Common Vulnerabilities and Exposures (CVE)

CVE-2026-65759

Jul 24, 2026 05:38:22 UTC

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attacke...

CVE-2026-65756

Jul 24, 2026 05:36:06 UTC

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

CVE-2026-65763

Jul 24, 2026 05:35:26 UTC

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability.

CVE-2026-65758

Jul 24, 2026 05:34:47 UTC

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

CVE-2026-65761

Jul 24, 2026 05:34:21 UTC

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including cr...

CVE-2026-65760

Jul 24, 2026 05:33:43 UTC

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the s...

CVE-2026-54422

Jul 24, 2026 05:07:23 UTC

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

CVE-2026-16870

Jul 24, 2026 04:40:41 UTC

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code executi...

CVE-2026-66141

Jul 24, 2026 04:37:46 UTC

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

CVE-2026-66140

Jul 24, 2026 04:32:08 UTC

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

CVE-2026-66139

Jul 24, 2026 04:14:41 UTC

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

CVE-2023-4875

Jul 24, 2026 04:08:36 UTC

Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12

CVE-2023-4874

Jul 24, 2026 04:08:31 UTC

Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12

CVE-2026-47669

Jul 24, 2026 03:56:33 UTC

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A ...

CVE-2026-47670

Jul 24, 2026 03:56:32 UTC

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `...