Recent
Open Redirect in MISP Installer-Generated Apache Configuration
Published 2026-07-28 by CIRCL
Apache Tomcat: DoS via WebSocket chat example
Published 2026-07-28 by apache
Anchore Enterprise Privilege Escalation via User Management API
Published 2026-07-28 by VulnCheck
Search Order Hijacking in ArkSigner's ArkSigner Desktop Client
Published 2026-07-28 by TR-CERT
SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory
Published 2026-07-28 by Mattermost
DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick
Published 2026-07-28 by CIRCL
Apache Axis2/Java: deserialization of untrusted Data
Published 2026-07-28 by apache
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Published 2026-07-28 by apache
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Published 2026-07-28 by apache
Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests
Published 2026-07-28 by CIRCL
Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Graph Manipulation and Denial of Service
Published 2026-07-28 by CIRCL
Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node References
Published 2026-07-28 by CIRCL
Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
Published 2026-07-28 by CIRCL
Stored DOM-Based Cross-Site Scripting in Node Modal Headers
Published 2026-07-28 by CIRCL
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
Published 2026-07-28 by VulDB
Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash
Published 2026-07-28 by redhat
DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons
Published 2026-07-28 by CIRCL
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
Published 2026-07-28 by Joomla
Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute
Published 2026-07-28 by Wordfence
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Published 2026-07-28 by Wordfence
Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1
Published 2026-07-28 by Joomla
PoD: Don't try to reclaim special pages
Published 2026-07-28 by XEN
correct buffer checks for DM_OP hypercalls
Published 2026-07-28 by XEN
evtchn: Race between FIFO expand and reset
Published 2026-07-28 by XEN
Viridian STIMER division by zero
Published 2026-07-28 by XEN
x86: Out-of-bounds read in vRTC emulation
Published 2026-07-28 by XEN
vNUMA domain cleanup may race other operations
Published 2026-07-28 by XEN
grant-table: version change racing with other operations
Published 2026-07-28 by XEN
grant-table: version change racing with other operations
Published 2026-07-28 by XEN
grant-table: type confusion in grant-copy
Published 2026-07-28 by XEN
sysctl and platform-op locks open to abuse
Published 2026-07-28 by XEN
sysctl and platform-op locks open to abuse
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
buffer overruns in libfsimage iso9660 handling
Published 2026-07-28 by XEN
vIRQ event channel binding may break Xenstore
Published 2026-07-28 by XEN
x86 shadow paging is deprecated
Published 2026-07-28 by XEN
Improper Authentication in Universal Sotware's UKBS
Published 2026-07-28 by TR-CERT
Zip Bomb in Lookyloo Capture Upload Allows Denial of Service
Published 2026-07-28 by CIRCL
Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams
Published 2026-07-28 by redhat
Hard-coded admin credentials in Quick.Cart
Published 2026-07-28 by CERT-PL
Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
Published 2026-07-28 by INCIBE
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action
Published 2026-07-28 by Wordfence
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action
Published 2026-07-28 by Wordfence
Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter
Published 2026-07-28 by Wordfence
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter
Published 2026-07-28 by Wordfence
WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action
Published 2026-07-28 by Wordfence
WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action
Published 2026-07-28 by Wordfence
Load more ↓