Search
3,173 CVEs
CVEs (3,173, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 3,173 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65757 | NONE | — | 2026-07-23 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data … | |
| CVE-2026-65756 | MEDIUM | 6.1 | 2026-07-23 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. | |
| CVE-2026-65755 | NONE | — | 2026-07-23 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a… | |
| CVE-2026-65754 | NONE | — | 2026-07-23 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory. | |
| CVE-2026-65713 | NONE | — | 2026-07-23 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. | |
| CVE-2026-65712 | NONE | — | 2026-07-23 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing loc… | |
| CVE-2026-65706 | HIGH | 7.8 | 2026-07-23 | FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a c… | |
| CVE-2026-65705 | HIGH | 7.8 | 2026-07-23 | FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a … | |
| CVE-2026-65704 | HIGH | 7.8 | 2026-07-23 | FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -s… | |
| CVE-2026-65703 | HIGH | 7.8 | 2026-07-23 | FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying … | |
| CVE-2026-65702 | HIGH | 8.6 | 2026-07-23 | Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write… | |
| CVE-2026-65701 | CRITICAL | 9.1 | 2026-07-23 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote att… | |
| CVE-2026-65700 | CRITICAL | 9.8 | 2026-07-23 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbi… | |
| CVE-2026-65699 | MEDIUM | 4.2 | 2026-07-23 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent ru… | |
| CVE-2026-65698 | MEDIUM | 5.3 | 2026-07-23 | Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside th… | |
| CVE-2026-65697 | MEDIUM | 6.1 | 2026-07-23 | Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javasc… | |
| CVE-2026-65696 | MEDIUM | 5.4 | 2026-07-23 | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, re… | |
| CVE-2026-65695 | MEDIUM | 6.8 | 2026-07-23 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read ar… | |
| CVE-2026-65694 | HIGH | 7.5 | 2026-07-23 | Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by … | |
| CVE-2026-65690 | HIGH | Patched | 8.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attac… |
| CVE-2026-65689 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated att… |
| CVE-2026-65688 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attac… |
| CVE-2026-65687 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attack… |
| CVE-2026-65650 | MEDIUM | Patched | 4.3 | 2026-07-22 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. |
| CVE-2026-65608 | HIGH | Patched | 8.8 | 2026-07-23 | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling c… |