Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,972
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,161 - 2,180 of 34,601 CVEs

A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import. This vulnerability was p...

Published: Jun 11, 2026
Source: NVD
CVE-2026-3553 LOW - 3.1

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-1500 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a s...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-10733 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.

Vendor: GitLab
Product: GitLab
Published: Jun 11, 2026
Source: NVD
CVE-2026-10087 HIGH - 8.7

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a target...

Vendor: GitLab
Product: GitLab
Published: Jun 11, 2026
Source: NVD
CVE-2023-32959 MEDIUM - 4.3

Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.

Vendor: Sparkle WP
Product: MetroStore
Published: Jun 11, 2026
Source: NVD
CVE-2023-25969 MEDIUM - 5.4

Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form & Lead Form Elementor Builder: from n/a through 1.8.4.

Vendor: ThemeHunk
Product: Contact Form & Lead Form Elementor Builder
Published: Jun 11, 2026
Source: NVD
CVE-2022-47150 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10.

Vendor: weDevs
Product: WooCommerce Conversion Tracking
Published: Jun 11, 2026
Source: NVD
CVE-2022-45813 MEDIUM - 5.4

Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3.

Vendor: BeRocket
Product: Advanced AJAX Product Filters
Published: Jun 11, 2026
Source: NVD
CVE-2026-5497 HIGH - 7.5

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method splits the base64 data string on commas to extract individual J...

Vendor: vllm
Product: vllm
Published: Jun 11, 2026
Source: NVD

Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In affected entities that did not explicitly mark id as inaccessible, an authenticated attacker could submit a crafted edit reques...

Vendor: cerebrate
Product: cerebrate
Published: Jun 11, 2026
Source: NVD
CVE-2026-11850 MEDIUM - 5.0

An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 11, 2026
Source: NVD
CVE-2025-7064 MEDIUM - 6.6

Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.

Published: Jun 11, 2026
Source: NVD
CVE-2022-44630 MEDIUM - 4.6

Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery. This issue affects YITH WooCommerce Product Slider Carousel: from n/a through 1.16.0.

Vendor: YITH
Product: YITH WooCommerce Product Slider Carousel
Published: Jun 11, 2026
Source: NVD
CVE-2022-42479 MEDIUM - 5.4

Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Soledad: from n/a through 8.2.5.

Vendor: TemplateHouse
Product: Soledad
Published: Jun 11, 2026
Source: NVD

Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $params before normalizing the request through __massageInput(). Because the normalized $input could still contain an id field, a us...

Vendor: cerebrate
Product: cerebrate
Published: Jun 11, 2026
Source: NVD
CVE-2024-32110 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.

Vendor: Magepeople inc.
Product: WpEvently
Published: Jun 11, 2026
Source: NVD
CVE-2023-40200 MEDIUM - 5.3

Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6.

Vendor: Essential Plugin
Product: WP Logo Showcase Responsive Slider and Carousel
Published: Jun 11, 2026
Source: NVD
CVE-2023-33999 HIGH - 7.1

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.

Vendor: WPVibes
Product: WP Mail Log
Published: Jun 11, 2026
Source: NVD
CVE-2026-41856 HIGH - 7.5

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at...

Vendor: Spring
Product: Spring for GraphQL
Published: Jun 11, 2026
Source: NVD