CVE ID :CVE-2026-55685 Published : July 27, 2026, 10:17 p.m. | 2 hours, 20 minutes ago Description :React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be…
CVE-2026-66824 – Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding
CVE ID :CVE-2026-66824 Published : July 27, 2026, 9:17 p.m. | 3 hours, 20 minutes ago Description :A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized…
CVE-2026-66014 – Potential authentication bypass leading to privilege escalation in Artifactory
CVE ID :CVE-2026-66014 Published : July 27, 2026, 8:16 p.m. | 4 hours, 21 minutes ago Description :JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow…
CVE-2026-65921 – Potential path traversal leading to unauthorized file writes
CVE ID :CVE-2026-65921 Published : July 27, 2026, 8:16 p.m. | 4 hours, 21 minutes ago Description :A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside…
CVE-2026-65617 – Potential remote code execution on an Artifactory package service container.
CVE ID :CVE-2026-65617 Published : July 27, 2026, 8:16 p.m. | 4 hours, 21 minutes ago Description :A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity,…
CVE-2026-17497 – NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
CVE ID :CVE-2026-17497 Published : July 26, 2026, 3:16 p.m. | 9 hours, 21 minutes ago Description :NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary…
CVE-2026-17496 – NoteGen chat preview XSS via unsanitized AI/skill HTML rendering
CVE ID :CVE-2026-17496 Published : July 26, 2026, 3:16 p.m. | 9 hours, 21 minutes ago Description :NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into…
CVE-2026-15962 – Fluent Forms Pro Add On Pack <= 6.2.6 – Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field
CVE ID :CVE-2026-15962 Published : July 26, 2026, 2:16 a.m. | 22 hours, 21 minutes ago Description :The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in…
CVE-2026-66013 – OpenRemote before 1.26.2 Authentication Bypass via Console Registration
CVE ID :CVE-2026-66013 Published : July 25, 2026, 11:17 a.m. | 13 hours, 20 minutes ago Description :OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers…
CVE-2026-66012 – SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP
CVE ID :CVE-2026-66012 Published : July 25, 2026, 11:17 a.m. | 13 hours, 20 minutes ago Description :SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated…