Total CVEs

150,798

Critical Severity

4,991

High Severity

17,614

Last 7 Days

2,022
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,081 - 2,100 of 47,203 CVEs

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.

Vendor: phoca.cz
Product: Phoca Guestbook extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65702 HIGH - 8.6

Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from outside the intended store...

Vendor: vanna-ai
Product: vanna
Published: Jul 23, 2026
Source: NVD
CVE-2026-65701 CRITICAL - 9.1

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the audio_path field of ...

Vendor: svc-develop-team
Product: so-vits-svc
Published: Jul 23, 2026
Source: NVD
CVE-2026-65700 CRITICAL - 9.8

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The get_user_dir function in ...

Vendor: h2oai
Product: h2ogpt
Published: Jul 23, 2026
Source: NVD
CVE-2026-65699 MEDIUM - 4.2

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_t...

Vendor: reworkd
Product: AgentGPT
Published: Jul 23, 2026
Source: NVD
CVE-2026-47769 MEDIUM - 5.3

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverSlug/:eventName` endpoint accepts arbitrary unauthenticated JSON and stores it in Redis and the `webho...

Vendor: Work90210
Product: APIFold
Published: Jul 23, 2026
Source: NVD
CVE-2026-47755 MEDIUM - 6.5

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with a...

Vendor: itflow-org
Product: itflow
Published: Jul 23, 2026
Source: NVD
CVE-2026-47752 CRITICAL - 9.9

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed `jinja2.Environment`, a...

Vendor: Quenary
Product: tugtainer
Published: Jul 23, 2026
Source: NVD

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

Vendor: joomshaper.com
Product: Easy Store extension for Joomla
Published: Jul 23, 2026
Source: NVD

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

Vendor: joomshaper.com
Product: Easy Store extension for Joomla
Published: Jul 23, 2026
Source: NVD

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orde...

Vendor: joomshaper.com
Product: Easy Store extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65698 MEDIUM - 5.3

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecting instructions into content the agent processes. Attackers can supply absolute paths or file:// URIs...

Vendor: voideditor
Product: void
Published: Jul 23, 2026
Source: NVD
CVE-2026-65697 MEDIUM - 6.1

Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javascript: URI into the Top Pages dashboard by supplying a crafted hostname and pathname to the unauthenticated /collect endpoint. Th...

Vendor: usefathom
Product: fathom
Published: Jul 23, 2026
Source: NVD
CVE-2026-65696 MEDIUM - 5.4

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can e...

Vendor: sct
Product: overseerr
Published: Jul 23, 2026
Source: NVD
CVE-2026-65695 MEDIUM - 6.8

Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers can supply absolute pa...

Vendor: GongRzhe
Product: Office-Word-MCP-Server
Published: Jul 23, 2026
Source: NVD
CVE-2026-44909 HIGH - 7.5

Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies...

Vendor: Facebook
Product: proxygen
Published: Jul 23, 2026
Source: NVD
CVE-2026-16768 MEDIUM - 5.3

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette ...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 23, 2026
Source: NVD
CVE-2026-65917 HIGH - 8.8

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate oth...

Vendor: usmannasir
Product: cyberpanel
Published: Jul 23, 2026
Source: NVD
CVE-2026-65916 HIGH - 8.1

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDo...

Vendor: usmannasir
Product: cyberpanel
Published: Jul 23, 2026
Source: NVD
CVE-2026-48539 MEDIUM - 5.4

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by...

Vendor: GFI Software
Product: GFI Archiver
Published: Jul 23, 2026
Source: NVD