VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,030 CVE recordsPage 138 of 1202 · EPSS data 2026.08.07
ReviewCritical
CVE-2026-64796

regularlabs.com Sourcerer extension for Joomla

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-64793

regularlabs.com Articles Anywhere extension for Joomla, Modules Anywhere extension for Joomla

Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-64792

regularlabs.com Articles Anywhere extension for Joomla, Conditional Content extension for Joomla, Modules Anywhere extension for Joomla

Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-64791

regularlabs.com Regular Labs Extension Manager extension for Joomla

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63685

regularlabs.com DB Replacer extension for Joomla

Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63684

regularlabs.com Content Templater extension for Joomla, ReReplacer extension for Joomla, Snippets extension for Joomla

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63683

regularlabs.com Advanced Module Manager extension for Joomla, Conditional Content extension for Joomla, Content Templater Pro extension for Joomla

Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63280

regularlabs.com Advanced Module Manager extension for Joomla, Conditional Content extension for Joomla, Content Templater Pro extension for Joomla

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63265

regularlabs.com Advanced Module Manager extension for Joomla, Articles Anywhere extension for Joomla, Articles Field extension for Joomla

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13089

RITOU OIDC::Lite

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin an algorithm, OIDC::Lite::Model::IDToken::verify sets $self->alg($self->header->{alg}) from the token's own header and then calls decode_jwt(token, key, 1, [$self->alg]), handing JSON::WebToken an accepted-algorithm allowlist taken from the untrusted token. A token with alg=none yields ['none'], so decode_jwt returns the claims with no signature check, and a token with alg=HS256 is verified with the RP's RSA public key as...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-60835

the affected product

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50330

the affected product

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-50329

the affected product

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50327

the affected product

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-50324

the affected product

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

The CVSS severity warrants an early asset and exposure review.