Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,861 - 2,880 of 36,778 CVEs
CVE-2025-60085 HIGH - 8.1

Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.

Vendor: ThemeREX Group
Product: Learnify
Published: Jun 17, 2026
Source: NVD
CVE-2025-59872 MEDIUM - 4.3

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. ...

Vendor: HCL Software
Product: ZIE
Published: Jun 17, 2026
Source: NVD
CVE-2025-59563 HIGH - 8.8

Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

Vendor: SONAAR MUSIC
Product: Sonaar
Published: Jun 17, 2026
Source: NVD
CVE-2025-59560 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.

Vendor: SONAAR MUSIC
Product: Sonaar
Published: Jun 17, 2026
Source: NVD
CVE-2025-58954 HIGH - 8.1

Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.

Vendor: ThemeREX
Product: HomeRoofer
Published: Jun 17, 2026
Source: NVD
CVE-2025-58953 HIGH - 8.1

Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.

Vendor: ThemeREX
Product: Joly
Published: Jun 17, 2026
Source: NVD
CVE-2025-58952 HIGH - 8.1

Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.

Vendor: ThemeREX
Product: Neuronet
Published: Jun 17, 2026
Source: NVD
CVE-2025-58924 HIGH - 8.1

Unauthenticated Local File Inclusion in Geya <= 1.15 versions.

Vendor: ThemeREX Group
Product: Geya
Published: Jun 17, 2026
Source: NVD
CVE-2025-49403 HIGH - 7.5

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

Vendor: AA-Team
Product: Premium Age Verification / Restriction for WordPress
Published: Jun 17, 2026
Source: NVD
CVE-2025-48643 HIGH - 7.8

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48640 HIGH - 8.0

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48617 HIGH - 7.8

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48571 MEDIUM - 4.3

In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-31013 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6.

Vendor: Themify
Product: Themify Folo
Published: Jun 17, 2026
Source: NVD

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,. * Pr...

Vendor: Netskope
Product: Netskope Client
Published: Jun 17, 2026
Source: NVD

Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti...

Vendor: Netskope
Product: Netskope Client
Published: Jun 17, 2026
Source: NVD
CVE-2024-52488 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

Vendor: Zidithemes
Product: Grip
Published: Jun 17, 2026
Source: NVD
CVE-2024-49269 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

Vendor: Mythemes
Product: my flatonica
Published: Jun 17, 2026
Source: NVD
CVE-2024-37496 MEDIUM - 4.3

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.

Vendor: Rara Themes
Product: Metro Magazine
Published: Jun 17, 2026
Source: NVD
CVE-2024-37210 MEDIUM - 6.5

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

Vendor: ali2woo
Product: AliNext
Published: Jun 17, 2026
Source: NVD