Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78064 | UNKNOWN | — | Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the `carts` view's tasks … | Sep 03, 2026 |
| CVE-2026-78000 | UNKNOWN | — | Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL … | Sep 03, 2026 |
| CVE-2026-77999 | UNKNOWN | — | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature … | Sep 03, 2026 |
| CVE-2026-76642 | HIGH | 7.8 | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on … | Sep 03, 2026 |
| CVE-2026-76178 | UNKNOWN | — | A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content … | Sep 03, 2026 |
| CVE-2026-76177 | UNKNOWN | — | Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges … | Sep 03, 2026 |
| CVE-2026-76176 | UNKNOWN | — | SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated … | Sep 03, 2026 |
| CVE-2026-76175 | UNKNOWN | — | SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL … | Sep 03, 2026 |
| CVE-2026-76174 | UNKNOWN | — | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided … | Sep 03, 2026 |
| CVE-2026-74769 | MEDIUM | 6.5 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit … | Sep 03, 2026 |
| CVE-2026-74768 | MEDIUM | 4.1 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could … | Sep 03, 2026 |
| CVE-2026-73600 | HIGH | 7.8 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially … | Sep 03, 2026 |
| CVE-2026-71224 | MEDIUM | 4.7 | A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata … | Sep 03, 2026 |
| CVE-2026-71222 | MEDIUM | 5.3 | A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap … | Sep 03, 2026 |
| CVE-2026-71221 | HIGH | 7.0 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without … | Sep 03, 2026 |
| CVE-2026-71220 | HIGH | 7.0 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without … | Sep 03, 2026 |
| CVE-2026-71219 | MEDIUM | 4.7 | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk … | Sep 03, 2026 |
| CVE-2026-68860 | MEDIUM | 6.8 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading … | Sep 03, 2026 |
| CVE-2026-3852 | MEDIUM | 6.4 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions … | Sep 03, 2026 |
| CVE-2026-3416 | MEDIUM | 5.9 | The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy … | Sep 03, 2026 |
| CVE-2026-2573 | MEDIUM | 6.4 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCss’ … | Sep 03, 2026 |
| CVE-2026-17539 | MEDIUM | 5.9 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry … | Sep 03, 2026 |
| CVE-2026-15933 | UNKNOWN | — | OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), … | Sep 03, 2026 |
| CVE-2026-15926 | UNKNOWN | — | Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed | Sep 03, 2026 |
| CVE-2021-43614 | MEDIUM | 6.7 | Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure. | Sep 03, 2026 |