Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50663
Total
4071
Critical
15059
High
14768
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67215 | HIGH | 7.5 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). … | Jul 29, 2026 |
| CVE-2026-67214 | MEDIUM | 5.9 | nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given … | Jul 29, 2026 |
| CVE-2026-67213 | MEDIUM | 5.9 | nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, … | Jul 29, 2026 |
| CVE-2026-66490 | MEDIUM | 6.1 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | Jul 29, 2026 |
| CVE-2026-66489 | UNKNOWN | — | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 | Jul 29, 2026 |
| CVE-2026-66488 | UNKNOWN | — | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | Jul 29, 2026 |
| CVE-2026-66400 | MEDIUM | 4.8 | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token … | Jul 29, 2026 |
| CVE-2026-65890 | UNKNOWN | — | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. | Jul 29, 2026 |
| CVE-2026-65889 | UNKNOWN | — | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories. | Jul 29, 2026 |
| CVE-2026-55995 | UNKNOWN | — | A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb. | Jul 29, 2026 |
| CVE-2026-18174 | MEDIUM | 5.3 | @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims … | Jul 29, 2026 |
| CVE-2026-16751 | UNKNOWN | — | Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to … | Jul 29, 2026 |
| CVE-2026-65946 | MEDIUM | 6.1 | Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | Jul 29, 2026 |
| CVE-2026-65944 | UNKNOWN | — | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | Jul 29, 2026 |
| CVE-2026-65943 | HIGH | 7.5 | Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0 | Jul 29, 2026 |
| CVE-2026-65891 | UNKNOWN | — | Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper … | Jul 29, 2026 |
| CVE-2026-65885 | UNKNOWN | — | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns … | Jul 29, 2026 |
| CVE-2026-65884 | UNKNOWN | — | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register … | Jul 29, 2026 |
| CVE-2026-50641 | UNKNOWN | — | Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to … | Jul 29, 2026 |
| CVE-2026-44944 | UNKNOWN | — | An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. | Jul 29, 2026 |
| CVE-2026-44943 | UNKNOWN | — | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the … | Jul 29, 2026 |
| CVE-2026-33385 | UNKNOWN | — | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel … | Jul 29, 2026 |
| CVE-2026-14354 | UNKNOWN | — | CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local … | Jul 29, 2026 |
| CVE-2026-12927 | UNKNOWN | — | CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to … | Jul 29, 2026 |
| CVE-2026-0667 | UNKNOWN | — | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when … | Jul 29, 2026 |