Total CVEs

149,967

Critical Severity

4,910

High Severity

17,396

Last 7 Days

1,774
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 581 - 600 of 46,372 CVEs
CVE-2026-59532 HIGH - 7.5

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

Vendor: magepeopleteam
Product: Booking and Rental Manager
Published: Jul 27, 2026
Source: NVD
CVE-2026-59531 HIGH - 7.5

Unauthenticated Unknown in Falcon โ€“ WordPress Optimizations & Tweaks <= 2.10.0 versions.

Vendor: Anh Tran
Product: Falcon โ€“ WordPress Optimizations & Tweaks
Published: Jul 27, 2026
Source: NVD
CVE-2026-59530 HIGH - 7.5

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

Vendor: Payment Plugins
Product: Stripe For WooCommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-59529 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

Vendor: motov.net
Product: Ebook Store
Published: Jul 27, 2026
Source: NVD
CVE-2026-59528 HIGH - 7.5

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

Vendor: shiptime
Product: ShipTime: Discounted Shipping Rates
Published: Jul 27, 2026
Source: NVD
CVE-2026-59527 CRITICAL - 9.3

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Vendor: RomanCode
Product: MapSVG
Published: Jul 27, 2026
Source: NVD
CVE-2026-10819 MEDIUM - 6.5

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded ...

Vendor: Mattermost
Product: Mattermost
Published: Jul 27, 2026
Source: NVD
CVE-2026-10600 MEDIUM - 4.3

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on...

Vendor: Mattermost
Product: Mattermost
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.

Vendor: Ericsson
Product: Ericsson Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD
CVE-2026-65879 CRITICAL - 9.8

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD
CVE-2026-61511 CRITICAL - 9.8

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] ...

Vendor: vBulletin
Product: vBulletin
Published: Jul 27, 2026
Source: NVD
CVE-2026-17514 MEDIUM - 5.3

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The projec...

Vendor: ZJONSSON
Product: node-unzipper
Published: Jul 27, 2026
Source: NVD