Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,900
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 321 - 340 of 12,881 CVEs
CVE-2026-52714 MEDIUM - 5.9

Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.

Vendor: SEO Squirrly
Product: SEO Plugin by Squirrly SEO
Published: Jun 16, 2026
Source: NVD
CVE-2026-40809 MEDIUM - 6.5

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.

Vendor: Rara Themes
Product: Metro Magazine
Published: Jun 16, 2026
Source: NVD
CVE-2026-2381 MEDIUM - 6.5

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when...

Published: Jun 16, 2026
Source: NVD
CVE-2026-10093 MEDIUM - 6.4

The File Sharing & Download Manager โ€“ User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Vendor: deepakkite
Product: Secure Client Portal and Private File Sharing Plugin โ€“ User Private Files
Published: Jun 16, 2026
Source: NVD
CVE-2025-9912 MEDIUM - 6.3

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

Published: Jun 16, 2026
Source: NVD
CVE-2026-9187 MEDIUM - 5.3

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_re...

Published: Jun 16, 2026
Source: NVD
CVE-2026-5149 MEDIUM - 6.5

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it pos...

Published: Jun 16, 2026
Source: NVD
CVE-2026-50255 MEDIUM - 6.7

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges.

Vendor: Sony Corporation
Product: Optical Disc Archive Software for Windows
Published: Jun 16, 2026
Source: NVD
CVE-2026-10780 MEDIUM - 4.3

The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_...

Vendor: mohammadtanzilurrahman
Product: Static Block
Published: Jun 16, 2026
Source: NVD
CVE-2026-10635 MEDIUM - 6.3

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded inside the caller-owned struct k_mem_domain. When a domain is destroyed via k_mem_domain_de...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2025-10262 MEDIUM - 6.3

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privileges.

Vendor: Nokia
Product: SR Linux
Published: Jun 16, 2026
Source: NVD
CVE-2026-6964 MEDIUM - 5.3

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the...

Published: Jun 16, 2026
Source: NVD
CVE-2026-42014 MEDIUM - 6.6

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 16, 2026
Source: NVD
CVE-2026-1767 MEDIUM - 5.6

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calcula...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1766 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker co...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1765 MEDIUM - 5.6

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Deni...

Published: Jun 16, 2026
Source: NVD
CVE-2026-1764 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attac...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-12162 MEDIUM - 5.5

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-9262 MEDIUM - 6.5

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD
CVE-2026-9261 MEDIUM - 6.8

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD