Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,640
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,741 - 2,760 of 36,815 CVEs
CVE-2026-39522 HIGH - 8.1

Unauthenticated Local File Inclusion in Solene <= 3.4 versions.

Vendor: Elated-Themes
Product: Solene
Published: Jun 17, 2026
Source: NVD
CVE-2026-39446 HIGH - 8.1

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

Vendor: PressLayouts
Product: Kapee
Published: Jun 17, 2026
Source: NVD
CVE-2026-39443 HIGH - 8.1

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

Vendor: PressLayouts
Product: EmallShop
Published: Jun 17, 2026
Source: NVD
CVE-2026-39438 CRITICAL - 9.3

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

Vendor: Emraan Cheema
Product: ListingPro
Published: Jun 17, 2026
Source: NVD
CVE-2026-39433 MEDIUM - 6.5

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

Vendor: mojoomla
Product: WPAMS
Published: Jun 17, 2026
Source: NVD
CVE-2026-34895 HIGH - 8.1

Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.

Vendor: WebGeniusLab
Product: Softlab Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-34894 HIGH - 8.1

Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions.

Vendor: WebGeniusLab
Product: Integrio Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-34893 HIGH - 8.1

Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.

Vendor: WebGeniusLab
Product: Thegov Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-34888 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

Vendor: Bricksforge
Product: Bricksforge
Published: Jun 17, 2026
Source: NVD
CVE-2026-32967 CRITICAL - 9.1

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-32966 CRITICAL - 9.8

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-2604 MEDIUM - 5.6

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modificat...

Published: Jun 17, 2026
Source: NVD
CVE-2026-28615 HIGH - 7.8

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28587 MEDIUM - 5.5

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28576 MEDIUM - 5.5

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28575 MEDIUM - 5.5

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. Use...

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS)  payload into the 'Hostname' field of the c...

Vendor: Teldat
Product: Regesta Smart HD-PLC - TLDPH16D2
Published: Jun 17, 2026
Source: NVD

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, with a Slow Loris attack, cause Denial of Service (DoS) on the web interface of the device. This issue affects Regesta Smar...

Vendor: Teldat
Product: Regesta Smart HD-PLC - TLDPH16D2
Published: Jun 17, 2026
Source: NVD

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting i...

Vendor: Teldat
Product: Regesta Smart HD-PLC - TLDPH16D2
Published: Jun 17, 2026
Source: NVD
CVE-2026-27429 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

Vendor: BoldThemes
Product: Nifty
Published: Jun 17, 2026
Source: NVD