Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · joomla

joomla

· 26 Critical

Total CVEs

963

Critical

26

Products

148

Search All CVEs →

963

Products (148)

joomla\!631 CVEsjoomla215 CVEsbsq sitestats6 CVEsrs gallery24 CVEscom weblinks3 CVEscom beamospetition3 CVEsjd-wiki2 CVEscom sef2 CVEscom rapidrecipe2 CVEscom mailto2 CVEscom downloads2 CVEscom facileforms2 CVEscom pcchess2 CVEscom pccookbook2 CVEscom astatspro2 CVEscom casiino blackjack1 CVEscom casino1 CVEscom casino videopoker1 CVEscom casinobase1 CVEscom clasifier1 CVEscom classifieds1 CVEscom comments1 CVEscom comprofiler1 CVEscom comprofiler component1 CVEscom content1 CVEscom datsogallery1 CVEscom detail1 CVEscom dhforum1 CVEscom directory1 CVEscom doc1 CVEscom dtregister1 CVEscom elite experts1 CVEscom eventing1 CVEscom events1 CVEscom ewriting1 CVEscom expshop1 CVEscom ezstore1 CVEscom filebase component1 CVEscom flippingbook1 CVEscom fq1 CVEscom galeria1 CVEscom gallery1 CVEscom gameq1 CVEscom garyscookbook1 CVEscom gsticketsystem1 CVEscom hotproperties1 CVEscom idoblog1 CVEscom imagebrowser1 CVEscom iomezun1 CVEscom jb21 CVEscom jokes1 CVEscom joobb1 CVEscom joomradio1 CVEscom jotloader1 CVEscom jvcomment1 CVEscom libros1 CVEscom lms1 CVEscom mamml1 CVEscom marketplace1 CVEscom mcquiz1 CVEscom mediaslide1 CVEscom mezun1 CVEscom mosmedia1 CVEscom musica1 CVEscom mycontent1 CVEscom neogallery1 CVEscom neoreferences1 CVEscom news portal1 CVEscom newsfeeds1 CVEscom newsletter1 CVEscom noticias1 CVEscom paxgallery1 CVEscom profile1 CVEscom quiz1 CVEscom recipes1 CVEscom ricette component1 CVEscom rssreader1 CVEscom salesrep1 CVEscom scheduling component1 CVEscom school1 CVEscom search1 CVEscom search component1 CVEscom shambo21 CVEscom simpleshop1 CVEscom sobi21 CVEscom user1 CVEscom waticketsystem1 CVEscom xewebtv1 CVEscom xsstream-dm1 CVEscom ynews1 CVEscom yvcomment1 CVEsdatsogallery1 CVEseasybook component1 CVEseventlist1 CVEsevents module1 CVEsexpose1 CVEsflash fun component1 CVEsglossary1 CVEshot properties1 CVEsignitegallery1 CVEsj reactions1 CVEsjambook1 CVEsjd-wordpress1 CVEsjim component1 CVEsjim instant messaging component1 CVEsjoom12pic component1 CVEsjoomla radio1 CVEsjoomlalib1 CVEskemas antonius com quran1 CVEsletterman subscriber1 CVEslmo1 CVEsmoslistmessenger component1 CVEsmosmedia1 CVEsmusepoes component1 CVEsneorecruit1 CVEsnfn address book1 CVEsnice talk1 CVEspc cookbook1 CVEsperforms component1 CVEspony gallery1 CVEsprince clan chess component1 CVEsrapid recipe1 CVEsrsfiles1 CVEsrssxt component1 CVEsrwcards component1 CVEssef4040x1 CVEssession1 CVEsswmenu component1 CVEstaskhopper component1 CVEstour de france pool1 CVEswebring component1 CVEsx-shop component1 CVEsakobook1 CVEsxstandard1 CVEsbe it easypartner component1 CVEsbibtex1 CVEscar manager1 CVEsclassifieds component1 CVEscolophon1 CVEscom acajoom1 CVEscom acctexp1 CVEscom artistavenue1 CVEscom awesom1 CVEscom biblestudy1 CVEscom books1 CVEscom brightweblinks1 CVEscom buslicense1 CVEscom camelcitydb21 CVEs

Recent Vulnerabilities

View all 963
CVE-2026-48904CRITICAL 9.8

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

CVE-2026-48903MEDIUM 6.1

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

CVE-2026-48902CRITICAL 9.8

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

CVE-2026-48901HIGH 7.5

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

CVE-2026-48900MEDIUM 4.3

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

CVE-2026-48899CRITICAL 9.8

An improper access check allows privilege escalation through the com_users batch task.

CVE-2026-48898CRITICAL 9.8

An improper access check allows privilege escalation through the com_users batch task.

CVE-2026-48897HIGH 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

CVE-2026-48896HIGH 7.5

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

CVE-2026-40384HIGH 7.5

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

CVE-2026-40383CRITICAL 9.8

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

CVE-2026-35223CRITICAL 9.8

An improper access check allows unauthorized access to com_config webservice endpoints.

CVE-2026-35222CRITICAL 9.8

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

CVE-2026-35221CRITICAL 9.8

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

CVE-2026-30895MEDIUM 6.1

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

CVE-2026-30894MEDIUM 6.1

Lack of output escaping leads to a XSS vector in the content history component.

CVE-2026-25901MEDIUM 6.1

Lack of output escaping leads to a XSS vector in the multilingual associations component.

CVE-2026-48905MEDIUM 6.1

Lack of input filtering leads to an XSS vector in the HTML filter code.

CVE-2026-35220MEDIUM 4.3

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

CVE-2026-25900MEDIUM 6.1

Lack of output escaping leads to a XSS vector in the feed modules.

CVE-2026-23899HIGH 8.8

An improper access check allows unauthorized access to webservice endpoints.

CVE-2026-23898HIGH 7.2

Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

CVE-2026-21632MEDIUM 5.4

Lack of output escaping for article titles leads to XSS vectors in various locations.

CVE-2026-21631MEDIUM 5.4

Lack of output escaping leads to a XSS vector in the multilingual associations component.

CVE-2026-21630HIGH 8.8

Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.