Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44895
Total
3603
Critical
13333
High
13202
Medium
CVE ID Severity Score Description Published
CVE-2026-75952 UNKNOWN Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, … Aug 19, 2026
CVE-2026-75951 UNKNOWN Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 Aug 19, 2026
CVE-2026-75950 UNKNOWN Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including … Aug 19, 2026
CVE-2026-75949 UNKNOWN Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point … Aug 19, 2026
CVE-2026-71961 HIGH 8.8 Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges … Aug 19, 2026
CVE-2026-71960 CRITICAL 9.1 Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated … Aug 19, 2026
CVE-2026-71176 HIGH 8.8 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged … Aug 19, 2026
CVE-2026-67268 MEDIUM 6.5 Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access … Aug 19, 2026
CVE-2026-67267 MEDIUM 5.5 Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker … Aug 19, 2026
CVE-2026-67266 MEDIUM 5.5 Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … Aug 19, 2026
CVE-2026-58565 HIGH 8.8 Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … Aug 19, 2026
CVE-2026-58564 HIGH 7.8 Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this … Aug 19, 2026
CVE-2026-58562 HIGH 7.3 Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … Aug 19, 2026
CVE-2026-56797 HIGH 7.3 Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit … Aug 19, 2026
CVE-2026-56796 MEDIUM 6.6 Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local … Aug 19, 2026
CVE-2026-54793 MEDIUM 4.6 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with … Aug 19, 2026
CVE-2026-53477 HIGH 7.8 Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially … Aug 19, 2026
CVE-2026-53452 MEDIUM 5.3 Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command … Aug 19, 2026
CVE-2026-53451 CRITICAL 9.8 Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command … Aug 19, 2026
CVE-2026-52889 CRITICAL 9.8 Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer … Aug 19, 2026
CVE-2026-52834 HIGH 7.3 jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform … Aug 19, 2026
CVE-2026-52792 UNKNOWN Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling filepath.Ext() without first … Aug 19, 2026
CVE-2026-50149 MEDIUM 6.5 Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: … Aug 19, 2026
CVE-2026-49817 HIGH 7.8 Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … Aug 19, 2026
CVE-2026-49816 HIGH 7.8 Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … Aug 19, 2026