Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

450 CVEs · published 2026-07-27 to 2026-07-27

CVEs (450)

Showing 1–25 of 450

CVE ID Severity Patch CVSS Published Description
CVE-2021-32084 NONE — 2026-07-27 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpo…
CVE-2021-32085 NONE — 2026-07-27 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a passwo…
CVE-2021-32086 NONE — 2026-07-27 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (…
CVE-2021-32087 NONE — 2026-07-27 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, wh…
CVE-2021-32088 NONE — 2026-07-27 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. T…
CVE-2025-15662 HIGH Patched 8.6 2026-07-27 The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not …
CVE-2025-50455 CRITICAL 9.1 2026-07-27 SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from u&hellip;
CVE-2025-59172 NONE &mdash; 2026-07-27 Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary &hellip;
CVE-2025-59177 NONE &mdash; 2026-07-27 Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted comma&hellip;
CVE-2025-59178 NONE &mdash; 2026-07-27 Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attac&hellip;
CVE-2025-59180 NONE &mdash; 2026-07-27 Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with k&hellip;
CVE-2025-59181 NONE &mdash; 2026-07-27 Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change &hellip;
CVE-2025-63913 NONE &mdash; 2026-07-27 An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching coun&hellip;
CVE-2026-10082 MEDIUM Patched 6.1 2026-07-27 The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor ro&hellip;
CVE-2026-10600 MEDIUM 4.3 2026-07-27 Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document conten&hellip;
CVE-2026-10682 MEDIUM 6.6 2026-07-27 The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id paramete&hellip;
CVE-2026-10683 LOW 2.4 2026-07-27 In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler gates the write_requested() callback on dw->state&hellip;
CVE-2026-10819 MEDIUM 6.5 2026-07-27 Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated G&hellip;
CVE-2026-12001 NONE &mdash; 2026-07-27 A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5).  Authentication-relat&hellip;
CVE-2026-12255 HIGH Patched 8.1 2026-07-27 The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disa&hellip;
CVE-2026-12383 HIGH 7.5 2026-07-27 A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_cla&hellip;
CVE-2026-12394 CRITICAL Patched 9.8 2026-07-27 The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an&hellip;
CVE-2026-12493 HIGH Patched 7.5 2026-07-27 The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooComm&hellip;
CVE-2026-12495 NONE &mdash; 2026-07-27 Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated a&hellip;
CVE-2026-12982 MEDIUM Patched 6.1 2026-07-27 The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX act&hellip;