Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

95 CVEs · published 2026-07-15 to 2026-07-15, High severity

CVEs (95)

Showing 1–25 of 95

CVE ID Severity Patch CVSS Published Description
CVE-2026-55234 HIGH Patched 8.5 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissio…
CVE-2026-52890 HIGH Patched 7.1 2026-07-15 Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP met…
CVE-2026-48795 HIGH Patched 8.6 2026-07-15 AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart …
CVE-2026-45313 HIGH Patched 7.7 2026-07-15 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores a…
CVE-2026-36590 HIGH 7.5 2026-07-15 An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component
CVE-2026-62312 HIGH Patched 8.8 2026-07-15 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by co…
CVE-2026-59950 HIGH Patched 8.1 2026-07-15 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_serve…
CVE-2026-49353 HIGH 7.5 2026-07-15 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to pro…
CVE-2026-52870 HIGH Patched 7.6 2026-07-15 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.exper…
CVE-2026-52869 HIGH Patched 7.1 2026-07-15 The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp…
CVE-2026-50144 HIGH 7.1 2026-07-15 ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows…
CVE-2026-45738 HIGH Patched 7.3 2026-07-15 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argoc…
CVE-2026-40957 HIGH Patched 7.5 2026-07-15 o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it t…
CVE-2026-40952 HIGH Patched 7.8 2026-07-15 CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the c…
CVE-2026-62351 HIGH Patched 7.5 2026-07-15 TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMs…
CVE-2026-62350 HIGH Patched 7.2 2026-07-15 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared…
CVE-2026-62349 HIGH Patched 8.3 2026-07-15 TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks spac…
CVE-2026-46485 HIGH Patched 8.2 2026-07-15 Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes …
CVE-2026-15895 HIGH Patched 7.8 2026-07-15 OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted …
CVE-2026-12997 HIGH 7.5 2026-07-15 The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter.…
CVE-2026-62389 HIGH Patched 7.5 2026-07-15 ws before 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches maxFragments, allowing att…
CVE-2026-59258 HIGH Patched 8.3 2026-07-15 immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles with…
CVE-2026-59255 HIGH Patched 7.1 2026-07-15 BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to mo…
CVE-2026-58660 HIGH Patched 8.1 2026-07-15 Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the att…
CVE-2026-58659 HIGH Patched 7.8 2026-07-15 PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-cont…