Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-46343 — Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_r…

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster…

Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-44254 — Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes a pointer i…

Remote | Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.9 MEDIUM
CVE-2026-44253 — Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and …

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol in framework/wazuh/core/cluster/commo…

Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.7 HIGH
CVE-2026-44252 — Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permis…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.3 MEDIUM
CVE-2026-19672 — tarfile extraction filter bypass allows creation of directories outside the destination

The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. T…

cpython cpython | Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.2 HIGH
CVE-2026-18430 — HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administra…

HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original au…

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.7 HIGH
CVE-2026-16819 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-of-check time-of-use race condition.

aix | Race Condition
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76614 — OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for …

Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.1 MEDIUM
CVE-2026-76203 — CSS sanitizer bypass in Pentestify report themes allows forced outbound requests

Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from ot…

pentestify | Remote | Server-Side Request Forgery
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.7 HIGH
CVE-2026-75956 — Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-Busin…

Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limits…

Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.1 MEDIUM
CVE-2026-75955 — Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory <…

Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.3 CRITICAL
CVE-2026-75954 — Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory …

Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the s…

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-75953 — Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3

Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offe…

| Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.6 MEDIUM
CVE-2026-75952 — Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6…

Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, m…

Remote | Cross-Site Request Forgery
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.9 MEDIUM
CVE-2026-75951 — Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/A…

Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.9 MEDIUM
CVE-2026-75950 — Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-Busine…

Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for l…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
10.0 CRITICAL
CVE-2026-75949 — Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in …

Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the c…

Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-71961 — Cudy WR3000 2.0 OS Command Injection via Mesh MQTT Command Handler

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsa…

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.1 CRITICAL
CVE-2026-71960 — Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers t…

Remote | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-71176 — Dell OpenManage Enterprise SQL Injection Vulnerability

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with rem…

openmanage_enterprise | Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12435 Results