| CVE-2026-16450 |
zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization |
21.07.2026 |
|
| CVE-2026-28302 |
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28304 |
SolarWinds Serv-U Remote Code Execution Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28305 |
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28306 |
SolarWinds Serv-U Privilege Escalation Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28307 |
SolarWinds Serv-U Privilege Escalation Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28308 |
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28309 |
SolarWinds Serv-U Broken Access Control Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28310 |
SolarWinds Serv-U Privilege Escalation Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28312 |
SolarWinds Serv-U Privilege Escalation Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28313 |
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28314 |
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28315 |
SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability |
21.07.2026 |
6.2 |
| CVE-2026-28316 |
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28317 |
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-28321 |
SolarWinds Serv-U Broken Access Control Vulnerability |
21.07.2026 |
9.1 |
| CVE-2026-47391 |
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution |
21.07.2026 |
9.8 |
| CVE-2026-47392 |
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) |
21.07.2026 |
9.9 |
| CVE-2026-47393 |
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
21.07.2026 |
9.8 |
| CVE-2026-47394 |
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate |
21.07.2026 |
|
| CVE-2026-47395 |
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context |
21.07.2026 |
5.5 |
| CVE-2026-47396 |
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset |
21.07.2026 |
9.8 |
| CVE-2026-64824 |
Home Assistant Core < 2026.6.0 Symlink Path Traversal RCE via backup-restore |
21.07.2026 |
|
| CVE-2026-64825 |
Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload |
21.07.2026 |
|
| CVE-2026-16449 |
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection |
21.07.2026 |
|
| CVE-2026-47390 |
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings |
21.07.2026 |
5.5 |
| CVE-2026-56585 |
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing |
21.07.2026 |
3.1 |
| CVE-2026-56586 |
HCL IEM was affected with X-Content-Type-Options Header Missing |
21.07.2026 |
3.1 |
| CVE-2026-64823 |
Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI |
21.07.2026 |
|
| CVE-2024-5300 |
AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd |
21.07.2026 |
5.6 |
| CVE-2026-11876 |
Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml |
21.07.2026 |
|
| CVE-2026-15226 |
snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates |
21.07.2026 |
8.4 |
| CVE-2026-16448 |
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection |
21.07.2026 |
|
| CVE-2026-46681 |
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty |
21.07.2026 |
|
| CVE-2026-47122 |
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection |
21.07.2026 |
4.2 |
| CVE-2026-56584 |
HCL IEM was affected with the Information disclosure nginx server |
21.07.2026 |
3.7 |
| CVE-2026-56587 |
HCL IEM was affected with Strict transport security not enforced |
21.07.2026 |
3.7 |
| CVE-2026-59849 |
Libssh: libssh: denial of service via automatic certificate authentication loop |
21.07.2026 |
|
| CVE-2026-59850 |
Libssh: libssh: use-after-free via data callbacks on closed channels |
21.07.2026 |
|
| CVE-2026-59851 |
Libssh: libssh: authentication bypass via missing gssapi principal check |
21.07.2026 |
|
| CVE-2026-65048 |
Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index |
21.07.2026 |
|
| CVE-2026-65049 |
Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action |
21.07.2026 |
|
| CVE-2026-65050 |
Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors |
21.07.2026 |
|
| CVE-2026-65051 |
Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler |
21.07.2026 |
|
| CVE-2026-65052 |
Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields |
21.07.2026 |
|
| CVE-2026-8933 |
snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup |
21.07.2026 |
7.8 |
| CVE-2025-66390 |
|
21.07.2026 |
|
| CVE-2026-16447 |
D-Link DNS-320 multi_uploadify.php unrestricted upload |
21.07.2026 |
|
| CVE-2026-47121 |
Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta |
21.07.2026 |
6.1 |
| CVE-2026-59847 |
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification |
21.07.2026 |
|
| CVE-2026-59848 |
Libssh: libssh: denial of service via sftp responses with unknown request ids |
21.07.2026 |
|
| CVE-2026-9499 |
Out-of-bounds read in QTextCodec::codecForName() in Qt |
21.07.2026 |
|
| CVE-2026-16445 |
Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module |
21.07.2026 |
|
| CVE-2026-59846 |
Libssh: libssh: information disclosure via proxycommand %r username expansion |
21.07.2026 |
|
| CVE-2026-16349 |
Same-origin policy bypass in the DOM: Navigation component |
21.07.2026 |
|
| CVE-2026-16350 |
Incorrect boundary conditions in the Audio/Video: cubeb component |
21.07.2026 |
|
| CVE-2026-16351 |
Sandbox escape due to use-after-free in the DOM: Navigation component |
21.07.2026 |
|
| CVE-2026-16352 |
Sandbox escape due to use-after-free in the Disability Access APIs component |
21.07.2026 |
|
| CVE-2026-16353 |
Invalid pointer in the DOM: Bindings (WebIDL) component |
21.07.2026 |
|
| CVE-2026-16354 |
Information disclosure in the Graphics: ImageLib component |
21.07.2026 |
|
| CVE-2026-16355 |
JIT miscompilation in the JavaScript Engine: JIT component |
21.07.2026 |
|
| CVE-2026-16356 |
Sandbox escape due to use-after-free in the Disability Access APIs component |
21.07.2026 |
|
| CVE-2026-16357 |
Incorrect boundary conditions in the Graphics component |
21.07.2026 |
|
| CVE-2026-16358 |
Site isolation issue in the Graphics: WebRender component |
21.07.2026 |
|
| CVE-2026-16359 |
Incorrect boundary conditions in the Audio/Video: GMP component |
21.07.2026 |
|
| CVE-2026-16360 |
Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 |
21.07.2026 |
|
| CVE-2026-16361 |
Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 |
21.07.2026 |
|
| CVE-2026-16362 |
Use-after-free in the WebRTC: Audio/Video component |
21.07.2026 |
|
| CVE-2026-16363 |
JIT miscompilation in the JavaScript: WebAssembly component |
21.07.2026 |
|
| CVE-2026-16364 |
Incorrect boundary conditions in the Audio/Video: Playback component |
21.07.2026 |
|
| CVE-2026-16365 |
Privilege escalation in the DOM: Workers component |
21.07.2026 |
|
| CVE-2026-16366 |
Privilege escalation in the DOM: Navigation component |
21.07.2026 |
|
| CVE-2026-16367 |
Sandbox escape due to invalid pointer in the Disability Access APIs component |
21.07.2026 |
|
| CVE-2026-16368 |
Incorrect boundary conditions in the JavaScript: WebAssembly component |
21.07.2026 |
|
| CVE-2026-16369 |
Integer overflow in the JavaScript: WebAssembly component |
21.07.2026 |
|
| CVE-2026-16370 |
Mitigation bypass in the DOM: Networking component |
21.07.2026 |
|
| CVE-2026-16371 |
Privilege escalation in the DOM: Navigation component |
21.07.2026 |
|
| CVE-2026-16372 |
Privilege escalation in the DOM: Content Processes component |
21.07.2026 |
|
| CVE-2026-16373 |
Information disclosure in the Privacy component in Firefox for Android |
21.07.2026 |
|
| CVE-2026-16374 |
Information disclosure in the Framework component in DevTools |
21.07.2026 |
|
| CVE-2026-16375 |
Site isolation issue in the Networking: HTTP component |
21.07.2026 |
|
| CVE-2026-16376 |
Denial-of-service in the Graphics: WebGPU component |
21.07.2026 |
|
| CVE-2026-16377 |
Mitigation bypass in the PDF Viewer component |
21.07.2026 |
|
| CVE-2026-16378 |
Other issue in the DOM: Copy & Paste and Drag & Drop component |
21.07.2026 |
|
| CVE-2026-16379 |
Privilege escalation in the DOM: Content Processes component |
21.07.2026 |
|
| CVE-2026-16380 |
Mitigation bypass in the Networking component |
21.07.2026 |
|
| CVE-2026-16381 |
Same-origin policy bypass in the Networking: DNS component |
21.07.2026 |
|
| CVE-2026-16382 |
Mitigation bypass in the DOM: Service Workers component |
21.07.2026 |
|
| CVE-2026-16383 |
Mitigation bypass in the DOM: Networking component |
21.07.2026 |
|
| CVE-2026-16384 |
Information disclosure due to uninitialized memory in the Graphics: WebGPU component |
21.07.2026 |
|
| CVE-2026-16385 |
Information disclosure due to uninitialized memory in the Graphics: WebGPU component |
21.07.2026 |
|
| CVE-2026-16386 |
Information disclosure due to uninitialized memory in the Graphics: WebGPU component |
21.07.2026 |
|
| CVE-2026-16387 |
Site isolation issue in the Networking component |
21.07.2026 |
|
| CVE-2026-16388 |
Sandbox escape in the DOM: Networking component |
21.07.2026 |
|
| CVE-2026-16389 |
Incorrect boundary conditions, integer overflow in the Libraries component in NSS |
21.07.2026 |
|
| CVE-2026-16390 |
Mitigation bypass in the Enterprise Policies component |
21.07.2026 |
|
| CVE-2026-16391 |
Information disclosure in the Storage: IndexedDB component |
21.07.2026 |
|
| CVE-2026-16392 |
JIT miscompilation in the JavaScript Engine: JIT component |
21.07.2026 |
|
| CVE-2026-16393 |
Incorrect boundary conditions in the Graphics: WebGPU component |
21.07.2026 |
|
| CVE-2026-16394 |
Mitigation bypass in the DOM: Security component |
21.07.2026 |
|
| CVE-2026-16395 |
Integer overflow in the Audio/Video component |
21.07.2026 |
|
| CVE-2026-16396 |
Privilege escalation in WebExtensions |
21.07.2026 |
|
| CVE-2026-16397 |
Clickjacking issue in the WebExtensions component in Firefox for Android |
21.07.2026 |
|
| CVE-2026-16398 |
Site isolation issue in the Graphics component |
21.07.2026 |
|
| CVE-2026-16399 |
Site isolation issue in the DOM: Navigation component |
21.07.2026 |
|
| CVE-2026-16400 |
Information disclosure in the DOM: Security component |
21.07.2026 |
|
| CVE-2026-16401 |
Privilege escalation in the Data Loss Prevention component |
21.07.2026 |
|
| CVE-2026-16402 |
Integer overflow in the Graphics: ImageLib component |
21.07.2026 |
|
| CVE-2026-16403 |
Spoofing issue in the Address Bar component |
21.07.2026 |
|
| CVE-2026-16404 |
Spoofing issue in Firefox for Android |
21.07.2026 |
|
| CVE-2026-16405 |
Information disclosure in the Networking: WebSockets component |
21.07.2026 |
|
| CVE-2026-16406 |
Mitigation bypass in the Networking component |
21.07.2026 |
|
| CVE-2026-16407 |
Mitigation bypass in the DOM: Service Workers component |
21.07.2026 |
|
| CVE-2026-16408 |
Integer overflow in the Audio/Video: Playback component |
21.07.2026 |
|
| CVE-2026-16409 |
Invalid pointer in the Security: PSM component |
21.07.2026 |
|
| CVE-2026-16410 |
JIT miscompilation in the JavaScript Engine: JIT component |
21.07.2026 |
|
| CVE-2026-16411 |
Memory safety bugs fixed in Firefox 153 |
21.07.2026 |
|
| CVE-2026-16412 |
Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 |
21.07.2026 |
|
| CVE-2026-6792 |
Improper Authorization in Universal Sotware's FlexCity |
21.07.2026 |
6.5 |
| CVE-2026-8284 |
Open Redirect in Universal Sotware's FlexCity |
21.07.2026 |
6.1 |
| CVE-2026-8285 |
OTP Bypass in Universal Sotware's FlexCity |
21.07.2026 |
4.3 |
| CVE-2026-16461 |
Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting |
21.07.2026 |
|
| CVE-2026-59844 |
Libssh: libssh: denial of service via oversized sftp read length |
21.07.2026 |
|
| CVE-2026-64627 |
Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion |
21.07.2026 |
|
| CVE-2026-64628 |
Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers |
21.07.2026 |
|
| CVE-2026-65007 |
Grav before 1.0.8 Missing Authorization on API Key Generation |
21.07.2026 |
|
| CVE-2026-65008 |
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData |
21.07.2026 |
|
| CVE-2026-65009 |
OpenRemote before 1.26.2 Information Disclosure via Syslog REST API |
21.07.2026 |
|
| CVE-2026-1617 |
SQLi in Turkmesh's Turkhotspot 5651 Loglama |
21.07.2026 |
9.8 |
| CVE-2026-59842 |
Libssh: libssh: information disclosure via short gssapi curve25519 public key |
21.07.2026 |
|
| CVE-2026-59843 |
Libssh: libssh: denial of service via zero advertised channel packet size |
21.07.2026 |
|
| CVE-2026-59845 |
Libssh: libssh: denial of service via unchecked proxycommand fork() failure |
21.07.2026 |
|
| CVE-2026-60080 |
Apache Fory: Rust MetaString heap use-after-free |
21.07.2026 |
|
| CVE-2026-64606 |
Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface |
21.07.2026 |
|
| CVE-2026-62415 |
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 |
21.07.2026 |
|
| CVE-2026-64608 |
Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths |
21.07.2026 |
|
| CVE-2026-64609 |
Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization |
21.07.2026 |
|
| CVE-2026-15370 |
Libssh: libssh: stack buffer overflow in sftp server longname construction |
21.07.2026 |
|
| CVE-2026-15145 |
Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget |
21.07.2026 |
6.4 |
| CVE-2026-1372 |
Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation |
21.07.2026 |
4.3 |
| CVE-2026-1771 |
MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint |
21.07.2026 |
7.2 |
| CVE-2026-3183 |
Multi Factor Auth Bypass |
21.07.2026 |
7.1 |
| CVE-2026-8593 |
Fix Business Intelligence API Pack permission |
21.07.2026 |
|
| CVE-2026-11767 |
CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form |
21.07.2026 |
|
| CVE-2026-13693 |
Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal |
21.07.2026 |
|
| CVE-2026-13694 |
Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass |
21.07.2026 |
|
| CVE-2026-14183 |
Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR |
21.07.2026 |
|
| CVE-2026-14184 |
Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR |
21.07.2026 |
|
| CVE-2026-14185 |
WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update |
21.07.2026 |
|
| CVE-2026-8082 |
Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection |
21.07.2026 |
|
| CVE-2023-37507 |
An information disclosure vulnerability affects HCL DevOps Plan |
21.07.2026 |
|
| CVE-2026-13439 |
Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint |
21.07.2026 |
9.8 |
| CVE-2026-15782 |
WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content |
21.07.2026 |
4.9 |
| CVE-2026-15811 |
Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes |
21.07.2026 |
|
| CVE-2026-15812 |
Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links |
21.07.2026 |
|
| CVE-2026-15927 |
Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation |
21.07.2026 |
|
| CVE-2026-16266 |
|
21.07.2026 |
4 |
| CVE-2026-3182 |
Sensitive Data Exposure |
21.07.2026 |
4.3 |
| CVE-2023-37508 |
HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability |
21.07.2026 |
|
| CVE-2026-15156 |
Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings |
21.07.2026 |
6.4 |
| CVE-2026-16336 |
trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect |
21.07.2026 |
|
| CVE-2026-59776 |
|
21.07.2026 |
|
| CVE-2026-16332 |
D-Link DNS-320 multi_uploadify.php unrestricted upload |
21.07.2026 |
|
| CVE-2026-16334 |
itsourcecode Hospital Management System prescriptionorder.php sql injection |
21.07.2026 |
|
| CVE-2026-63729 |
TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File |
21.07.2026 |
|
| CVE-2026-6952 |
|
21.07.2026 |
7.2 |
| CVE-2026-16329 |
D-Link DNS-320 uploadify.php unrestricted upload |
21.07.2026 |
|
| CVE-2026-16330 |
D-Link DNS-320 uploadify.php unrestricted upload |
21.07.2026 |
|
| CVE-2026-16331 |
D-Link DNS-320 save_ajax.php unrestricted upload |
21.07.2026 |
|
| CVE-2026-16327 |
D-Link DNS-320 upload.php unrestricted upload |
21.07.2026 |
|
| CVE-2026-63728 |
Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature |
20.07.2026 |
|
| CVE-2026-55831 |
Netty SPDY SETTINGS frame count materializes unbounded settings map |
20.07.2026 |
7.5 |
| CVE-2026-55833 |
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation |
21.07.2026 |
7.5 |
| CVE-2026-15899 |
|
20.07.2026 |
|
| CVE-2026-15900 |
|
20.07.2026 |
|
| CVE-2026-15901 |
|
20.07.2026 |
|
| CVE-2026-15902 |
|
20.07.2026 |
|
| CVE-2026-15903 |
|
20.07.2026 |
|
| CVE-2026-15904 |
|
20.07.2026 |
|
| CVE-2026-15905 |
|
21.07.2026 |
|
| CVE-2026-47144 |
Shamefile has an arbitrary file read via shamefile.yaml in shame next |
20.07.2026 |
5.5 |
| CVE-2026-47255 |
AgenticMail API/storage and outbound relay hardening |
21.07.2026 |
8.2 |
| CVE-2026-57494 |
AgenticMail: Cross-agent task authorization bypass in AgenticMail API |
21.07.2026 |
|
| CVE-2026-57495 |
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake) |
20.07.2026 |
|
| CVE-2026-57852 |
Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check |
21.07.2026 |
5.6 |
| CVE-2026-64624 |
FreeRDP RDP File Parser Remote Code Execution via CLI Options |
20.07.2026 |
|
| CVE-2026-64625 |
AVideo before 29.0 OS Command Injection via execAsync |
20.07.2026 |
|
| CVE-2026-64626 |
AVideo Encoder downloadURL SSRF via unpinned retry fallback |
20.07.2026 |
|
| CVE-2026-12900 |
Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block |
20.07.2026 |
6.4 |
| CVE-2026-16324 |
Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload |
20.07.2026 |
|
| CVE-2026-47128 |
nono: Sandbox escape on Linux via D-Bus: `systemd-run --user` |
21.07.2026 |
6.1 |
| CVE-2026-51025 |
|
21.07.2026 |
|
| CVE-2026-51031 |
|
21.07.2026 |
|
| CVE-2026-51385 |
|
21.07.2026 |
6.9 |
| CVE-2026-52656 |
|
21.07.2026 |
|
| CVE-2024-51312 |
|
21.07.2026 |
|
| CVE-2024-51314 |
|
21.07.2026 |
|
| CVE-2024-51315 |
|
21.07.2026 |
|
| CVE-2024-51316 |
|
21.07.2026 |
|
| CVE-2026-44510 |
|
21.07.2026 |
|
| CVE-2026-47133 |
ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshots |
21.07.2026 |
|
| CVE-2026-47134 |
ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy |
21.07.2026 |
|
| CVE-2026-55544 |
NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering |
20.07.2026 |
7.6 |
| CVE-2026-55550 |
NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product Catalog |
20.07.2026 |
7.1 |
| CVE-2024-51311 |
|
21.07.2026 |
|
| CVE-2024-51313 |
|
21.07.2026 |
|
| CVE-2026-44507 |
|
21.07.2026 |
|
| CVE-2026-44508 |
|
21.07.2026 |
|
| CVE-2026-44509 |
|
21.07.2026 |
|
| CVE-2026-47129 |
NextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accounts |
21.07.2026 |
8.1 |
| CVE-2026-47130 |
NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering |
20.07.2026 |
7.1 |
| CVE-2026-56452 |
Apache MINA SSHD: Path traversal in SCP file reception |
20.07.2026 |
|
| CVE-2026-56623 |
Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows |
20.07.2026 |
|
| CVE-2026-56624 |
Apache MINA SSHD: SSH certificate options lack validations |
20.07.2026 |
|
| CVE-2026-58624 |
Apache MINA SSHD: Remote execution of JGit commands can write files on the server |
20.07.2026 |
|
| CVE-2026-64650 |
AI SDK Codex Harness Tool Relay Authorization Bypass |
20.07.2026 |
|
| CVE-2026-64651 |
AI SDK OpenCode Harness Tool Relay Authorization Bypass |
21.07.2026 |
|
| CVE-2026-13380 |
VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses |
20.07.2026 |
|
| CVE-2026-13381 |
VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion |
20.07.2026 |
|
| CVE-2026-44583 |
Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module |
20.07.2026 |
5.3 |
| CVE-2026-44585 |
Paymenter: Broken object level authorization via service reference manipulation on ticket creation |
21.07.2026 |
5.4 |
| CVE-2026-47198 |
Paymenter: URL parameter injection bypasses paid plan limits at checkout |
20.07.2026 |
8.5 |
| CVE-2026-53594 |
FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path |
21.07.2026 |
4.9 |
| CVE-2026-53595 |
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL |
21.07.2026 |
9.4 |
| CVE-2026-53596 |
FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS) |
20.07.2026 |
5.3 |
| CVE-2026-55219 |
Paymenter: Race condition in payWithCredit() enables credit double-spend |
20.07.2026 |
5.3 |