Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44895
Total
3603
Critical
13333
High
13202
Medium
CVE ID Severity Score Description Published
CVE-2026-62673 UNKNOWN Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive … Aug 19, 2026
CVE-2026-62672 UNKNOWN Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly … Aug 19, 2026
CVE-2026-62671 MEDIUM 5.4 Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level … Aug 19, 2026
CVE-2026-62670 MEDIUM 6.3 Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in … Aug 19, 2026
CVE-2026-62669 HIGH 7.4 Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that … Aug 19, 2026
CVE-2026-62668 UNKNOWN Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API … Aug 19, 2026
CVE-2026-62667 HIGH 8.1 Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API … Aug 19, 2026
CVE-2026-62666 HIGH 8.8 Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin … Aug 19, 2026
CVE-2026-61842 MEDIUM 6.5 Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, … Aug 19, 2026
CVE-2026-61690 MEDIUM 6.5 Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, file-count, or nesting-depth … Aug 19, 2026
CVE-2026-61607 MEDIUM 4.6 Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API … Aug 19, 2026
CVE-2026-53654 UNKNOWN Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an … Aug 19, 2026
CVE-2026-46343 UNKNOWN Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows … Aug 19, 2026
CVE-2026-44254 MEDIUM 5.3 Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes … Aug 19, 2026
CVE-2026-44253 MEDIUM 4.9 Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol … Aug 19, 2026
CVE-2026-44252 UNKNOWN Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only … Aug 19, 2026
CVE-2026-19672 UNKNOWN The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such … Aug 19, 2026
CVE-2026-18430 UNKNOWN HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the … Aug 19, 2026
CVE-2026-16819 HIGH 7.7 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity … Aug 19, 2026
CVE-2026-76614 MEDIUM 4.3 OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler … Aug 19, 2026
CVE-2026-76203 UNKNOWN Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound … Aug 19, 2026
CVE-2026-75956 UNKNOWN Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for … Aug 19, 2026
CVE-2026-75955 UNKNOWN Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML … Aug 19, 2026
CVE-2026-75954 UNKNOWN Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 … Aug 19, 2026
CVE-2026-75953 UNKNOWN Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of … Aug 19, 2026