Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,079
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,561 - 2,580 of 47,325 CVEs
CVE-2026-63685 HIGH - 8.8

Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causin...

Vendor: regularlabs.com
Product: DB Replacer extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63684 HIGH - 8.8

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Una...

Vendor: regularlabs.com
Product: Content Templater extension for Joomla, ReReplacer extension for Joomla, Snippets extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63683 HIGH - 7.5

Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

Vendor: regularlabs.com
Product: Advanced Module Manager extension for Joomla, Conditional Content extension for Joomla, Content Templater Pro extension for Joomla, ReReplacer extension Pro for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63281 MEDIUM - 4.8

Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.

Vendor: regularlabs.com
Product: Advanced Module Manager extension for Joomla, Conditional Content extension for Joomla, Content Templater Pro extension for Joomla, ReReplacer extension Pro for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63280 HIGH - 8.8

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

Vendor: regularlabs.com
Product: Advanced Module Manager extension for Joomla, Conditional Content extension for Joomla, Content Templater Pro extension for Joomla, ReReplacer extension Pro for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63265 HIGH - 8.0

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form confi...

Published: Jul 22, 2026
Source: NVD
CVE-2026-13089 HIGH - 7.5

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin an algorithm, OIDC::Lite::Model::IDToken::verify sets $self->alg($self->header->{alg}) from the token's own heade...

Vendor: RITOU
Product: OIDC::Lite
Published: Jul 22, 2026
Source: NVD
CVE-2025-60835 HIGH - 7.8

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

Published: Jul 22, 2026
Source: NVD
CVE-2025-50330 HIGH - 8.8

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

Published: Jul 22, 2026
Source: NVD
CVE-2025-50329 CRITICAL - 9.8

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

Published: Jul 22, 2026
Source: NVD
CVE-2025-50327 HIGH - 8.8

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism

Published: Jul 22, 2026
Source: NVD
CVE-2025-50325 MEDIUM - 5.4

BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip

Published: Jul 22, 2026
Source: NVD
CVE-2025-50324 HIGH - 8.8

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

Published: Jul 22, 2026
Source: NVD
CVE-2025-44090 HIGH - 8.8

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Published: Jul 22, 2026
Source: NVD
CVE-2025-44089 HIGH - 8.8

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Published: Jul 22, 2026
Source: NVD

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker can trigger PHP memo...

Vendor: composer
Product: dompdf/dompdf
Published: Jul 22, 2026
Source: GitHub

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with  realpath() . Because normalization strips the trailing directory separator from  $chrootPath , the check only ve...

Vendor: composer
Product: dompdf/dompdf
Published: Jul 22, 2026
Source: GitHub
CVE-2026-9737 MEDIUM - 6.5

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.

Published: Jul 22, 2026
Source: NVD
CVE-2026-64829 HIGH - 7.4

Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. ...

Vendor: q2a
Product: question2answer
Published: Jul 22, 2026
Source: NVD
CVE-2026-14899 HIGH - 7.5

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thu...

Vendor: Mozilla
Product: Thunderbird
Published: Jul 22, 2026
Source: NVD