Search
68 CVEs · published 2026-07-15 to 2026-07-15, Medium severity
CVEs (68)
Showing 1–25 of 68
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-62314 | MEDIUM | Patched | 5.8 | 2026-07-15 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/c… |
| CVE-2026-53447 | MEDIUM | Patched | 6.5 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board exp… |
| CVE-2026-52892 | MEDIUM | Patched | 6.5 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of… |
| CVE-2026-50183 | MEDIUM | 4.7 | 2026-07-15 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the s… | |
| CVE-2026-50182 | MEDIUM | 6.1 | 2026-07-15 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. Th… | |
| CVE-2026-38974 | MEDIUM | 5.3 | 2026-07-15 | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. | |
| CVE-2026-38754 | MEDIUM | 5.1 | 2026-07-15 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |
| CVE-2026-26719 | MEDIUM | 6.1 | 2026-07-15 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script | |
| CVE-2026-62361 | MEDIUM | Patched | 5.5 | 2026-07-15 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled quer… |
| CVE-2026-56678 | MEDIUM | Patched | 6.4 | 2026-07-15 | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled regi… |
| CVE-2026-55608 | MEDIUM | Patched | 4.2 | 2026-07-15 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI… |
| CVE-2026-55410 | MEDIUM | Patched | 6.7 | 2026-07-15 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored… |
| CVE-2026-55399 | MEDIUM | Patched | 4.3 | 2026-07-15 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create… |
| CVE-2026-52888 | MEDIUM | Patched | 6.8 | 2026-07-15 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection… |
| CVE-2026-38753 | MEDIUM | 4.9 | 2026-07-15 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | |
| CVE-2026-33684 | MEDIUM | Patched | 5.3 | 2026-07-15 | WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows an… |
| CVE-2026-33445 | MEDIUM | Patched | 5.9 | 2026-07-15 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel proto… |
| CVE-2026-56743 | MEDIUM | Patched | 5.4 | 2026-07-15 | Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without… |
| CVE-2026-56742 | MEDIUM | Patched | 5.9 | 2026-07-15 | Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to creat… |
| CVE-2026-45737 | MEDIUM | Patched | 6.3 | 2026-07-15 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret va… |
| CVE-2026-40953 | MEDIUM | Patched | 4.4 | 2026-07-15 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can… |
| CVE-2026-33443 | MEDIUM | Patched | 5.9 | 2026-07-15 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can … |
| CVE-2026-62947 | MEDIUM | Patched | 4.9 | 2026-07-15 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus… |
| CVE-2026-62355 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could… |
| CVE-2026-62353 | MEDIUM | Patched | 5.4 | 2026-07-15 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailin… |