Common Vulnerabilities and Exposures (CVE)

CVE-2026-9734

Jul 22, 2026 16:09:10 UTC

The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possi...

CVE-2026-1372

Jul 22, 2026 16:08:10 UTC

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` f...

CVE-2026-16552

Jul 22, 2026 16:08:02 UTC

A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d configuration entry that writes to a file, systemd-tmpfiles can follow a symbolic link placed by an unprivileged local user, and an existing safety check does not detect thi...

CVE-2026-62486

Jul 22, 2026 16:05:18 UTC

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attac...

CVE-2026-40714

Jul 22, 2026 16:04:11 UTC

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privilege...

CVE-2026-62484

Jul 22, 2026 16:03:35 UTC

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attac...

CVE-2026-16370

Jul 22, 2026 16:02:55 UTC

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.

CVE-2026-44187

Jul 22, 2026 16:02:42 UTC

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The e...

CVE-2026-62483

Jul 22, 2026 16:02:40 UTC

Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit...

CVE-2026-65603

Jul 22, 2026 16:00:38 UTC

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler do...

CVE-2026-16096

Jul 22, 2026 15:59:47 UTC

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate th...

CVE-2026-62482

Jul 22, 2026 15:59:06 UTC

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attac...

CVE-2026-65597

Jul 22, 2026 15:58:12 UTC

n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass al...

CVE-2026-62480

Jul 22, 2026 15:57:11 UTC

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attac...

CVE-2026-62479

Jul 22, 2026 15:55:54 UTC

Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attac...