Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,501 - 2,520 of 36,778 CVEs
CVE-2024-47477 MEDIUM - 6.5

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.

Vendor: Dell
Product: PowerFlex Manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-54016 MEDIUM - 4.3

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin search_knowledge_files tool. When native function calling is enabled and the selected model has no...

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub

Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.

Published: Jun 17, 2026
Source: NVD
CVE-2026-55738 HIGH - 8.8

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy() without guaranteeing null termination of the source. The POSIX ustar format permits these fixed-width ...

Vendor: rxi
Product: microtar
Published: Jun 17, 2026
Source: NVD
CVE-2026-54819 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

Vendor: Webilia Inc.
Product: Listdom
Published: Jun 17, 2026
Source: NVD
CVE-2026-54818 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

Vendor: VeronaLabs
Product: Slimstat Analytics
Published: Jun 17, 2026
Source: NVD
CVE-2026-54817 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

Vendor: FluxBuilder
Product: MStore API
Published: Jun 17, 2026
Source: NVD
CVE-2026-54816 HIGH - 7.5

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.

Vendor: Monetizemore
Product: Advanced Ads
Published: Jun 17, 2026
Source: NVD
CVE-2026-54815 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.

Vendor: Cargo RD
Product: Cargo Shipping Location for WooCommerce
Published: Jun 17, 2026
Source: NVD
CVE-2026-54814 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

Vendor: StylemixThemes
Product: Motors
Published: Jun 17, 2026
Source: NVD
CVE-2026-54813 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.

Vendor: Brainstorm Force
Product: SureDash
Published: Jun 17, 2026
Source: NVD
CVE-2026-54809 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.

Vendor: VillaTheme
Product: GIFT4U
Published: Jun 17, 2026
Source: NVD
CVE-2026-54808 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.

Vendor: WP Travel
Product: WP Travel Gutenberg Blocks
Published: Jun 17, 2026
Source: NVD
CVE-2026-54417 HIGH - 7.5

An integer overflow in the mtar_next() function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next() computes the offset to the next record as round_up(h.size, 512) + sizeof...

Vendor: rxi
Product: microtar
Published: Jun 17, 2026
Source: NVD
CVE-2026-54193 HIGH - 7.7

Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.

Vendor: ThemeFusion
Product: Fusion Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-52716 MEDIUM - 6.5

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

Vendor: purethemes
Product: WorkScout-Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-52707 HIGH - 8.1

Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

Vendor: Mikado-Themes
Product: Kastell
Published: Jun 17, 2026
Source: NVD
CVE-2026-49268 CRITICAL - 9.1

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: Jun 17, 2026
Source: NVD
CVE-2026-49108 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

Vendor: park_of_ideas
Product: Moderno
Published: Jun 17, 2026
Source: NVD
CVE-2026-40757 HIGH - 8.1

Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

Vendor: Mikado-Themes
Product: Château
Published: Jun 17, 2026
Source: NVD