Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26387
Total
1955
Critical
7970
High
8222
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2017-20256 | HIGH | 8.2 | Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | Jun 19, 2026 |
| CVE-2017-20255 | HIGH | 8.2 | Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | Jun 19, 2026 |
| CVE-2017-20254 | HIGH | 8.2 | Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | Jun 19, 2026 |
| CVE-2017-20253 | HIGH | 8.2 | Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | Jun 19, 2026 |
| CVE-2017-20252 | HIGH | 8.2 | Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send … | Jun 19, 2026 |
| CVE-2026-52910 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below … | Jun 19, 2026 |
| CVE-2026-52909 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus reported that vti6_init_net() does … | Jun 19, 2026 |
| CVE-2026-52908 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW … | Jun 19, 2026 |
| CVE-2026-49358 | LOW | 3.0 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and … | Jun 19, 2026 |
| CVE-2026-21768 | MEDIUM | 6.3 | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content … | Jun 19, 2026 |
| CVE-2025-71326 | HIGH | 7.8 | AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. … | Jun 19, 2026 |
| CVE-2023-54353 | HIGH | 7.8 | Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted … | Jun 19, 2026 |
| CVE-2022-50971 | HIGH | 7.8 | Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the … | Jun 19, 2026 |
| CVE-2021-47985 | HIGH | 7.8 | Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a … | Jun 19, 2026 |
| CVE-2020-37254 | HIGH | 7.8 | Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious … | Jun 19, 2026 |
| CVE-2020-37253 | HIGH | 7.8 | Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables … | Jun 19, 2026 |
| CVE-2020-37252 | HIGH | 7.8 | Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can … | Jun 19, 2026 |
| CVE-2020-37251 | HIGH | 7.8 | RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious … | Jun 19, 2026 |
| CVE-2020-37250 | HIGH | 7.8 | TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. … | Jun 19, 2026 |
| CVE-2019-25747 | HIGH | 7.8 | Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in … | Jun 19, 2026 |
| CVE-2016-20095 | HIGH | 7.8 | Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code … | Jun 19, 2026 |
| CVE-2016-20094 | HIGH | 7.8 | AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers … | Jun 19, 2026 |
| CVE-2016-20093 | HIGH | 7.8 | Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users … | Jun 19, 2026 |
| CVE-2016-20092 | HIGH | 7.8 | NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can … | Jun 19, 2026 |
| CVE-2016-20091 | HIGH | 7.8 | Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. … | Jun 19, 2026 |