Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,721 - 2,740 of 35,119 CVEs
CVE-2026-53460 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and ...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-52726 HIGH - 7.5

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension `porcelain.clone(..., recurse_submodules=True)`, materializes attacker-controlled submodule paths from a crafte...

Vendor: jelmer
Product: dulwich
Published: Jun 10, 2026
Source: NVD
CVE-2026-50223 HIGH - 8.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: ...

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: Jun 10, 2026
Source: NVD
CVE-2026-49219 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in v...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-49218 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48994 MEDIUM - 5.9

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 an...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48734 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48733 MEDIUM - 4.7

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search operation can happen when using a crafted image. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48724 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write. This issue has been patched in version 7.1.2-24.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-47342 HIGH - 8.8

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache OFBiz
Published: Jun 10, 2026
Source: NVD
CVE-2026-44693 HIGH - 8.8

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue ...

Vendor: pi-hole
Product: FTL
Published: Jun 10, 2026
Source: NVD
CVE-2026-42558 HIGH - 7.6

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users with DataSet permissions to use the Data Connector functiona...

Vendor: xibosignage
Product: xibo-cms
Published: Jun 10, 2026
Source: NVD
CVE-2024-21944 MEDIUM - 5.3

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrit...

Vendor: AMD
Product: AMD EPYCโ„ข 7003 Series Processors, AMD EPYCโ„ข 9004 Series Processor
Published: Jun 10, 2026
Source: NVD
CVE-2026-53742 MEDIUM - 5.4

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.

Vendor: quantumcloud
Product: Simple Link Directory
Published: Jun 10, 2026
Source: NVD
CVE-2026-53741 MEDIUM - 5.4

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.

Vendor: quantumcloud
Product: Simple Link Directory
Published: Jun 10, 2026
Source: NVD
CVE-2026-53740 MEDIUM - 5.4

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.

Vendor: Yoast
Product: Yoast Duplicate Post
Published: Jun 10, 2026
Source: NVD
CVE-2026-53739 MEDIUM - 4.3

Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressin...

Vendor: Yoast
Product: Yoast Duplicate Post
Published: Jun 10, 2026
Source: NVD
CVE-2026-53738 HIGH - 8.1

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.

Vendor: Inisev
Product: Copy & Delete Posts
Published: Jun 10, 2026
Source: NVD
CVE-2026-53737 MEDIUM - 6.1

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.

Vendor: saas.group
Product: Juicer
Published: Jun 10, 2026
Source: NVD
CVE-2026-53736 MEDIUM - 4.3

Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type.

Vendor: bplugins
Product: Easy Twitter Feeds
Published: Jun 10, 2026
Source: NVD