Common Vulnerabilities and Exposures (CVE)

CVE-2026-89169

Sep 11, 2026 05:19:34 UTC

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

CVE-2026-85150

Sep 11, 2026 05:18:14 UTC

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around...

CVE-2026-78085

Sep 11, 2026 04:47:51 UTC

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

CVE-2026-78302

Sep 11, 2026 04:46:57 UTC

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendere...

CVE-2026-78374

Sep 11, 2026 04:46:10 UTC

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captch...

CVE-2026-78083

Sep 11, 2026 04:45:48 UTC

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoi...

CVE-2026-78084

Sep 11, 2026 04:45:11 UTC

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal...

CVE-2026-78082

Sep 11, 2026 04:44:05 UTC

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, p...

CVE-2026-89060

Sep 11, 2026 04:42:30 UTC

A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an...

CVE-2026-78303

Sep 11, 2026 04:40:56 UTC

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potenti...

CVE-2026-89162

Sep 11, 2026 04:15:04 UTC

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

CVE-2026-89161

Sep 11, 2026 04:11:51 UTC

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

CVE-2026-89160

Sep 11, 2026 04:09:06 UTC

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

CVE-2026-89158

Sep 11, 2026 04:07:21 UTC

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

CVE-2026-89157

Sep 11, 2026 04:05:27 UTC

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.