Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91951 | MEDIUM | 6.5 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte … | Sep 15, 2026 |
| CVE-2026-91950 | MEDIUM | 6.5 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP … | Sep 15, 2026 |
| CVE-2026-91949 | CRITICAL | 9.3 | FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers … | Sep 15, 2026 |
| CVE-2026-91948 | HIGH | 7.5 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel … | Sep 15, 2026 |
| CVE-2026-91947 | HIGH | 7.5 | FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients … | Sep 15, 2026 |
| CVE-2026-91946 | MEDIUM | 6.5 | FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed … | Sep 15, 2026 |
| CVE-2026-91945 | MEDIUM | 6.5 | FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated … | Sep 15, 2026 |
| CVE-2026-91944 | MEDIUM | 6.1 | crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON … | Sep 15, 2026 |
| CVE-2026-91943 | HIGH | 7.7 | Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply … | Sep 15, 2026 |
| CVE-2026-91942 | MEDIUM | 5.4 | crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious … | Sep 15, 2026 |
| CVE-2026-91941 | HIGH | 7.5 | Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF … | Sep 15, 2026 |
| CVE-2026-91940 | HIGH | 7.5 | crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted … | Sep 15, 2026 |
| CVE-2026-91938 | HIGH | 7.1 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide … | Sep 15, 2026 |
| CVE-2026-91937 | HIGH | 7.5 | Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator … | Sep 15, 2026 |
| CVE-2026-91936 | MEDIUM | 6.8 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers … | Sep 15, 2026 |
| CVE-2026-91935 | HIGH | 8.3 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update … | Sep 15, 2026 |
| CVE-2026-91934 | HIGH | 8.8 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write … | Sep 15, 2026 |
| CVE-2026-91933 | HIGH | 7.1 | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying … | Sep 15, 2026 |
| CVE-2026-91932 | HIGH | 8.5 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can … | Sep 15, 2026 |
| CVE-2026-91931 | HIGH | 8.5 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx … | Sep 15, 2026 |
| CVE-2026-91930 | HIGH | 7.5 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers … | Sep 15, 2026 |
| CVE-2026-91929 | HIGH | 7.1 | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete … | Sep 15, 2026 |
| CVE-2026-91849 | MEDIUM | 6.3 | A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. … | Sep 15, 2026 |
| CVE-2026-91848 | HIGH | 7.3 | A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the … | Sep 15, 2026 |
| CVE-2026-89307 | UNKNOWN | — | The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced … | Sep 15, 2026 |