|
2026-07-27
|
CVE-2026-64799
|
CVE-2026-64799 - Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions
|
-
|
PHP
|
|
2026-07-27
|
CVE-2026-64874
|
CVE-2026-64874 - Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension
|
-
|
PHP
|
|
2026-07-27
|
CVE-2026-65756
|
CVE-2026-65756 - Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension
|
3.1 (MEDIUM)
|
PHP
|
|
2026-07-27
|
CVE-2026-65712
|
CVE-2026-65712 - Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension
|
3.1 (MEDIUM)
|
PHP
|
|
2026-07-27
|
CVE-2026-64872
|
CVE-2026-64872 - Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension
|
3.1 (MEDIUM)
|
PHP
|
|
2026-07-27
|
CVE-2026-64876
|
CVE-2026-64876 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension
|
-
|
PHP
|
|
2026-07-27
|
CVE-2026-64875
|
CVE-2026-64875 - Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension
|
-
|
PHP
|
|
2026-07-27
|
CVE-2026-65754
|
CVE-2026-65754 - Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension
|
-
|
PHP
|
|
2026-07-27
|
CVE-2026-65755
|
CVE-2026-65755 - Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension
|
-
|
PHP
|
|
2026-07-27
|
CVE-2026-65757
|
CVE-2026-65757 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension
|
3.1 (HIGH)
|
PHP
|
|
2026-07-27
|
CVE-2026-64871
|
CVE-2026-64871 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension
|
3.1 (MEDIUM)
|
PHP
|
|
2026-07-27
|
CVE-2026-64873
|
CVE-2026-64873 - Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension
|
3.1 (CRITICAL)
|
PHP
|
|
2026-07-27
|
CVE-2026-65713
|
CVE-2026-65713 - Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension
|
3.1 (MEDIUM)
|
PHP
|
|
2026-07-27
|
CVE-2024-58023
|
CVE-2024-58023 - Bosch Configuration Manager Information Disclosure
|
3.1 (HIGH)
|
|
|
2026-07-27
|
CVE-2024-58330
|
CVE-2024-58330 - Bosch IP Cameras Missing Authentication Vulnerability
|
3.1 (HIGH)
|
Hardware/IoT
|
|
2026-07-26
|
CVE-2026-16287
|
CVE-2026-16287 - Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update
|
3.1 (HIGH)
|
|
|
2026-07-26
|
CVE-2026-16723
|
CVE-2026-16723 - Remote Code Execution in fastjson 1.2.68–1.2.83
|
3.1 (CRITICAL)
|
|
|
2026-07-26
|
CVE-2026-52684
|
CVE-2026-52684 - Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack
|
3.1 (LOW)
|
|
|
2026-07-26
|
CVE-2026-52686
|
CVE-2026-52686 - Wildcard CNAME proof validation bypass
|
3.1 (LOW)
|
|
|
2026-07-26
|
CVE-2026-52688
|
CVE-2026-52688 - RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
|
3.1 (HIGH)
|
|
|
2026-07-26
|
CVE-2026-59677
|
CVE-2026-59677 - Process Kill Attack Vector in killall() in seunshare
|
4.0 (MEDIUM)
|
|
|
2026-07-26
|
CVE-2026-59678
|
CVE-2026-59678 - portprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager
|
4.0 (HIGH)
|
|
|
2026-07-26
|
CVE-2026-12421
|
CVE-2026-12421 - ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values
|
3.1 (HIGH)
|
|
|
2026-07-26
|
CVE-2026-9729
|
CVE-2026-9729 - Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter
|
3.1 (MEDIUM)
|
|
|
2026-07-26
|
CVE-2026-9635
|
CVE-2026-9635 - WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute
|
3.1 (MEDIUM)
|
|