Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51763
Total
4101
Critical
15352
High
15010
Medium
CVE ID Severity Score Description Published
CVE-2026-64194 UNKNOWN — Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into … Jul 20, 2026
CVE-2026-64193 UNKNOWN — Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC … Jul 20, 2026
CVE-2026-63771 HIGH 7.1 Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header … Jul 20, 2026
CVE-2026-63770 HIGH 7.5 Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary … Jul 20, 2026
CVE-2026-63769 HIGH 7.7 Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by … Jul 20, 2026
CVE-2026-63768 MEDIUM 4.3 cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting … Jul 20, 2026
CVE-2026-63731 HIGH 7.7 HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a … Jul 20, 2026
CVE-2026-63730 MEDIUM 5.0 HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network … Jul 20, 2026
CVE-2026-63108 HIGH 8.8 Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions … Jul 20, 2026
CVE-2026-63107 HIGH 7.7 LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the … Jul 20, 2026
CVE-2026-62414 UNKNOWN — The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. Jul 20, 2026
CVE-2026-61901 UNKNOWN — The Joomla extension Hikashop is vulnerable to an open redirect. Jul 20, 2026
CVE-2026-61900 UNKNOWN — The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. Jul 20, 2026
CVE-2026-61425 UNKNOWN — The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access. Jul 20, 2026
CVE-2026-61424 UNKNOWN — The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. Jul 20, 2026
CVE-2026-60034 UNKNOWN — The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS. Jul 20, 2026
CVE-2026-60033 UNKNOWN — The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses. Jul 20, 2026
CVE-2026-60032 UNKNOWN — The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute … Jul 20, 2026
CVE-2026-60031 UNKNOWN — The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses. Jul 20, 2026
CVE-2026-60030 UNKNOWN — The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management … Jul 20, 2026
CVE-2026-60029 UNKNOWN — The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that … Jul 20, 2026
CVE-2026-60028 UNKNOWN — The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor … Jul 20, 2026
CVE-2026-60027 UNKNOWN — The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths … Jul 20, 2026
CVE-2026-60026 UNKNOWN — The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element … Jul 20, 2026
CVE-2026-48389 HIGH 7.8 DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context … Jul 20, 2026