Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 1–25 of 289
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-13230 | NONE | — | 2026-07-15 | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information… | |
| CVE-2026-9770 | NONE | — | 2026-07-15 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to th… | |
| CVE-2026-11851 | NONE | — | 2026-07-15 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authentic… | |
| CVE-2026-13385 | NONE | — | 2026-07-15 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the r… | |
| CVE-2026-13585 | NONE | — | 2026-07-15 | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Bu… | |
| CVE-2026-15029 | NONE | — | 2026-07-15 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrar… | |
| CVE-2026-15030 | NONE | — | 2026-07-15 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond … | |
| CVE-2026-8919 | NONE | — | 2026-07-15 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a cra… | |
| CVE-2026-8920 | NONE | — | 2026-07-15 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file o… | |
| CVE-2026-11579 | MEDIUM | Patched | 5.3 | 2026-07-15 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a f… |
| CVE-2026-11580 | MEDIUM | Patched | 5.5 | 2026-07-15 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, all… |
| CVE-2026-12281 | HIGH | Patched | 8.1 | 2026-07-15 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carr… |
| CVE-2026-12512 | HIGH | Patched | 8.6 | 2026-07-15 | The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated atta… |
| CVE-2026-42936 | HIGH | 7.8 | 2026-07-15 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code m… | |
| CVE-2026-14251 | HIGH | 7.7 | 2026-07-15 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped … | |
| CVE-2026-15583 | HIGH | 8.6 | 2026-07-15 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by su… | |
| CVE-2026-15804 | HIGH | 8.8 | 2026-07-15 | The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the co… | |
| CVE-2026-57831 | NONE | — | 2026-07-15 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthentic… | |
| CVE-2026-57832 | NONE | — | 2026-07-15 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection. | |
| CVE-2026-35152 | HIGH | Patched | 8.8 | 2026-07-15 | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are inc… |
| CVE-2026-49501 | MEDIUM | Patched | 6.7 | 2026-07-15 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged a… |
| CVE-2026-56287 | HIGH | Patched | 8.1 | 2026-07-15 | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sort… |
| CVE-2026-57821 | HIGH | Patched | 8.1 | 2026-07-15 | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is c… |
| CVE-2026-57833 | NONE | — | 2026-07-15 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relatio… | |
| CVE-2026-58077 | NONE | — | 2026-07-15 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A special… |