Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 251–275 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-58655 | HIGH | Patched | 8.8 | 2026-07-15 | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic … |
| CVE-2026-57996 | HIGH | Patched | 8.8 | 2026-07-15 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A … |
| CVE-2026-56764 | LOW | Patched | 3.7 | 2026-07-15 | Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual fun… |
| CVE-2026-56699 | CRITICAL | Patched | 10.0 | 2026-07-15 | Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON o… |
| CVE-2026-56400 | HIGH | Patched | 8.3 | 2026-07-15 | open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1… |
| CVE-2026-56398 | HIGH | Patched | 7.3 | 2026-07-15 | Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file ex… |
| CVE-2026-56375 | LOW | 3.3 | 2026-07-15 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources… | |
| CVE-2026-56353 | MEDIUM | Patched | 4.8 | 2026-07-15 | n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the… |
| CVE-2026-56352 | MEDIUM | Patched | 6.4 | 2026-07-15 | n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the fil… |
| CVE-2026-56349 | NONE | — | 2026-07-15 | n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can cra… | |
| CVE-2026-56339 | HIGH | Patched | 7.5 | 2026-07-15 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that… |
| CVE-2026-59235 | NONE | — | 2026-07-15 | Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Pros… | |
| CVE-2026-40633 | HIGH | Patched | 7.8 | 2026-07-15 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A lo… |
| CVE-2026-8281 | NONE | — | 2026-07-15 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-58077 | NONE | — | 2026-07-15 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A special… | |
| CVE-2026-57833 | NONE | — | 2026-07-15 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relatio… | |
| CVE-2026-57821 | HIGH | Patched | 8.1 | 2026-07-15 | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is c… |
| CVE-2026-56287 | HIGH | Patched | 8.1 | 2026-07-15 | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sort… |
| CVE-2026-49501 | MEDIUM | Patched | 6.7 | 2026-07-15 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged a… |
| CVE-2026-35152 | HIGH | Patched | 8.8 | 2026-07-15 | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are inc… |
| CVE-2026-57832 | NONE | — | 2026-07-15 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection. | |
| CVE-2026-57831 | NONE | — | 2026-07-15 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthentic… | |
| CVE-2026-15804 | HIGH | 8.8 | 2026-07-15 | The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the co… | |
| CVE-2026-15583 | HIGH | 8.6 | 2026-07-15 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by su… | |
| CVE-2026-14251 | HIGH | 7.7 | 2026-07-15 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped … |