Common Vulnerabilities and Exposures (CVE)

CVE-2026-93304

Sep 27, 2026 09:05:37 UTC

A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the se...

CVE-2026-94417

Sep 27, 2026 09:00:59 UTC

When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certifica...

CVE-2026-94418

Sep 27, 2026 08:58:56 UTC

Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse return...

CVE-2026-94419

Sep 27, 2026 08:54:18 UTC

Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it aga...

CVE-2026-13742

Sep 27, 2026 06:12:21 UTC

Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, leading to the replacement of downloaded f...

CVE-2026-0014

Sep 27, 2026 05:07:46 UTC

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction i...

CVE-2025-47828

Sep 27, 2026 05:07:45 UTC

Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.

CVE-2026-94130

Sep 27, 2026 04:50:32 UTC

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.

CVE-2026-94131

Sep 27, 2026 04:49:04 UTC

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cl...

CVE-2026-97161

Sep 27, 2026 04:49:00 UTC

Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-97163

Sep 27, 2026 04:47:20 UTC

Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-97162

Sep 27, 2026 04:47:07 UTC

Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-94132

Sep 27, 2026 04:44:35 UTC

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so a...

CVE-2026-97160

Sep 27, 2026 04:44:21 UTC

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

CVE-2026-85542

Sep 27, 2026 03:55:28 UTC

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to ...