Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25534
Total
1899
Critical
7798
High
8005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44422 | HIGH | 7.5 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple … | May 29, 2026 |
| CVE-2026-44421 | HIGH | 8.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP … | May 29, 2026 |
| CVE-2026-44420 | HIGH | 8.8 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side … | May 29, 2026 |
| CVE-2026-44287 | MEDIUM | 6.3 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax … | May 29, 2026 |
| CVE-2026-44285 | HIGH | 7.7 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress … | May 29, 2026 |
| CVE-2026-42500 | MEDIUM | 5.3 | Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. | May 29, 2026 |
| CVE-2026-34127 | UNKNOWN | — | A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the … | May 29, 2026 |
| CVE-2026-9051 | CRITICAL | 9.1 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading … | May 29, 2026 |
| CVE-2026-49386 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas | May 29, 2026 |
| CVE-2026-49385 | MEDIUM | 6.5 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts | May 29, 2026 |
| CVE-2026-49384 | MEDIUM | 6.1 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible | May 29, 2026 |
| CVE-2026-49383 | LOW | 3.3 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible | May 29, 2026 |
| CVE-2026-49382 | MEDIUM | 4.5 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin | May 29, 2026 |
| CVE-2026-49381 | LOW | 3.4 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | May 29, 2026 |
| CVE-2026-49380 | LOW | 3.1 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | May 29, 2026 |
| CVE-2026-49379 | MEDIUM | 6.5 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | May 29, 2026 |
| CVE-2026-49378 | MEDIUM | 4.3 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | May 29, 2026 |
| CVE-2026-49377 | MEDIUM | 4.3 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | May 29, 2026 |
| CVE-2026-49376 | MEDIUM | 6.5 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | May 29, 2026 |
| CVE-2026-49375 | MEDIUM | 6.1 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | May 29, 2026 |
| CVE-2026-49374 | HIGH | 7.6 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | May 29, 2026 |
| CVE-2026-49373 | HIGH | 7.1 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | May 29, 2026 |
| CVE-2026-49372 | HIGH | 7.5 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | May 29, 2026 |
| CVE-2026-49371 | HIGH | 7.1 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | May 29, 2026 |
| CVE-2026-49370 | LOW | 3.4 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | May 29, 2026 |