Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25534
Total
1899
Critical
7798
High
8005
Medium
CVE ID Severity Score Description Published
CVE-2026-44422 HIGH 7.5 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple … May 29, 2026
CVE-2026-44421 HIGH 8.8 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP … May 29, 2026
CVE-2026-44420 HIGH 8.8 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side … May 29, 2026
CVE-2026-44287 MEDIUM 6.3 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax … May 29, 2026
CVE-2026-44285 HIGH 7.7 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress … May 29, 2026
CVE-2026-42500 MEDIUM 5.3 Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image. May 29, 2026
CVE-2026-34127 UNKNOWN A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the … May 29, 2026
CVE-2026-9051 CRITICAL 9.1 There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading … May 29, 2026
CVE-2026-49386 MEDIUM 6.5 In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas May 29, 2026
CVE-2026-49385 MEDIUM 6.5 In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts May 29, 2026
CVE-2026-49384 MEDIUM 6.1 In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible May 29, 2026
CVE-2026-49383 LOW 3.3 In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible May 29, 2026
CVE-2026-49382 MEDIUM 4.5 In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin May 29, 2026
CVE-2026-49381 LOW 3.4 In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible May 29, 2026
CVE-2026-49380 LOW 3.1 In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible May 29, 2026
CVE-2026-49379 MEDIUM 6.5 In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names May 29, 2026
CVE-2026-49378 MEDIUM 4.3 In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion May 29, 2026
CVE-2026-49377 MEDIUM 4.3 In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters May 29, 2026
CVE-2026-49376 MEDIUM 6.5 In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin May 29, 2026
CVE-2026-49375 MEDIUM 6.1 In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page May 29, 2026
CVE-2026-49374 HIGH 7.6 In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters May 29, 2026
CVE-2026-49373 HIGH 7.1 In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings May 29, 2026
CVE-2026-49372 HIGH 7.5 In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible May 29, 2026
CVE-2026-49371 HIGH 7.1 In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible May 29, 2026
CVE-2026-49370 LOW 3.4 In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests May 29, 2026