Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 1–25 of 289
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32781 | MEDIUM | Patched | 6.5 | 2026-07-15 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application… |
| CVE-2025-65720 | CRITICAL | 9.8 | 2026-07-15 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | |
| CVE-2026-10673 | HIGH | 8.3 | 2026-07-15 | The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ethernet frames in OPEN Alliance (OA) SPI mode by copying… | |
| CVE-2026-11579 | MEDIUM | Patched | 5.3 | 2026-07-15 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a f… |
| CVE-2026-11580 | MEDIUM | Patched | 5.5 | 2026-07-15 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, all… |
| CVE-2026-11851 | NONE | — | 2026-07-15 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authentic… | |
| CVE-2026-12281 | HIGH | Patched | 8.1 | 2026-07-15 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carr… |
| CVE-2026-12382 | HIGH | 8.2 | 2026-07-15 | A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite… | |
| CVE-2026-12512 | HIGH | Patched | 8.6 | 2026-07-15 | The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated atta… |
| CVE-2026-12997 | HIGH | 7.5 | 2026-07-15 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter.… | |
| CVE-2026-13230 | NONE | — | 2026-07-15 | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information… | |
| CVE-2026-13385 | NONE | — | 2026-07-15 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the r… | |
| CVE-2026-13585 | NONE | — | 2026-07-15 | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Bu… | |
| CVE-2026-14251 | HIGH | 7.7 | 2026-07-15 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped … | |
| CVE-2026-14960 | CRITICAL | 9.8 | 2026-07-15 | Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_REA… | |
| CVE-2026-14961 | MEDIUM | 6.2 | 2026-07-15 | Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispa… | |
| CVE-2026-15029 | NONE | — | 2026-07-15 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrar… | |
| CVE-2026-15030 | NONE | — | 2026-07-15 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond … | |
| CVE-2026-15583 | HIGH | 8.6 | 2026-07-15 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by su… | |
| CVE-2026-1562 | MEDIUM | Patched | 4.8 | 2026-07-15 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged use… |
| CVE-2026-1563 | MEDIUM | Patched | 4.8 | 2026-07-15 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged … |
| CVE-2026-15746 | MEDIUM | Patched | 6.5 | 2026-07-15 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including th… |
| CVE-2026-15779 | MEDIUM | 6.1 | 2026-07-15 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical sys… | |
| CVE-2026-15804 | HIGH | 8.8 | 2026-07-15 | The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the co… | |
| CVE-2026-15809 | HIGH | 7.8 | 2026-07-15 | A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variab… |