|
1151
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Lack of output escaping leads to a XSS vector in the readmore links for com_content.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-30895
|
2026-05-27 22:28 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1152
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-35220
|
2026-05-27 22:18 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1153
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
New
|
CWE-89
SQL Injection
|
CVE-2026-35221
|
2026-05-27 22:05 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1154
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
New
|
CWE-89
SQL Injection
|
CVE-2026-35222
|
2026-05-27 21:28 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1155
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
New
|
CWE-22
Path Traversal
|
CVE-2026-40383
|
2026-05-27 21:24 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1156
|
7.5 |
HIGH
Network
|
microsoft
|
global_secure_access
|
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-23663
|
2026-05-27 21:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1157
|
10.0 |
CRITICAL
Network
|
microsoft
|
entra_id
|
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-346
Origin Validation Error
|
CVE-2026-42901
|
2026-05-27 21:13 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1158
|
- |
|
-
|
-
|
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48906
|
2026-05-27 20:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1159
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11…
New
|
CWE-89
SQL Injection
|
CVE-2026-8054
|
2026-05-27 18:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1160
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and mo…
New
|
CWE-284
Improper Access Control
|
CVE-2026-49002
|
2026-05-27 18:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|