Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,084
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,481 - 2,500 of 47,325 CVEs
CVE-2026-14282 CRITICAL - 9.8

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() functi...

Vendor: rtcamp
Product: GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more
Published: Jul 23, 2026
Source: NVD
CVE-2026-13119 MEDIUM - 6.5

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard&...

Vendor: roundupwp
Product: Registrations for the Events Calendar – Event Registration Plugin
Published: Jul 23, 2026
Source: NVD
CVE-2026-13009 MEDIUM - 6.5

The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

Vendor: wupsales
Product: AI Copilot – Content Generator
Published: Jul 23, 2026
Source: NVD
CVE-2026-52688 HIGH - 7.5

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

Vendor: PowerDNS
Product: Recursor
Published: Jul 23, 2026
Source: NVD

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

Vendor: PowerDNS
Product: Recursor
Published: Jul 23, 2026
Source: NVD

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used...

Vendor: PowerDNS
Product: Recursor
Published: Jul 23, 2026
Source: NVD
CVE-2026-16723 CRITICAL - 9.0

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Vendor: Alibaba
Product: Fastjson
Published: Jul 23, 2026
Source: NVD
CVE-2026-16287 HIGH - 7.8

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.

Vendor: TUBITAK BILGEM Software Technologies Research Institute
Product: pardus-update
Published: Jul 23, 2026
Source: NVD
CVE-2024-58330 HIGH - 7.5

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

Vendor: Bosch
Product: Camera Firmware
Published: Jul 23, 2026
Source: NVD
CVE-2024-58023 HIGH - 8.4

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

Vendor: Bosch
Product: Bosch Configuration Manager
Published: Jul 23, 2026
Source: NVD
CVE-2026-9729 MEDIUM - 6.4

The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the save...

Published: Jul 23, 2026
Source: NVD
CVE-2026-9713 HIGH - 7.5

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping o...

Published: Jul 23, 2026
Source: NVD
CVE-2026-9635 MEDIUM - 6.4

The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which ...

Published: Jul 23, 2026
Source: NVD

An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.

Vendor: Linux-Gaming
Product: PortProtonQt
Published: Jul 23, 2026
Source: NVD

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.

Vendor: SELinuxProject
Product: selinux
Published: Jul 23, 2026
Source: NVD
CVE-2026-12421 HIGH - 7.2

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

Product: ARforms
Published: Jul 23, 2026
Source: NVD
CVE-2026-9577 MEDIUM - 4.8

The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator'...

Published: Jul 23, 2026
Source: NVD
CVE-2026-9066 MEDIUM - 6.1

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress pl...

Published: Jul 23, 2026
Source: NVD

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

Vendor: SELinuxProject
Product: selinux
Published: Jul 23, 2026
Source: NVD
CVE-2026-14291 HIGH - 7.5

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced...

Vendor: Unknown
Product: security-ninja-premium
Published: Jul 23, 2026
Source: NVD