Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
CRITICAL 10.0
CVE-2026-76607
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
No fix yet
CRITICAL 10.0
CVE-2026-76606
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
No fix yet
CRITICAL 10.0
CVE-2026-76605
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
No fix yet
CRITICAL 10.0
CVE-2026-76604
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable t…
No fix yet
MEDIUM 6.9
CVE-2026-76603
Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perfo…
No fix yet
CRITICAL 9.3
CVE-2026-76602
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries…
No fix yet
MEDIUM 6.9
CVE-2026-76601
Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.
No fix yet
MEDIUM 6.9
CVE-2026-76600
Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access c…
No fix yet
HIGH 8.7
CVE-2026-76599
Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the e…
No fix yet
HIGH 8.7
CVE-2026-76598
Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method …
No fix yet
HIGH 8.7
CVE-2026-76597
Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin c…
No fix yet
HIGH 8.7
CVE-2026-76596
Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks A…
No fix yet
CRITICAL 9.3
CVE-2026-76571
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed…
No fix yet
MEDIUM 6.2
CVE-2026-70626
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside …
No fix yet
MEDIUM 6.1
CVE-2026-68768
hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a f…
Patch available
MEDIUM 6.1
CVE-2026-68767
hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer …
Patch available
HIGH 7.8
CVE-2026-68766
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and…
Patch available
HIGH 7.5
CVE-2026-66393
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of se…
No fix yet
MEDIUM 6.5
CVE-2026-65915
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against…
No fix yet
HIGH 7.5
CVE-2026-63312
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.op…
No fix yet
MEDIUM 5.3
CVE-2026-63311
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in…
No fix yet
HIGH 7.1
CVE-2026-63310
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man…
No fix yet
HIGH 7.5
CVE-2026-62388
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exc…
No fix yet
MEDIUM 5.9
CVE-2026-62385
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML fi…
No fix yet
HIGH 7.5
CVE-2026-62384
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside …
No fix yet
MEDIUM 5.5
CVE-2026-62383
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validati…
No fix yet
HIGH 8.8
CVE-2026-71513
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the glob…
Patch available
MEDIUM 6.4
CVE-2026-4561
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (…
No fix yet
MEDIUM 6.4
CVE-2026-4559
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all…
No fix yet
HIGH 7.5
CVE-2026-2996
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, a…
No fix yet