Search

Search Results (373030 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-76918 1 Wireshark 1 Wireshark 2026-08-20 5.5 Medium
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76917 1 Wireshark 1 Wireshark 2026-08-20 5.5 Medium
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76891 1 Wireshark 1 Wireshark 2026-08-20 3.1 Low
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76885 1 Wireshark 1 Wireshark 2026-08-20 3.1 Low
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76880 1 Wireshark 1 Wireshark 2026-08-20 7.5 High
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-75952 1 Cmsjunkie.com 1 J-businessdirectory Extension For Joomla 2026-08-20 N/A
Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive, payment notification send, mobile push). Frontend CSRF needs a registered/listing-owner session; admin CSRF needs a backend admin session.
CVE-2026-75114 2026-08-20 N/A
Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation.
CVE-2026-74804 2026-08-20 N/A
Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping.
CVE-2026-74803 2026-08-20 N/A
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
CVE-2026-73347 2 Themetechmount, Wordpress 2 Truebooker, Wordpress 2026-08-20 9.8 Critical
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
CVE-2026-73185 2 Wordpress, Wpo-hr 2 Wordpress, Ngg Smart Image Search 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
CVE-2026-71961 2026-08-20 8.8 High
Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT command interface. The sync_command binary forwards unsanitized input directly to a shell execution sink in command.lua, enabling attackers with access to the MQTT broker to exploit the default-enabled command execution path to achieve full root-level system compromise.
CVE-2026-67364 2026-08-20 N/A
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.
CVE-2026-67363 2026-08-20 N/A
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping.
CVE-2026-67268 1 Dell 1 Dell Command Update (dcu) 2026-08-20 6.5 Medium
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.
CVE-2026-66680 2 Plainwaire, Wordpress 2 Locatoraid Store Locator, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66668 2 Peepso, Wordpress 2 Community By Peepso, Wordpress 2026-08-20 8.5 High
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
CVE-2026-66613 2026-08-20 9.8 Critical
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVE-2026-66604 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
CVE-2026-66595 2 Passionate Programmer Peter, Wordpress 2 Wp Data Access, Wordpress 2026-08-20 5.9 Medium
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.