Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57048
Total
4535
Critical
16933
High
16775
Medium
CVE ID Severity Score Description Published
CVE-2026-92180 HIGH 7.8 pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations … Sep 15, 2026
CVE-2026-92179 HIGH 7.8 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … Sep 15, 2026
CVE-2026-92178 HIGH 7.8 pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … Sep 15, 2026
CVE-2026-92177 HIGH 7.8 pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … Sep 15, 2026
CVE-2026-92176 HIGH 7.8 pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge … Sep 15, 2026
CVE-2026-90971 UNKNOWN — Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials … Sep 15, 2026
CVE-2026-90969 UNKNOWN — Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain … Sep 15, 2026
CVE-2026-84850 UNKNOWN — Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to … Sep 15, 2026
CVE-2026-84048 UNKNOWN — Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1 - The TUS endpoint allows arbitrary file uploads, … Sep 15, 2026
CVE-2026-82191 UNKNOWN — Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal … Sep 15, 2026
CVE-2026-82190 UNKNOWN — Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a … Sep 15, 2026
CVE-2026-82189 UNKNOWN — Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: … Sep 15, 2026
CVE-2026-81924 UNKNOWN — Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created … Sep 15, 2026
CVE-2026-81923 UNKNOWN — In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the … Sep 15, 2026
CVE-2026-81922 UNKNOWN — Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the sitemap Explore dashboard controller, the send_to_top … Sep 15, 2026
CVE-2026-81921 UNKNOWN — Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid … Sep 15, 2026
CVE-2026-81920 UNKNOWN — Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word … Sep 15, 2026
CVE-2026-81919 UNKNOWN — Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization … Sep 15, 2026
CVE-2026-81568 UNKNOWN — Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital … Sep 15, 2026
CVE-2026-81567 UNKNOWN — Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary … Sep 15, 2026
CVE-2026-79411 UNKNOWN — Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to … Sep 15, 2026
CVE-2026-79410 HIGH 8.1 Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate … Sep 15, 2026
CVE-2026-79409 MEDIUM 6.5 An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components. Sep 15, 2026
CVE-2026-78081 UNKNOWN — Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a … Sep 15, 2026
CVE-2026-73467 MEDIUM 6.3 On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers Sep 15, 2026