Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,647
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,121 - 2,140 of 34,996 CVEs
CVE-2026-9062 LOW - 3.4

The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.

Published: Jun 13, 2026
Source: NVD
CVE-2026-9061 LOW - 3.5

The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks eve...

Published: Jun 13, 2026
Source: NVD

We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports loading dashboards & library panels using the jsonnet dat...

Vendor: Grafana
Product: Grafana Operator
Published: Jun 13, 2026
Source: NVD
CVE-2026-9848 HIGH - 7.5

The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks WordPress's `posts_request` filter with `wp_ticket_com_posts_request()`, which calls `emd_author_search_results()` when the c...

Published: Jun 13, 2026
Source: NVD
CVE-2026-54231 MEDIUM - 5.5

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A lo...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-54230 HIGH - 7.0

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writ...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-54229 HIGH - 7.0

A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. Th...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-54228 HIGH - 7.8

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing packa...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-12089 MEDIUM - 4.9

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting <link rel="stylesheet" href="..."> values harvested ...

Vendor: aurelienlws
Product: LWS Optimize – All-in-One Speed Booster & Cache Tools
Published: Jun 13, 2026
Source: NVD
CVE-2026-11443 MEDIUM - 4.6

Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User interaction is required to exploit this vulnerability in that the target must visit a malicious page ...

Vendor: Allegra
Product: Allegra
Published: Jun 13, 2026
Source: NVD
CVE-2026-11442 MEDIUM - 6.5

Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw exists within the exportRepor...

Vendor: Allegra
Product: Allegra
Published: Jun 13, 2026
Source: NVD
CVE-2026-6676 HIGH - 7.8

Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.27...

Published: Jun 12, 2026
Source: NVD
CVE-2026-12068 HIGH - 7.4

Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection. This issue affects Avira Password Manager when u...

Vendor: Gen Digital
Product: Avira Password Manager
Published: Jun 12, 2026
Source: NVD
CVE-2025-9033 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.76.

Published: Jun 12, 2026
Source: NVD
CVE-2025-9032 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.98...

Published: Jun 12, 2026
Source: NVD
CVE-2025-14098 HIGH - 7.8

Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux fo...

Vendor: Gen Digital
Product: Avira Antivirus
Published: Jun 12, 2026
Source: NVD

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects, the sharing group valida...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD

Rejected reason: CVE ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-53826. Reason: This candidate is a duplicate of CVE-2025-53826. Notes: All CVE users should reference CVE-2025-53826 instead of this candidate

Published: Jun 12, 2026
Source: NVD
CVE-2026-53868 HIGH - 7.5

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can permanently lock legitimate users out of the platform for 30 d...

Vendor: Capgo
Product: Capgo
Published: Jun 12, 2026
Source: NVD