Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-94130 — Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery exte…

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to …

Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.3 CRITICAL
CVE-2026-100720 — Froxlor before 2.3.12 Stored XSS via SSL certificate issuer

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Cert…

froxlor | Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100719 — Froxlor before 2.3.12 Credential Disclosure via DirProtections API

Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcry…

froxlor | Remote | Information Disclosure
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100718 — Froxlor before 2.3.12 Authentication Bypass via EmailSender.add

Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external a…

froxlor | Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.9 CRITICAL
CVE-2026-100717 — froxlor before 2.3.12 CRLF Injection via validateUrl userinfo

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components return…

froxlor | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.9 CRITICAL
CVE-2026-100716 — Froxlor before 2.3.12 Privilege Escalation via Symlink

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\Fi…

froxlor | Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.6 CRITICAL
CVE-2026-100715 — Froxlor before 2.3.12 Arbitrary File Deletion via Symlink

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls Fil…

froxlor | Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.4 CRITICAL
CVE-2026-100714 — Froxlor before 2.3.12 Command Injection via letsencryptchallengepath

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and…

froxlor | Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.8 HIGH
CVE-2026-100713 — Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync

Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containme…

froxlor | Race Condition
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100712 — froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF

froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=del…

froxlor | Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100711 — froxlor before 2.3.12 Authentication Bypass via Session Persistence

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA…

froxlor | Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.9 MEDIUM
CVE-2026-100710 — Froxlor before 2.3.12 DKIM Private Key Disclosure via API

Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDomains::get(), and the admin branch of SubDomains::listing() perform a wildcard SE…

froxlor | Remote | Information Disclosure
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.7 HIGH
CVE-2026-100709 — Froxlor before 2.3.12 2FA Bypass via Namespace Confusion

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrain…

froxlor | Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100708 — Froxlor before 2.3.13 Private Key Disclosure via Certificates API

Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands…

froxlor | Remote | Information Disclosure
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100707 — Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path

Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low…

kyverno | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
9.9 CRITICAL
CVE-2026-100706 — kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespac…

kyverno | Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100705 — Kyverno before 1.19.1 SSRF via legacy apiCall service executor

Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-toke…

kyverno | Remote | Server-Side Request Forgery
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100704 — Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass

Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fiel…

kyverno | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100703 — Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Li…

kyverno | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.2 HIGH
CVE-2026-100702 — Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested…

nodemailer | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14453 Results