Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,581 - 2,600 of 36,778 CVEs
CVE-2026-54761 MEDIUM - 7.1

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossProviderNamespaces allowlist. For HTTPRoute rules that declare multiple (WRR) backendRefs, Traefik evaluates the allo...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Jun 17, 2026
Source: GitHub
CVE-2026-53765 MEDIUM - 6.1

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon writes its PID file with fs.writeFileSync() to a deterministic runtime path. On typical macOS environments, and on Linux sessions...

Vendor: npm
Product: chrome-devtools-mcp
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54325 MEDIUM - 4.4

Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. This included project-local extensions, which are executable TypeScript or JavaScript modules load...

Vendor: npm
Product: @earendil-works/pi-coding-agent
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54328 HIGH - 7.3

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directo...

Vendor: npm
Product: @earendil-works/pi-coding-agent
Published: Jun 17, 2026
Source: GitHub

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could briefly create or rewrite this file with permissions derived from the process umask before tightening the file to owner-only permiss...

Vendor: npm
Product: @mariozechner/pi-coding-agent
Published: Jun 17, 2026
Source: GitHub
CVE-2026-9690 HIGH - 7.5

Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.

Published: Jun 17, 2026
Source: NVD
CVE-2026-9570 HIGH - 7.1

The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user.

Published: Jun 17, 2026
Source: NVD
CVE-2026-8607 MEDIUM - 6.4

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program โ€“ myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output es...

Published: Jun 17, 2026
Source: NVD
CVE-2026-8494 MEDIUM - 6.4

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level...

Published: Jun 17, 2026
Source: NVD
CVE-2026-8383 MEDIUM - 5.3

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a...

Published: Jun 17, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 17, 2026
Source: NVD
CVE-2026-8089 HIGH - 7.1

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated att...

Published: Jun 17, 2026
Source: NVD
CVE-2026-7850 MEDIUM - 5.9

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks agains...

Published: Jun 17, 2026
Source: NVD

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for...

Published: Jun 17, 2026
Source: NVD
CVE-2026-55706 MEDIUM - 5.8

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

Vendor: OpenBSD
Product: OpenBSD
Published: Jun 17, 2026
Source: NVD
CVE-2026-54811 CRITICAL - 9.3

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

Vendor: Tips and Tricks HQ
Product: WP eMember
Published: Jun 17, 2026
Source: NVD
CVE-2026-54807 CRITICAL - 9.8

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

Vendor: ThemeGrill
Product: Registration Form for WooCommerce
Published: Jun 17, 2026
Source: NVD
CVE-2026-54806 CRITICAL - 9.8

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

Vendor: Melapress
Product: WP Activity Log
Published: Jun 17, 2026
Source: NVD
CVE-2026-54805 HIGH - 8.8

Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

Vendor: sbouey
Product: Falang multilanguage
Published: Jun 17, 2026
Source: NVD
CVE-2026-54804 HIGH - 7.6

Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.

Vendor: melhorenvio
Product: Melhor Envio
Published: Jun 17, 2026
Source: NVD