Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 1–25 of 289
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9770 | NONE | — | 2026-07-15 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to th… | |
| CVE-2026-9007 | NONE | — | 2026-07-15 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (… | |
| CVE-2026-8920 | NONE | — | 2026-07-15 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file o… | |
| CVE-2026-8919 | NONE | — | 2026-07-15 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a cra… | |
| CVE-2026-8281 | NONE | — | 2026-07-15 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-8055 | NONE | — | 2026-07-15 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a reservation duplicate of CVE-2026-48866. Notes: All … | |
| CVE-2026-63175 | NONE | — | 2026-07-15 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Captu… | |
| CVE-2026-62948 | CRITICAL | Patched | 9.6 | 2026-07-15 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/… |
| CVE-2026-62947 | MEDIUM | Patched | 4.9 | 2026-07-15 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus… |
| CVE-2026-62843 | MEDIUM | Patched | 6.8 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browse… |
| CVE-2026-62685 | HIGH | Patched | 8.1 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser buil… |
| CVE-2026-62683 | LOW | Patched | 3.1 | 2026-07-15 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can … |
| CVE-2026-62389 | HIGH | Patched | 7.5 | 2026-07-15 | ws before 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches maxFragments, allowing att… |
| CVE-2026-62378 | CRITICAL | Patched | 9.0 | 2026-07-15 | RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and compo… |
| CVE-2026-62361 | MEDIUM | Patched | 5.5 | 2026-07-15 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled quer… |
| CVE-2026-62355 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could… |
| CVE-2026-62353 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailin… |
| CVE-2026-62351 | HIGH | Patched | 7.5 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMs… |
| CVE-2026-62350 | HIGH | Patched | 7.2 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared… |
| CVE-2026-62349 | HIGH | Patched | 8.3 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks spac… |
| CVE-2026-62348 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run K… |
| CVE-2026-62314 | MEDIUM | Patched | 5.8 | 2026-07-15 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/c… |
| CVE-2026-62312 | HIGH | Patched | 8.8 | 2026-07-15 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by co… |
| CVE-2026-62294 | NONE | Patched | — | 2026-07-15 | Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks,… |
| CVE-2026-62287 | NONE | — | 2026-07-15 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61873. Reason: This candidate is a duplicate of CVE-2026-61873. Notes: All CVE users sh… |