| CVE-2026-17039 |
Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm authorization check performed by enrollment path |
24.07.2026 |
|
| CVE-2026-64208 |
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks |
24.07.2026 |
|
| CVE-2026-64209 |
phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config |
24.07.2026 |
|
| CVE-2026-64210 |
net/mlx5e: xsk: Fix unlocked writing to ICOSQ |
24.07.2026 |
|
| CVE-2026-64211 |
srcu: Don't queue workqueue handlers to never-online CPUs |
24.07.2026 |
|
| CVE-2026-64212 |
wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it |
24.07.2026 |
|
| CVE-2026-64213 |
hwmon: (lm90) Add lock protection to lm90_alert |
24.07.2026 |
|
| CVE-2026-64214 |
powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() |
24.07.2026 |
|
| CVE-2026-64215 |
drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table |
24.07.2026 |
|
| CVE-2026-64216 |
netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() |
24.07.2026 |
|
| CVE-2026-64217 |
netfs: Fix overrun check in netfs_extract_user_iter() |
24.07.2026 |
|
| CVE-2026-64218 |
batman-adv: bla: fix report_work leak on backbone_gw purge |
24.07.2026 |
|
| CVE-2026-64219 |
drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async |
24.07.2026 |
|
| CVE-2026-64220 |
device property: set fwnode->secondary to NULL in fwnode_init() |
24.07.2026 |
|
| CVE-2026-64221 |
spi: ti-qspi: fix use-after-free after DMA setup failure |
24.07.2026 |
|
| CVE-2026-64222 |
octeontx2-pf: avoid double free of pool->stack on AQ init failure |
24.07.2026 |
|
| CVE-2026-64223 |
wifi: mac80211: consume only present negotiated TTLM maps |
24.07.2026 |
|
| CVE-2026-64224 |
octeontx2-pf: fix double free in rvu_rep_rsrc_init() |
24.07.2026 |
|
| CVE-2026-64225 |
octeontx2-af: CGX: add bounds check to cgx_speed_mbps index |
24.07.2026 |
|
| CVE-2026-64226 |
sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path |
24.07.2026 |
|
| CVE-2026-64227 |
ACPI: driver: Check ACPI_COMPANION() against NULL during probe |
24.07.2026 |
|
| CVE-2026-64228 |
net: ethtool: phy: avoid NULL deref when PHY driver is unbound |
24.07.2026 |
|
| CVE-2026-64229 |
x86/mm: Disable broadcast TLB flush when PCID is disabled |
24.07.2026 |
|
| CVE-2026-64230 |
regulator: tps65219: fix irq_data.rdev not being assigned |
24.07.2026 |
|
| CVE-2026-64231 |
drm/msm/dsi: don't dump registers past the mapped region |
24.07.2026 |
|
| CVE-2026-64232 |
block: recompute nr_integrity_segments in blk_insert_cloned_request |
24.07.2026 |
|
| CVE-2026-64233 |
usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind |
24.07.2026 |
|
| CVE-2026-64234 |
tty: serial: pch_uart: add check for dma_alloc_coherent() |
24.07.2026 |
|
| CVE-2026-64235 |
x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines |
24.07.2026 |
|
| CVE-2026-64236 |
i2c: davinci: fix division by zero on missing clock-frequency |
24.07.2026 |
|
| CVE-2026-64237 |
Input: elan_i2c - validate firmware size before use |
24.07.2026 |
|
| CVE-2026-64238 |
gpio: shared: fix deadlock on shared proxy's parent removal |
24.07.2026 |
|
| CVE-2026-64239 |
mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() |
24.07.2026 |
|
| CVE-2026-64240 |
media: rc: igorplugusb: fix control request setup packet |
24.07.2026 |
|
| CVE-2026-64241 |
gpio: rockchip: teardown bugs and resource leaks |
24.07.2026 |
|
| CVE-2026-64242 |
usb: gadget: net2280: Fix double free in probe error path |
24.07.2026 |
|
| CVE-2026-64243 |
ASoC: codecs: simple-mux: Fix enum control bounds check |
24.07.2026 |
|
| CVE-2026-64244 |
drivers/base/memory: set mem->altmap after successful device registration |
24.07.2026 |
|
| CVE-2026-64245 |
fbdev: modedb: fix a possible UAF in fb_find_mode() |
24.07.2026 |
|
| CVE-2026-64246 |
power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() |
24.07.2026 |
|
| CVE-2026-64247 |
KVM: x86: hyper-v: Bound the bank index when querying sparse banks |
24.07.2026 |
|
| CVE-2026-64248 |
MIPS: smp: report dying CPU to RCU in stop_this_cpu() |
24.07.2026 |
|
| CVE-2026-64249 |
fpga: region: fix use-after-free in child_regions_with_firmware() |
24.07.2026 |
|
| CVE-2026-64250 |
LoongArch: Report dying CPU to RCU in stop_this_cpu() |
24.07.2026 |
|
| CVE-2026-64251 |
pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() |
24.07.2026 |
|
| CVE-2026-64252 |
MIPS: DEC: Prevent initial console buffer from landing in XKPHYS |
24.07.2026 |
|
| CVE-2026-64253 |
kernel/fork: clear PF_BLOCK_TS in copy_process() |
24.07.2026 |
|
| CVE-2026-64254 |
NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR |
24.07.2026 |
|
| CVE-2026-64255 |
wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers |
24.07.2026 |
|
| CVE-2026-65693 |
Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates |
24.07.2026 |
|
| CVE-2026-66027 |
Suna < 0.9.102 Broken Access Control via Message Queue API |
24.07.2026 |
|
| CVE-2026-16798 |
|
24.07.2026 |
|
| CVE-2026-16799 |
|
24.07.2026 |
|
| CVE-2026-16800 |
|
24.07.2026 |
|
| CVE-2026-16801 |
|
24.07.2026 |
|
| CVE-2026-16802 |
|
24.07.2026 |
|
| CVE-2026-49326 |
Apache HBase: Missing scanner instance owner check in thrift delegation service |
24.07.2026 |
|
| CVE-2026-56163 |
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
24.07.2026 |
10 |
| CVE-2026-57106 |
Data Quality Elevation of Privilege Vulnerability |
24.07.2026 |
10 |
| CVE-2026-58586 |
Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp |
24.07.2026 |
|
| CVE-2026-58630 |
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability |
24.07.2026 |
10 |
| CVE-2026-66004 |
BlenderMCP Path Traversal via download_polyhaven_asset API |
24.07.2026 |
|
| CVE-2026-66005 |
Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding |
24.07.2026 |
|
| CVE-2026-66006 |
lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs |
24.07.2026 |
|
| CVE-2026-66007 |
Datasets Path Traversal via Unsanitized file_name Metadata |
24.07.2026 |
|
| CVE-2026-8789 |
Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion |
24.07.2026 |
8.1 |
| CVE-2026-12496 |
Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server |
24.07.2026 |
|
| CVE-2026-12502 |
Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo |
24.07.2026 |
|
| CVE-2026-12503 |
Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter |
24.07.2026 |
|
| CVE-2026-12504 |
Loytec LINX firmware: Improper Authentication in PAM configuration |
24.07.2026 |
|
| CVE-2026-17059 |
Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter |
24.07.2026 |
|
| CVE-2026-55728 |
Loytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict |
24.07.2026 |
|
| CVE-2026-55729 |
Loytec LWEB802: Exposure of Sensitive Information in browser localStorage |
24.07.2026 |
|
| CVE-2026-55730 |
Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802 |
24.07.2026 |
|
| CVE-2026-55731 |
Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent |
24.07.2026 |
|
| CVE-2026-55732 |
Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod) |
24.07.2026 |
|
| CVE-2026-7007 |
Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image |
24.07.2026 |
4.6 |
| CVE-2026-8308 |
Reflected XSS Polen Media's Website Template |
24.07.2026 |
6.1 |
| CVE-2026-17048 |
Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api |
24.07.2026 |
|
| CVE-2026-16743 |
Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users |
24.07.2026 |
|
| CVE-2026-45811 |
Apache NimBLE: Buffer overflow in socket HCI transport |
24.07.2026 |
|
| CVE-2026-45812 |
Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler |
24.07.2026 |
|
| CVE-2026-45813 |
Apache NimBLE: Incorrect data validation in BASS add/modify source operation |
24.07.2026 |
|
| CVE-2026-45815 |
Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler |
24.07.2026 |
|
| CVE-2026-45816 |
Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request |
24.07.2026 |
|
| CVE-2026-46452 |
Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure |
24.07.2026 |
|
| CVE-2026-66008 |
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages |
24.07.2026 |
|
| CVE-2026-66009 |
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages |
24.07.2026 |
|
| CVE-2026-66010 |
DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING |
24.07.2026 |
|
| CVE-2026-66142 |
Apache Neethi: Uncontrolled recursion in policy processing |
24.07.2026 |
|
| CVE-2026-66143 |
Apache Neethi: Missing global alternative-output budget across policy computation paths |
24.07.2026 |
|
| CVE-2026-66144 |
Apache Neethi: Remote PolicyReference fetch lacks resource bounds |
24.07.2026 |
|
| CVE-2026-7484 |
Improper Access Control in Abis Technology's AVESİS |
24.07.2026 |
5.3 |
| CVE-2026-9765 |
CVE-2026-9765 CVE Record |
24.07.2026 |
7.1 |
| CVE-2026-15243 |
Improper Validation of Certificate in CAS Client |
24.07.2026 |
|
| CVE-2026-16730 |
Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup |
24.07.2026 |
|
| CVE-2026-10610 |
Local privilege escalation in ESET security applications for macOS |
24.07.2026 |
|
| CVE-2026-15810 |
Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover |
24.07.2026 |
|
| CVE-2026-10033 |
EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action |
24.07.2026 |
7.3 |
| CVE-2026-15401 |
VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter |
24.07.2026 |
7.2 |
| CVE-2026-15663 |
Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key |
24.07.2026 |
4.9 |
| CVE-2026-16634 |
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99 |
24.07.2026 |
|
| CVE-2026-7483 |
Local privilege escalation in ESET security applications for macOS |
24.07.2026 |
|
| CVE-2026-12702 |
|
24.07.2026 |
|
| CVE-2026-24727 |
SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type |
24.07.2026 |
|
| CVE-2026-49743 |
GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed |
24.07.2026 |
|
| CVE-2026-49744 |
GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() |
24.07.2026 |
|
| CVE-2026-49745 |
GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 |
24.07.2026 |
|
| CVE-2026-15346 |
VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter |
24.07.2026 |
6.1 |
| CVE-2026-15704 |
CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components |
24.07.2026 |
9.8 |
| CVE-2026-15739 |
Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute |
24.07.2026 |
6.4 |
| CVE-2026-15821 |
SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
24.07.2026 |
6.4 |
| CVE-2026-56391 |
Out‑of‑bounds Read in GNU coreutils |
24.07.2026 |
|
| CVE-2026-56392 |
Heap-based Buffer Overflow in GNU coreutils |
24.07.2026 |
|
| CVE-2026-63317 |
Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML |
24.07.2026 |
|
| CVE-2026-12654 |
Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret |
24.07.2026 |
5.3 |
| CVE-2026-15333 |
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute |
24.07.2026 |
6.4 |
| CVE-2026-15334 |
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block Attribute |
24.07.2026 |
6.4 |
| CVE-2026-15464 |
WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute |
24.07.2026 |
6.4 |
| CVE-2026-15648 |
Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute |
24.07.2026 |
6.4 |
| CVE-2026-15653 |
Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter |
24.07.2026 |
6.4 |
| CVE-2026-15665 |
Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute |
24.07.2026 |
6.4 |
| CVE-2026-15755 |
Open User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
24.07.2026 |
6.4 |
| CVE-2026-16519 |
GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability |
24.07.2026 |
7.3 |
| CVE-2026-16910 |
Quay: ssrf in red hat quay notification webhooks (slack/generic) |
24.07.2026 |
|
| CVE-2026-12497 |
ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection |
24.07.2026 |
|
| CVE-2026-12688 |
ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery |
24.07.2026 |
|
| CVE-2026-12689 |
ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization |
24.07.2026 |
|
| CVE-2026-12690 |
ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization |
24.07.2026 |
|
| CVE-2026-12877 |
Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter |
24.07.2026 |
|
| CVE-2026-12981 |
CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset |
24.07.2026 |
|
| CVE-2026-14172 |
Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation |
24.07.2026 |
7.8 |
| CVE-2026-14603 |
WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection |
24.07.2026 |
|
| CVE-2026-16870 |
Multiple Security Vulnerabilities in Snowflake libsnowflakeclient |
24.07.2026 |
8.8 |
| CVE-2026-54422 |
|
24.07.2026 |
5.5 |
| CVE-2026-66138 |
|
24.07.2026 |
7.2 |
| CVE-2026-66139 |
|
24.07.2026 |
4.8 |
| CVE-2026-66140 |
|
24.07.2026 |
8.4 |
| CVE-2026-66141 |
|
24.07.2026 |
7.4 |
| CVE-2025-9205 |
MapSVG Lite <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
24.07.2026 |
6.4 |
| CVE-2026-11354 |
Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter |
24.07.2026 |
5.3 |
| CVE-2026-11922 |
Rate-limit Bypass in zenml-io/zenml |
24.07.2026 |
|
| CVE-2026-12736 |
WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint |
24.07.2026 |
8 |
| CVE-2026-13464 |
Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter |
24.07.2026 |
5.3 |
| CVE-2026-15100 |
Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute |
24.07.2026 |
6.4 |
| CVE-2026-15420 |
Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter |
24.07.2026 |
4.3 |
| CVE-2026-6454 |
Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute |
24.07.2026 |
6.4 |
| CVE-2026-35425 |
Azure API Management (APIM) Remote Code Execution Vulnerability |
24.07.2026 |
8 |
| CVE-2026-49159 |
Microsoft Graph Information Disclosure Vulnerability |
24.07.2026 |
6.5 |
| CVE-2026-50517 |
Microsoft M365 Copilot Remote Code Execution Vulnerability |
24.07.2026 |
9.9 |
| CVE-2026-54120 |
Microsoft Surface Remote Code Execution Vulnerability |
24.07.2026 |
9.9 |
| CVE-2026-56160 |
Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability |
24.07.2026 |
9.1 |
| CVE-2026-56165 |
Microsoft Account Remote Code Execution Vulnerability |
24.07.2026 |
9.8 |
| CVE-2026-56167 |
Azure AI Search Elevation of Privilege Vulnerability |
24.07.2026 |
8.5 |
| CVE-2026-56191 |
Microsoft Exchange Online Tampering Vulnerability |
24.07.2026 |
10 |
| CVE-2026-58275 |
Azure DNS Elevation of Privilege Vulnerability |
24.07.2026 |
10 |
| CVE-2026-62825 |
Azure Key Vault Elevation of Privilege Vulnerability |
24.07.2026 |
10 |
| CVE-2026-16767 |
Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal |
24.07.2026 |
|
| CVE-2026-28698 |
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs |
24.07.2026 |
8.6 |
| CVE-2026-40430 |
Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs |
24.07.2026 |
7.5 |
| CVE-2026-42933 |
Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs |
24.07.2026 |
10 |
| CVE-2026-44955 |
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs |
24.07.2026 |
5.3 |
| CVE-2026-50044 |
Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs |
24.07.2026 |
6.8 |
| CVE-2026-16765 |
CodeAstro Online Classroom loginlinkadmin.php sql injection |
24.07.2026 |
|
| CVE-2026-16804 |
|
24.07.2026 |
|
| CVE-2026-16805 |
|
24.07.2026 |
|
| CVE-2026-16806 |
|
24.07.2026 |
|
| CVE-2026-16807 |
|
24.07.2026 |
|
| CVE-2024-58353 |
Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
24.07.2026 |
|
| CVE-2024-58354 |
cal.com Repository Takeover via pull_request_target Workflow |
24.07.2026 |
|
| CVE-2024-58355 |
Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
24.07.2026 |
|
| CVE-2025-71389 |
Cal.com before 5.9.9 Remote Code Execution via RSC |
23.07.2026 |
|
| CVE-2026-16763 |
localstack serverless-localstack Configuration index.js os command injection |
24.07.2026 |
|
| CVE-2026-16764 |
OWASP DefectDojo API/Web serializers.py UserSerializer privileges management |
24.07.2026 |
|
| CVE-2026-63313 |
9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch |
24.07.2026 |
|
| CVE-2026-63732 |
9router before 0.4.60 Remote Code Execution via default password |
23.07.2026 |
|
| CVE-2026-65604 |
Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass |
24.07.2026 |
|
| CVE-2026-65694 |
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController |
24.07.2026 |
|
| CVE-2026-16002 |
Out-of-bounds Read in MZ Automation lib60870 |
24.07.2026 |
8.2 |
| CVE-2026-49035 |
Stack-based Buffer Overflow in MZ Automation libIEC61850 |
24.07.2026 |
8.1 |
| CVE-2026-50032 |
NULL Pointer Dereference in MZ Automation libIEC61850 |
24.07.2026 |
7.5 |
| CVE-2026-50103 |
Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850 |
24.07.2026 |
6.5 |
| CVE-2026-6924 |
Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path |
24.07.2026 |
|
| CVE-2026-15981 |
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter |
23.07.2026 |
9.8 |
| CVE-2026-21653 |
CCure and Victor Application Server - Server Side Request Forgery |
24.07.2026 |
|
| CVE-2026-34496 |
victor Web - Priviledge Escalation |
24.07.2026 |
|
| CVE-2026-38764 |
|
23.07.2026 |
|
| CVE-2026-47724 |
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation |
23.07.2026 |
9.9 |
| CVE-2026-50039 |
Stack-based Buffer Overflow in MZ Automation libIEC61850 |
24.07.2026 |
7.5 |
| CVE-2026-52439 |
|
23.07.2026 |
|
| CVE-2026-10697 |
MFA Bypass in MOVEit Transfer |
24.07.2026 |
7.5 |
| CVE-2026-15630 |
CVE-2026-15630 |
23.07.2026 |
|
| CVE-2026-15966 |
Improper CORS handling in MOVEit Transfer |
24.07.2026 |
7.5 |
| CVE-2026-15967 |
MOVEit Transfer refresh-token processing does not enforce updated account restrictions |
24.07.2026 |
7.5 |
| CVE-2026-15968 |
Stored XSS vulnerability in MOVEit Transfer |
24.07.2026 |
7.1 |
| CVE-2026-16796 |
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() |
24.07.2026 |
7.3 |
| CVE-2026-21655 |
C-CURE 9000 and Victor application server - Deserialization of Untrusted Data |
24.07.2026 |
|
| CVE-2026-39155 |
|
23.07.2026 |
|
| CVE-2026-47723 |
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) |
24.07.2026 |
|