|
1791
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
|
CWE-89
SQL Injection
|
CVE-2026-35221
|
2026-05-27 22:05 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1792
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
|
CWE-89
SQL Injection
|
CVE-2026-35222
|
2026-05-27 21:28 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1793
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
|
CWE-22
Path Traversal
|
CVE-2026-40383
|
2026-05-27 21:24 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1794
|
7.5 |
HIGH
Network
|
microsoft
|
global_secure_access
|
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
|
CWE-269
Improper Privilege Management
|
CVE-2026-23663
|
2026-05-27 21:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1795
|
10.0 |
CRITICAL
Network
|
microsoft
|
entra_id
|
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
|
CWE-346
Origin Validation Error
|
CVE-2026-42901
|
2026-05-27 21:13 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1796
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11…
|
CWE-89
SQL Injection
|
CVE-2026-8054
|
2026-05-27 18:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1797
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and mo…
|
CWE-284
Improper Access Control
|
CVE-2026-49002
|
2026-05-27 18:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1798
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampe…
|
CWE-352
Origin Validation Error
|
CVE-2026-49001
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1799
|
7.0 |
HIGH
Network
|
-
|
-
|
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakag…
|
CWE-310
Cryptographic Issues
|
CVE-2026-49000
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1800
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically lo…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48999
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|