Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 1–25 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-63175 | NONE | — | 2026-07-15 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Captu… | |
| CVE-2026-62314 | MEDIUM | Patched | 5.8 | 2026-07-15 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/c… |
| CVE-2026-55652 | CRITICAL | Patched | 9.8 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the c… |
| CVE-2026-55576 | NONE | — | 2026-07-15 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled g… | |
| CVE-2026-55445 | NONE | Patched | — | 2026-07-15 | Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts ch… |
| CVE-2026-55234 | HIGH | Patched | 8.5 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissio… |
| CVE-2026-54458 | CRITICAL | 9.6 | 2026-07-15 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated re… | |
| CVE-2026-53447 | MEDIUM | Patched | 6.5 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board exp… |
| CVE-2026-53446 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js are stored from user input and later fetched by serve… |
| CVE-2026-53445 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board… |
| CVE-2026-53444 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/mode… |
| CVE-2026-52893 | NONE | Patched | — | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when … |
| CVE-2026-52892 | MEDIUM | Patched | 6.5 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of… |
| CVE-2026-52891 | CRITICAL | Patched | 9.9 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec… |
| CVE-2026-52890 | HIGH | Patched | 7.1 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP met… |
| CVE-2026-50183 | MEDIUM | 4.7 | 2026-07-15 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the s… | |
| CVE-2026-50182 | MEDIUM | 6.1 | 2026-07-15 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. Th… | |
| CVE-2026-49279 | NONE | — | 2026-07-15 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSo… | |
| CVE-2026-48795 | HIGH | Patched | 8.6 | 2026-07-15 | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart … |
| CVE-2026-45313 | HIGH | Patched | 7.7 | 2026-07-15 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores a… |
| CVE-2026-38974 | MEDIUM | 5.3 | 2026-07-15 | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. | |
| CVE-2026-38755 | LOW | 2.9 | 2026-07-15 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |
| CVE-2026-38754 | MEDIUM | 5.1 | 2026-07-15 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |
| CVE-2026-38752 | LOW | 2.9 | 2026-07-15 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | |
| CVE-2026-36590 | HIGH | 7.5 | 2026-07-15 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component |