Search
450 CVEs · published 2026-07-27 to 2026-07-27
CVEs (450)
Showing 1–25 of 450
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51565 | NONE | — | 2026-07-27 | Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the act… | |
| CVE-2025-63913 | NONE | — | 2026-07-27 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching coun… | |
| CVE-2026-59240 | NONE | — | 2026-07-27 | The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. Th… | |
| CVE-2026-55685 | NONE | Patched | — | 2026-07-27 | React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy loa… |
| CVE-2026-53669 | NONE | Patched | — | 2026-07-27 | React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a fol… |
| CVE-2026-51077 | NONE | — | 2026-07-27 | SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component | |
| CVE-2026-51078 | NONE | — | 2026-07-27 | An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component | |
| CVE-2026-51564 | NONE | — | 2026-07-27 | An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request. | |
| CVE-2021-32085 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a passwo… | |
| CVE-2021-32086 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (… | |
| CVE-2021-32087 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, wh… | |
| CVE-2021-32088 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. T… | |
| CVE-2021-32084 | NONE | — | 2026-07-27 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpo… | |
| CVE-2026-66824 | NONE | — | 2026-07-27 | A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline Jav… | |
| CVE-2026-66825 | NONE | — | 2026-07-27 | Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, we… | |
| CVE-2026-64769 | NONE | Patched | — | 2026-07-27 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS … |
| CVE-2026-64770 | NONE | Patched | — | 2026-07-27 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS … |
| CVE-2026-64771 | NONE | Patched | — | 2026-07-27 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS … |
| CVE-2026-64772 | NONE | Patched | — | 2026-07-27 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.… |
| CVE-2026-64774 | NONE | Patched | — | 2026-07-27 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26… |
| CVE-2026-64775 | NONE | Patched | — | 2026-07-27 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS… |
| CVE-2026-64776 | NONE | Patched | — | 2026-07-27 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kern… |
| CVE-2026-64783 | NONE | Patched | — | 2026-07-27 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS… |
| CVE-2026-64755 | NONE | Patched | — | 2026-07-27 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to access sensitive user data. |
| CVE-2026-64757 | NONE | Patched | — | 2026-07-27 | A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watch… |