Known Vulnerabilities for Data-hub by Pimcore
Listed below are 1 of the newest known vulnerabilities associated with "Data-hub" by "Pimcore".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66144 json | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API i... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-66032 json | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-66009 json | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-66008 json | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class na... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-65902 json | DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEF... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65758 json | Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions vie... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65757 json | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The ed... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65703 json | FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote a... | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-65696 json | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription ... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65608 json | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() reso... | Not Provided | 2026-07-23 | 2026-07-23 |