Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-48958 — Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

joomla\! | Remote | Authorization
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
8.8 HIGH
CVE-2026-48957 — Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints

An improper access check allows unauthorized users to access com_privacy datasets.

joomla\! | Remote | Authorization
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.4 MEDIUM
CVE-2026-48956 — Joomla! Core - [20260710] - Incorrect Access Control in com_modules

An improper access check allows users to display a list of modules in the frontend.

joomla\! | Remote | Authorization
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.5 MEDIUM
CVE-2026-48955 — Joomla! Core - [20260709] - Incorrect Access Control in com_workflow

An improper access check allows unauthorized users to access workflow stage and transition information.

joomla\! | Remote | Authorization
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-48954 — Joomla! Core - [20260708] - XSS through language overrides

Improper validation leads to a generic XSS vector in the language override feature.

joomla\! | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-48953 — Joomla! Core - [20260707] - XSS in the generic image output layout

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

joomla\! | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-48952 — Joomla! Core - [20260706] - XSS in com_installer

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

joomla\! | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-48951 — Joomla! Core - [20260705] - XSS in various modalreturn layouts

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

joomla\! | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-48950 — Joomla! Core - [20260704] - XSS in com_templates

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

joomla\! | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-48949 — Joomla! Core - [20260703] - XSS in MFA method management

Lack of validation leads to an XSS vulnerability in the MFA management views.

joomla\! | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
8.8 HIGH
CVE-2026-48948 — Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

joomla\! | Remote | Authorization
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.4 MEDIUM
CVE-2026-48947 — Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints

An improper access check allows privileged users to overwrite media files without editing permissions.

joomla\! | Remote | Authorization
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
8.5 HIGH
CVE-2026-57851 — MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write a…

| Memory Corruption
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
8.6 HIGH
CVE-2026-23698 — Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by su…

vtiger_crm crm | Remote | Authentication
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
8.8 HIGH
CVE-2026-23697 — Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code t…

vtiger_crm crm | Remote | Misconfiguration
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
7.1 HIGH
CVE-2026-14904 — RES Auth.GetUserPrivateKey Arbitrary File Read

AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper li…

res | Remote | Path Traversal
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
9.8 CRITICAL
CVE-2026-13020 — Weak Password Recovery Mechanism in Portal for ArcGIS

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume owner…

linux_kernel kubernetes windows portal_for_arcgis | Remote | Authentication
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
9.8 CRITICAL
CVE-2026-13019 — Missing Authentication

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access…

linux_kernel kubernetes windows portal_for_arcgis | Remote | Authentication
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
6.5 MEDIUM
CVE-2025-12799 — Jastow: jastow cross-site scripting attack due to unsanitized uri

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow,…

jboss_enterprise_application_platform single_sign-on | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
7.5 HIGH
CVE-2026-56812 — Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototy…

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent clien…

phoenix | Remote | Denial of Service
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
Showing 20 of 9365 Results