Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73347 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | Aug 19, 2026 |
| CVE-2026-73185 | CRITICAL | 9.3 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | Aug 19, 2026 |
| CVE-2026-73184 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. | Aug 19, 2026 |
| CVE-2026-73183 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | Aug 19, 2026 |
| CVE-2026-73182 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. | Aug 19, 2026 |
| CVE-2026-67364 | UNKNOWN | — | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The … | Aug 19, 2026 |
| CVE-2026-67363 | UNKNOWN | — | Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from … | Aug 19, 2026 |
| CVE-2026-66668 | HIGH | 8.5 | Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. | Aug 19, 2026 |
| CVE-2026-66613 | CRITICAL | 9.8 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | Aug 19, 2026 |
| CVE-2026-66596 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. | Aug 19, 2026 |
| CVE-2026-61986 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. | Aug 19, 2026 |
| CVE-2026-32552 | HIGH | 8.5 | Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | Aug 19, 2026 |
| CVE-2026-19490 | UNKNOWN | — | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 … | Aug 19, 2026 |
| CVE-2026-19489 | UNKNOWN | — | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 … | Aug 19, 2026 |
| CVE-2026-18372 | UNKNOWN | — | CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other … | Aug 19, 2026 |
| CVE-2026-18371 | UNKNOWN | — | HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users. | Aug 19, 2026 |
| CVE-2026-16440 | UNKNOWN | — | In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault. | Aug 19, 2026 |
| CVE-2026-76166 | MEDIUM | 4.3 | A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" … | Aug 19, 2026 |
| CVE-2026-76164 | UNKNOWN | — | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can … | Aug 19, 2026 |
| CVE-2026-75900 | MEDIUM | 6.1 | An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead … | Aug 19, 2026 |
| CVE-2026-75589 | UNKNOWN | — | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature … | Aug 19, 2026 |
| CVE-2026-72889 | UNKNOWN | — | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method … | Aug 19, 2026 |
| CVE-2026-58088 | HIGH | 7.4 | The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the … | Aug 19, 2026 |
| CVE-2026-58087 | HIGH | 7.8 | The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer … | Aug 19, 2026 |
| CVE-2026-58086 | UNKNOWN | — | As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root … | Aug 19, 2026 |