Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50855
Total
4075
Critical
15116
High
14809
Medium
CVE ID Severity Score Description Published
CVE-2026-66724 UNKNOWN — MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST … Jul 29, 2026
CVE-2026-66723 UNKNOWN — MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for … Jul 29, 2026
CVE-2026-65947 UNKNOWN — Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 Jul 29, 2026
CVE-2026-65888 UNKNOWN — Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on … Jul 29, 2026
CVE-2026-65887 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing … Jul 29, 2026
CVE-2026-65886 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files. Jul 29, 2026
CVE-2026-59247 UNKNOWN — Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution. During dependency … Jul 29, 2026
CVE-2026-54666 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and … Jul 29, 2026
CVE-2026-54664 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping … Jul 29, 2026
CVE-2026-54663 MEDIUM 6.1 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to … Jul 29, 2026
CVE-2026-54662 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into … Jul 29, 2026
CVE-2026-54661 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without … Jul 29, 2026
CVE-2026-54660 HIGH 7.4 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while … Jul 29, 2026
CVE-2026-12703 HIGH 8.0 TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured … Jul 29, 2026
CVE-2026-9177 UNKNOWN — A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an … Jul 29, 2026
CVE-2026-67217 MEDIUM 5.3 cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or … Jul 29, 2026
CVE-2026-67216 MEDIUM 5.9 cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each … Jul 29, 2026
CVE-2026-67215 HIGH 7.5 cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). … Jul 29, 2026
CVE-2026-67214 MEDIUM 5.9 nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given … Jul 29, 2026
CVE-2026-67213 MEDIUM 5.9 nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, … Jul 29, 2026
CVE-2026-66490 MEDIUM 6.1 Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 Jul 29, 2026
CVE-2026-66489 UNKNOWN — Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 Jul 29, 2026
CVE-2026-66488 UNKNOWN — Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 Jul 29, 2026
CVE-2026-66400 MEDIUM 4.8 Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token … Jul 29, 2026
CVE-2026-65890 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. Jul 29, 2026