Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 76–100 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-40952 | HIGH | Patched | 7.8 | 2026-07-15 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the c… |
| CVE-2026-33443 | MEDIUM | Patched | 5.9 | 2026-07-15 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can … |
| CVE-2026-62947 | MEDIUM | Patched | 4.9 | 2026-07-15 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus… |
| CVE-2026-62355 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could… |
| CVE-2026-62353 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailin… |
| CVE-2026-62351 | HIGH | Patched | 7.5 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMs… |
| CVE-2026-62350 | HIGH | Patched | 7.2 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared… |
| CVE-2026-62349 | HIGH | Patched | 8.3 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks spac… |
| CVE-2026-62348 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run K… |
| CVE-2026-54443 | NONE | Patched | — | 2026-07-15 | Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values befor… |
| CVE-2026-49988 | NONE | Patched | — | 2026-07-15 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and… |
| CVE-2026-49987 | NONE | Patched | — | 2026-07-15 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly … |
| CVE-2026-46485 | HIGH | Patched | 8.2 | 2026-07-15 | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes … |
| CVE-2026-46421 | NONE | Patched | — | 2026-07-15 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for tha… |
| CVE-2026-26032 | MEDIUM | Patched | 5.4 | 2026-07-15 | The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an A… |
| CVE-2026-15895 | HIGH | Patched | 7.8 | 2026-07-15 | OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted … |
| CVE-2026-15746 | MEDIUM | Patched | 6.5 | 2026-07-15 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including th… |
| CVE-2026-12997 | HIGH | 7.5 | 2026-07-15 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter.… | |
| CVE-2026-8055 | NONE | — | 2026-07-15 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a reservation duplicate of CVE-2026-48866. Notes: All … | |
| CVE-2026-62948 | CRITICAL | Patched | 9.6 | 2026-07-15 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/… |
| CVE-2026-62389 | HIGH | Patched | 7.5 | 2026-07-15 | ws before 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches maxFragments, allowing att… |
| CVE-2026-61643 | MEDIUM | Patched | 5.9 | 2026-07-15 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's … |
| CVE-2026-59258 | HIGH | Patched | 8.3 | 2026-07-15 | immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles with… |
| CVE-2026-59255 | HIGH | Patched | 7.1 | 2026-07-15 | BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to mo… |
| CVE-2026-58660 | HIGH | Patched | 8.1 | 2026-07-15 | Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the att… |