Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 July 2026
RSS183 vulnerabilities published on 21 July 2026
Severity:
Easy Form Builder by WhiteStudio <= 4.0.11 - Hackers can gain admin access
CVE-2026-13439
The Easy Form Builder plugin for WordPress has a security weakness in versions up to 4.0.11. This means that hackers can gain full access to your WordPress site, including the ability to change passwo...
9.8
Argo CD: Developer-to-admin privilege escalation via malicious link
GHSA-h98r-wv3h-fr38
CVE-2026-45738
BIT-argo-cd-2026-45738
A developer with write access to an Argo CD application can create a link that, when clicked by an admin, executes arbitrary JavaScript in the admin's session, allowing the developer to access admin p...
8.7
Microsoft .NET Core Network Denial of Service
CVE-2026-57108
GHSA-rp2p-6cmp-jxj9
BIT-dotnet-sdk-2026-57108
An attacker can cause .NET Core servers to become unresponsive, disrupting service to users. This affects .NET Core applications, which should be updated to the latest version to prevent service disru...
7.5
Netty: Uncontrolled Resource Consumption via Malicious SPDY Headers
DEBIAN-CVE-2026-55833
A bug in Netty's SPDY header decoding could cause a malicious peer to consume excessive system resources, leading to performance issues and potential system crashes. This issue affects users of Netty ...
7.5
Netty SPDY zlib compression amplification vulnerability
CVE-2026-55833
The Netty SPDY library has a vulnerability that allows a malicious user to cause excessive CPU and memory usage by sending a compressed header that expands into a much larger amount of data. This can ...
7.5
Netty SPDY SETTINGS decoder allows large data attack
DEBIAN-CVE-2026-55831
Netty's SPDY decoder didn't limit the amount of data sent by a remote peer. This could cause a server to run low on memory and slow down, potentially leading to a denial-of-service. The issue has been...
7.5
Netty SPDY SETTINGS frame overflows and crashes the server
CVE-2026-55831
A vulnerability in Netty's SPDY protocol implementation can cause a server to run out of memory or slow down when receiving a large SETTINGS frame from a remote peer. This can happen if the server is ...
7.5
D-Link DNS-320: Unrestricted File Upload via Malicious Data
CVE-2026-16332
An unknown function in the D-Link DNS-320's multi_uploadify.php file allows attackers to upload any file without restrictions. This can lead to unauthorized access to the device and potentially compro...
5.5
D-Link DNS-320 allows unauthorized file uploads
CVE-2026-16331
A security weakness in the D-Link DNS-320 allows hackers to upload any file they want without permission, potentially leading to system compromise or data theft. This vulnerability can be exploited re...
5.5
D-Link DNS-320 allows attackers to upload files
CVE-2026-16330
An unknown function in the D-Link DNS-320's uploadify.php file allows attackers to upload files without restrictions. This could allow attackers to install malware or take control of the device. Updat...
5.5
D-Link DNS-320 allows malicious file uploads
CVE-2026-16329
A security issue affects the D-Link DNS-320, allowing hackers to upload any file they want without restrictions. This could lead to the DNS-320 being compromised or used to spread malware. To stay saf...
5.5
D-Link DNS-320: Unrestricted File Upload via Remote Attack
CVE-2026-16327
A vulnerability in the D-Link DNS-320 allows attackers to upload unauthorized files remotely. This could potentially allow hackers to install malicious software on the device. To mitigate this risk, u...
5.5
MapSVG <= 8.14.0: Administrator Can Upload Any File
CVE-2026-1771
The MapSVG plugin for WordPress allows administrators to upload any file, potentially leading to malicious code being executed on the site. This is a serious issue because it could allow an attacker t...
7.2
Zyxel AX7501-B1: Malicious Commands via Log Server
CVE-2026-6952
An attacker with admin access can run malicious commands on a Zyxel AX7501-B1 router if it's configured to send logs to a specific server. This could allow the attacker to take control of the router o...
7.2
ManageEngine ADSelfService Plus MFA Bypass
CVE-2026-3183
ManageEngine ADSelfService Plus, a self-service password reset tool, is vulnerable to a bypass of its multi-factor authentication feature. This means an attacker could potentially gain unauthorized ac...
7.1
HCL DevOps Plan Leaks Sensitive Information
CVE-2023-37507
An attacker can access sensitive information about your project or organization through HCL DevOps Plan. This can help them launch targeted attacks. To protect yourself, update HCL DevOps Plan to the ...
6.9
Red Hat Quay: Malicious Mirror Configuration Can Expose Internal Services
CVE-2026-15927
A security flaw in Red Hat Quay's mirror configuration feature allows an attacker to trick the system into accessing internal network services or cloud metadata endpoints that should not be reachable....
6.8
FeliCa IC Chips May Leak Stored Information Before 2017
CVE-2026-59776
Certain FeliCa IC chips shipped before 2017 have a security flaw that could allow unauthorized access to the information stored on the chip. This means that sensitive data, such as personal informatio...
7.0
Libssh: SFTP Server Crashes or Executes Malicious Code
CVE-2026-15370
The libssh SFTP server can crash or allow malicious code to run on the server if it's forced to list long filenames from an attacker. This could potentially be exploited by a malicious client. To prot...
6.7
TeX Live and Evince crash or code execution risk with malformed SyncTeX files
CVE-2026-63729
A security issue affects TeX Live and its embedded SyncTeX parser in Evince. If an attacker sends a corrupted SyncTeX file, it can cause the program to crash or potentially run malicious code. To stay...
6.8
Essential Addons for Elementor <= 6.6.11 - Malicious Code Injection
CVE-2026-15145
The Essential Addons for Elementor plugin has a security flaw that allows an attacker with some level of access to insert malicious code into website pages. This code can run whenever a user visits th...
6.4
Essential Addons for Elementor <= 6.6.11 - Malicious Scripts on Your Site
CVE-2026-15156
A security flaw in the Essential Addons for Elementor plugin for WordPress allows attackers with some level of access to inject malicious code on your site. This can lead to unauthorized actions or da...
6.4
itsourcecode Hospital Management System: Malicious Prescription Orders
CVE-2026-16334
A security flaw in itsourcecode Hospital Management System allows hackers to inject malicious code into the system, potentially manipulating patient information and prescriptions. This could lead to u...
2.1
Gitleaks Report Templates Can Leak Sensitive Data
CVE-2026-63728
Gitleaks before version 8.30.1 has a security flaw that allows attackers to access sensitive information, like API keys and credentials, by creating malicious report templates. This can happen if an a...
8.1
Kronosnet: Encryption Keys Left in Memory
CVE-2026-15811
A security issue affects Kronosnet versions 1.35 and earlier. If an attacker can access the memory of a Kronosnet system, they may be able to obtain the encryption keys and decrypt sensitive informati...
5.8