Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
Showing 2,361 - 2,380 of 12,907 CVEs
CVE-2026-47123 HIGH - 7.5

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / References headers. The notification reply pa...

Vendor: freescout-help-desk
Product: freescout
Published: May 29, 2026
Source: NVD
CVE-2026-46599 HIGH - 7.5

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

Vendor: golang.org/x/image
Product: golang.org/x/image/tiff
Published: May 29, 2026
Source: NVD
CVE-2026-46527 HIGH - 7.5

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwarded-For header whose value parses to no valid...

Vendor: yhirose
Product: cpp-httplib
Published: May 29, 2026
Source: NVD
CVE-2026-44422 HIGH - 7.5

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused acr...

Vendor: FreeRDP
Product: FreeRDP
Published: May 29, 2026
Source: NVD
CVE-2026-44421 HIGH - 8.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX...

Vendor: FreeRDP
Product: FreeRDP
Published: May 29, 2026
Source: NVD
CVE-2026-44420 HIGH - 8.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server pr...

Vendor: FreeRDP
Product: FreeRDP
Published: May 29, 2026
Source: NVD
CVE-2026-44285 HIGH - 7.7

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi...

Vendor: labring
Product: FastGPT
Published: May 29, 2026
Source: NVD
CVE-2026-47260 HIGH - 7.7

Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + public IP check), but the individual episode <enclosure url="..."> values extracted from the RSS XML are stored directly into the d...

Vendor: composer
Product: phanan/koel
Published: May 29, 2026
Source: GitHub
CVE-2026-46702 HIGH - 7.5

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabled, russh accepted compressed packets whose on-wire size passed the normal transport packet-length checks but whose decompressed size was much larger. This allowed a remote pee...

Vendor: rust
Product: russh
Published: May 29, 2026
Source: GitHub

AgenticMail API/storage and outbound relay hardening fixes

Vendor: npm
Product: @agenticmail/api
Published: May 29, 2026
Source: GitHub
CVE-2026-49374 HIGH - 7.6

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49373 HIGH - 7.1

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49372 HIGH - 7.5

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49371 HIGH - 7.1

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

Vendor: JetBrains
Product: TeamCity
Published: May 29, 2026
Source: NVD
CVE-2026-49368 HIGH - 8.7

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Vendor: JetBrains
Product: YouTrack
Published: May 29, 2026
Source: NVD
CVE-2026-49367 HIGH - 8.0

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

Vendor: JetBrains
Product: IntelliJ IDEA
Published: May 29, 2026
Source: NVD
CVE-2026-49366 HIGH - 7.8

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

Vendor: JetBrains
Product: IntelliJ IDEA
Published: May 29, 2026
Source: NVD
CVE-2026-47740 HIGH - 8.1

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete...

Vendor: shopperlabs
Product: shopper
Published: May 29, 2026
Source: NVD
CVE-2026-42941 HIGH - 8.3

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

Vendor: Danelec
Product: MacGregor Voyage Data Recorder (VDR) G4e
Published: May 29, 2026
Source: NVD
CVE-2026-42929 HIGH - 8.3

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

Vendor: Danelec
Product: MacGregor Voyage Data Recorder (VDR) G4e
Published: May 29, 2026
Source: NVD