Search
95 CVEs · published 2026-07-15 to 2026-07-15, High severity
CVEs (95)
Showing 1–25 of 95
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-55234 | HIGH | Patched | 8.5 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissio… |
| CVE-2026-52890 | HIGH | Patched | 7.1 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP met… |
| CVE-2026-48795 | HIGH | Patched | 8.6 | 2026-07-15 | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart … |
| CVE-2026-45313 | HIGH | Patched | 7.7 | 2026-07-15 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores a… |
| CVE-2026-36590 | HIGH | 7.5 | 2026-07-15 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component | |
| CVE-2026-62312 | HIGH | Patched | 8.8 | 2026-07-15 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by co… |
| CVE-2026-59950 | HIGH | Patched | 8.1 | 2026-07-15 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_serve… |
| CVE-2026-49353 | HIGH | 7.5 | 2026-07-15 | 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to pro… | |
| CVE-2026-52870 | HIGH | Patched | 7.6 | 2026-07-15 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.exper… |
| CVE-2026-52869 | HIGH | Patched | 7.1 | 2026-07-15 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp… |
| CVE-2026-50144 | HIGH | 7.1 | 2026-07-15 | ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows… | |
| CVE-2026-45738 | HIGH | Patched | 7.3 | 2026-07-15 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argoc… |
| CVE-2026-40957 | HIGH | Patched | 7.5 | 2026-07-15 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it t… |
| CVE-2026-40952 | HIGH | Patched | 7.8 | 2026-07-15 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the c… |
| CVE-2026-62351 | HIGH | Patched | 7.5 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMs… |
| CVE-2026-62350 | HIGH | Patched | 7.2 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared… |
| CVE-2026-62349 | HIGH | Patched | 8.3 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks spac… |
| CVE-2026-46485 | HIGH | Patched | 8.2 | 2026-07-15 | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes … |
| CVE-2026-15895 | HIGH | Patched | 7.8 | 2026-07-15 | OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted … |
| CVE-2026-12997 | HIGH | 7.5 | 2026-07-15 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter.… | |
| CVE-2026-62389 | HIGH | Patched | 7.5 | 2026-07-15 | ws before 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches maxFragments, allowing att… |
| CVE-2026-59258 | HIGH | Patched | 8.3 | 2026-07-15 | immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles with… |
| CVE-2026-59255 | HIGH | Patched | 7.1 | 2026-07-15 | BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to mo… |
| CVE-2026-58660 | HIGH | Patched | 8.1 | 2026-07-15 | Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the att… |
| CVE-2026-58659 | HIGH | Patched | 7.8 | 2026-07-15 | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-cont… |