Common Vulnerabilities and Exposures (CVE)

CVE-2026-0014

Sep 27, 2026 05:07:46 UTC

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction i...

CVE-2025-47828

Sep 27, 2026 05:07:45 UTC

Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.

CVE-2026-94130

Sep 27, 2026 04:50:32 UTC

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.

CVE-2026-94131

Sep 27, 2026 04:49:04 UTC

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cl...

CVE-2026-97161

Sep 27, 2026 04:49:00 UTC

Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-97163

Sep 27, 2026 04:47:20 UTC

Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-97162

Sep 27, 2026 04:47:07 UTC

Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-94132

Sep 27, 2026 04:44:35 UTC

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so a...

CVE-2026-97160

Sep 27, 2026 04:44:21 UTC

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-85542

Sep 27, 2026 03:55:28 UTC

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to ...

CVE-2026-100746

Sep 27, 2026 03:30:18 UTC

A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results i...

CVE-2026-100745

Sep 27, 2026 02:00:16 UTC

A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard Handler. The manipulation of the argument interface1/interface2 leads to...

CVE-2026-100837

Sep 27, 2026 01:30:05 UTC

Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) wit...

CVE-2026-100836

Sep 27, 2026 01:29:58 UTC

Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh ...

CVE-2026-100865

Sep 27, 2026 01:28:53 UTC

Heym before 0.0.53 contains multiple independent vulnerabilities. (1) The workflow condition evaluator uses Python eval() without an effective sandbox, allowing any user who can edit a workflow branch/condition node — or who can import a wo...