Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-63771 — Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header

Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP head…

adminer | Remote | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.2 HIGH
CVE-2026-63770 — Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass

Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary…

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.7 HIGH
CVE-2026-63769 — Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting …

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.3 MEDIUM
CVE-2026-63768 — cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state paramet…

cal.diy | Remote | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.7 HIGH
CVE-2026-63731 — HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-control…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.3 MEDIUM
CVE-2026-63730 — HyperDX < 2.31.0 SSRF via Webhook Test Endpoint

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by s…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.8 HIGH
CVE-2026-63108 — Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions …

roo_code | Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.7 HIGH
CVE-2026-63107 — LimeSurvey SSRF via REST API Survey Template Host Header

LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitra…

limesurvey | Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-62414 — Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

| Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-61901 — Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2

The Joomla extension Hikashop is vulnerable to an open redirect.

| Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
10.0 CRITICAL
CVE-2026-61900 — Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownl…

The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
9.4 CRITICAL
CVE-2026-61425 — Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0

The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
10.0 CRITICAL
CVE-2026-61424 — Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classi…

The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

Remote | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
9.4 CRITICAL
CVE-2026-60034 — Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0

The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.1 MEDIUM
CVE-2026-60033 — Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0

The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
9.4 CRITICAL
CVE-2026-60032 — Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0

The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.9 MEDIUM
CVE-2026-60031 — Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1

The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.

Remote | Information Disclosure
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.7 HIGH
CVE-2026-60030 — Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Pa…

The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.1 MEDIUM
CVE-2026-60029 — Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.6 HIGH
CVE-2026-60028 — Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
Showing 20 of 8278 Results