Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 151–175 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-20157 | HIGH | 7.5 | 2026-07-15 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. T… | |
| CVE-2026-20156 | HIGH | 8.1 | 2026-07-15 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. T… | |
| CVE-2026-20153 | HIGH | 7.5 | 2026-07-15 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. T… | |
| CVE-2026-20150 | HIGH | 8.8 | 2026-07-15 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. T… | |
| CVE-2026-20146 | MEDIUM | Patched | 5.5 | 2026-07-15 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path tra… |
| CVE-2026-1563 | MEDIUM | Patched | 4.8 | 2026-07-15 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged … |
| CVE-2026-1562 | MEDIUM | Patched | 4.8 | 2026-07-15 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged use… |
| CVE-2025-32781 | MEDIUM | Patched | 6.5 | 2026-07-15 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application… |
| CVE-2026-9007 | NONE | — | 2026-07-15 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (… | |
| CVE-2026-62843 | MEDIUM | Patched | 6.8 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browse… |
| CVE-2026-62685 | HIGH | Patched | 8.1 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser buil… |
| CVE-2026-62683 | LOW | Patched | 3.1 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can … |
| CVE-2026-61828 | NONE | Patched | — | 2026-07-15 | Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL serv… |
| CVE-2026-61605 | NONE | — | 2026-07-15 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-58655. Reason: This candidate is a duplicate of CVE-2026-58655. Notes: All CVE users sh… | |
| CVE-2026-61371 | HIGH | Patched | 7.5 | 2026-07-15 | Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive eff… |
| CVE-2026-60005 | HIGH | 8.2 | 2026-07-15 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a back… | |
| CVE-2026-55242 | HIGH | Patched | 8.8 | 2026-07-15 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger serve… |
| CVE-2026-50148 | CRITICAL | Patched | 10.0 | 2026-07-15 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase… |
| CVE-2026-50147 | HIGH | Patched | 7.6 | 2026-07-15 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a M… |
| CVE-2026-47164 | HIGH | Patched | 7.7 | 2026-07-15 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation … |
| CVE-2026-47160 | MEDIUM | Patched | 5.8 | 2026-07-15 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including shou… |
| CVE-2026-47159 | NONE | Patched | — | 2026-07-15 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadat… |
| CVE-2026-47158 | HIGH | Patched | 8.3 | 2026-07-15 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /conn… |
| CVE-2026-46709 | HIGH | Patched | 7.8 | 2026-07-15 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active… |
| CVE-2026-45806 | HIGH | Patched | 7.7 | 2026-07-15 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/m… |