Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,800
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 341 - 360 of 36,728 CVEs
CVE-2026-54825 CRITICAL - 9.3

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

Vendor: wpDataTables
Product: wpDataTables
Published: Jun 26, 2026
Source: NVD
CVE-2026-54824 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

Vendor: Ads WPQuads
Product: Ads by WPQuads
Published: Jun 26, 2026
Source: NVD
CVE-2026-54820 CRITICAL - 9.3

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetBooking
Published: Jun 26, 2026
Source: NVD
CVE-2026-52701 MEDIUM - 6.5

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

Vendor: Themegrill
Product: User Registration
Published: Jun 26, 2026
Source: NVD
CVE-2026-4339 MEDIUM - 6.5

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request f...

Published: Jun 26, 2026
Source: NVD
CVE-2026-45257 HIGH - 7.8

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous M_EXTPG pages or EXT...

Vendor: freebsd
Product: freebsd
Published: Jun 26, 2026
Source: NVD
CVE-2026-45256 MEDIUM - 5.5

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not check the result before delivering the signal. The signal was sent even when the permission check failed. The system call returned the resulting error ...

Vendor: freebsd
Product: freebsd
Published: Jun 26, 2026
Source: NVD
CVE-2026-3472 LOW - 3.5

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image synta...

Published: Jun 26, 2026
Source: NVD
CVE-2026-30041 HIGH - 7.5

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.

Published: Jun 26, 2026
Source: NVD
CVE-2026-30040 MEDIUM - 6.5

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file.

Published: Jun 26, 2026
Source: NVD
CVE-2026-24547 MEDIUM - 5.3

Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.

Vendor: SiteGround
Product: SiteGround Email Marketing
Published: Jun 26, 2026
Source: NVD
CVE-2025-68075 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

Vendor: Kerry
Product: BNE Testimonials
Published: Jun 26, 2026
Source: NVD
CVE-2025-68074 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

Vendor: GhozyLab
Product: Image Carousel
Published: Jun 26, 2026
Source: NVD
CVE-2025-68064 HIGH - 7.5

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

Vendor: Everthemess
Product: Goya Core
Published: Jun 26, 2026
Source: NVD
CVE-2025-68063 HIGH - 7.5

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

Vendor: StylemixThemes
Product: Splash - Sport Club WordPress Theme for Basketball, Football, Hockey
Published: Jun 26, 2026
Source: NVD
CVE-2025-68052 HIGH - 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

Vendor: Eagle-Themes
Product: Eagle Booking
Published: Jun 26, 2026
Source: NVD
CVE-2025-66123 MEDIUM - 5.3

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

Vendor: About Envato
Product: BookPro
Published: Jun 26, 2026
Source: NVD
CVE-2025-64637 MEDIUM - 5.3

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

Vendor: Opal_WP
Product: Auros Core
Published: Jun 26, 2026
Source: NVD
CVE-2025-64636 MEDIUM - 5.3

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

Vendor: rhewlif
Product: Donation Thermometer
Published: Jun 26, 2026
Source: NVD
CVE-2025-63079 MEDIUM - 4.3

Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

Vendor: bdthemes
Product: Live Copy Paste for Elementor
Published: Jun 26, 2026
Source: NVD