Skip to content

Menu
  • Home
Menu

CVE-2026-63728 – Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature

Posted on July 21, 2026

CVE ID :CVE-2026-63728 Published : July 21, 2026, 12:17 a.m. | 18 minutes ago Description :Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report…

CVE-2026-64625 – AVideo before 29.0 OS Command Injection via execAsync

Posted on July 21, 2026

CVE ID :CVE-2026-64625 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh…

CVE-2026-64624 – FreeRDP RDP File Parser Remote Code Execution via CLI Options

Posted on July 21, 2026

CVE ID :CVE-2026-64624 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing…

CVE-2026-57495 – AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator’s Claude Code session (bridge-wake)

Posted on July 21, 2026

CVE ID :CVE-2026-57495 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex…

CVE-2026-47255 – AgenticMail API/storage and outbound relay hardening

Posted on July 21, 2026

CVE ID :CVE-2026-47255 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core…

CVE-2026-44359 – Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow

Posted on July 20, 2026

CVE ID :CVE-2026-44359 Published : July 20, 2026, 12:16 a.m. | 18 minutes ago Description :Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository’s main_matrix.yml workflow…

CVE-2026-10130 – QueryWeaver Authentication Bypass via Email Signup Token Issuance for Existing Accounts

Posted on July 19, 2026

CVE ID :CVE-2026-10130 Published : July 18, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing…

CVE-2026-12228 – Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms

Posted on July 19, 2026

CVE ID :CVE-2026-12228 Published : July 18, 2026, 9:17 p.m. | 3 hours, 18 minutes ago Description :A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The…

CVE-2026-9323 – Insecure PRNG and Information Exposure in urwid Web Display Backend

Posted on July 19, 2026

CVE ID :CVE-2026-9323 Published : July 18, 2026, 2:17 p.m. | 10 hours, 18 minutes ago Description :The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9)…

CVE-2026-16117 – @fastify/http-proxy vulnerable to prefix escape via URL-encoded characters

Posted on July 19, 2026

CVE ID :CVE-2026-16117 Published : July 18, 2026, 2:17 p.m. | 10 hours, 18 minutes ago Description :Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…

Posts pagination

1 2 … 114 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme