Search
450 CVEs · published 2026-07-27 to 2026-07-27
CVEs (450)
Showing 1–25 of 450
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32084 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpo… | |
| CVE-2021-32085 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a passwo… | |
| CVE-2021-32086 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (… | |
| CVE-2021-32087 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, wh… | |
| CVE-2021-32088 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. T… | |
| CVE-2025-15662 | HIGH | Patched | 8.6 | 2026-07-27 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not … |
| CVE-2025-50455 | CRITICAL | 9.1 | 2026-07-27 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from u… | |
| CVE-2025-59172 | NONE | — | 2026-07-27 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary … | |
| CVE-2025-59177 | NONE | — | 2026-07-27 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted comma… | |
| CVE-2025-59178 | NONE | — | 2026-07-27 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attac… | |
| CVE-2025-59180 | NONE | — | 2026-07-27 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with k… | |
| CVE-2025-59181 | NONE | — | 2026-07-27 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change … | |
| CVE-2025-63913 | NONE | — | 2026-07-27 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching coun… | |
| CVE-2026-10082 | MEDIUM | Patched | 6.1 | 2026-07-27 | The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor ro… |
| CVE-2026-10600 | MEDIUM | 4.3 | 2026-07-27 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document conten… | |
| CVE-2026-10682 | MEDIUM | 6.6 | 2026-07-27 | The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id paramete… | |
| CVE-2026-10683 | LOW | 2.4 | 2026-07-27 | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler gates the write_requested() callback on dw->state… | |
| CVE-2026-10819 | MEDIUM | 6.5 | 2026-07-27 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated G… | |
| CVE-2026-12001 | NONE | — | 2026-07-27 | A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-relat… | |
| CVE-2026-12255 | HIGH | Patched | 8.1 | 2026-07-27 | The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disa… |
| CVE-2026-12383 | HIGH | 7.5 | 2026-07-27 | A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_cla… | |
| CVE-2026-12394 | CRITICAL | Patched | 9.8 | 2026-07-27 | The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an… |
| CVE-2026-12493 | HIGH | Patched | 7.5 | 2026-07-27 | The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooComm… |
| CVE-2026-12495 | NONE | — | 2026-07-27 | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated a… | |
| CVE-2026-12982 | MEDIUM | Patched | 6.1 | 2026-07-27 | The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX act… |