Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64194 | UNKNOWN | — | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into … | Jul 20, 2026 |
| CVE-2026-64193 | UNKNOWN | — | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC … | Jul 20, 2026 |
| CVE-2026-63771 | HIGH | 7.1 | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header … | Jul 20, 2026 |
| CVE-2026-63770 | HIGH | 7.5 | Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary … | Jul 20, 2026 |
| CVE-2026-63769 | HIGH | 7.7 | Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by … | Jul 20, 2026 |
| CVE-2026-63768 | MEDIUM | 4.3 | cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting … | Jul 20, 2026 |
| CVE-2026-63731 | HIGH | 7.7 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a … | Jul 20, 2026 |
| CVE-2026-63730 | MEDIUM | 5.0 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network … | Jul 20, 2026 |
| CVE-2026-63108 | HIGH | 8.8 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions … | Jul 20, 2026 |
| CVE-2026-63107 | HIGH | 7.7 | LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the … | Jul 20, 2026 |
| CVE-2026-62414 | UNKNOWN | — | The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | Jul 20, 2026 |
| CVE-2026-61901 | UNKNOWN | — | The Joomla extension Hikashop is vulnerable to an open redirect. | Jul 20, 2026 |
| CVE-2026-61900 | UNKNOWN | — | The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. | Jul 20, 2026 |
| CVE-2026-61425 | UNKNOWN | — | The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. | Jul 20, 2026 |
| CVE-2026-61424 | UNKNOWN | — | The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. | Jul 20, 2026 |
| CVE-2026-60034 | UNKNOWN | — | The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS. | Jul 20, 2026 |
| CVE-2026-60033 | UNKNOWN | — | The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses. | Jul 20, 2026 |
| CVE-2026-60032 | UNKNOWN | — | The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute … | Jul 20, 2026 |
| CVE-2026-60031 | UNKNOWN | — | The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses. | Jul 20, 2026 |
| CVE-2026-60030 | UNKNOWN | — | The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management … | Jul 20, 2026 |
| CVE-2026-60029 | UNKNOWN | — | The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that … | Jul 20, 2026 |
| CVE-2026-60028 | UNKNOWN | — | The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor … | Jul 20, 2026 |
| CVE-2026-60027 | UNKNOWN | — | The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths … | Jul 20, 2026 |
| CVE-2026-60026 | UNKNOWN | — | The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element … | Jul 20, 2026 |
| CVE-2026-48389 | HIGH | 7.8 | DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context … | Jul 20, 2026 |