Retour aux CVE tendances

Semaine du 20 juillet 2026

CVE tendances* des 7 derniers jours (du 13 juillet 2026 au 20 juillet 2026)

1
CVE-2026-63030Wordpress / Wordpress
Nouveau
Score SYRN97
CVSS9.8
Activité127
Publié17/07/2026
StatutTrès actif

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

2
CVE-2026-15409Sonicwall / Sma6210 Firmware
NouveauKEV
Score SYRN98
CVSS10.0
Activité107
Publié14/07/2026
StatutTrès actif

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

3
CVE-2026-60137Wordpress / Wordpress
Nouveau
Score SYRN96
CVSS5.9
Activité90
Publié17/07/2026
StatutTrès actif

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

4
CVE-2026-15410Sonicwall / Sma6210 Firmware
NouveauKEV
Score SYRN96
CVSS7.2
Activité67
Publié14/07/2026
StatutTrès actif

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

5
CVE-2026-56164Microsoft / Microsoft SharePoint
NouveauKEV
Score SYRN95
CVSS5.3
Activité67
Publié14/07/2026
StatutTrès actif

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

6
CVE-2026-58644Microsoft / Microsoft SharePoint
NouveauKEV
Score SYRN96
CVSS9.8
Activité63
Publié14/07/2026
StatutTrès actif

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

7
CVE-2026-46817Oracle / E-Business Suite
KEV
Score SYRN97
CVSS9.8
Activité50
Publié28/05/2026
StatutTrès actif

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

8
CVE-2026-43499Linux / Linux Kernel
Score SYRN62
CVSS7.8
Activité49
Publié21/05/2026
StatutTrès actif

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]

9
CVE-2026-56155Microsoft / Microsoft Windows
NouveauKEV
Score SYRN90
CVSS7.8
Activité42
Publié14/07/2026
StatutTrès actif

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

10
CVE-2026-53412Zoom Communications / Zoom Workplace For Windows
Nouveau
Score SYRN50
CVSS9.8
Activité40
Publié16/07/2026
StatutTrès actif

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement