Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-63730 — HyperDX < 2.31.0 SSRF via Webhook Test Endpoint

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by s…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-63108 — Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions …

roo_code | Remote | Injection
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
7.7 HIGH
CVE-2026-63107 — LimeSurvey SSRF via REST API Survey Template Host Header

LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitra…

limesurvey | Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
9.1 CRITICAL
CVE-2026-62414 — Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

Remote | Authorization
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
6.1 MEDIUM
CVE-2026-61901 — Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

Remote | Misconfiguration
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2026-61900 — Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownl…

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to ful…

Remote | Authentication
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
9.4 CRITICAL
CVE-2026-61425 — Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

gridbox | Remote | Authentication
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2026-61424 — Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classi…

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading …

Remote | Misconfiguration
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
9.4 CRITICAL
CVE-2026-60034 — Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served with…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
5.1 MEDIUM
CVE-2026-60033 — Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0

Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target interna…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
9.4 CRITICAL
CVE-2026-60032 — Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Execut…

Remote | Authentication
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
6.9 MEDIUM
CVE-2026-60031 — Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1

Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflect…

Remote | Information Disclosure
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-60030 — Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Pa…

Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. A…

Remote | Authorization
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
5.1 MEDIUM
CVE-2026-60029 — Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Auth…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
8.6 HIGH
CVE-2026-60028 — Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Auth…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-60027 — Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Pa…

Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traver…

Remote | Path Traversal
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
8.9 HIGH
CVE-2026-60026 — Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder…

Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Au…

Remote | Injection
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-48389 — DNG SDK | Stack-based Buffer Overflow (CWE-121)

DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of t…

dng_software_development_kit | Memory Corruption
Jul 20, 2026 Aug 11, 2026
Jul 20, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-12341 — SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.

identityiq | Remote | Authentication
Jul 20, 2026 Jul 30, 2026
Jul 20, 2026
Jul 30, 2026
8.7 HIGH
CVE-2026-8170 — ExtremeXOS Privilege Escalation via Symlink Following in File Utilities

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An att…

Remote | Path Traversal
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
Showing 20 of 12452 Results