Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57083
Total
4536
Critical
16949
High
16800
Medium
CVE ID Severity Score Description Published
CVE-2026-91953 MEDIUM 6.5 FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed … Sep 15, 2026
CVE-2026-91952 MEDIUM 6.5 FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker … Sep 15, 2026
CVE-2026-91951 MEDIUM 6.5 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte … Sep 15, 2026
CVE-2026-91950 MEDIUM 6.5 FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP … Sep 15, 2026
CVE-2026-91949 CRITICAL 9.3 FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers … Sep 15, 2026
CVE-2026-91948 HIGH 7.5 FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel … Sep 15, 2026
CVE-2026-91947 HIGH 7.5 FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients … Sep 15, 2026
CVE-2026-91946 MEDIUM 6.5 FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed … Sep 15, 2026
CVE-2026-91945 MEDIUM 6.5 FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated … Sep 15, 2026
CVE-2026-91944 MEDIUM 6.1 crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON … Sep 15, 2026
CVE-2026-91943 HIGH 7.7 Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply … Sep 15, 2026
CVE-2026-91942 MEDIUM 5.4 crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious … Sep 15, 2026
CVE-2026-91941 HIGH 7.5 Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF … Sep 15, 2026
CVE-2026-91940 HIGH 7.5 crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted … Sep 15, 2026
CVE-2026-91938 HIGH 7.1 Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide … Sep 15, 2026
CVE-2026-91937 HIGH 7.5 Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator … Sep 15, 2026
CVE-2026-91936 MEDIUM 6.8 Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers … Sep 15, 2026
CVE-2026-91935 HIGH 8.3 Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update … Sep 15, 2026
CVE-2026-91934 HIGH 8.8 Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write … Sep 15, 2026
CVE-2026-91933 HIGH 7.1 Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying … Sep 15, 2026
CVE-2026-91932 HIGH 8.5 Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can … Sep 15, 2026
CVE-2026-91931 HIGH 8.5 Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx … Sep 15, 2026
CVE-2026-91930 HIGH 7.5 Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers … Sep 15, 2026
CVE-2026-91929 HIGH 7.1 Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete … Sep 15, 2026
CVE-2026-91849 MEDIUM 6.3 A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. … Sep 15, 2026