Common Vulnerabilities and Exposures (CVE)

CVE-2026-7260

Jul 30, 2026 11:22:53 UTC

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* be...

CVE-2026-17544

Jul 30, 2026 11:22:24 UTC

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVE-2026-17543

Jul 30, 2026 11:22:04 UTC

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVE-2026-64560

Jul 30, 2026 11:10:46 UTC

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related race which can result in an UAF: sys_t...

CVE-2026-18369

Jul 30, 2026 11:06:28 UTC

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME ...

CVE-2026-15397

Jul 30, 2026 11:03:24 UTC

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via t...

CVE-2026-18363

Jul 30, 2026 10:35:26 UTC

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided t...

CVE-2026-9800

Jul 30, 2026 10:27:56 UTC

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-...

CVE-2026-22620

Jul 30, 2026 10:22:09 UTC

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.

CVE-2026-22622

Jul 30, 2026 10:21:17 UTC

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.

CVE-2026-22621

Jul 30, 2026 10:16:28 UTC

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.

CVE-2026-65526

Jul 30, 2026 09:53:48 UTC

Contributor SQL Injection in Visualizer <= 4.0.6 versions.

CVE-2026-55654

Jul 30, 2026 09:47:18 UTC

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-...

CVE-2026-16970

Jul 30, 2026 09:45:24 UTC

The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.

CVE-2026-18362

Jul 30, 2026 09:44:32 UTC

The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.