Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54274
Total
4303
Critical
16132
High
15830
Medium
CVE ID Severity Score Description Published
CVE-2026-90918 UNKNOWN — Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, … Sep 29, 2026
CVE-2026-90917 UNKNOWN — Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows … Sep 29, 2026
CVE-2026-90916 UNKNOWN — Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows … Sep 29, 2026
CVE-2026-90915 UNKNOWN — Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group … Sep 29, 2026
CVE-2026-90914 UNKNOWN — Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an … Sep 29, 2026
CVE-2026-90913 UNKNOWN — Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows … Sep 29, 2026
CVE-2026-90907 UNKNOWN — Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check … Sep 29, 2026
CVE-2026-90906 UNKNOWN — Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method … Sep 29, 2026
CVE-2026-102796 UNKNOWN — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue … Sep 29, 2026
CVE-2026-102697 HIGH 7.8 Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell … Sep 29, 2026
CVE-2026-102676 HIGH 8.3 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest … Sep 29, 2026
CVE-2026-102675 HIGH 7.4 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol … Sep 29, 2026
CVE-2026-102674 HIGH 8.2 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a … Sep 29, 2026
CVE-2026-102673 HIGH 8.2 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed … Sep 29, 2026
CVE-2026-102635 LOW 3.7 ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF … Sep 29, 2026
CVE-2026-102634 HIGH 7.5 SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send … Sep 29, 2026
CVE-2026-102633 MEDIUM 5.9 libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to … Sep 29, 2026
CVE-2026-102623 MEDIUM 6.5 A flaw was found in KubeVirt. An authenticated user with permission to create Virtual Machine Instances (VMIs) can cause a Denial of Service (DoS) by … Sep 29, 2026
CVE-2026-102557 HIGH 8.6 A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits … Sep 29, 2026
CVE-2026-102556 HIGH 8.6 A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the … Sep 29, 2026
CVE-2026-102425 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs … Sep 29, 2026
CVE-2026-102424 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state … Sep 29, 2026
CVE-2026-101127 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's … Sep 29, 2026
CVE-2026-101126 UNKNOWN — Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, … Sep 29, 2026
CVE-2026-101112 UNKNOWN — Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and … Sep 29, 2026