Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,096
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,441 - 2,460 of 47,325 CVEs
CVE-2026-25405 HIGH - 8.5

Contributor SQL Injection in eRoom <= 1.7.1 versions.

Vendor: DigitalME
Product: eRoom
Published: Jul 23, 2026
Source: NVD
CVE-2026-24639 MEDIUM - 4.4

Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.

Vendor: Ronald Huereca
Product: Photo Block
Published: Jul 23, 2026
Source: NVD
CVE-2026-24628 MEDIUM - 5.9

Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

Vendor: Supsystic
Product: Photo Gallery by Supsystic
Published: Jul 23, 2026
Source: NVD
CVE-2026-24552 HIGH - 8.5

Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.

Vendor: mischiefmarmot
Product: Create by Mediavine
Published: Jul 23, 2026
Source: NVD
CVE-2026-24537 MEDIUM - 4.3

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

Vendor: Alex Volkov
Product: WP Accessibility Helper (WAH)
Published: Jul 23, 2026
Source: NVD
CVE-2025-68081 MEDIUM - 5.9

Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

Vendor: Lester Chan
Product: WP-Polls
Published: Jul 23, 2026
Source: NVD
CVE-2026-64611 HIGH - 7.5

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially cr...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 23, 2026
Source: NVD
CVE-2026-16745 HIGH - 8.8

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized...

Vendor: Red Hat
Product: Red Hat OpenShift AI (RHOAI)
Published: Jul 23, 2026
Source: NVD

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

Vendor: tassos.gr
Product: Convert Forms extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65757 HIGH - 8.1

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.

Vendor: regularlabs.com
Product: Modules Anywhere extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65756 MEDIUM - 6.1

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

Vendor: regularlabs.com
Product: Keyboard Shortcuts extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65755 HIGH - 7.5

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing...

Vendor: regularlabs.com
Product: Articles Anywhere extension for Joomla, Users Anywhere extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65754 HIGH - 7.5

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

Vendor: regularlabs.com
Product: ReReplacer PRo extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65713 MEDIUM - 6.5

Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

Vendor: regularlabs.com
Product: Modals Pro extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65712 MEDIUM - 6.2

Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.

Vendor: regularlabs.com
Product: CDN for Joomla Pro extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65431 CRITICAL - 9.8

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

Vendor: regularlabs.com
Product: GeoIP extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-65430 HIGH - 7.5

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

Vendor: regularlabs.com
Product: GeoIP extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-64876 HIGH - 8.8

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.

Vendor: regularlabs.com
Product: GeoIP extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-64875 MEDIUM - 6.5

Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.

Vendor: regularlabs.com
Product: GeoIP extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-64874 CRITICAL - 9.8

Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

Vendor: regularlabs.com
Product: Cache Cleaner Pro extension for Joomla
Published: Jul 23, 2026
Source: NVD