Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-30865 | HIGH | 7.1 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save … | Aug 21, 2026 |
| CVE-2026-30826 | HIGH | 8.0 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL … | Aug 21, 2026 |
| CVE-2026-77810 | CRITICAL | 9.9 | In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute … | Aug 21, 2026 |
| CVE-2026-76876 | MEDIUM | 5.9 | Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the … | Aug 21, 2026 |
| CVE-2026-74252 | UNKNOWN | — | Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) … | Aug 21, 2026 |
| CVE-2026-67362 | UNKNOWN | — | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user … | Aug 21, 2026 |
| CVE-2026-67361 | UNKNOWN | — | Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests … | Aug 21, 2026 |
| CVE-2026-67360 | UNKNOWN | — | Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their … | Aug 21, 2026 |
| CVE-2026-67359 | UNKNOWN | — | Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to … | Aug 21, 2026 |
| CVE-2026-67358 | UNKNOWN | — | Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the … | Aug 21, 2026 |
| CVE-2026-62960 | HIGH | 7.4 | Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), … | Aug 21, 2026 |
| CVE-2026-50290 | UNKNOWN | — | SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be … | Aug 21, 2026 |
| CVE-2026-50288 | UNKNOWN | — | SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, … | Aug 21, 2026 |
| CVE-2026-30866 | HIGH | 7.5 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has … | Aug 21, 2026 |
| CVE-2026-30819 | HIGH | 7.3 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert … | Aug 21, 2026 |
| CVE-2026-27490 | HIGH | 7.5 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a … | Aug 21, 2026 |
| CVE-2026-27463 | MEDIUM | 5.3 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains … | Aug 21, 2026 |
| CVE-2026-27462 | HIGH | 7.5 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in … | Aug 21, 2026 |
| CVE-2026-77795 | MEDIUM | 6.3 | A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to … | Aug 21, 2026 |
| CVE-2026-63466 | MEDIUM | 4.1 | Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templates. … | Aug 21, 2026 |
| CVE-2026-63462 | HIGH | 7.5 | Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request … | Aug 21, 2026 |
| CVE-2026-63004 | MEDIUM | 5.5 | Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts … | Aug 21, 2026 |
| CVE-2026-56875 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 21, 2026 |
| CVE-2026-55850 | UNKNOWN | — | Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML … | Aug 21, 2026 |
| CVE-2026-54682 | HIGH | 8.2 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync … | Aug 21, 2026 |