Common Vulnerabilities and Exposures (CVE)

CVE-2026-60031

Jul 22, 2026 05:35:35 UTC

The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.

CVE-2026-28369

Jul 22, 2026 05:35:33 UTC

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP stan...

CVE-2026-61424

Jul 22, 2026 05:35:33 UTC

The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

CVE-2026-60029

Jul 22, 2026 05:35:29 UTC

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.

CVE-2026-60026

Jul 22, 2026 05:35:28 UTC

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requir...

CVE-2026-62414

Jul 22, 2026 05:35:19 UTC

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

CVE-2026-61900

Jul 22, 2026 05:35:12 UTC

The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

CVE-2026-61901

Jul 22, 2026 05:34:11 UTC

The Joomla extension Hikashop is vulnerable to an open redirect.

CVE-2026-50343

Jul 22, 2026 03:55:49 UTC

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-55133

Jul 22, 2026 03:55:48 UTC

Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.

CVE-2026-42990

Jul 22, 2026 03:55:48 UTC

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

CVE-2026-60137

Jul 22, 2026 03:55:47 UTC

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

CVE-2026-63030

Jul 22, 2026 03:55:46 UTC

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injec...

CVE-2021-27137

Jul 22, 2026 03:55:45 UTC

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploita...

CVE-2026-0770

Jul 22, 2026 03:55:44 UTC

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication i...