Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,759
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 401 - 420 of 35,133 CVEs
CVE-2017-20278 HIGH - 8.2

Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL payloads in the category...

Vendor: Joomboost
Product: JoomRecipe
Published: Jun 19, 2026
Source: NVD
CVE-2017-20277 HIGH - 8.2

Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques.

Vendor: Joomboost
Product: Joomla JoomRecipe
Published: Jun 19, 2026
Source: NVD
CVE-2017-20276 HIGH - 8.2

Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy, view=latest parameters an...

Vendor: Simbunch
Product: SIMGenealogy
Published: Jun 19, 2026
Source: NVD
CVE-2017-20275 HIGH - 8.2

Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_phpbridge&view=phpview parameters a...

Vendor: Henryschorradt
Product: Bridge
Published: Jun 19, 2026
Source: NVD
CVE-2017-20274 HIGH - 8.2

Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learning...

Vendor: King-products
Product: LMS King Professional
Published: Jun 19, 2026
Source: NVD
CVE-2017-20273 HIGH - 8.2

Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=cate...

Vendor: Joomlashowroom
Product: Event Registration Pro Calendar
Published: Jun 19, 2026
Source: NVD
CVE-2017-20272 HIGH - 8.2

Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=prop...

Vendor: Faboba
Product: Ultimate Property Listing
Published: Jun 19, 2026
Source: NVD
CVE-2017-20271 HIGH - 8.2

Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters...

Vendor: Nordmograph
Product: StreetGuessr Game
Published: Jun 19, 2026
Source: NVD
CVE-2017-20270 HIGH - 8.2

Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters...

Vendor: Raindropsinfotech
Product: Twitch Tv
Published: Jun 19, 2026
Source: NVD
CVE-2017-20269 HIGH - 8.2

Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive inf...

Vendor: Terrywcarter
Product: KissGallery
Published: Jun 19, 2026
Source: NVD
CVE-2017-20268 HIGH - 8.2

Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL pay...

Vendor: Zcontent
Product: Zap Calendar Lite
Published: Jun 19, 2026
Source: NVD

The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

Vendor: Microchip
Product: GridTime 3000
Published: Jun 19, 2026
Source: NVD

Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.

Vendor: Microchip
Product: GridTime 3000
Published: Jun 19, 2026
Source: NVD

The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

Vendor: Microchip
Product: GridTime 3000
Published: Jun 19, 2026
Source: NVD

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

Vendor: Microchip
Product: GridTime 3000
Published: Jun 19, 2026
Source: NVD
CVE-2017-20267 HIGH - 8.2

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitiv...

Vendor: Joomlathat
Product: Calendar Planner
Published: Jun 19, 2026
Source: NVD
CVE-2017-20266 HIGH - 8.2

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchw...

Vendor: Joomshaper
Product: SP Movie Database
Published: Jun 19, 2026
Source: NVD
CVE-2017-20265 HIGH - 7.1

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid...

Vendor: Pulseextensions
Product: Flip Wall
Published: Jun 19, 2026
Source: NVD
CVE-2017-20264 HIGH - 7.1

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_sponsorwall&task=click&...

Vendor: Pulseextensions
Product: Sponsor Wall
Published: Jun 19, 2026
Source: NVD
CVE-2017-20263 HIGH - 8.2

Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and...

Vendor: Focalpointx
Product: FocalPoint Pro / Free
Published: Jun 19, 2026
Source: NVD