cve
Veille des vulnérabilités Archive complète
identifiantvulnérabilitésévéritépublié
CVE-2026-16765A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. Élevée CVSS 7.3 CVE-2026-16796Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.
To mitigate this issue, users should upgrade to the patched version 1.18.1.Analyse NVD en cours Élevée CVSS 7.3 CVE-2026-16804Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)Google Chrome Élevée CVSS 8.3 CVE-2026-16805Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)Google Chrome Élevée CVSS 8.8 CVE-2026-16806Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)Google Chrome Élevée CVSS 8.8 CVE-2026-16807Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)Google Chrome Élevée CVSS 8.8 CVE-2026-21653Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.Analyse NVD en cours Élevée CVSS 7.2 CVE-2026-21655Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586.
This issue affects victor: from 2.9 before 3.0.Analyse NVD en cours Élevée CVSS 8.7 CVE-2026-24552Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions. Élevée CVSS 8.5 CVE-2026-25405Contributor SQL Injection in eRoom <= 1.7.1 versions. Élevée CVSS 8.5 CVE-2026-25800Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buffer overhead, enabling memory exhaustion. Version 0.11.15 fixes the issue.Analyse NVD en cours Élevée CVSS 7.5 CVE-2026-27064Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. Critique CVSS 9.1 CVE-2026-28698Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem. Élevée CVSS 8.6 CVE-2026-34496Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.
This issue affects victor Web: before 7.1.Analyse NVD en cours Élevée CVSS 7.1 CVE-2026-38764An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysAnalyse NVD en cours Élevée CVSS 7.8 CVE-2026-40430Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API. Élevée CVSS 7.5 CVE-2026-42933Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation. Critique CVSS 10 CVE-2026-43820NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.Analyse NVD en cours Élevée CVSS 7.7 CVE-2026-43823When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.Analyse NVD en cours Élevée CVSS 7.5 CVE-2026-44909Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected. Élevée CVSS 7.5 CVE-2026-47668DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch. Critique CVSS 10 CVE-2026-47669DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue.Analyse NVD en cours Critique CVSS 9.3 CVE-2026-47670DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.Analyse NVD en cours Critique CVSS 9.4 CVE-2026-47722nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`. `internal/web/advanced.go:20-35` accepts both with only `strings.TrimSpace` — no character or shape validation. Version 0.3.2 fixes the issue.Analyse NVD en cours Élevée CVSS 8.7 CVE-2026-47723nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`, `Strict-Transport-Security`, `X-Content-Type-Options`, `Referrer-Policy` returns zero matches across the codebase. Version 0.3.1 fixes the issue.Analyse NVD en cours Élevée CVSS 7.1 CVE-2026-47724nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API trusts the bearer token for authorisation; per-CA ownership is enforced only in the Web layer." The Web UI gates state-changing routes through `loadAccessibleCA` (`internal/web/cas.go`); CA-management endpoints in `internal/api/cas.go` ALSO have proper `canAccessCA` gates. The gap is on the host, network, firewall, mobile-bundle, and most operator endpoints. Combined with the per-operator CA model from ADR 0002, this gives any non-admin operator API key broad cross-tenant access — instant privilege escalation in the worst case. Version 0.3.4 fixes the issue.Analyse NVD en cours Critique CVSS 9.9 CVE-2026-47743Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, bypassing the implicit scoping enforced by the page routing. Second, `Customers/Create::store()` re-passed a `Hidden` `_password` form field straight into the create payload. The plaintext password was rendered into the HTML and transported through the Livewire snapshot in clear text, exposing credentials in the page DOM and in any logging that captures Livewire payloads. Finally, the product barcode field was rendered through `DNS1DFacade::getBarcodeHTML()` with `{!! !!}`. An attacker with `edit_products` permission could persist malicious payload in the barcode field that would execute in the browser of any admin user viewing that product, enabling session theft and privileged-action chaining. Starting in v2.8.0, all vulnerable Livewire model identifiers are now marked `#[Locked]`; `Customers/Create` no longer round-trips the password through a Hidden form field; the plaintext password is hashed at action boundary and never returned to the client; and the product barcode rendering now escapes the value before passing it to the barcode generator and the output is wrapped in an `<svg>` context that does not interpret event handlers. No known workarounds are available. Élevée CVSS 8.7 CVE-2026-47752Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed `jinja2.Environment`, allowing any authenticated user to execute arbitrary OS commands as root inside the container. Version 1.30.2 fixes the issue. Critique CVSS 9.9 CVE-2026-49035The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.Analyse NVD en cours Élevée CVSS 8.1 CVE-2026-50032A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.Analyse NVD en cours Élevée CVSS 7.5 CVE-2026-50039The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.Analyse NVD en cours Élevée CVSS 7.5 CVE-2026-52439An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanismAnalyse NVD en cours Critique CVSS 9.8 CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationAnalyse NVD en cours Élevée CVSS 7.5 CVE-2026-57367Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. Élevée CVSS 7.1 CVE-2026-57370Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. Élevée CVSS 7.1 CVE-2026-57374Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. Élevée CVSS 7.1 CVE-2026-57397Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions. Élevée CVSS 7.1 CVE-2026-57427Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. Élevée CVSS 7.1 CVE-2026-57428Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. Élevée CVSS 7.1 CVE-2026-57626Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery.
This issue affects MailPoet: from 5.30.0 through 5.33.0. Élevée CVSS 7.1 CVE-2026-57696Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. Élevée CVSS 7.1 CVE-2026-57699Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. Élevée CVSS 7.1 CVE-2026-57701Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. Élevée CVSS 7.1 CVE-2026-57704Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. Élevée CVSS 7.1 CVE-2026-57735Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. Élevée CVSS 7.1 CVE-2026-57767Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. Élevée CVSS 7.1 CVE-2026-57769Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. Élevée CVSS 7.1 CVE-2026-57784Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. Critique CVSS 9.6 CVE-2026-57785Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. Élevée CVSS 8.8 CVE-2026-57809Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. Élevée CVSS 7.1 CVE-2026-59512Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. Élevée CVSS 7.1 CVE-2026-59514Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. Critique CVSS 9.3 CVE-2026-59517Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. Élevée CVSS 7.1 CVE-2026-59525Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. Critique CVSS 9.3 CVE-2026-59526Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. Critique CVSS 9.3 CVE-2026-59540Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. Critique CVSS 9.8 CVE-2026-59541Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. Élevée CVSS 8.8 CVE-2026-59542Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. Élevée CVSS 7.7 CVE-2026-59543Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. Critique CVSS 9.9 CVE-2026-59544Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. Critique CVSS 9.8 CVE-2026-59545Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. Élevée CVSS 8.1 CVE-2026-59547Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. Élevée CVSS 7.5 CVE-2026-59554Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions. Élevée CVSS 7.5 CVE-2026-59555Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. Critique CVSS 10 CVE-2026-59678An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager.
This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe. Élevée CVSS 7.1 CVE-2026-60122gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.Analyse NVD en cours Élevée CVSS 7.8 CVE-2026-61943Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. Élevée CVSS 7.5 CVE-2026-61944Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. Élevée CVSS 7.1 CVE-2026-61947Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. Élevée CVSS 7.1 CVE-2026-61948Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. Critique CVSS 9.3 CVE-2026-61949Unauthenticated SQL Injection in Bookly <= 27.7 versions. Critique CVSS 9.3 CVE-2026-61950Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. Critique CVSS 9.3 CVE-2026-61951Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. Critique CVSS 9.8 CVE-2026-61954Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions. Élevée CVSS 7.5 CVE-2026-633139Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch content. The URL is only validated as syntactically valid via new URL() with no blocklist for private IP ranges, cloud metadata endpoints (e.g., 169.254.169.254), link-local addresses, or internal hostnames. An authenticated or locally-connected user can cause the server to fetch arbitrary internal URLs and have the response content returned, enabling read-access SSRF that can expose cloud metadata credentials, reach internal services, and bypass authentication on localhost endpoints.Analyse NVD en cours Élevée CVSS 7.7 CVE-2026-63359The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.Analyse NVD en cours Critique CVSS 9.8 CVE-2026-637329router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote, unauthenticated attacker can log in with the default credential, spoof the Host header to reach local-only routes, and register a malicious MCP plugin (e.g. node -e <payload>) to achieve arbitrary code execution on the host operating system when the plugin's SSE endpoint is triggered.Analyse NVD en cours Critique CVSS 9.9 CVE-2026-63765Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed PUT URLs to write arbitrary data to the application's storage backend. Élevée CVSS 8.2 CVE-2026-64600In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,
a data fork mapping, and a cow fork mapping. Unfortunately, these two
helpers cycle the ILOCK to grab a transaction, which means that the
mappings are stale as soon as we reacquire the ILOCK. Currently we
refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but
we don't refresh the data fork mapping beforehand, which means that the
xfs_bmap_trim_cow in that function queries the refcount btree about the
wrong physical blocks and returns an inaccurate value in *shared.
If *shared is now false, the directio write proceeds with a stale data
fork mapping. Fix this by querying the data fork mapping if the
sequence counter changes across the ILOCK cycle.Analyse NVD en cours Élevée CVSS 7.8 CVE-2026-64611A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.Analyse NVD en cours Élevée CVSS 7.5 CVE-2026-64799Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder. Élevée CVSS 7.5 CVE-2026-64802In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integrationAnalyse NVD en cours Élevée CVSS 7.8 CVE-2026-64803In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDKAnalyse NVD en cours Élevée CVSS 7.8 CVE-2026-64804In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter toolingAnalyse NVD en cours Élevée CVSS 8.4 CVE-2026-64805In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager toolingAnalyse NVD en cours Élevée CVSS 8.4 CVE-2026-64806In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreterAnalyse NVD en cours Élevée CVSS 8.4 CVE-2026-64807In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configurationAnalyse NVD en cours Élevée CVSS 7.8 CVE-2026-64808In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project toolingAnalyse NVD en cours Élevée CVSS 8.4 CVE-2026-64809In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreterAnalyse NVD en cours Élevée CVSS 8.4 CVE-2026-64811In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configurationAnalyse NVD en cours Élevée CVSS 7.8 CVE-2026-64812In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionAnalyse NVD en cours Critique CVSS 10 CVE-2026-64813In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development sessionAnalyse NVD en cours Critique CVSS 10 CVE-2026-64814In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development sessionAnalyse NVD en cours Élevée CVSS 8.6 CVE-2026-64815In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form filesAnalyse NVD en cours Élevée CVSS 8.1 CVE-2026-64873Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. Critique CVSS 9.8 CVE-2026-64874Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. Critique CVSS 9.8 CVE-2026-6516Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.Analyse NVD en cours Critique CVSS 10 CVE-2026-65430Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability. Élevée CVSS 7.5 CVE-2026-65431Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. Critique CVSS 9.8 CVE-2026-65450Contributor SQL Injection in MapSVG <= 8.14.0 versions. Élevée CVSS 8.5 401–500 / 5155 CVE