Total CVEs

149,971

Critical Severity

4,911

High Severity

17,397

Last 7 Days

1,772
Quick preset (or use dates below)
Clear Filters
Showing 601 - 620 of 149,971 CVEs

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD
CVE-2026-61511 CRITICAL - 9.8

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] ...

Vendor: vBulletin
Product: vBulletin
Published: Jul 27, 2026
Source: NVD
CVE-2026-17514 MEDIUM - 5.3

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The projec...

Vendor: ZJONSSON
Product: node-unzipper
Published: Jul 27, 2026
Source: NVD

A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through...

Vendor: ggml-org
Product: whisper.cpp
Published: Jul 27, 2026
Source: NVD
CVE-2026-15003 MEDIUM - 5.6

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file,...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jul 27, 2026
Source: NVD
CVE-2026-59690 HIGH - 8.0

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be access...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, Multi Tenant
Published: Jul 27, 2026
Source: NVD
CVE-2026-59689 HIGH - 8.0

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compro...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD
CVE-2026-59688 HIGH - 8.4

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functio...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD
CVE-2026-59687 HIGH - 8.4

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location managemen...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD
CVE-2026-59686 HIGH - 8.4

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, ...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

Vendor: HCLSoftware
Product: Connections
Published: Jul 27, 2026
Source: NVD

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

Vendor: HCLSoftware
Product: Connections
Published: Jul 27, 2026
Source: NVD

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.

Vendor: ggml-org
Product: whisper.cpp
Published: Jul 27, 2026
Source: NVD

The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking technique...

Vendor: Ghost Robotics
Product: Vision 60
Published: Jul 27, 2026
Source: NVD

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active,...

Vendor: Ghost Robotics
Product: Vision 60
Published: Jul 27, 2026
Source: NVD

A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization...

Vendor: Ghost Robotics
Product: Vision 60
Published: Jul 27, 2026
Source: NVD
CVE-2026-66053 MEDIUM - 5.9

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-58662 CRITICAL - 9.1

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-58389 HIGH - 7.5

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD