View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

CVE-2026-74253: CVSS 10.0 unauthenticated RCE in Joomla extension

🔓 CVEs & KEV

  • CVE-2026-74253 — CVSS 10.0 — Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified r...

  • CVE-2026-74254 — CVSS 9.3 — Joomla Extension - joomlack.fr - SQL injection in Page Builder CK before 3.6.5Joom...

  • CVE-2026-62982 — CVSS 8.8 — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypas...

  • CVE-2026-54284 — CVSS 8.7 — sqlparse: TokenList.init materializes O(subtree) value per group, causing...

  • CVE-2026-71491 — CVSS 8.7 — sqlparse: Quadratic O(n2) DoS in group_commentssqlparse is a non-validating S...

  • CVE-2026-59902 — CVSS 7.5 — Netty: Memory Exhaustion in SctpMessageCompletionHandlerNetty is an asynchron...

  • CVE-2026-59893 — CVSS 7.5 — sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to R...

  • CVE-2026-68519 — CVSS 7.1 — Glances: --disable-config-exec does not cover on-alert action commands (inc...

  • CVE-2026-32608 — Nicolargo Glances — CVSS 7.0 — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypas...

  • CVE-2026-59903 — CVSS 6.5 — Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwr...

  • CVE-2026-73424 — CVSS 6.5 — Astro: Unauthenticated path override in the @astrojs/vercel ISR functionAstro...

  • CVE-2026-68517 — CVSS 6.5 — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membersh...

  • CVE-2026-59894 — CVSS 6.2 — sqlparse: Generated Python and PHP snippets allow SQL string breakout through...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check