Search
450 CVEs · published 2026-07-27 to 2026-07-27
EOL hidden · Show all products
CVEs (450)
Showing 1–25 of 450
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-66473 | HIGH | 7.5 | 2026-07-27 | Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. | |
| CVE-2026-65448 | MEDIUM | 6.5 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. | |
| CVE-2026-65447 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | |
| CVE-2026-65446 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | |
| CVE-2026-65445 | MEDIUM | 6.5 | 2026-07-27 | Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions. | |
| CVE-2026-65443 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. | |
| CVE-2026-65442 | HIGH | 7.2 | 2026-07-27 | Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. | |
| CVE-2026-65441 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | |
| CVE-2026-65440 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | |
| CVE-2026-65439 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | |
| CVE-2026-65438 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | |
| CVE-2026-65437 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | |
| CVE-2026-61957 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | |
| CVE-2026-61953 | HIGH | 7.2 | 2026-07-27 | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | |
| CVE-2026-51565 | NONE | — | 2026-07-27 | Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the act… | |
| CVE-2025-63913 | NONE | — | 2026-07-27 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching coun… | |
| CVE-2026-59240 | NONE | — | 2026-07-27 | The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. Th… | |
| CVE-2026-55685 | NONE | Patched | — | 2026-07-27 | React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy loa… |
| CVE-2026-53669 | NONE | Patched | — | 2026-07-27 | React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a fol… |
| CVE-2026-53668 | MEDIUM | Patched | 6.9 | 2026-07-27 | React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker co… |
| CVE-2026-53667 | MEDIUM | Patched | 6.9 | 2026-07-27 | React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. Th… |
| CVE-2026-53666 | MEDIUM | Patched | 6.1 | 2026-07-27 | React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspe… |
| CVE-2026-51564 | NONE | — | 2026-07-27 | An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request. | |
| CVE-2026-51078 | NONE | — | 2026-07-27 | An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component | |
| CVE-2026-51077 | NONE | — | 2026-07-27 | SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component |