Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41987
Total
3420
Critical
12405
High
12324
Medium
CVE ID Severity Score Description Published
CVE-2026-78064 UNKNOWN Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the `carts` view's tasks … Sep 03, 2026
CVE-2026-78000 UNKNOWN Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL … Sep 03, 2026
CVE-2026-77999 UNKNOWN Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature … Sep 03, 2026
CVE-2026-76642 HIGH 7.8 util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on … Sep 03, 2026
CVE-2026-76178 UNKNOWN A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content … Sep 03, 2026
CVE-2026-76177 UNKNOWN Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges … Sep 03, 2026
CVE-2026-76176 UNKNOWN SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated … Sep 03, 2026
CVE-2026-76175 UNKNOWN SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL … Sep 03, 2026
CVE-2026-76174 UNKNOWN Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided … Sep 03, 2026
CVE-2026-74769 MEDIUM 6.5 Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit … Sep 03, 2026
CVE-2026-74768 MEDIUM 4.1 Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could … Sep 03, 2026
CVE-2026-73600 HIGH 7.8 Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially … Sep 03, 2026
CVE-2026-71224 MEDIUM 4.7 A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata … Sep 03, 2026
CVE-2026-71222 MEDIUM 5.3 A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap … Sep 03, 2026
CVE-2026-71221 HIGH 7.0 A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without … Sep 03, 2026
CVE-2026-71220 HIGH 7.0 A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without … Sep 03, 2026
CVE-2026-71219 MEDIUM 4.7 A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk … Sep 03, 2026
CVE-2026-68860 MEDIUM 6.8 Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading … Sep 03, 2026
CVE-2026-3852 MEDIUM 6.4 The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions … Sep 03, 2026
CVE-2026-3416 MEDIUM 5.9 The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy … Sep 03, 2026
CVE-2026-2573 MEDIUM 6.4 The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCss’ … Sep 03, 2026
CVE-2026-17539 MEDIUM 5.9 RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry … Sep 03, 2026
CVE-2026-15933 UNKNOWN OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), … Sep 03, 2026
CVE-2026-15926 UNKNOWN Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed Sep 03, 2026
CVE-2021-43614 MEDIUM 6.7 Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure. Sep 03, 2026