Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 51–75 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-33444 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol… |
| CVE-2026-56743 | MEDIUM | Patched | 5.4 | 2026-07-15 | Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without… |
| CVE-2026-56742 | MEDIUM | Patched | 5.9 | 2026-07-15 | Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to creat… |
| CVE-2026-52870 | HIGH | Patched | 7.6 | 2026-07-15 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.exper… |
| CVE-2026-52869 | HIGH | Patched | 7.1 | 2026-07-15 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp… |
| CVE-2026-50144 | HIGH | 7.1 | 2026-07-15 | ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows… | |
| CVE-2026-50124 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasour… |
| CVE-2026-50030 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/da… |
| CVE-2026-49867 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit TemplateManageRequest.s… |
| CVE-2026-49445 | CRITICAL | Patched | 9.2 | 2026-07-15 | Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envo… |
| CVE-2026-46684 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values … |
| CVE-2026-45738 | HIGH | Patched | 7.3 | 2026-07-15 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argoc… |
| CVE-2026-45737 | MEDIUM | Patched | 6.3 | 2026-07-15 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret va… |
| CVE-2026-45535 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries su… |
| CVE-2026-45534 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configur… |
| CVE-2026-45533 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bu… |
| CVE-2026-45419 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesTo… |
| CVE-2026-45417 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into g… |
| CVE-2026-45320 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transF… |
| CVE-2026-40958 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can crea… |
| CVE-2026-40957 | HIGH | Patched | 7.5 | 2026-07-15 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it t… |
| CVE-2026-40956 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel … |
| CVE-2026-40955 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total… |
| CVE-2026-40954 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total… |
| CVE-2026-40953 | MEDIUM | Patched | 4.4 | 2026-07-15 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can… |