Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

289 CVEs · published 2026-07-15 to 2026-07-15

CVEs (289)

Showing 1–25 of 289

CVE ID Severity Patch CVSS Published Description
CVE-2026-52887 CRITICAL Patched 10.0 2026-07-15 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-…
CVE-2026-46339 CRITICAL Patched 10.0 2026-07-15 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated…
CVE-2026-50148 CRITICAL Patched 10.0 2026-07-15 Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase…
CVE-2026-56699 CRITICAL Patched 10.0 2026-07-15 Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON o…
CVE-2026-52891 CRITICAL Patched 9.9 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec…
CVE-2026-54052 CRITICAL Patched 9.9 2026-07-15 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled …
CVE-2026-44986 CRITICAL Patched 9.9 2026-07-15 Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations…
CVE-2026-55652 CRITICAL Patched 9.8 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the c…
CVE-2026-30618 CRITICAL 9.8 2026-07-15 xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly…
CVE-2026-30623 CRITICAL 9.8 2026-07-15 LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configur…
CVE-2025-65720 CRITICAL 9.8 2026-07-15 An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.
CVE-2026-51380 CRITICAL 9.8 2026-07-15 Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via …
CVE-2026-49352 CRITICAL Patched 9.8 2026-07-15 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/r…
CVE-2026-14960 CRITICAL 9.8 2026-07-15 Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_REA…
CVE-2026-54458 CRITICAL 9.6 2026-07-15 WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated re…
CVE-2026-62948 CRITICAL Patched 9.6 2026-07-15 OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/…
CVE-2026-53513 CRITICAL Patched 9.6 2026-07-15 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider e…
CVE-2026-61451 CRITICAL Patched 9.6 2026-07-15 The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoin…
CVE-2026-46684 NONE Patched — 2026-07-15 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values …
CVE-2026-13385 NONE — 2026-07-15 An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the r…
CVE-2026-55445 NONE Patched — 2026-07-15 Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts ch…
CVE-2026-46421 NONE Patched — 2026-07-15 The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for tha…
CVE-2026-50562 NONE — 2026-07-15 FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .g…
CVE-2026-52842 CRITICAL Patched 9.3 2026-07-15 Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority compon…
CVE-2026-52843 CRITICAL Patched 9.3 2026-07-15 Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTT…