Search
26 CVEs · published 2026-07-15 to 2026-07-15, Critical severity
CVEs (26)
Showing 1–25 of 26
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-55652 | CRITICAL | Patched | 9.8 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the c… |
| CVE-2026-54458 | CRITICAL | 9.6 | 2026-07-15 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated re… | |
| CVE-2026-52891 | CRITICAL | Patched | 9.9 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec… |
| CVE-2026-30623 | CRITICAL | 9.8 | 2026-07-15 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configur… | |
| CVE-2026-30618 | CRITICAL | 9.8 | 2026-07-15 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly… | |
| CVE-2026-26718 | CRITICAL | 9.1 | 2026-07-15 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue … | |
| CVE-2025-65720 | CRITICAL | 9.8 | 2026-07-15 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | |
| CVE-2026-54052 | CRITICAL | Patched | 9.9 | 2026-07-15 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled … |
| CVE-2026-52887 | CRITICAL | Patched | 10.0 | 2026-07-15 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-… |
| CVE-2026-51380 | CRITICAL | 9.8 | 2026-07-15 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via … | |
| CVE-2026-49352 | CRITICAL | Patched | 9.8 | 2026-07-15 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/r… |
| CVE-2026-46339 | CRITICAL | Patched | 10.0 | 2026-07-15 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated… |
| CVE-2026-49445 | CRITICAL | Patched | 9.2 | 2026-07-15 | Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envo… |
| CVE-2026-62948 | CRITICAL | Patched | 9.6 | 2026-07-15 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/… |
| CVE-2026-53513 | CRITICAL | Patched | 9.6 | 2026-07-15 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider e… |
| CVE-2026-53512 | CRITICAL | Patched | 9.1 | 2026-07-15 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refre… |
| CVE-2026-14960 | CRITICAL | 9.8 | 2026-07-15 | Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_REA… | |
| CVE-2026-62378 | CRITICAL | Patched | 9.0 | 2026-07-15 | RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and compo… |
| CVE-2026-52843 | CRITICAL | Patched | 9.3 | 2026-07-15 | Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTT… |
| CVE-2026-52842 | CRITICAL | Patched | 9.3 | 2026-07-15 | Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority compon… |
| CVE-2026-50148 | CRITICAL | Patched | 10.0 | 2026-07-15 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase… |
| CVE-2026-44986 | CRITICAL | Patched | 9.9 | 2026-07-15 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations… |
| CVE-2026-61736 | CRITICAL | Patched | 9.3 | 2026-07-15 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api… |
| CVE-2026-43637 | CRITICAL | Patched | 9.1 | 2026-07-15 | Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache directory by supplying a cr… |
| CVE-2026-61451 | CRITICAL | Patched | 9.6 | 2026-07-15 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoin… |