Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 1–25 of 289
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63175 | NONE | — | 2026-07-15 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Captu… | |
| CVE-2026-55445 | NONE | Patched | — | 2026-07-15 | Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts ch… |
| CVE-2026-55576 | NONE | — | 2026-07-15 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled g… | |
| CVE-2026-53446 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js are stored from user input and later fetched by serve… |
| CVE-2026-52893 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when … |
| CVE-2026-53444 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/mode… |
| CVE-2026-53445 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board… |
| CVE-2026-49279 | NONE | — | 2026-07-15 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSo… | |
| CVE-2026-56679 | NONE | Patched | — | 2026-07-15 | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, all… |
| CVE-2026-50030 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/da… |
| CVE-2026-50124 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasour… |
| CVE-2026-49867 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit TemplateManageRequest.s… |
| CVE-2026-46684 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values … |
| CVE-2026-45419 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesTo… |
| CVE-2026-45533 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bu… |
| CVE-2026-45534 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configur… |
| CVE-2026-45535 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries su… |
| CVE-2026-45320 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transF… |
| CVE-2026-45417 | NONE | Patched | — | 2026-07-15 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into g… |
| CVE-2026-54443 | NONE | Patched | — | 2026-07-15 | Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values befor… |
| CVE-2026-49987 | NONE | Patched | — | 2026-07-15 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly … |
| CVE-2026-49988 | NONE | Patched | — | 2026-07-15 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and… |
| CVE-2026-46421 | NONE | Patched | — | 2026-07-15 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for tha… |
| CVE-2026-8055 | NONE | — | 2026-07-15 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a reservation duplicate of CVE-2026-48866. Notes: All … | |
| CVE-2026-50562 | NONE | — | 2026-07-15 | FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .g… |