Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

289 CVEs · published 2026-07-15 to 2026-07-15

CVEs (289)

Showing 1–25 of 289

CVE ID Severity Patch CVSS Published Description
CVE-2026-13230 NONE — 2026-07-15 An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information…
CVE-2026-9770 NONE — 2026-07-15 Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to th…
CVE-2026-11851 NONE — 2026-07-15 Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authentic…
CVE-2026-13385 NONE — 2026-07-15 An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the r…
CVE-2026-13585 NONE — 2026-07-15 Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Bu…
CVE-2026-15029 NONE — 2026-07-15 Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrar…
CVE-2026-15030 NONE — 2026-07-15 Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond …
CVE-2026-8919 NONE — 2026-07-15 Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a cra…
CVE-2026-8920 NONE — 2026-07-15 Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file o…
CVE-2026-11579 MEDIUM Patched 5.3 2026-07-15 The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a f…
CVE-2026-11580 MEDIUM Patched 5.5 2026-07-15 The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, all…
CVE-2026-12281 HIGH Patched 8.1 2026-07-15 The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carr…
CVE-2026-12512 HIGH Patched 8.6 2026-07-15 The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated atta…
CVE-2026-42936 HIGH 7.8 2026-07-15 The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code m…
CVE-2026-14251 HIGH 7.7 2026-07-15 A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped …
CVE-2026-15583 HIGH 8.6 2026-07-15 A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by su…
CVE-2026-15804 HIGH 8.8 2026-07-15 The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the co…
CVE-2026-57831 NONE — 2026-07-15 Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthentic…
CVE-2026-57832 NONE &mdash; 2026-07-15 Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
CVE-2026-35152 HIGH Patched 8.8 2026-07-15 A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are inc&hellip;
CVE-2026-49501 MEDIUM Patched 6.7 2026-07-15 Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged a&hellip;
CVE-2026-56287 HIGH Patched 8.1 2026-07-15 A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sort&hellip;
CVE-2026-57821 HIGH Patched 8.1 2026-07-15 A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is c&hellip;
CVE-2026-57833 NONE &mdash; 2026-07-15 Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relatio&hellip;
CVE-2026-58077 NONE &mdash; 2026-07-15 Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A special&hellip;