Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 401 - 420 of 35,119 CVEs

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

Vendor: Microchip
Product: GridTime 3000
Published: Jun 19, 2026
Source: NVD
CVE-2017-20267 HIGH - 8.2

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitiv...

Vendor: Joomlathat
Product: Calendar Planner
Published: Jun 19, 2026
Source: NVD
CVE-2017-20266 HIGH - 8.2

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchw...

Vendor: Joomshaper
Product: SP Movie Database
Published: Jun 19, 2026
Source: NVD
CVE-2017-20265 HIGH - 7.1

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid...

Vendor: Pulseextensions
Product: Flip Wall
Published: Jun 19, 2026
Source: NVD
CVE-2017-20264 HIGH - 7.1

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_sponsorwall&task=click&...

Vendor: Pulseextensions
Product: Sponsor Wall
Published: Jun 19, 2026
Source: NVD
CVE-2017-20263 HIGH - 8.2

Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and...

Vendor: Focalpointx
Product: FocalPoint Pro / Free
Published: Jun 19, 2026
Source: NVD
CVE-2017-20262 HIGH - 8.2

Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters...

Vendor: Webkul
Product: Ajax Quiz
Published: Jun 19, 2026
Source: NVD
CVE-2017-20261 HIGH - 8.2

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice v...

Vendor: Weborange
Product: Bargain Product VM3
Published: Jun 19, 2026
Source: NVD
CVE-2017-20260 HIGH - 8.2

Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the prod...

Vendor: Weborange
Product: Price Alert
Published: Jun 19, 2026
Source: NVD
CVE-2017-20259 HIGH - 8.2

Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract...

Vendor: Joomlashack
Product: OSDownloads
Published: Jun 19, 2026
Source: NVD
CVE-2017-20258 HIGH - 8.2

Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&i...

Vendor: Extro
Product: RPC
Published: Jun 19, 2026
Source: NVD
CVE-2017-20257 HIGH - 8.2

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database q...

Vendor: Joomplace
Product: Quiz Deluxe
Published: Jun 19, 2026
Source: NVD
CVE-2017-20256 HIGH - 8.2

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter...

Vendor: Joomplace
Product: Survey Force Deluxe
Published: Jun 19, 2026
Source: NVD
CVE-2017-20255 HIGH - 8.2

Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and view=popup parameters,...

Vendor: Joombooking
Product: JB Visa
Published: Jun 19, 2026
Source: NVD
CVE-2017-20254 HIGH - 8.2

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid parameter. Attackers can send GET requests to index.php with the option=com_userbench&view=detail&use...

Vendor: Gegabyte
Product: User Bench
Published: Jun 19, 2026
Source: NVD
CVE-2017-20253 HIGH - 8.2

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract s...

Vendor: Gegabyte
Product: My Projects
Published: Jun 19, 2026
Source: NVD
CVE-2017-20252 HIGH - 8.2

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname param...

Vendor: nextgeneditor
Product: NextGen Editor
Published: Jun 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog and replaces it with a new one while another thread is sending a...

Vendor: Linux
Product: Linux
Published: Jun 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus reported that vti6_init_net() does not set the netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0). Other similar tunnel drivers (...

Vendor: Linux
Product: Linux
Published: Jun 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be re-evaluated to ensure it is properly pinned as RW. Since the umem is hidden inside each driver'...

Vendor: Linux
Product: Linux
Published: Jun 19, 2026
Source: NVD