Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,900
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 201 - 220 of 12,881 CVEs
CVE-2024-37210 MEDIUM - 6.5

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

Vendor: ali2woo
Product: AliNext
Published: Jun 17, 2026
Source: NVD
CVE-2024-35690 MEDIUM - 6.5

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.

Vendor: MarketingFire
Product: Widget Options
Published: Jun 17, 2026
Source: NVD
CVE-2024-35648 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.

Vendor: Andy Moyle
Product: Emergency Password Reset
Published: Jun 17, 2026
Source: NVD
CVE-2024-34810 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

Vendor: Extend Themes
Product: Skyline WP
Published: Jun 17, 2026
Source: NVD
CVE-2024-33909 MEDIUM - 5.3

Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.

Vendor: Avirtum
Product: iPages Flipbook
Published: Jun 17, 2026
Source: NVD
CVE-2024-33685 MEDIUM - 4.3

Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.

Vendor: Jegstudio
Product: Startupzy
Published: Jun 17, 2026
Source: NVD
CVE-2024-31435 MEDIUM - 4.3

: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6.

Vendor: Inisev
Product: Social Media & Share Icons
Published: Jun 17, 2026
Source: NVD
CVE-2024-24709 MEDIUM - 4.3

Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11.

Vendor: Shareaholic
Product: Shareaholic
Published: Jun 17, 2026
Source: NVD
CVE-2026-48776 MEDIUM - 4.2

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource ope...

Vendor: langchain-ai
Product: langchain-ai, langchain-sdk
Published: Jun 17, 2026
Source: NVD
CVE-2026-46979 MEDIUM - 6.5

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise People...

Published: Jun 17, 2026
Source: NVD
CVE-2026-46877 MEDIUM - 6.0

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromis...

Vendor: oracle
Product: vm_virtualbox
Published: Jun 17, 2026
Source: NVD
CVE-2026-46871 MEDIUM - 6.5

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. Successful attac...

Published: Jun 17, 2026
Source: NVD
CVE-2026-46869 MEDIUM - 6.5

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell. ...

Vendor: oracle
Product: mysql_shell
Published: Jun 17, 2026
Source: NVD
CVE-2026-46825 MEDIUM - 6.0

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromis...

Vendor: oracle
Product: vm_virtualbox
Published: Jun 17, 2026
Source: NVD
CVE-2026-46812 MEDIUM - 6.1

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle ...

Vendor: oracle
Product: access_manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-46810 MEDIUM - 6.5

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Identity Man...

Vendor: oracle
Product: identity_manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-46790 MEDIUM - 5.3

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content....

Vendor: oracle
Product: webcenter_content
Published: Jun 17, 2026
Source: NVD
CVE-2026-46772 MEDIUM - 4.7

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure wh...

Vendor: oracle
Product: application_development_framework
Published: Jun 17, 2026
Source: NVD
CVE-2026-46771 MEDIUM - 4.1

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infra...

Vendor: oracle
Product: application_development_framework
Published: Jun 17, 2026
Source: NVD
CVE-2026-46770 MEDIUM - 6.1

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP...

Vendor: oracle
Product: application_development_framework
Published: Jun 17, 2026
Source: NVD