Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54949
Total
4343
Critical
16375
High
16061
Medium
CVE ID Severity Score Description Published
CVE-2026-93618 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a … Sep 23, 2026
CVE-2026-93529 MEDIUM 6.5 Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions. Sep 23, 2026
CVE-2026-93527 HIGH 8.5 Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. Sep 23, 2026
CVE-2026-93526 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. Sep 23, 2026
CVE-2026-93513 MEDIUM 4.3 Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions. Sep 23, 2026
CVE-2026-93421 UNKNOWN — Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and … Sep 23, 2026
CVE-2026-92730 UNKNOWN — LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page. Sep 23, 2026
CVE-2026-92700 UNKNOWN — Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case … Sep 23, 2026
CVE-2026-92692 UNKNOWN — Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release … Sep 23, 2026
CVE-2026-92284 UNKNOWN — Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body reads the complete request body … Sep 23, 2026
CVE-2026-90905 UNKNOWN — Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core … Sep 23, 2026
CVE-2026-90904 UNKNOWN — Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php … Sep 23, 2026
CVE-2026-90903 UNKNOWN — Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated … Sep 23, 2026
CVE-2026-90902 UNKNOWN — Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) … Sep 23, 2026
CVE-2026-90901 UNKNOWN — Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest … Sep 23, 2026
CVE-2026-90900 UNKNOWN — Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint … Sep 23, 2026
CVE-2026-90899 UNKNOWN — Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest … Sep 23, 2026
CVE-2026-84502 CRITICAL 9.9 A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a … Sep 23, 2026
CVE-2026-84499 HIGH 7.7 A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as … Sep 23, 2026
CVE-2026-84486 HIGH 8.2 A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are … Sep 23, 2026
CVE-2026-84474 CRITICAL 9.9 A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate … Sep 23, 2026
CVE-2026-82368 UNKNOWN — Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. … Sep 23, 2026
CVE-2026-82356 HIGH 7.5 Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely … Sep 23, 2026
CVE-2026-77602 CRITICAL 9.9 OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator … Sep 23, 2026
CVE-2026-77601 HIGH 8.8 OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated … Sep 23, 2026