Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 276–289 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-42936 | HIGH | 7.8 | 2026-07-15 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code m… | |
| CVE-2026-12512 | HIGH | Patched | 8.6 | 2026-07-15 | The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated atta… |
| CVE-2026-12281 | HIGH | Patched | 8.1 | 2026-07-15 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carr… |
| CVE-2026-11580 | MEDIUM | Patched | 5.5 | 2026-07-15 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, all… |
| CVE-2026-11579 | MEDIUM | Patched | 5.3 | 2026-07-15 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a f… |
| CVE-2026-8920 | NONE | — | 2026-07-15 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file o… | |
| CVE-2026-8919 | NONE | — | 2026-07-15 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a cra… | |
| CVE-2026-15030 | NONE | — | 2026-07-15 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond … | |
| CVE-2026-15029 | NONE | — | 2026-07-15 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrar… | |
| CVE-2026-13585 | NONE | — | 2026-07-15 | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Bu… | |
| CVE-2026-13385 | NONE | — | 2026-07-15 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the r… | |
| CVE-2026-11851 | NONE | — | 2026-07-15 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authentic… | |
| CVE-2026-9770 | NONE | — | 2026-07-15 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to th… | |
| CVE-2026-13230 | NONE | — | 2026-07-15 | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information… |