Recent
coollabsio Coolify Route-Level Middleware CanUpdateResource.php authorization
Published 2026-09-27 by VulDB
D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write
Published 2026-09-27 by VulDB
mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection
Published 2026-09-26 by VulDB
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Kibana Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-09-26 by elastic
Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
Published 2026-09-26 by elastic
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data
Published 2026-09-26 by elastic
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation
Published 2026-09-26 by elastic
Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field
Published 2026-09-26 by Wordfence
Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode
Published 2026-09-26 by Wordfence
miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter
Published 2026-09-26 by Wordfence
Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Published 2026-09-26 by Joomla
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Published 2026-09-26 by Joomla
Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Published 2026-09-26 by Joomla
Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Published 2026-09-26 by Joomla
Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0
Published 2026-09-26 by Joomla
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0
Published 2026-09-26 by Joomla
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3
Published 2026-09-26 by Joomla
capgo through 12.128.2 IDOR via PUT /app icon endpoint
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 Stored XSS via SSL certificate issuer
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 Credential Disclosure via DirProtections API
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 Authentication Bypass via EmailSender.add
Published 2026-09-26 by VulnCheck
froxlor before 2.3.12 CRLF Injection via validateUrl userinfo
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 Privilege Escalation via Symlink
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 Arbitrary File Deletion via Symlink
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 Command Injection via letsencryptchallengepath
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync
Published 2026-09-26 by VulnCheck
froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF
Published 2026-09-26 by VulnCheck
froxlor before 2.3.12 Authentication Bypass via Session Persistence
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 DKIM Private Key Disclosure via API
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.12 2FA Bypass via Namespace Confusion
Published 2026-09-26 by VulnCheck
Froxlor before 2.3.13 Private Key Disclosure via Certificates API
Published 2026-09-26 by VulnCheck
Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path
Published 2026-09-26 by VulnCheck
kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath
Published 2026-09-26 by VulnCheck
Kyverno before 1.19.1 SSRF via legacy apiCall service executor
Published 2026-09-26 by VulnCheck
Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass
Published 2026-09-26 by VulnCheck
Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib
Published 2026-09-26 by VulnCheck
Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays
Published 2026-09-26 by VulnCheck
Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion
Published 2026-09-26 by VulnCheck
nodemailer before 10.0.6 Denial of Service via addressparser
Published 2026-09-26 by VulnCheck
Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment
Published 2026-09-26 by VulnCheck
Adminer before 6.0.2 Privileged-Port SSRF via host_port Regex
Published 2026-09-26 by VulnCheck
Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver
Published 2026-09-26 by VulnCheck
Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver
Published 2026-09-26 by VulnCheck
Load more ↓