Search
90 CVEs · published 2026-07-27 to 2026-07-27, High severity
CVEs (90)
Showing 1–25 of 90
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-66473 | HIGH | 7.5 | 2026-07-27 | Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. | |
| CVE-2026-65447 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | |
| CVE-2026-65446 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | |
| CVE-2026-65443 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. | |
| CVE-2026-65442 | HIGH | 7.2 | 2026-07-27 | Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. | |
| CVE-2026-65441 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | |
| CVE-2026-65440 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | |
| CVE-2026-65439 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | |
| CVE-2026-65438 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | |
| CVE-2026-65437 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | |
| CVE-2026-61957 | HIGH | 7.1 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. | |
| CVE-2026-61953 | HIGH | 7.2 | 2026-07-27 | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | |
| CVE-2026-43776 | HIGH | Patched | 7.8 | 2026-07-27 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a malicio… |
| CVE-2026-43755 | HIGH | Patched | 7.0 | 2026-07-27 | A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges. |
| CVE-2026-43749 | HIGH | Patched | 7.8 | 2026-07-27 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Taho… |
| CVE-2026-43723 | HIGH | Patched | 7.8 | 2026-07-27 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, … |
| CVE-2026-43698 | HIGH | Patched | 7.8 | 2026-07-27 | An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain ro… |
| CVE-2026-43693 | HIGH | Patched | 7.0 | 2026-07-27 | A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain … |
| CVE-2026-39875 | HIGH | Patched | 7.8 | 2026-07-27 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be a… |
| CVE-2026-39874 | HIGH | Patched | 7.8 | 2026-07-27 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be a… |
| CVE-2026-66015 | HIGH | 7.2 | 2026-07-27 | An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant tempora… | |
| CVE-2026-66014 | HIGH | 8.8 | 2026-07-27 | JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges … | |
| CVE-2026-65922 | HIGH | 7.1 | 2026-07-27 | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas u… | |
| CVE-2026-65921 | HIGH | 8.8 | 2026-07-27 | A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location. | |
| CVE-2026-65617 | HIGH | 8.8 | 2026-07-27 | A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific rep… |