Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54949
Total
4343
Critical
16375
High
16061
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93618 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a … | Sep 23, 2026 |
| CVE-2026-93529 | MEDIUM | 6.5 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. | Sep 23, 2026 |
| CVE-2026-93527 | HIGH | 8.5 | Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. | Sep 23, 2026 |
| CVE-2026-93526 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. | Sep 23, 2026 |
| CVE-2026-93513 | MEDIUM | 4.3 | Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions. | Sep 23, 2026 |
| CVE-2026-93421 | UNKNOWN | — | Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and … | Sep 23, 2026 |
| CVE-2026-92730 | UNKNOWN | — | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page. | Sep 23, 2026 |
| CVE-2026-92700 | UNKNOWN | — | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case … | Sep 23, 2026 |
| CVE-2026-92692 | UNKNOWN | — | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release … | Sep 23, 2026 |
| CVE-2026-92284 | UNKNOWN | — | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body reads the complete request body … | Sep 23, 2026 |
| CVE-2026-90905 | UNKNOWN | — | Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core … | Sep 23, 2026 |
| CVE-2026-90904 | UNKNOWN | — | Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php … | Sep 23, 2026 |
| CVE-2026-90903 | UNKNOWN | — | Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated … | Sep 23, 2026 |
| CVE-2026-90902 | UNKNOWN | — | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) … | Sep 23, 2026 |
| CVE-2026-90901 | UNKNOWN | — | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest … | Sep 23, 2026 |
| CVE-2026-90900 | UNKNOWN | — | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint … | Sep 23, 2026 |
| CVE-2026-90899 | UNKNOWN | — | Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest … | Sep 23, 2026 |
| CVE-2026-84502 | CRITICAL | 9.9 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a … | Sep 23, 2026 |
| CVE-2026-84499 | HIGH | 7.7 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as … | Sep 23, 2026 |
| CVE-2026-84486 | HIGH | 8.2 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are … | Sep 23, 2026 |
| CVE-2026-84474 | CRITICAL | 9.9 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate … | Sep 23, 2026 |
| CVE-2026-82368 | UNKNOWN | — | Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. … | Sep 23, 2026 |
| CVE-2026-82356 | HIGH | 7.5 | Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely … | Sep 23, 2026 |
| CVE-2026-77602 | CRITICAL | 9.9 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator … | Sep 23, 2026 |
| CVE-2026-77601 | HIGH | 8.8 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated … | Sep 23, 2026 |