Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,152
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 601 - 620 of 35,345 CVEs
CVE-2026-51846 CRITICAL - 9.8

In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.

Published: Jun 19, 2026
Source: NVD
CVE-2026-51845 CRITICAL - 9.8

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.

Published: Jun 19, 2026
Source: NVD
CVE-2026-51844 CRITICAL - 9.8

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.

Published: Jun 19, 2026
Source: NVD
CVE-2026-51843 CRITICAL - 9.8

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.

Published: Jun 19, 2026
Source: NVD
CVE-2026-49260 HIGH - 8.2

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On...

Vendor: pontedilana
Product: php-weasyprint
Published: Jun 19, 2026
Source: NVD
CVE-2026-3196 MEDIUM - 5.5

An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.

Published: Jun 19, 2026
Source: NVD
CVE-2026-3195 HIGH - 7.4

A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.

Published: Jun 19, 2026
Source: NVD
CVE-2019-25748 HIGH - 8.2

Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms...

Vendor: Cmsjunkie
Product: JHotelReservation
Published: Jun 19, 2026
Source: NVD
CVE-2017-20282 HIGH - 8.2

Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the option=com_jcart&route=product/produ...

Vendor: Soft-Php
Product: jCart for OpenCart
Published: Jun 19, 2026
Source: NVD
CVE-2017-20281 HIGH - 8.2

Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malici...

Vendor: Joomlaboat
Product: Extra Search
Published: Jun 19, 2026
Source: NVD
CVE-2017-20280 HIGH - 8.2

Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the task=project&view=grid en...

Vendor: Myportfolio
Product: Myportfolio
Published: Jun 19, 2026
Source: NVD
CVE-2017-20279 HIGH - 8.2

Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive databa...

Vendor: Extensions
Product: Joomla Payage
Published: Jun 19, 2026
Source: NVD
CVE-2017-20278 HIGH - 8.2

Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL payloads in the category...

Vendor: Joomboost
Product: JoomRecipe
Published: Jun 19, 2026
Source: NVD
CVE-2017-20277 HIGH - 8.2

Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques.

Vendor: Joomboost
Product: Joomla JoomRecipe
Published: Jun 19, 2026
Source: NVD
CVE-2017-20276 HIGH - 8.2

Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy, view=latest parameters an...

Vendor: Simbunch
Product: SIMGenealogy
Published: Jun 19, 2026
Source: NVD
CVE-2017-20275 HIGH - 8.2

Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_phpbridge&view=phpview parameters a...

Vendor: Henryschorradt
Product: Bridge
Published: Jun 19, 2026
Source: NVD
CVE-2017-20274 HIGH - 8.2

Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learning...

Vendor: King-products
Product: LMS King Professional
Published: Jun 19, 2026
Source: NVD
CVE-2017-20273 HIGH - 8.2

Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=cate...

Vendor: Joomlashowroom
Product: Event Registration Pro Calendar
Published: Jun 19, 2026
Source: NVD
CVE-2017-20272 HIGH - 8.2

Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=prop...

Vendor: Faboba
Product: Ultimate Property Listing
Published: Jun 19, 2026
Source: NVD
CVE-2017-20271 HIGH - 8.2

Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters...

Vendor: Nordmograph
Product: StreetGuessr Game
Published: Jun 19, 2026
Source: NVD