Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

289 CVEs · published 2026-07-15 to 2026-07-15

CVEs (289)

Showing 76–100 of 289

CVE ID Severity Patch CVSS Published Description
CVE-2026-40952 HIGH Patched 7.8 2026-07-15 CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the c…
CVE-2026-33443 MEDIUM Patched 5.9 2026-07-15 CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can …
CVE-2026-62947 MEDIUM Patched 4.9 2026-07-15 OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus…
CVE-2026-62355 MEDIUM Patched 5.4 2026-07-15 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could…
CVE-2026-62353 MEDIUM Patched 5.4 2026-07-15 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailin…
CVE-2026-62351 HIGH Patched 7.5 2026-07-15 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMs…
CVE-2026-62350 HIGH Patched 7.2 2026-07-15 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared…
CVE-2026-62349 HIGH Patched 8.3 2026-07-15 TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks spac…
CVE-2026-62348 MEDIUM Patched 5.4 2026-07-15 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run K…
CVE-2026-54443 NONE Patched — 2026-07-15 Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values befor…
CVE-2026-49988 NONE Patched — 2026-07-15 Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and…
CVE-2026-49987 NONE Patched — 2026-07-15 Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly …
CVE-2026-46485 HIGH Patched 8.2 2026-07-15 Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes …
CVE-2026-46421 NONE Patched — 2026-07-15 The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for tha…
CVE-2026-26032 MEDIUM Patched 5.4 2026-07-15 The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an A…
CVE-2026-15895 HIGH Patched 7.8 2026-07-15 OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted …
CVE-2026-15746 MEDIUM Patched 6.5 2026-07-15 Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including th…
CVE-2026-12997 HIGH 7.5 2026-07-15 The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter.…
CVE-2026-8055 NONE — 2026-07-15 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a reservation duplicate of CVE-2026-48866. Notes: All …
CVE-2026-62948 CRITICAL Patched 9.6 2026-07-15 OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/…
CVE-2026-62389 HIGH Patched 7.5 2026-07-15 ws before 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches maxFragments, allowing att…
CVE-2026-61643 MEDIUM Patched 5.9 2026-07-15 FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's …
CVE-2026-59258 HIGH Patched 8.3 2026-07-15 immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles with…
CVE-2026-59255 HIGH Patched 7.1 2026-07-15 BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to mo…
CVE-2026-58660 HIGH Patched 8.1 2026-07-15 Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the att…