Total CVEs

149,971

Critical Severity

4,911

High Severity

17,397

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
Showing 641 - 660 of 149,971 CVEs

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.

Vendor: phoca.cz
Product: Phoca Commander extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.

Vendor: phoca.cz
Product: Phoca Commander extension for Joomla
Published: Jul 27, 2026
Source: NVD

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to ...

Vendor: DaveGamble
Product: cJSON
Published: Jul 27, 2026
Source: NVD

Rejected reason: This is a duplicate.

Published: Jul 27, 2026
Source: NVD

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an a...

Vendor: CP-Plus
Product: EZ-P21 IP Camera
Published: Jul 27, 2026
Source: NVD

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful ex...

Vendor: CP-Plus
Product: EZ-P21 IP Camera
Published: Jul 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop The loop in is_ap_in_tkip() iterates over IEs without verifying that enough bytes remain before dereferencing the IE header or its payload: - pIE->element_id and pIE...

Vendor: Linux
Product: Linux
Published: Jul 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data...

Vendor: Linux
Product: Linux
Published: Jul 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via th...

Vendor: Linux
Product: Linux
Published: Jul 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conversion log_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY records when replaying version 0 restart tables. During this conversion, the memmove() length is derived ...

Vendor: Linux
Product: Linux
Published: Jul 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} In do_action()'s UpdateRecordDataRoot (fslog.c:3489) and UpdateRecordDataAllocation (fslog.c:3697) cases, the memmove destination is `Add2Ptr(e, le16_...

Vendor: Linux
Product: Linux
Published: Jul 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") ...

Vendor: Linux
Product: Linux
Published: Jul 27, 2026
Source: NVD
CVE-2026-14837 HIGH - 7.8

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized a...

Vendor: Lenze
Product: c430, c520, c550, i950 GenA, i950 GenB
Published: Jul 27, 2026
Source: NVD
CVE-2026-9830 HIGH - 8.2

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users...

Published: Jul 27, 2026
Source: NVD
CVE-2026-66412 MEDIUM - 6.5

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can enumerate integer milestone ...

Vendor: Leantime
Product: Leantime
Published: Jul 27, 2026
Source: NVD
CVE-2026-14827 MEDIUM - 6.8

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.

Vendor: Unknown
Product: Calendar
Published: Jul 27, 2026
Source: NVD
CVE-2026-14820 MEDIUM - 5.3

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid use...

Vendor: Unknown
Product: Quiz and Survey Master (QSM)
Published: Jul 27, 2026
Source: NVD
CVE-2026-14568 MEDIUM - 6.5

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership before deleting an attachment, allowing unauthenticated attackers to permanently delete author-less attachments s...

Vendor: Unknown
Product: User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration
Published: Jul 27, 2026
Source: NVD
CVE-2026-14289 CRITICAL - 9.0

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into...

Vendor: Unknown
Product: FacturaONE para WooCommerce con VeriFactu
Published: Jul 27, 2026
Source: NVD
CVE-2026-14236 MEDIUM - 4.7

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an arbitrary external site after...

Vendor: Unknown
Product: Contact Form 7
Published: Jul 27, 2026
Source: NVD