Common Vulnerabilities and Exposures (CVE)

CVE-2026-38765

Jul 22, 2026 22:18:11 UTC

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

CVE-2026-38763

Jul 22, 2026 22:16:41 UTC

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828

CVE-2026-16630

Jul 22, 2026 22:15:12 UTC

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be app...

CVE-2026-16629

Jul 22, 2026 21:15:10 UTC

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os ...

CVE-2026-63684

Jul 22, 2026 21:02:20 UTC

Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and item...

CVE-2026-16628

Jul 22, 2026 21:00:12 UTC

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command inj...

CVE-2026-42504

Jul 22, 2026 20:58:40 UTC

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

CVE-2026-50522

Jul 22, 2026 20:46:35 UTC

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVE-2026-16232

Jul 22, 2026 20:46:35 UTC

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful e...

CVE-2026-64793

Jul 22, 2026 20:45:25 UTC

Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.

CVE-2026-64794

Jul 22, 2026 20:45:24 UTC

User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.

CVE-2026-63264

Jul 22, 2026 20:44:43 UTC

The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.

CVE-2026-63047

Jul 22, 2026 20:44:26 UTC

The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

CVE-2026-64797

Jul 22, 2026 20:44:08 UTC

IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

CVE-2026-63265

Jul 22, 2026 20:44:05 UTC

Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lo...