Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,909
Quick preset (or use dates below)
Clear Filters
Showing 181 - 200 of 13,286 CVEs
CVE-2026-8383 MEDIUM - 5.3

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a...

Published: Jun 17, 2026
Source: NVD
CVE-2026-7850 MEDIUM - 5.9

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks agains...

Published: Jun 17, 2026
Source: NVD
CVE-2026-55706 MEDIUM - 5.8

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

Vendor: OpenBSD
Product: OpenBSD
Published: Jun 17, 2026
Source: NVD
CVE-2026-54196 MEDIUM - 6.8

Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.

Vendor: Jetmonsters
Product: JetFormBuilder
Published: Jun 17, 2026
Source: NVD
CVE-2026-49072 MEDIUM - 6.5

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

Vendor: OPMC
Product: WooCommerce Anti-Fraud
Published: Jun 17, 2026
Source: NVD
CVE-2026-49071 MEDIUM - 6.5

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

Vendor: OPMC
Product: WooCommerce Dropshipping
Published: Jun 17, 2026
Source: NVD
CVE-2026-48783 MEDIUM - 4.8

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose....

Vendor: gitroomhq
Product: postiz-app
Published: Jun 17, 2026
Source: NVD
CVE-2026-48782 MEDIUM - 6.8

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous fix, CVE-2026-46678, d...

Vendor: pydantic
Product: pydantic-ai, pydantic-ai-slim
Published: Jun 17, 2026
Source: NVD
CVE-2026-47340 MEDIUM - 6.5

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-47277 MEDIUM - 6.5

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arbitrary file read through app-store logo symlinks. The path guard checks only the...

Vendor: runtipi
Product: runtipi
Published: Jun 17, 2026
Source: NVD
CVE-2026-45436 MEDIUM - 6.5

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

Vendor: Rain-Task Ltd.
Product: WPBakery Page Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-42357 MEDIUM - 6.5

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-41280 MEDIUM - 4.9

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-40724 MEDIUM - 6.5

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

Vendor: Client Portal Ltd.
Product: Client Portal (Pro)
Published: Jun 17, 2026
Source: NVD
CVE-2026-40723 MEDIUM - 4.3

Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.

Vendor: Bricks
Product: Bricks Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-40722 MEDIUM - 5.5

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.

Vendor: Yoast BV
Product: Yoast SEO Premium
Published: Jun 17, 2026
Source: NVD
CVE-2026-39595 MEDIUM - 4.7

Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.

Vendor: BoldGrid
Product: W3 Total Cache
Published: Jun 17, 2026
Source: NVD
CVE-2026-39578 MEDIUM - 5.5

Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.

Vendor: Elated-Themes
Product: Valiance
Published: Jun 17, 2026
Source: NVD
CVE-2026-39577 MEDIUM - 5.5

Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.

Vendor: Elated-Themes
Product: Playroom
Published: Jun 17, 2026
Source: NVD
CVE-2026-39433 MEDIUM - 6.5

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

Vendor: mojoomla
Product: WPAMS
Published: Jun 17, 2026
Source: NVD