CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-20272

    Last Modified: 19 Aug 2026

    Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting parameters to extract sensitive database information including table names and column structures.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20271

    Last Modified: 21 Aug 2026

    Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters and inject SQL code in the catid parameter to extract sensitive database information including version and database names.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20270

    Last Modified: 21 Aug 2026

    Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL injection payloads to extract sensitive database information including credentials and configuration data.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20269

    Last Modified: 21 Aug 2026

    Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20268

    Last Modified: 21 Aug 2026

    Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive database information including database names and table structures.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20267

    Last Modified: 19 Aug 2026

    Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20266

    Last Modified: 19 Aug 2026

    Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information.

    Published: 19 Jun 2026
    7.1
    High

    CVE-2017-20265

    Last Modified: 19 Aug 2026

    Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information.

    Published: 19 Jun 2026
    4.6
    Medium

    CVE-2026-12620

    Last Modified: 22 Jun 2026

    The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

    Published: 19 Jun 2026
    7.1
    High

    CVE-2017-20264

    Last Modified: 19 Aug 2026

    Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_sponsorwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information including credentials and configuration data.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20263

    Last Modified: 19 Aug 2026

    Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and a crafted id parameter containing SQL commands to extract sensitive database information.

    Published: 19 Jun 2026
    5.3
    Medium

    CVE-2026-12621

    Last Modified: 22 Jun 2026

    Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20262

    Last Modified: 19 Aug 2026

    Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract sensitive database information including table names and column structures.

    Published: 19 Jun 2026
    5.3
    Medium

    CVE-2026-12622

    Last Modified: 22 Jun 2026

    The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20261

    Last Modified: 19 Aug 2026

    Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20260

    Last Modified: 19 Aug 2026

    Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the product_id parameter to extract sensitive database information including credentials and configuration data.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20259

    Last Modified: 19 Aug 2026

    Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database information including credentials and configuration data.

    Published: 19 Jun 2026
    5.1
    Medium

    CVE-2026-12619

    Last Modified: 22 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20258

    Last Modified: 19 Aug 2026

    Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&id=[SQL] to extract sensitive database information.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20257

    Last Modified: 19 Aug 2026

    Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract sensitive information.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20256

    Last Modified: 19 Aug 2026

    Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract sensitive database information.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20255

    Last Modified: 19 Aug 2026

    Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and view=popup parameters, injecting SQL commands in the visatype parameter to extract sensitive database information including credentials and table contents.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20254

    Last Modified: 19 Aug 2026

    Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid parameter. Attackers can send GET requests to index.php with the option=com_userbench&view=detail&userid parameter containing SQL injection payloads to extract sensitive database information including credentials and configuration data.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20253

    Last Modified: 19 Aug 2026

    Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract sensitive database information including credentials and system data.

    Published: 19 Jun 2026
    8.8
    High

    CVE-2017-20252

    Last Modified: 19 Aug 2026

    Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information.

    Published: 19 Jun 2026
    3
    Low

    CVE-2026-49358

    Last Modified: 23 Jun 2026

    PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls `unlink()` on every entry without verifying that the path is contained within the temporary folder. Any code holding a reference to a generator instance can push an arbitrary path into the array and have it deleted on script shutdown. This mirrors the KnpLabs/snappy issue GHSA-87qc-37cw-84h4. PhpWeasyPrint version 2.6.0 contains a patch for the issue.

    Published: 19 Jun 2026
    6.3
    Medium

    CVE-2026-21768

    Last Modified: 22 Jun 2026

    The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.

    Published: 19 Jun 2026
    6.3
    Medium

    CVE-2026-12726

    Last Modified: 24 Jun 2026

    A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access Token as its webhook credential, the controller later POSTs that token to the stored callback URL when posting job status updates. An attacker who can submit a correctly signed forged webhook using the job template's webhook_key can redirect the callback to an attacker-controlled URL and exfiltrate the configured GitHub PAT.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2025-71326

    Last Modified: 14 Jul 2026

    AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-privileged users to execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that execute with high-level system permissions.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2023-54353

    Last Modified: 23 Jun 2026

    Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attackers to execute arbitrary code by placing malicious executables in unquoted path directories. Attackers with write access to C:\ or subdirectories like C:\Program Files (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberService.exe file that executes with LocalSystem privileges when the service starts automatically at boot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2022-50971

    Last Modified: 15 Jul 2026

    Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2021-47985

    Last Modified: 22 Jun 2026

    Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2020-37254

    Last Modified: 15 Jul 2026

    Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2020-37253

    Last Modified: 22 Jun 2026

    Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2020-37252

    Last Modified: 28 Jul 2026

    Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSystem privileges during service startup or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2020-37251

    Last Modified: 23 Jun 2026

    RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2020-37250

    Last Modified: 24 Jun 2026

    TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be executed during service startup or system reboot with LocalSystem privileges.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2019-25747

    Last Modified: 15 Jul 2026

    Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with LocalSystem privileges when the service starts or restarts.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20095

    Last Modified: 23 Jun 2026

    Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted name to be executed by the service during startup, gaining elevated privileges.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20094

    Last Modified: 15 Jul 2026

    AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20093

    Last Modified: 15 Jul 2026

    Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that execute during service startup or system reboot with elevated privileges.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20092

    Last Modified: 24 Jun 2026

    NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20091

    Last Modified: 15 Jul 2026

    Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20090

    Last Modified: 22 Jun 2026

    Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20089

    Last Modified: 23 Jun 2026

    Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be executed with elevated privileges during service startup or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20088

    Last Modified: 22 Jun 2026

    Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20087

    Last Modified: 22 Jun 2026

    Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service binary path. Attackers can insert malicious executables in the system root path that execute with SYSTEM privileges during service startup or system reboot.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20086

    Last Modified: 28 Jul 2026

    Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and restart the service to execute code with LocalSystem privileges.

    Published: 19 Jun 2026
    8.5
    High

    CVE-2016-20085

    Last Modified: 15 Jul 2026

    Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious executable in the service path. Attackers can insert an executable file in the unquoted path and restart the service to execute code with LocalSystem privileges.

    Published: 19 Jun 2026
    6.3
    Medium

    CVE-2026-9143

    Last Modified: 22 Jun 2026

    There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen.  This may silently discard high bits if a size value exceeded the target type's range. This affects NI grpc-device 2.17.0 and prior versions.

    Published: 19 Jun 2026