Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 321 - 340 of 34,601 CVEs
CVE-2026-12528 MEDIUM - 5.4

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 17, 2026
Source: NVD
CVE-2026-11311 HIGH - 8.1

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilt...

Vendor: F5
Product: NGINX Gateway Fabric
Published: Jun 17, 2026
Source: NVD

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.

Vendor: Plane
Product: Plane
Published: Jun 17, 2026
Source: NVD
CVE-2024-47477 MEDIUM - 6.5

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.

Vendor: Dell
Product: PowerFlex Manager
Published: Jun 17, 2026
Source: NVD
CVE-2026-54016 MEDIUM - 4.3

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub

Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.

Published: Jun 17, 2026
Source: NVD
CVE-2026-55738 HIGH - 8.8

A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy() without guaranteeing null termination of the source. The POSIX ustar format permits these fixed-width ...

Vendor: rxi
Product: microtar
Published: Jun 17, 2026
Source: NVD
CVE-2026-54819 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

Vendor: Webilia Inc.
Product: Listdom
Published: Jun 17, 2026
Source: NVD
CVE-2026-54818 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

Vendor: VeronaLabs
Product: Slimstat Analytics
Published: Jun 17, 2026
Source: NVD
CVE-2026-54817 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

Vendor: FluxBuilder
Product: MStore API
Published: Jun 17, 2026
Source: NVD
CVE-2026-54816 HIGH - 7.5

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.

Vendor: Monetizemore
Product: Advanced Ads
Published: Jun 17, 2026
Source: NVD
CVE-2026-54815 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.

Vendor: Cargo RD
Product: Cargo Shipping Location for WooCommerce
Published: Jun 17, 2026
Source: NVD
CVE-2026-54814 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

Vendor: StylemixThemes
Product: Motors
Published: Jun 17, 2026
Source: NVD
CVE-2026-54813 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.

Vendor: Brainstorm Force
Product: SureDash
Published: Jun 17, 2026
Source: NVD
CVE-2026-54809 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.

Vendor: VillaTheme
Product: GIFT4U
Published: Jun 17, 2026
Source: NVD
CVE-2026-54808 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.

Vendor: WP Travel
Product: WP Travel Gutenberg Blocks
Published: Jun 17, 2026
Source: NVD
CVE-2026-54417 HIGH - 7.5

An integer overflow in the mtar_next() function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next() computes the offset to the next record as round_up(h.size, 512) + sizeof...

Vendor: rxi
Product: microtar
Published: Jun 17, 2026
Source: NVD
CVE-2026-54193 HIGH - 7.7

Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.

Vendor: ThemeFusion
Product: Fusion Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-52716 MEDIUM - 6.5

Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

Vendor: purethemes
Product: WorkScout-Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-52707 HIGH - 8.1

Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

Vendor: Mikado-Themes
Product: Kastell
Published: Jun 17, 2026
Source: NVD