Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.4 CRITICAL
CVE-2026-9177 — Server-Side Template Injection in SecureTransport's Apache Velocity mail templates

A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker w…

securetransport | Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-67217 — cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose desti…

cjson | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-67216 — cJSON cJSON_Compare Exponential Complexity Denial of Service

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with…

cjson | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.7 HIGH
CVE-2026-67215 — cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseS…

cjson | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-67214 — nanoid before 5.1.16 Infinite Loop via Negative Size in non-secure module

nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the l…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-67213 — nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never sati…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-66490 — Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Grid…

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

| Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-66489 — Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbo…

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

| Information Disclosure
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-66488 — Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

| Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.3 MEDIUM
CVE-2026-66400 — Grav Login Plugin before 3.8.13 Insufficient Session Expiration

Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token times…

grav | Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.2 CRITICAL
CVE-2026-65890 — Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.2 CRITICAL
CVE-2026-65889 — Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox …

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

Remote | Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.7 HIGH
CVE-2026-55995 — Double-free in the iSNS attribute decoder in open-iscsi

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

Remote | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.3 MEDIUM
CVE-2026-18174 — @fastify/forwarded vulnerable to improper input validation via unstripped tab characters …

@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims only space chara…

| Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-16751 — Ente Museum Server Authorization Bypass Vulnerability

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the con…

| Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-65946 — Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

| Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-65944 — Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

| Cross-Site Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-65943 — Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0

Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0

| Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-65891 — Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file…

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file…

| Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.4 CRITICAL
CVE-2026-65885 — Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RC…

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
Showing 20 of 9598 Results