CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2026-77994 published: Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerab...
View full advisory →CVE-2026-78255 published: The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the request...
View full advisory →CVE-2026-78202 published: A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The ma...
View full advisory →CVE-2026-8173 published: The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated admini...
View full advisory →CVE-2026-78201 published: A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php...
View full advisory →CVE-2026-78200 published: A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.ph...
View full advisory →CVE-2026-78199 published: A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/v...
View full advisory →CVE-2026-78198 published: A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown proc...
View full advisory →CVE-2026-78197 published: A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the f...
View full advisory →CVE-2026-78186 published: A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. Th...
View full advisory →CVE-2026-78187 published: A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manip...
View full advisory →CVE-2026-78196 published: A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoSh...
View full advisory →CVE-2026-59561 published: Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directe...
View full advisory →CVE-2026-78182 published: A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B...
View full advisory →CVE-2026-78185 published: A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pag...
View full advisory →CVE-2026-78211 published: 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can ...
View full advisory →CVE-2026-78212 published: 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can e...
View full advisory →CVE-2026-78213 published: Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject p...
View full advisory →CVE-2026-78180 published: A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps ...
View full advisory →CVE-2026-78181 published: A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. E...
View full advisory →