Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,386
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 261 - 280 of 11,951 CVEs
CVE-2016-20081 HIGH - 7.5

WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access ...

Vendor: Husain
Product: HB Audio Gallery Lite
Published: Jun 15, 2026
Source: NVD
CVE-2016-20076 HIGH - 7.5

WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation us...

Vendor: ChrisHurst
Product: Simple Backup
Published: Jun 15, 2026
Source: NVD
CVE-2016-20075 HIGH - 8.8

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Produ...

Vendor: Etoilewebdesign
Product: Ultimate Product Catalog
Published: Jun 15, 2026
Source: NVD
CVE-2016-20073 HIGH - 8.2

Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' POST parameter. Attackers can submit crafted SQL statements to the modal.php endpoint to e...

Vendor: mattkaye
Product: Answer My Question
Published: Jun 15, 2026
Source: NVD
CVE-2016-20072 HIGH - 8.2

BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the uid parameter. Attackers can craft requests to pages using the plugin's shortcode with UNION-based SQ...

Vendor: bbsetheme
Product: BBS e-Franchise
Published: Jun 15, 2026
Source: NVD
CVE-2016-20071 HIGH - 8.2

The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads ...

Vendor: 404-redirection-manager
Product: 404 Redirection Manager
Published: Jun 15, 2026
Source: NVD
CVE-2016-20069 HIGH - 8.2

WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to exec...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20068 HIGH - 8.2

WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpo...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20066 HIGH - 7.2

WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers like onerror attributes to execute arbitrary Ja...

Vendor: dwbooster
Product: CP Polls
Published: Jun 15, 2026
Source: NVD
CVE-2026-12057 HIGH - 8.6

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.

Vendor: Foxit Software Inc.
Product: Foxit AI
Published: Jun 15, 2026
Source: NVD
CVE-2026-50100 HIGH - 7.8

Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted ...

Vendor: Ricoh Company, Ltd., KONICA MINOLTA JAPAN, INC.
Product: Multiple printer drivers
Published: Jun 15, 2026
Source: NVD
CVE-2026-12222 HIGH - 8.0

A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer overflow. The attack needs t...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12221 HIGH - 8.0

A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The attack needs to be app...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12220 HIGH - 8.0

A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the argument uid leads to stack-based buffer overflow. The attack ca...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12218 HIGH - 8.0

A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local netw...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12217 HIGH - 7.8

A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclos...

Vendor: DVDFab
Product: Virtual Drive
Published: Jun 15, 2026
Source: NVD
CVE-2026-12214 HIGH - 7.8

A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a...

Vendor: Qihoo
Product: 360 Total Security
Published: Jun 15, 2026
Source: NVD
CVE-2026-12204 HIGH - 7.3

A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a manipulation can lead to authorization bypass. The...

Product: ShopXO
Published: Jun 15, 2026
Source: NVD
CVE-2026-12200 HIGH - 7.3

A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the library libeay32.dll.html of the component Header Handler. The manipulation of the argument Authorization leads to stack-based buffer overflow. The attack can be initiate...

Vendor: Ritlabs
Product: TinyWeb Server
Published: Jun 15, 2026
Source: NVD
CVE-2026-12198 HIGH - 7.3

A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nosession/thumbnail_img of the component API Endpoint. Executing a manipulation of the argument cache_path_relative can lead to path traversal. It is possible to launch the attack rem...

Product: Microweber
Published: Jun 15, 2026
Source: NVD