Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-65947

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-65946

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

PUBLISHED
Vendor
rolandd.com
Product
RO CSVI extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65944

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

PUBLISHED
Vendor
rolandd.com
Product
RO CSVI extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-65943

Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0

PUBLISHED
Vendor
rolandd.com
Product
RO CSVI extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-6594

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototype attributes. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
brikcss
Product
merge
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-6593

A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
ComfyUI
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-65925

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

PUBLISHED
Vendor
jfrog
Product
artifactory
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65924

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.

PUBLISHED
Vendor
jfrog
Product
artifactory
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65923

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.

PUBLISHED
Vendor
jfrog
Product
artifactory
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65922

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.

PUBLISHED
Vendor
jfrog
Product
artifactory
Provider severity
HIGH
Conflicts
0

CVE-2026-65921

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

PUBLISHED
Vendor
jfrog
Product
artifactory
Provider severity
HIGH
Conflicts
0

CVE-2026-65920

Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading.

PUBLISHED
Vendor
huggingface
Product
diffusers
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6592

A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
ComfyUI
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-65919

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.

PUBLISHED
Vendor
meshery
Product
meshery
Provider severity
HIGH
Conflicts
1

CVE-2026-65918

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.

PUBLISHED
Vendor
pytorch
Product
vision
Provider severity
HIGH
Conflicts
1

CVE-2026-65917

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID that is never re-scoped to the authorized domain. Attackers can enumerate sequential backup IDs to rea

PUBLISHED
Vendor
usmannasir
Product
cyberpanel
Provider severity
HIGH
Conflicts
1

CVE-2026-65916

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants.

PUBLISHED
Vendor
usmannasir
Product
cyberpanel
Provider severity
HIGH
Conflicts
1

CVE-2026-65914

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65913

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65912

DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attribute and tag combinations to bypass URI-safe validation, allowing unsafe protocols like javascript: to survive sanitization and execute as DOM-based XSS when the link is activated.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65911

In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subsequent sanitize() calls on the same instance. If a later call on the same instance provides ADD_ATTR or ADD_TAGS as an array rather than a function, the previously set function handler is neither cleared nor overwritten, so it continues to approve attacker-controlled attributes or tags. This can allow dangerous event-handler attri

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6591

A flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This manipulation of the argument Name causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
ComfyUI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65908

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

PUBLISHED
Vendor
JetBrains
Product
PyCharm
Provider severity
HIGH
Conflicts
0

CVE-2026-65907

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

PUBLISHED
Vendor
JetBrains
Product
TeamCity
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65906

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

PUBLISHED
Vendor
JetBrains
Product
TeamCity
Provider severity
HIGH
Conflicts
0

CVE-2026-65904

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to stringify the element (yielding '[object HTMLDivElement]'), silently reset IN_PLACE to false, and return the unsanitized element unchanged with any XSS payloads intact.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-65903

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65902

DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags / data.allowedAttributes when sanitize is called without an explicit cfg.ALLOWED_TAGS / cfg.ALLOWED_ATTR array. A hook that mutates these fields permanently widens the default allow-lists for the lifetime of the DOMPurify instance, so all subsequent default-config sanitiz

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65901

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65900

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6590

A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
ComfyUI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65899

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call als

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65898

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

PUBLISHED
Vendor
cure53
Product
DOMPurify
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-65897

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding those permissions.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
1

CVE-2026-65896

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversal sequences (e.g., 01.home/../../../pwned) to move an entire page directory (content and media) to a

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
1

CVE-2026-65895

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
1

CVE-2026-65894

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to live video snapshots from the targeted device.

PUBLISHED
Vendor
CP-Plus
Product
EZ-P21 IP Camera
Provider severity
HIGH
Conflicts
0

CVE-2026-65893

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug mechanism. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with elevated privileges on the targeted device.

PUBLISHED
Vendor
CP-Plus
Product
EZ-P21 IP Camera
Provider severity
HIGH
Conflicts
0

CVE-2026-65891

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.

PUBLISHED
Vendor
joomlacontenteditor.net
Product
Joomla Content Editor (JCE) extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65890

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-6589

A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
ComfyUI
Provider severity
MEDIUM
Conflicts
2

CVE-2026-65889

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
CRITICAL
Conflicts
1

CVE-2026-65888

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65887

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65886

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65885

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65884

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65883

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

PUBLISHED
Vendor
aimy-extensions.com
Product
Aimy Captcha-Less Form Guard plugin for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65882

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.

PUBLISHED
Vendor
joomdle.com
Product
Joomdle component for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65881

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.

PUBLISHED
Vendor
joomdle.com
Product
Joomdle component for Joomla
Provider severity
HIGH
Conflicts
1