Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57048
Total
4535
Critical
16933
High
16775
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92180 | HIGH | 7.8 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations … | Sep 15, 2026 |
| CVE-2026-92179 | HIGH | 7.8 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Sep 15, 2026 |
| CVE-2026-92178 | HIGH | 7.8 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Sep 15, 2026 |
| CVE-2026-92177 | HIGH | 7.8 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Sep 15, 2026 |
| CVE-2026-92176 | HIGH | 7.8 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge … | Sep 15, 2026 |
| CVE-2026-90971 | UNKNOWN | — | Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials … | Sep 15, 2026 |
| CVE-2026-90969 | UNKNOWN | — | Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain … | Sep 15, 2026 |
| CVE-2026-84850 | UNKNOWN | — | Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to … | Sep 15, 2026 |
| CVE-2026-84048 | UNKNOWN | — | Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1 - The TUS endpoint allows arbitrary file uploads, … | Sep 15, 2026 |
| CVE-2026-82191 | UNKNOWN | — | Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal … | Sep 15, 2026 |
| CVE-2026-82190 | UNKNOWN | — | Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a … | Sep 15, 2026 |
| CVE-2026-82189 | UNKNOWN | — | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: … | Sep 15, 2026 |
| CVE-2026-81924 | UNKNOWN | — | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created … | Sep 15, 2026 |
| CVE-2026-81923 | UNKNOWN | — | In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the … | Sep 15, 2026 |
| CVE-2026-81922 | UNKNOWN | — | Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the sitemap Explore dashboard controller, the send_to_top … | Sep 15, 2026 |
| CVE-2026-81921 | UNKNOWN | — | Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid … | Sep 15, 2026 |
| CVE-2026-81920 | UNKNOWN | — | Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word … | Sep 15, 2026 |
| CVE-2026-81919 | UNKNOWN | — | Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization … | Sep 15, 2026 |
| CVE-2026-81568 | UNKNOWN | — | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital … | Sep 15, 2026 |
| CVE-2026-81567 | UNKNOWN | — | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary … | Sep 15, 2026 |
| CVE-2026-79411 | UNKNOWN | — | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to … | Sep 15, 2026 |
| CVE-2026-79410 | HIGH | 8.1 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate … | Sep 15, 2026 |
| CVE-2026-79409 | MEDIUM | 6.5 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components. | Sep 15, 2026 |
| CVE-2026-78081 | UNKNOWN | — | Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a … | Sep 15, 2026 |
| CVE-2026-73467 | MEDIUM | 6.3 | On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers | Sep 15, 2026 |