Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44750
Total
3597
Critical
13289
High
13145
Medium
CVE ID Severity Score Description Published
CVE-2026-30865 HIGH 7.1 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save … Aug 21, 2026
CVE-2026-30826 HIGH 8.0 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL … Aug 21, 2026
CVE-2026-77810 CRITICAL 9.9 In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute … Aug 21, 2026
CVE-2026-76876 MEDIUM 5.9 Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the … Aug 21, 2026
CVE-2026-74252 UNKNOWN Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) … Aug 21, 2026
CVE-2026-67362 UNKNOWN Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user … Aug 21, 2026
CVE-2026-67361 UNKNOWN Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests … Aug 21, 2026
CVE-2026-67360 UNKNOWN Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their … Aug 21, 2026
CVE-2026-67359 UNKNOWN Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to … Aug 21, 2026
CVE-2026-67358 UNKNOWN Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the … Aug 21, 2026
CVE-2026-62960 HIGH 7.4 Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), … Aug 21, 2026
CVE-2026-50290 UNKNOWN SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be … Aug 21, 2026
CVE-2026-50288 UNKNOWN SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, … Aug 21, 2026
CVE-2026-30866 HIGH 7.5 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has … Aug 21, 2026
CVE-2026-30819 HIGH 7.3 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert … Aug 21, 2026
CVE-2026-27490 HIGH 7.5 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a … Aug 21, 2026
CVE-2026-27463 MEDIUM 5.3 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains … Aug 21, 2026
CVE-2026-27462 HIGH 7.5 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in … Aug 21, 2026
CVE-2026-77795 MEDIUM 6.3 A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to … Aug 21, 2026
CVE-2026-63466 MEDIUM 4.1 Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templates. … Aug 21, 2026
CVE-2026-63462 HIGH 7.5 Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request … Aug 21, 2026
CVE-2026-63004 MEDIUM 5.5 Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts … Aug 21, 2026
CVE-2026-56875 UNKNOWN Rejected reason: reserved but not needed Aug 21, 2026
CVE-2026-55850 UNKNOWN Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML … Aug 21, 2026
CVE-2026-54682 HIGH 8.2 DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync … Aug 21, 2026