Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-67217
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing…
Cjson
after 1.7.19
HIGH 7.5
CVE-2026-67216
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each …
Cjson
after 1.7.19
HIGH 7.5
CVE-2026-67215
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUt…
Cjson
after 1.7.19
HIGH 7.5
CVE-2026-67214
nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-s…
Nanoid
5.1.16+
MEDIUM 5.3
CVE-2026-66489
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
Gridbox
2.20.2+
MEDIUM 5.3
CVE-2026-66488
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Gridbox
2.20.2+
HIGH 7.5
CVE-2026-67213
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a …
Nanoid
3.3.17 / 5.1.6+
MEDIUM 6.1
CVE-2026-66490
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
Gridbox
2.20.2+
CRITICAL 9.8
CVE-2026-65890
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…
Gridbox
2.20.2+
HIGH 7.5
CVE-2026-65889
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…
Gridbox
2.20.2+
HIGH 8.7
CVE-2026-55995
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
This issue affects open-iscsi: from ? through 5…
Patch available
MEDIUM 6.5
CVE-2026-16751
Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured…
No fix yet
MEDIUM 5.3
CVE-2026-18174
@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma se…
Fastify\/forwarded
3.0.2+
HIGH 8.8
CVE-2026-65944
Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
Ro Csvi
9.11.0+
MEDIUM 6.1
CVE-2026-65946
Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
Ro Csvi
9.11.0+
HIGH 7.5
CVE-2026-65943
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
Ro Csvi
9.11.0+
MEDIUM 6.5
CVE-2026-65891
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE…
Jce
2.20.2+
HIGH 8.8
CVE-2026-65885
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo…
Gridbox
2.20.2+
CRITICAL 9.8
CVE-2026-65884
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…
Gridbox
2.20.2+
HIGH 7.1
CVE-2026-50641
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database
This issue was fixed in version 6.8.0.0, users were …
No fix yet
HIGH 8.5
CVE-2026-44944
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.
This issue affects…
Patch available
MEDIUM 6.9
CVE-2026-44943
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create…
Patch available
MEDIUM 5.1
CVE-2026-33385
A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multip…
No fix yet
HIGH 8.7
CVE-2026-14354
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, po…
No fix yet
HIGH 8.4
CVE-2026-12927
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file…
No fix yet
CRITICAL 9.3
CVE-2026-0667
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of …
No fix yet
HIGH 8.8
CVE-2026-14270
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in…
No fix yet
MEDIUM 6.4
CVE-2026-8791
The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to…
No fix yet
MEDIUM 6.4
CVE-2026-7436
The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_bes…
No fix yet
CRITICAL 9.8
CVE-2026-65883
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o…
Aimy Captcha Less Form Guard
after 20.0