Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74592 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate hooks Instantiate the file_truncate and path_truncate LSM hooks to reset … | Aug 22, 2026 |
| CVE-2026-74591 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index before retrying In __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is applied repeatedly: each … | Aug 22, 2026 |
| CVE-2026-74590 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions The BPF verifier and the dynptr abstraction ensure that the … | Aug 22, 2026 |
| CVE-2026-74589 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix sk_redir use-after-free in send verdict sk_psock_msg_verdict() takes a socket reference for psock->sk_redir. … | Aug 22, 2026 |
| CVE-2026-74588 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list it is queued on __sctp_outq_flush_rtx() moves a … | Aug 22, 2026 |
| CVE-2026-74587 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk addip_last_asconf caches the outstanding outbound ASCONF chunk. The … | Aug 22, 2026 |
| CVE-2026-74586 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in … | Aug 22, 2026 |
| CVE-2026-74585 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound the DROM dual link port number before indexing sw->ports tb_drom_parse_entry_port() validates the device-supplied … | Aug 22, 2026 |
| CVE-2026-4703 | CRITICAL | 9.8 | The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, … | Aug 22, 2026 |
| CVE-2026-77992 | UNKNOWN | — | Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access … | Aug 22, 2026 |
| CVE-2026-77027 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to … | Aug 22, 2026 |
| CVE-2026-76609 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks. | Aug 22, 2026 |
| CVE-2026-76608 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access … | Aug 22, 2026 |
| CVE-2026-76607 | UNKNOWN | — | Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???. | Aug 22, 2026 |
| CVE-2026-76606 | UNKNOWN | — | Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???. | Aug 22, 2026 |
| CVE-2026-76605 | UNKNOWN | — | Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???. | Aug 22, 2026 |
| CVE-2026-76604 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to … | Aug 22, 2026 |
| CVE-2026-76603 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.3 - The inineedit form controller does not perform any access checks, … | Aug 22, 2026 |
| CVE-2026-76602 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in … | Aug 22, 2026 |
| CVE-2026-76601 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks. | Aug 22, 2026 |
| CVE-2026-76600 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks. | Aug 22, 2026 |
| CVE-2026-76599 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows … | Aug 22, 2026 |
| CVE-2026-76598 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary … | Aug 22, 2026 |
| CVE-2026-76597 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin … | Aug 22, 2026 |
| CVE-2026-76596 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET … | Aug 22, 2026 |