Search
73 CVEs · published 2026-07-27 to 2026-07-27, Medium severity
CVEs (73)
Showing 1–25 of 73
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-65448 | MEDIUM | 6.5 | 2026-07-27 | Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. | |
| CVE-2026-65445 | MEDIUM | 6.5 | 2026-07-27 | Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions. | |
| CVE-2026-53668 | MEDIUM | Patched | 6.9 | 2026-07-27 | React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker co… |
| CVE-2026-53667 | MEDIUM | Patched | 6.9 | 2026-07-27 | React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. Th… |
| CVE-2026-53666 | MEDIUM | Patched | 6.1 | 2026-07-27 | React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspe… |
| CVE-2026-59728 | MEDIUM | Patched | 4.3 | 2026-07-27 | Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts a… |
| CVE-2026-66018 | MEDIUM | 6.5 | 2026-07-27 | Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while r… | |
| CVE-2026-65925 | MEDIUM | 6.5 | 2026-07-27 | A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response. | |
| CVE-2026-65924 | MEDIUM | 6.5 | 2026-07-27 | JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous acce… | |
| CVE-2026-65923 | MEDIUM | Patched | 6.8 | 2026-07-27 | A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side … |
| CVE-2026-65618 | MEDIUM | 6.5 | 2026-07-27 | Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposin… | |
| CVE-2026-66757 | MEDIUM | 5.5 | 2026-07-27 | A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysiz… | |
| CVE-2026-66031 | MEDIUM | 5.4 | 2026-07-27 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and Jav… | |
| CVE-2026-10682 | MEDIUM | 6.6 | 2026-07-27 | The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id paramete… | |
| CVE-2026-66030 | MEDIUM | 5.4 | 2026-07-27 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and Ja… | |
| CVE-2026-66029 | MEDIUM | 5.4 | 2026-07-27 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and Jav… | |
| CVE-2026-66028 | MEDIUM | 6.7 | 2026-07-27 | Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client a… | |
| CVE-2026-48052 | MEDIUM | Patched | 5.4 | 2026-07-27 | Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename … |
| CVE-2026-17570 | MEDIUM | 4.3 | 2026-07-27 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via… | |
| CVE-2026-66391 | MEDIUM | Patched | 6.5 | 2026-07-27 | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 … |
| CVE-2026-66390 | MEDIUM | Patched | 6.1 | 2026-07-27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9… |
| CVE-2026-17531 | MEDIUM | 5.0 | 2026-07-27 | A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the compo… | |
| CVE-2026-66399 | MEDIUM | Patched | 6.5 | 2026-07-27 | phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to… |
| CVE-2026-51298 | MEDIUM | 6.2 | 2026-07-27 | sqlite 3.41 is vulnerable to use after free in the JSON extraction function. After releasing JsonParse object memory via jsonParseFree(), the program still accesses interna… | |
| CVE-2026-17530 | MEDIUM | 6.3 | 2026-07-27 | A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/c… |