Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: products Clear
ID Title
CVE-2026-48904 Vulnerability in joomla (CVE-2026-48904)
vulnerability in joomla (CVE-2026-48904). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-48903 Cross-Site Scripting (XSS) in joomla (CVE-2026-48903)
cross-site scripting in joomla (CVE-2026-48903). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-48902 Vulnerability in joomla (CVE-2026-48902)
vulnerability in joomla (CVE-2026-48902). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-48901 Vulnerability in joomla (CVE-2026-48901)
vulnerability in joomla (CVE-2026-48901). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-48900 Vulnerability in joomla (CVE-2026-48900)
vulnerability in joomla (CVE-2026-48900). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-48899 Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
CVE-2026-48898 Joomla! Core - [20260513] - Privilege escalation through com_users batch task
Joomla! Core - [20260513] - Privilege escalation through com_users batch task
CVE-2026-48897 Joomla! Core - [20260512] - MFA Authentication Bypass
Joomla! Core - [20260512] - MFA Authentication Bypass
CVE-2026-48896 Joomla! Core - [20260511] - MFA Authentication Bypass
Joomla! Core - [20260511] - MFA Authentication Bypass
CVE-2026-40384 Path Traversal in joomla (CVE-2026-40384)
path traversal in joomla (CVE-2026-40384). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-40383 Joomla! Core - [20260509] - LFI in HTMLView layout parameter
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
CVE-2026-35223 Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
CVE-2026-35222 Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
CVE-2026-35221 SQL Injection in joomla (CVE-2026-35221)
SQL injection in joomla (CVE-2026-35221). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
CVE-2026-35220 Cross-Site Request Forgery (CSRF) in joomla (CVE-2026-35220)
vulnerability in joomla (CVE-2026-35220). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.1` or later.
CVE-2026-30895 Joomla! Core - [20260504] - XSS in readmore links
Joomla! Core - [20260504] - XSS in readmore links
CVE-2026-30894 Joomla! Core - [20260503] - XSS in com_contenthistory
Joomla! Core - [20260503] - XSS in com_contenthistory
CVE-2026-25901 Joomla! Core - [20260502] - XSS in com_associations
Joomla! Core - [20260502] - XSS in com_associations
CVE-2026-25900 Joomla! Core - [20260501] - XSS in feed modules
Joomla! Core - [20260501] - XSS in feed modules
CVE-2026-48687 OS Command Injection in c (CVE-2026-48687)
OS command injection in c (CVE-2026-48687). Successful exploitation can lead to full system takeover. Exploitable via ``date``.
CVE-2026-40564 Vulnerability in apache (CVE-2026-40564)
vulnerability in apache (CVE-2026-40564). Confidential information can be exposed externally.
CVE-2026-4480 OS Command Injection in redhat (CVE-2026-4480)
OS command injection in redhat (CVE-2026-4480). Successful exploitation can lead to full system takeover.
CVE-2026-45247 KEV [KEV] Unsafe Deserialization in Mirasvit full-page-cache-warmer (CVE-2026-45247)
vulnerability in Mirasvit full-page-cache-warmer (CVE-2026-45247). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-9542 Vulnerability in sqli (CVE-2026-9542)
vulnerability in sqli (CVE-2026-9542). Risk of unauthorized operations or information disclosure.
CVE-2026-39661 Vulnerability in CVE-2026-39661 (CVE-2026-39661)
vulnerability in CVE-2026-39661 (CVE-2026-39661). Successful exploitation can lead to full system takeover.
CVE-2026-9518 Cross-Site Scripting (XSS) in CVE-2026-9518 (CVE-2026-9518)
cross-site scripting in CVE-2026-9518 (CVE-2026-9518). Risk of unauthorized operations or information disclosure.
CVE-2026-9526 Vulnerability in sqli (CVE-2026-9526)
vulnerability in sqli (CVE-2026-9526). Risk of unauthorized operations or information disclosure.
CVE-2026-9527 Cross-Site Scripting (XSS) in c (CVE-2026-9527)
cross-site scripting in c (CVE-2026-9527). Risk of unauthorized operations or information disclosure.
CVE-2026-9528 Vulnerability in sqli (CVE-2026-9528)
vulnerability in sqli (CVE-2026-9528). Risk of unauthorized operations or information disclosure.
CVE-2026-9525 Vulnerability in sqli (CVE-2026-9525)
vulnerability in sqli (CVE-2026-9525). Risk of unauthorized operations or information disclosure.
CVE-2026-9517 Vulnerability in CVE-2026-9517 (CVE-2026-9517)
vulnerability in CVE-2026-9517 (CVE-2026-9517). Risk of unauthorized operations or information disclosure.
CVE-2026-43828 Vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828)
vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-44598 Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-43827 Vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827)
vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-48589 Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `3.0.0-alpha-2` or later.
CVE-2026-9485 Cross-Site Scripting (XSS) in CVE-2026-9485 (CVE-2026-9485)
cross-site scripting in CVE-2026-9485 (CVE-2026-9485). Risk of unauthorized operations or information disclosure.
CVE-2026-9484 Vulnerability in CVE-2026-9484 (CVE-2026-9484)
vulnerability in CVE-2026-9484 (CVE-2026-9484). Risk of unauthorized operations or information disclosure.
CVE-2026-9483 Vulnerability in CVE-2026-9483 (CVE-2026-9483)
vulnerability in CVE-2026-9483 (CVE-2026-9483). Risk of unauthorized operations or information disclosure.
CVE-2026-9474 Vulnerability in sqli (CVE-2026-9474)
vulnerability in sqli (CVE-2026-9474). Risk of unauthorized operations or information disclosure.
CVE-2026-9470 Vulnerability in sqli (CVE-2026-9470)
vulnerability in sqli (CVE-2026-9470). Risk of unauthorized operations or information disclosure.
CVE-2026-9469 Vulnerability in sqli (CVE-2026-9469)
vulnerability in sqli (CVE-2026-9469). Risk of unauthorized operations or information disclosure.
CVE-2026-9471 Cross-Site Scripting (XSS) in CVE-2026-9471 (CVE-2026-9471)
cross-site scripting in CVE-2026-9471 (CVE-2026-9471). Risk of unauthorized operations or information disclosure.
CVE-2026-9078 Vulnerability in mozilla (CVE-2026-9078)
vulnerability in mozilla (CVE-2026-9078). Risk of unauthorized operations or information disclosure.
CVE-2026-42782 Vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782)
vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-42797 Vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797)
vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.1` or later.
CVE-2018-25370 Cross-Site Request Forgery (CSRF) in CVE-2018-25370 (CVE-2018-25370)
vulnerability in CVE-2018-25370 (CVE-2018-25370). Risk of unauthorized operations or information disclosure.
CVE-2018-25372 SQL Injection in sqli (CVE-2018-25372)
SQL injection in sqli (CVE-2018-25372). Confidential information can be exposed externally.
CVE-2018-25374 Path Traversal in c (CVE-2018-25374)
path traversal in c (CVE-2018-25374). Confidential information can be exposed externally.
CVE-2018-25362 SQL Injection in sqli (CVE-2018-25362)
SQL injection in sqli (CVE-2018-25362). Confidential information can be exposed externally.
CVE-2018-25363 Cross-Site Request Forgery (CSRF) in CVE-2018-25363 (CVE-2018-25363)
vulnerability in CVE-2018-25363 (CVE-2018-25363). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →