Search
23 CVEs · published 2026-07-27 to 2026-07-27, Critical severity
CVEs (23)
Showing 1–23 of 23
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-55579 | CRITICAL | Patched | 9.8 | 2026-07-27 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-51… |
| CVE-2026-48030 | CRITICAL | Patched | 9.9 | 2026-07-27 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action h… |
| CVE-2026-63077 | CRITICAL | Patched | 9.8 | 2026-07-27 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
| CVE-2026-17191 | CRITICAL | 9.1 | 2026-07-27 | An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may resul… | |
| CVE-2026-66395 | CRITICAL | 9.6 | 2026-07-27 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by … | |
| CVE-2026-51303 | CRITICAL | 9.8 | 2026-07-27 | A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3Ex… | |
| CVE-2026-16812 | CRITICAL | Patched | 10.0 | 2026-07-27 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. … |
| CVE-2025-50455 | CRITICAL | 9.1 | 2026-07-27 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from u… | |
| CVE-2026-59550 | CRITICAL | 9.3 | 2026-07-27 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | |
| CVE-2026-59549 | CRITICAL | 9.3 | 2026-07-27 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | |
| CVE-2026-59538 | CRITICAL | 9.3 | 2026-07-27 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | |
| CVE-2026-59533 | CRITICAL | 9.3 | 2026-07-27 | Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | |
| CVE-2026-59527 | CRITICAL | 9.3 | 2026-07-27 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | |
| CVE-2026-61511 | CRITICAL | 9.8 | 2026-07-27 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that a… | |
| CVE-2026-58662 | CRITICAL | Patched | 9.1 | 2026-07-27 | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users… |
| CVE-2026-58023 | CRITICAL | Patched | 9.1 | 2026-07-27 | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, wh… |
| CVE-2026-55971 | CRITICAL | Patched | 9.8 | 2026-07-27 | Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.… |
| CVE-2026-48144 | CRITICAL | Patched | 9.1 | 2026-07-27 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommend… |
| CVE-2026-14289 | CRITICAL | Patched | 9.0 | 2026-07-27 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a crypto… |
| CVE-2026-13714 | CRITICAL | Patched | 9.8 | 2026-07-27 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated onl… |
| CVE-2026-13597 | CRITICAL | 9.1 | 2026-07-27 | The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated log… | |
| CVE-2026-13332 | CRITICAL | Patched | 9.1 | 2026-07-27 | The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthentic… |
| CVE-2026-12394 | CRITICAL | Patched | 9.8 | 2026-07-27 | The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an… |