CVE ID :CVE-2026-63728 Published : July 21, 2026, 12:17 a.m. | 18 minutes ago Description :Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report…
CVE-2026-64625 – AVideo before 29.0 OS Command Injection via execAsync
CVE ID :CVE-2026-64625 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh…
CVE-2026-64624 – FreeRDP RDP File Parser Remote Code Execution via CLI Options
CVE ID :CVE-2026-64624 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing…
CVE-2026-57495 – AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator’s Claude Code session (bridge-wake)
CVE ID :CVE-2026-57495 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex…
CVE-2026-47255 – AgenticMail API/storage and outbound relay hardening
CVE ID :CVE-2026-47255 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core…
CVE-2026-44359 – Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
CVE ID :CVE-2026-44359 Published : July 20, 2026, 12:16 a.m. | 18 minutes ago Description :Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository’s main_matrix.yml workflow…
CVE-2026-10130 – QueryWeaver Authentication Bypass via Email Signup Token Issuance for Existing Accounts
CVE ID :CVE-2026-10130 Published : July 18, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing…
CVE-2026-12228 – Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms
CVE ID :CVE-2026-12228 Published : July 18, 2026, 9:17 p.m. | 3 hours, 18 minutes ago Description :A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The…
CVE-2026-9323 – Insecure PRNG and Information Exposure in urwid Web Display Backend
CVE ID :CVE-2026-9323 Published : July 18, 2026, 2:17 p.m. | 10 hours, 18 minutes ago Description :The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9)…
CVE-2026-16117 – @fastify/http-proxy vulnerable to prefix escape via URL-encoded characters
CVE ID :CVE-2026-16117 Published : July 18, 2026, 2:17 p.m. | 10 hours, 18 minutes ago Description :Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…