|
1991
|
6.5 |
MEDIUM
Network
|
-
|
-
|
AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can sub…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-56346
|
2026-06-23 03:36 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1992
|
7.5 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the owning user_id for supplied API keys, creating an API key validity oracle and…
|
CWE-200
Information Exposure
|
CVE-2026-56242
|
2026-06-23 03:36 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1993
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users to elevate privileges from admin to super_admin. Attackers can exploit the ins…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56251
|
2026-06-23 03:36 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1994
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization be…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-56385
|
2026-06-23 03:36 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1995
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rend…
|
CWE-79
Cross-site Scripting
|
CVE-2026-56393
|
2026-06-23 03:36 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1996
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET reques…
|
CWE-89
SQL Injection
|
CVE-2017-20252
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1997
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attacker…
|
CWE-89
SQL Injection
|
CVE-2017-20257
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1998
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the…
|
CWE-89
SQL Injection
|
CVE-2017-20258
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1999
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id p…
|
CWE-89
SQL Injection
|
CVE-2017-20263
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2000
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious…
|
CWE-89
SQL Injection
|
CVE-2017-20269
|
2026-06-23 03:35 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|