Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,920
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 301 - 320 of 12,873 CVEs
CVE-2026-12309 MEDIUM - 6.5

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12308 MEDIUM - 5.3

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12307 MEDIUM - 5.3

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12306 MEDIUM - 5.3

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12303 MEDIUM - 4.3

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12302 MEDIUM - 6.5

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12301 MEDIUM - 5.3

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12300 MEDIUM - 5.3

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12299 MEDIUM - 5.4

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12298 MEDIUM - 5.4

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-54197 MEDIUM - 6.5

Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

Vendor: Wpmet
Product: GetGenie
Published: Jun 16, 2026
Source: NVD
CVE-2026-54190 MEDIUM - 6.5

Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

Vendor: Awesomemotive
Product: Envira Photo Gallery
Published: Jun 16, 2026
Source: NVD
CVE-2026-52714 MEDIUM - 5.9

Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.

Vendor: SEO Squirrly
Product: SEO Plugin by Squirrly SEO
Published: Jun 16, 2026
Source: NVD
CVE-2026-40809 MEDIUM - 6.5

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.

Vendor: Rara Themes
Product: Metro Magazine
Published: Jun 16, 2026
Source: NVD
CVE-2026-2381 MEDIUM - 6.5

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when...

Published: Jun 16, 2026
Source: NVD
CVE-2026-10093 MEDIUM - 6.4

The File Sharing & Download Manager โ€“ User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Vendor: deepakkite
Product: Secure Client Portal and Private File Sharing Plugin โ€“ User Private Files
Published: Jun 16, 2026
Source: NVD
CVE-2025-9912 MEDIUM - 6.3

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

Published: Jun 16, 2026
Source: NVD
CVE-2026-9187 MEDIUM - 5.3

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_re...

Published: Jun 16, 2026
Source: NVD
CVE-2026-5149 MEDIUM - 6.5

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it pos...

Published: Jun 16, 2026
Source: NVD
CVE-2026-50255 MEDIUM - 6.7

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges.

Vendor: Sony Corporation
Product: Optical Disc Archive Software for Windows
Published: Jun 16, 2026
Source: NVD