Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,084
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,501 - 2,520 of 47,325 CVEs
CVE-2026-12082 HIGH - 7.5

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

Vendor: Unknown
Product: Praison AI SEO
Published: Jul 23, 2026
Source: NVD
CVE-2026-7534 HIGH - 7.2

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionall...

Published: Jul 23, 2026
Source: NVD
CVE-2026-7232 HIGH - 7.2

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

Published: Jul 23, 2026
Source: NVD
CVE-2026-64600 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab ...

Vendor: Linux
Product: Linux
Published: Jul 23, 2026
Source: NVD
CVE-2026-63226 MEDIUM - 5.8

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

Vendor: Ricoh Company
Product: Ricoh printers and Multifunction Printers (MFPs)
Published: Jul 23, 2026
Source: NVD
CVE-2026-6390 MEDIUM - 6.8

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to...

Published: Jul 23, 2026
Source: NVD
CVE-2026-7120 MEDIUM - 5.3

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-ca...

Vendor: npm
Product: @fastify/static
Published: Jul 23, 2026
Source: NVD
CVE-2026-15074 HIGH - 7.5

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segmen...

Vendor: @fastify/static
Product: @fastify/static
Published: Jul 23, 2026
Source: NVD
CVE-2026-21723 MEDIUM - 5.3

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anon...

Vendor: Grafana
Product: Grafana OSS
Published: Jul 23, 2026
Source: NVD
CVE-2026-16653 MEDIUM - 5.3

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit h...

Vendor: boazsegev
Product: facil.io
Published: Jul 23, 2026
Source: NVD
CVE-2026-16632 HIGH - 7.3

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipulation of the argument on_message causes improper input validation. The attack ca...

Vendor: boazsegev
Product: facil.io
Published: Jul 23, 2026
Source: NVD
CVE-2026-16631 MEDIUM - 5.3

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection. Attacking locally is a requirement. The exploit is now public and may be ...

Product: publint
Published: Jul 23, 2026
Source: NVD
CVE-2026-61246 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60455 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60439 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60373 HIGH - 8.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60372 CRITICAL - 9.8

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to ...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60371 HIGH - 8.0

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical com...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60370 HIGH - 7.5

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD
CVE-2026-60369 CRITICAL - 9.9

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to c...

Vendor: oracle
Product: platform_security_for_java
Published: Jul 22, 2026
Source: NVD