Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,831 CVEs

CVEs (9,831, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 9,831 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-65762 NONE — 2026-07-23 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-65761 NONE — 2026-07-23 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated S…
CVE-2026-65760 NONE — 2026-07-23 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in us…
CVE-2026-65759 NONE — 2026-07-23 Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, ar…
CVE-2026-65758 NONE — 2026-07-23 Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenti…
CVE-2026-65757 NONE — 2026-07-23 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data …
CVE-2026-65756 MEDIUM 6.1 2026-07-23 Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.
CVE-2026-65755 NONE — 2026-07-23 Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a…
CVE-2026-65754 NONE — 2026-07-23 Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
CVE-2026-65713 NONE — 2026-07-23 Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.
CVE-2026-65712 NONE — 2026-07-23 Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing loc…
CVE-2026-65706 HIGH 7.8 2026-07-23 FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a c…
CVE-2026-65705 HIGH 7.8 2026-07-23 FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a …
CVE-2026-65704 HIGH 7.8 2026-07-23 FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -s…
CVE-2026-65703 HIGH 7.8 2026-07-23 FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying …
CVE-2026-65702 HIGH 8.6 2026-07-23 Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write…
CVE-2026-65701 CRITICAL 9.1 2026-07-23 SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote att…
CVE-2026-65700 CRITICAL 9.8 2026-07-23 h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbi…
CVE-2026-65699 MEDIUM 4.2 2026-07-23 AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent ru…
CVE-2026-65698 MEDIUM 5.3 2026-07-23 Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside th…
CVE-2026-65697 MEDIUM 6.1 2026-07-23 Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javasc…
CVE-2026-65696 MEDIUM 5.4 2026-07-23 Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, re…
CVE-2026-65695 MEDIUM 6.8 2026-07-23 Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read ar…
CVE-2026-65694 HIGH 7.5 2026-07-23 Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by …
CVE-2026-65690 HIGH Patched 8.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attac…