Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

73 CVEs · published 2026-07-27 to 2026-07-27, Medium severity

CVEs (73)

Showing 1–25 of 73

CVE ID Severity Patch CVSS Published Description
CVE-2026-65448 MEDIUM 6.5 2026-07-27 Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.
CVE-2026-65445 MEDIUM 6.5 2026-07-27 Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
CVE-2026-53668 MEDIUM Patched 6.9 2026-07-27 React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker co&hellip;
CVE-2026-53667 MEDIUM Patched 6.9 2026-07-27 React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. Th&hellip;
CVE-2026-53666 MEDIUM Patched 6.1 2026-07-27 React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspe&hellip;
CVE-2026-59728 MEDIUM Patched 4.3 2026-07-27 Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts a&hellip;
CVE-2026-66018 MEDIUM 6.5 2026-07-27 Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while r&hellip;
CVE-2026-65925 MEDIUM 6.5 2026-07-27 A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
CVE-2026-65924 MEDIUM 6.5 2026-07-27 JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous acce&hellip;
CVE-2026-65923 MEDIUM Patched 6.8 2026-07-27 A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side &hellip;
CVE-2026-65618 MEDIUM 6.5 2026-07-27 Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposin&hellip;
CVE-2026-66757 MEDIUM 5.5 2026-07-27 A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysiz&hellip;
CVE-2026-66031 MEDIUM 5.4 2026-07-27 Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and Jav&hellip;
CVE-2026-10682 MEDIUM 6.6 2026-07-27 The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id paramete&hellip;
CVE-2026-66030 MEDIUM 5.4 2026-07-27 Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and Ja&hellip;
CVE-2026-66029 MEDIUM 5.4 2026-07-27 Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and Jav&hellip;
CVE-2026-66028 MEDIUM 6.7 2026-07-27 Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client a&hellip;
CVE-2026-48052 MEDIUM Patched 5.4 2026-07-27 Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename &hellip;
CVE-2026-17570 MEDIUM 4.3 2026-07-27 Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via&hellip;
CVE-2026-66391 MEDIUM Patched 6.5 2026-07-27 Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 &hellip;
CVE-2026-66390 MEDIUM Patched 6.1 2026-07-27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9&hellip;
CVE-2026-17531 MEDIUM 5.0 2026-07-27 A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the compo&hellip;
CVE-2026-66399 MEDIUM Patched 6.5 2026-07-27 phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to&hellip;
CVE-2026-51298 MEDIUM 6.2 2026-07-27 sqlite 3.41 is vulnerable to use after free in the JSON extraction function. After releasing JsonParse object memory via jsonParseFree(), the program still accesses interna&hellip;
CVE-2026-17530 MEDIUM 6.3 2026-07-27 A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/c&hellip;