Total CVEs

150,976

Critical Severity

5,036

High Severity

17,677

Last 7 Days

2,131
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,601 - 2,620 of 47,381 CVEs
CVE-2026-59919 MEDIUM - 5.5

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF ...

Vendor: maven
Product: io.netty:netty-codec-haproxy
Published: Jul 22, 2026
Source: GitHub

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the eve...

Vendor: maven
Product: io.netty:netty-codec-compression
Published: Jul 22, 2026
Source: GitHub

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP...

Vendor: maven
Product: io.netty:netty-codec-http2
Published: Jul 22, 2026
Source: GitHub

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that ac...

Vendor: maven
Product: io.netty:netty-codec-http
Published: Jul 22, 2026
Source: GitHub

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers...

Vendor: maven
Product: io.netty:netty-codec-http
Published: Jul 22, 2026
Source: GitHub
CVE-2026-56822 HIGH - 7.4

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to ...

Vendor: maven
Product: io.netty:netty-handler-ssl-ocsp
Published: Jul 22, 2026
Source: GitHub
CVE-2026-56821 HIGH - 7.4

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path at...

Vendor: maven
Product: io.netty:netty-handler-ssl-ocsp
Published: Jul 22, 2026
Source: GitHub

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes the SVG twice and the second pass does not enforc...

Vendor: composer
Product: dompdf/dompdf
Published: Jul 22, 2026
Source: GitHub
CVE-2026-64798 CRITICAL - 9.1

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

Vendor: regularlabs.com
Product: IP Login extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-64797 HIGH - 7.5

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

Vendor: regularlabs.com
Product: IP Login extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-64796 CRITICAL - 9.8

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, at...

Vendor: regularlabs.com
Product: Sourcerer extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-64795 MEDIUM - 5.4

Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browse...

Vendor: regularlabs.com
Product: Modals extension for Joomla, Tooltips extension for Joomla, Articles Anywhere Pro extension for Joomla, Users Anywhere Pro extension for Joomla, Modules Anywhere Pro extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-64794 MEDIUM - 6.5

Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restrict...

Vendor: regularlabs.com
Product: Articles Anywhere extension for Joomla, Users Anywhere extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-64793 CRITICAL - 9.1

Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visito...

Vendor: regularlabs.com
Product: Articles Anywhere extension for Joomla, Modules Anywhere extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-64792 HIGH - 7.5

Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could conse...

Published: Jul 22, 2026
Source: NVD
CVE-2026-64791 HIGH - 8.8

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF...

Vendor: regularlabs.com
Product: Regular Labs Extension Manager extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63685 HIGH - 8.8

Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causin...

Vendor: regularlabs.com
Product: DB Replacer extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63684 HIGH - 8.8

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Una...

Vendor: regularlabs.com
Product: Content Templater extension for Joomla, ReReplacer extension for Joomla, Snippets extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63683 HIGH - 7.5

Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

Vendor: regularlabs.com
Product: Advanced Module Manager extension for Joomla, Conditional Content extension for Joomla, Content Templater Pro extension for Joomla, ReReplacer extension Pro for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63281 MEDIUM - 4.8

Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.

Vendor: regularlabs.com
Product: Advanced Module Manager extension for Joomla, Conditional Content extension for Joomla, Content Templater Pro extension for Joomla, ReReplacer extension Pro for Joomla
Published: Jul 22, 2026
Source: NVD