|
741
|
6.5 |
MEDIUM
Local
|
benoitc
|
hackney
|
Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed into a #hackney_url{}…
New
|
CWE-436 CWE-918
Interpretation Conflict Server-Side Request Forgery (SSRF)
|
CVE-2026-47076
|
2026-05-27 22:51 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
742
|
5.5 |
MEDIUM
Local
|
ibm
|
db2
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local …
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-13755
|
2026-05-27 22:49 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
743
|
9.8 |
CRITICAL
Network
|
nvidia
|
isaac_launchable
|
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalatio…
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-24212
|
2026-05-27 22:48 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
744
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Lack of output escaping leads to a XSS vector in the feed modules.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-25900
|
2026-05-27 22:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
745
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Lack of output escaping leads to a XSS vector in the multilingual associations component.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-25901
|
2026-05-27 22:40 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
746
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Lack of output escaping leads to a XSS vector in the content history component.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-30894
|
2026-05-27 22:29 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
747
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-30895
|
2026-05-27 22:28 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
748
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-35220
|
2026-05-27 22:18 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
749
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
New
|
CWE-89
SQL Injection
|
CVE-2026-35221
|
2026-05-27 22:05 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
750
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
New
|
CWE-89
SQL Injection
|
CVE-2026-35222
|
2026-05-27 21:28 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|