Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75952 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, … | Aug 19, 2026 |
| CVE-2026-75951 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 | Aug 19, 2026 |
| CVE-2026-75950 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including … | Aug 19, 2026 |
| CVE-2026-75949 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point … | Aug 19, 2026 |
| CVE-2026-71961 | HIGH | 8.8 | Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges … | Aug 19, 2026 |
| CVE-2026-71960 | CRITICAL | 9.1 | Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated … | Aug 19, 2026 |
| CVE-2026-71176 | HIGH | 8.8 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged … | Aug 19, 2026 |
| CVE-2026-67268 | MEDIUM | 6.5 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access … | Aug 19, 2026 |
| CVE-2026-67267 | MEDIUM | 5.5 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker … | Aug 19, 2026 |
| CVE-2026-67266 | MEDIUM | 5.5 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 19, 2026 |
| CVE-2026-58565 | HIGH | 8.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 19, 2026 |
| CVE-2026-58564 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this … | Aug 19, 2026 |
| CVE-2026-58562 | HIGH | 7.3 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 19, 2026 |
| CVE-2026-56797 | HIGH | 7.3 | Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 19, 2026 |
| CVE-2026-56796 | MEDIUM | 6.6 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local … | Aug 19, 2026 |
| CVE-2026-54793 | MEDIUM | 4.6 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with … | Aug 19, 2026 |
| CVE-2026-53477 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially … | Aug 19, 2026 |
| CVE-2026-53452 | MEDIUM | 5.3 | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command … | Aug 19, 2026 |
| CVE-2026-53451 | CRITICAL | 9.8 | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command … | Aug 19, 2026 |
| CVE-2026-52889 | CRITICAL | 9.8 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer … | Aug 19, 2026 |
| CVE-2026-52834 | HIGH | 7.3 | jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform … | Aug 19, 2026 |
| CVE-2026-52792 | UNKNOWN | — | Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling filepath.Ext() without first … | Aug 19, 2026 |
| CVE-2026-50149 | MEDIUM | 6.5 | Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: … | Aug 19, 2026 |
| CVE-2026-49817 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 19, 2026 |
| CVE-2026-49816 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 19, 2026 |