Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 581 - 600 of 35,345 CVEs
CVE-2026-49286 HIGH - 8.1

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrapper with a case-sensitive blacklist. PHP stream wrappers are case-insensitive, so `PHAR://`, `Phar://`,...

Vendor: pontedilana
Product: php-weasyprint
Published: Jun 19, 2026
Source: NVD
CVE-2026-49271 MEDIUM - 6.5

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector fr...

Vendor: strukturag
Product: libheif
Published: Jun 19, 2026
Source: NVD
CVE-2019-25762 HIGH - 7.5

Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&...

Vendor: Joomboost
Product: JoomProject
Published: Jun 19, 2026
Source: NVD
CVE-2019-25761 HIGH - 7.1

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send GET requests to index.php with option=com_joomcrm&view=contacts and inject SQ...

Vendor: Joomboost
Product: JoomCRM
Published: Jun 19, 2026
Source: NVD
CVE-2019-25760 MEDIUM - 6.2

Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage...

Vendor: Joomtech
Product: Easy Shop
Published: Jun 19, 2026
Source: NVD
CVE-2019-25759 HIGH - 7.1

Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values ...

Vendor: Wdmtech
Product: vBizz
Published: Jun 19, 2026
Source: NVD
CVE-2019-25758 HIGH - 8.8

Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execu...

Vendor: Wdmtech
Product: vBizz
Published: Jun 19, 2026
Source: NVD
CVE-2019-25757 HIGH - 7.1

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST requests to the component with crafted SQL payloads in these parameter...

Vendor: Wdmtech
Product: vWishlist
Published: Jun 19, 2026
Source: NVD
CVE-2019-25756 HIGH - 8.2

Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with crafted SQL payloads ...

Vendor: Wdmtech
Product: vAccount
Published: Jun 19, 2026
Source: NVD
CVE-2019-25755 HIGH - 8.2

Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with URL-encoded SQL UNION statement...

Vendor: Wdmtech
Product: vReview
Published: Jun 19, 2026
Source: NVD
CVE-2019-25754 HIGH - 8.2

Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint with crafted SQL payload...

Vendor: Wdmtech
Product: vRestaurant
Published: Jun 19, 2026
Source: NVD
CVE-2019-25753 HIGH - 8.2

Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the option=com_vmap&task=loadmarker parameters...

Vendor: Wdmtech
Product: VMap
Published: Jun 19, 2026
Source: NVD
CVE-2019-25752 HIGH - 8.2

Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the option=com_jbusinessdirectory&t...

Vendor: Cmsjunkie
Product: BusinessDirectory
Published: Jun 19, 2026
Source: NVD
CVE-2019-25751 HIGH - 8.2

Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch para...

Vendor: Cmsjunkie
Product: ClassifiedsManager
Published: Jun 19, 2026
Source: NVD
CVE-2019-25750 HIGH - 8.2

Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL...

Vendor: Cmsjunkie
Product: MultipleHotelReservation
Published: Jun 19, 2026
Source: NVD
CVE-2019-25749 HIGH - 7.1

Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adul...

Vendor: Cmsjunkie
Product: CruisePortal
Published: Jun 19, 2026
Source: NVD
CVE-2026-56211 HIGH - 7.1

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer co...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images
Published: Jun 19, 2026
Source: NVD
CVE-2026-56210 HIGH - 7.1

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap re...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images
Published: Jun 19, 2026
Source: NVD
CVE-2026-56209 HIGH - 7.1

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images
Published: Jun 19, 2026
Source: NVD
CVE-2026-56208 HIGH - 7.6

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 2...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Hardened Images
Published: Jun 19, 2026
Source: NVD