Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

90 CVEs · published 2026-07-27 to 2026-07-27, High severity

CVEs (90)

Showing 1–25 of 90

CVE ID Severity Patch CVSS Published Description
CVE-2026-66473 HIGH 7.5 2026-07-27 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-65447 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
CVE-2026-65446 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
CVE-2026-65443 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65442 HIGH 7.2 2026-07-27 Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-65441 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
CVE-2026-65440 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
CVE-2026-65439 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
CVE-2026-65438 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
CVE-2026-65437 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
CVE-2026-61957 HIGH 7.1 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61953 HIGH 7.2 2026-07-27 Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-43776 HIGH Patched 7.8 2026-07-27 A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a malicio&hellip;
CVE-2026-43755 HIGH Patched 7.0 2026-07-27 A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
CVE-2026-43749 HIGH Patched 7.8 2026-07-27 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Taho&hellip;
CVE-2026-43723 HIGH Patched 7.8 2026-07-27 A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, &hellip;
CVE-2026-43698 HIGH Patched 7.8 2026-07-27 An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain ro&hellip;
CVE-2026-43693 HIGH Patched 7.0 2026-07-27 A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain &hellip;
CVE-2026-39875 HIGH Patched 7.8 2026-07-27 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be a&hellip;
CVE-2026-39874 HIGH Patched 7.8 2026-07-27 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be a&hellip;
CVE-2026-66015 HIGH 7.2 2026-07-27 An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant tempora&hellip;
CVE-2026-66014 HIGH 8.8 2026-07-27 JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges &hellip;
CVE-2026-65922 HIGH 7.1 2026-07-27 An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas u&hellip;
CVE-2026-65921 HIGH 8.8 2026-07-27 A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
CVE-2026-65617 HIGH 8.8 2026-07-27 A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific rep&hellip;