Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,647
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 361 - 380 of 34,996 CVEs
CVE-2026-53915 HIGH - 7.1

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

Vendor: JetBrains
Product: GoLand
Published: Jun 19, 2026
Source: NVD
CVE-2026-50242 CRITICAL - 10.0

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

Vendor: JetBrains
Product: Hub
Published: Jun 19, 2026
Source: NVD

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

Vendor: SUSE
Product: Rancher
Published: Jun 19, 2026
Source: NVD
CVE-2026-12706 MEDIUM - 6.5

A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same buffer during move-table processing leaves the pointer dangling. An attacker could exploit this b...

Vendor: Red Hat
Product: Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)
Published: Jun 19, 2026
Source: NVD
CVE-2026-11941 MEDIUM - 5.6

Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via function arguments, but the owned “...

Vendor: Cloudflare
Product: Quiche
Published: Jun 19, 2026
Source: NVD

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.

Published: Jun 19, 2026
Source: NVD

AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as ...

Vendor: ail-project
Product: ail-framework
Published: Jun 19, 2026
Source: NVD

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources creating a write use after free scenario. A shared resource (memory page) managed by a CPU thread of control (driver) and accessed by a GPU thread of control (Firmware) ca...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 19, 2026
Source: NVD

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading to UAF of GPU page tables. The vulnerability allows physical memory allocated for MMU page tables to be used after being freed. This was caused by an error path that would not ...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 19, 2026
Source: NVD
CVE-2026-11576 HIGH - 7.5

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple error branches jump to ...

Vendor: Eclipse Foundation
Product: Eclipse ThreadX - NetX Duo
Published: Jun 19, 2026
Source: NVD
CVE-2026-6798 MEDIUM - 5.3

The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers...

Published: Jun 19, 2026
Source: NVD
CVE-2026-46461 HIGH - 7.8

Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: Server Hardware Manager
Published: Jun 19, 2026
Source: NVD
CVE-2026-3640 MEDIUM - 5.3

The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and including 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with a permission_callback of __return_true, which allows all incoming requests wit...

Published: Jun 19, 2026
Source: NVD

The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.

Published: Jun 19, 2026
Source: NVD
CVE-2026-9013 MEDIUM - 4.3

The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_post_translation. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the raw title, content, excerpt,...

Published: Jun 19, 2026
Source: NVD
CVE-2026-8713 CRITICAL - 9.1

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the ser...

Published: Jun 19, 2026
Source: NVD
CVE-2026-8118 MEDIUM - 6.5

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back...

Published: Jun 19, 2026
Source: NVD
CVE-2026-7547 MEDIUM - 4.9

The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name from the 'log_file...

Published: Jun 19, 2026
Source: NVD
CVE-2026-7515 CRITICAL - 9.8

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code ...

Published: Jun 19, 2026
Source: NVD
CVE-2026-56132 MEDIUM - 6.9

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

Vendor: libexpat project
Product: libexpat
Published: Jun 19, 2026
Source: NVD