Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16819 | HIGH | 7.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity … | Aug 19, 2026 |
| CVE-2026-76614 | MEDIUM | 4.3 | OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler … | Aug 19, 2026 |
| CVE-2026-76203 | UNKNOWN | — | Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound … | Aug 19, 2026 |
| CVE-2026-75956 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for … | Aug 19, 2026 |
| CVE-2026-75955 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML … | Aug 19, 2026 |
| CVE-2026-75954 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 … | Aug 19, 2026 |
| CVE-2026-75953 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of … | Aug 19, 2026 |
| CVE-2026-75952 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, … | Aug 19, 2026 |
| CVE-2026-75951 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 | Aug 19, 2026 |
| CVE-2026-75950 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including … | Aug 19, 2026 |
| CVE-2026-75949 | UNKNOWN | — | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point … | Aug 19, 2026 |
| CVE-2026-71961 | HIGH | 8.8 | Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges … | Aug 19, 2026 |
| CVE-2026-71960 | CRITICAL | 9.1 | Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated … | Aug 19, 2026 |
| CVE-2026-71176 | HIGH | 8.8 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged … | Aug 19, 2026 |
| CVE-2026-67268 | MEDIUM | 6.5 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access … | Aug 19, 2026 |
| CVE-2026-67267 | MEDIUM | 5.5 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker … | Aug 19, 2026 |
| CVE-2026-67266 | MEDIUM | 5.5 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 19, 2026 |
| CVE-2026-58565 | HIGH | 8.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 19, 2026 |
| CVE-2026-58564 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this … | Aug 19, 2026 |
| CVE-2026-58562 | HIGH | 7.3 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 19, 2026 |
| CVE-2026-56797 | HIGH | 7.3 | Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 19, 2026 |
| CVE-2026-56796 | MEDIUM | 6.6 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local … | Aug 19, 2026 |
| CVE-2026-54793 | MEDIUM | 4.6 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with … | Aug 19, 2026 |
| CVE-2026-53477 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially … | Aug 19, 2026 |
| CVE-2026-53452 | MEDIUM | 5.3 | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command … | Aug 19, 2026 |