Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-16629 — danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manip…

| Injection
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-16628 — oclif JIT Plugin Entry child_process.exec os command injection

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argu…

| Injection
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64798 — Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension

Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

| Cryptography
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64797 — Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension

IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

| Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64796 — Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension

Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across …

| Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64795 — Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regula…

Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.

| Cross-Site Scripting
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64794 — Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and …

User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.

| Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64793 — Joomla Extension - regularlabs.com - Content access and publication bypass in Articles An…

Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required ac…

| Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64792 — Joomla Extension - regularlabs.com - disclosure of restricted content via search index in…

Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in th…

| Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-64791 — Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in…

Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install,…

| Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-63685 — Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension

Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, po…

| Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-63684 — Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in…

Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create o…

| Cross-Site Request Forgery
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-63683 — Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs con…

IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

| Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-63281 — Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager

Stored condition values could also execute HTML/JavaScript in administrator summaries.

| Cross-Site Scripting
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-63280 — Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in…

Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

| Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-63265 — Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in…

Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privile…

| Cross-Site Request Forgery
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-13089 — OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass …

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin an algorithm, OIDC::Lite::…

| Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2025-60835 — IZArc unrar.dll Path Traversal Vulnerability

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

| Path Traversal
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2025-50330 — ZipGenius Arbitrary Code Execution Vulnerability

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

| Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2025-50329 — PowerArchiver Privilege Escalation and Arbitrary Code Execution

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

| Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
Showing 20 of 9643 Results