Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 176–200 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-45805 | HIGH | Patched | 8.8 | 2026-07-15 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:… |
| CVE-2026-45150 | NONE | Patched | — | 2026-07-15 | Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, a… |
| CVE-2026-44986 | CRITICAL | Patched | 9.9 | 2026-07-15 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations… |
| CVE-2026-41580 | MEDIUM | Patched | 6.1 | 2026-07-15 | Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf endpoint rendered PDF Tit… |
| CVE-2026-62294 | NONE | Patched | — | 2026-07-15 | Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks,… |
| CVE-2026-61836 | HIGH | Patched | 8.6 | 2026-07-15 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/util… |
| CVE-2026-61835 | HIGH | Patched | 7.7 | 2026-07-15 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypa… |
| CVE-2026-61740 | NONE | Patched | — | 2026-07-15 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key pro… |
| CVE-2026-61736 | CRITICAL | Patched | 9.3 | 2026-07-15 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api… |
| CVE-2026-61684 | NONE | Patched | — | 2026-07-15 | FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT… |
| CVE-2026-61646 | NONE | Patched | — | 2026-07-15 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request t… |
| CVE-2026-61644 | HIGH | Patched | 7.7 | 2026-07-15 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's… |
| CVE-2026-61613 | NONE | — | 2026-07-15 | Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled w… | |
| CVE-2026-60065 | LOW | 3.7 | 2026-07-15 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send reques… | |
| CVE-2026-60062 | MEDIUM | 6.4 | 2026-07-15 | The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config… | |
| CVE-2026-59762 | HIGH | 7.5 | 2026-07-15 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance c… | |
| CVE-2026-56434 | MEDIUM | 6.5 | 2026-07-15 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and p… | |
| CVE-2026-55723 | HIGH | Patched | 8.3 | 2026-07-15 | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator… |
| CVE-2026-54563 | HIGH | Patched | 7.1 | 2026-07-15 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/… |
| CVE-2026-54562 | MEDIUM | Patched | 6.5 | 2026-07-15 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/dow… |
| CVE-2026-54560 | HIGH | Patched | 7.6 | 2026-07-15 | Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so th… |
| CVE-2026-52865 | MEDIUM | Patched | 6.5 | 2026-07-15 | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServ… |
| CVE-2026-42533 | HIGH | 8.1 | 2026-07-15 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables bef… | |
| CVE-2026-33213 | MEDIUM | 6.1 | 2026-07-15 | Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped the scheme and netloc … | |
| CVE-2026-62175 | NONE | — | 2026-07-15 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60091. Reason: This candidate is a duplicate of CVE-2026-60091. Notes: All CVE users sh… |