Common Vulnerabilities and Exposures (CVE)

CVE-2026-15243

Jul 24, 2026 11:29:26 UTC

Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) ca...

CVE-2026-16730

Jul 24, 2026 11:26:18 UTC

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many ...

CVE-2026-10610

Jul 24, 2026 11:14:51 UTC

Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

CVE-2026-63313

Jul 24, 2026 11:13:06 UTC

9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina ...

CVE-2026-47722

Jul 24, 2026 11:11:20 UTC

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a...

CVE-2026-16767

Jul 24, 2026 11:09:57 UTC

A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversa...

CVE-2026-50517

Jul 24, 2026 11:09:19 UTC

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

CVE-2026-58275

Jul 24, 2026 11:08:38 UTC

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-12736

Jul 24, 2026 11:08:09 UTC

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'op...

CVE-2026-15810

Jul 24, 2026 11:04:59 UTC

A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaSc...

CVE-2026-15333

Jul 24, 2026 11:01:57 UTC

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including,...

CVE-2026-15755

Jul 24, 2026 10:59:33 UTC

The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.4.45 due to insufficient input sanitization and output escaping....

CVE-2026-16910

Jul 24, 2026 10:55:46 UTC

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST r...

CVE-2026-15663

Jul 24, 2026 10:53:25 UTC

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user ...

CVE-2026-7483

Jul 24, 2026 10:49:13 UTC

Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.