
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.1 MEDIUM
CVE-2026-47128 — nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`

nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abst…

| Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-44510 — Rsync: Receiver-side out-of-bounds read enables remote DoS from malicious server

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver-side out-of-bounds array read in rsync's recv_files()…

Remote | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.5 HIGH
CVE-2026-16324 — Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation of the argument File…

metacrm | Remote | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.4 MEDIUM
CVE-2026-12900 — Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scri…

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, …

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2024-51316 — Tenda TX9 Denial of Service Vulnerability

The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName

| Denial of Service
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2024-51315 — Tenda TX9 Stack Overflow Vulnerability

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName

| Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
Showing 20 of 8276 Results