| CVE-2026-55056 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55055 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55052 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | high | 2026-07-16 |
| CVE-2026-55051 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | medium | 2026-07-16 |
| CVE-2026-55050 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55049 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55047 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55046 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55045 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55044 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55043 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55042 | Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55041 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55039 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55038 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55037 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55036 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55035 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | low | 2026-07-16 |
| CVE-2026-55033 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55032 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55028 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55027 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55023 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-55022 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55020 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | medium | 2026-07-16 |
| CVE-2026-55018 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-55017 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-54988 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | medium | 2026-07-16 |
| CVE-2026-54733 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1. | critical | 2026-07-16 |
| CVE-2026-54568 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through ufo/server/ws/handler.py, because handle_device_info_request and get_device_info did not enforce the constellation-only role or object-level authorization boundary. This issue is fixed in version 3.0.6. | medium | 2026-07-16 |
| CVE-2026-54470 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | medium | 2026-07-16 |
| CVE-2026-54469 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | high | 2026-07-16 |
| CVE-2026-54468 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files. | medium | 2026-07-16 |
| CVE-2026-54458 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin of every administrator currently viewing a page that renders the YPTSocket online-users debug panel. plugin/YPTSocket/getWebSocket.json.php issues a signed WebSocket token to any anonymous caller, and MessageSQLiteV2::onOpen at plugin/YPTSocket/MessageSQLiteV2.php lines 91 and 110 reads the attacker-controlled webSocketSelfURI and page_title query parameters from the WebSocket connection URL with no validation. Both values persist into the in-memory SQLite connections table and broadcast inside the users_id_online array sent to every connected client; on the client, plugin/YPTSocket/script.js::updateSocketUserCard interpolates the broadcast page_title into an HTML template literal that is passed to jQuery $.append(html), which parses attacker bytes into live DOM nodes including <img> with inline event handlers. Successful attackers can can read non-HttpOnly cookies and the CSRF token rendered into the admin dashboard, issue authenticated requests to any admin-only endpoint, exfiltrate the admin dashboard DOM, and chain into any admin-context mutation. When the victim is an AVideo administrator, the attacker turns a single anonymous WebSocket connection into full administrative takeover via the admin's own session. This issue has been patched by https://github.com/WWBN/AVideo/commit/8be71e53ccbe9b84b30870db386fb4d2b11e1c16. | critical | 2026-07-16 |
| CVE-2026-54122 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | high | 2026-07-16 |
| CVE-2026-54063 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r="N"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel row limit (TotalRows = 1,048,576). A specially crafted XLSX file can trigger two denial-of-service variants: (A) an out-of-memory process kill when r=2147483647 forces a ~16 GB allocation attempt, and (B) a runtime panic via out-of-bounds slice indexing when r=-1. Any service that opens attacker-supplied XLSX files and calls GetCellValue is affected. No authentication is required. This issue is fixed in version 2.11.0. | high | 2026-07-16 |
| CVE-2026-53633 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker-controlled Node.js code. This issue is fixed in versions 3.2.5, 4.1.8, and 5.0.0-beta. | critical | 2026-07-16 |
| CVE-2026-53450 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by using the IPv4-mapped IPv6 peer address ::ffff:127.0.0.1 in a TURN XOR-PEER-ADDRESS attribute. ioa_addr_is_loopback checks for the literal IPv6 loopback shape before IPv4-mapped IPv6 handling, so good_peer_addr does not apply the default loopback rejection and an authenticated TURN client can expose services bound only to localhost on the coturn host through TURN relay traffic. This issue is fixed in version 4.13.0. | high | 2026-07-16 |
| CVE-2026-53449 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process because the command string is used as-is after stripping the psd prefix and leading spaces, allowing truncation and overwrite with session dump data. This issue is fixed in version 4.13.0. | medium | 2026-07-16 |
| CVE-2026-53448 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without sanitization. The is_secure_string filter that protects the STUN protocol path is not applied to the admin panel's delete-user, delete-secret, and delete-IP operations, so an authenticated admin can inject arbitrary SQL through the du, ds, and dip parameters, gaining full database control and potentially OS-level access via PostgreSQL COPY TO PROGRAM. This issue is fixed in version 4.12.0. | high | 2026-07-16 |
| CVE-2026-53447 | Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any authenticated user who knows a private board ID can clone the board into their own account and read its cards, comments, attachments, member information, and activities. This issue is fixed in version 9.35. | medium | 2026-07-16 |
| CVE-2026-53446 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js are stored from user input and later fetched by server/notifications/outgoing.js without applying the existing validateAttachmentUrl() private-network checks from models/lib/attachmentUrlValidation.js. A board administrator can configure webhook URLs that cause server-side requests to internal or metadata services. This issue is fixed in version 9.32. | medium | 2026-07-16 |
| CVE-2026-53445 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board ID without checking this.userId, membership, or admin access. Any authenticated user can copy a private board they are not a member of, including its cards, checklists, custom fields, labels, and rules, while the REST POST /api/boards/:boardId/copy path correctly checks board admin access. This issue is fixed in version 9.32. | high | 2026-07-16 |
| CVE-2026-53232 | In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events. This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves. | high | 2026-07-16 |
| CVE-2026-52892 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating custom-field routes. A read-only board member can call POST, PUT, and DELETE handlers for /api/boards/:boardId/custom-fields and custom-field dropdown items to create, update, or delete board custom fields. This issue is fixed in version 9.32. | medium | 2026-07-16 |
| CVE-2026-52890 | Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.path and versions.original.storage fields. The server/permissions/attachments.js insert rule checks only board write access, and FileStoreStrategyFilesystem.getReadStream() in models/lib/fileStoreStrategy.js streams the stored path without a storage-root containment check, allowing arbitrary file reads and denial of service through special files such as /dev/zero. This issue is fixed in version 9.31. | high | 2026-07-16 |
| CVE-2026-52888 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that did not restrict PostgreSQL system catalog tables such as pg_shadow, pg_roles, and pg_stat_activity, allowing an admin-role user to read password hashes and database metadata through the SQL Collection feature. This vulnerability is fixed in 2.1.0-alpha.46. | medium | 2026-07-16 |
| CVE-2026-52865 | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | high | 2026-07-16 |
| CVE-2026-51380 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cgi-bin/UploadCfg endpoint | critical | 2026-07-16 |