Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,830
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 21 - 40 of 36,708 CVEs
CVE-2026-13245 MEDIUM - 6.1

The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, and including, 9.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

Vendor: maxfoundry
Product: MaxButtons – Create buttons
Published: Jun 27, 2026
Source: NVD
CVE-2026-12404 MEDIUM - 5.3

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated atta...

Vendor: webaways
Product: NEX-Forms – Ultimate Forms Plugin for WordPress
Published: Jun 27, 2026
Source: NVD

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted subscription, allowing any authenticated user (Subscriber+) to cancel other...

Vendor: Unknown
Product: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content
Published: Jun 27, 2026
Source: NVD
CVE-2026-12415 CRITICAL - 9.8

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-cont...

Vendor: pravel
Product: Invoice Generator
Published: Jun 27, 2026
Source: NVD
CVE-2026-13422 MEDIUM - 4.3

The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new...

Vendor: harmonic_design
Product: HD Quiz
Published: Jun 27, 2026
Source: NVD
CVE-2026-13335 MEDIUM - 6.4

The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Vendor: codepeople
Product: CodePeople Post Map for Google Maps
Published: Jun 27, 2026
Source: NVD
CVE-2026-13333 MEDIUM - 6.5

The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...

Vendor: trainingbusinesspros
Product: Groundhogg β€” CRM, Newsletters, and Marketing Automation
Published: Jun 27, 2026
Source: NVD
CVE-2026-13331 MEDIUM - 6.5

The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...

Vendor: trainingbusinesspros
Product: Groundhogg β€” CRM, Newsletters, and Marketing Automation
Published: Jun 27, 2026
Source: NVD
CVE-2026-11356 MEDIUM - 4.4

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insufficient input sanitization and output escaping. This makes it...

Vendor: vinod-dalvi
Product: Ivory Search – WordPress Search Plugin
Published: Jun 27, 2026
Source: NVD
CVE-2025-59868 MEDIUM - 5.5

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.

Vendor: HCLSoftware
Product: Traveler for Microsoft Outlook
Published: Jun 27, 2026
Source: NVD
CVE-2023-37524 HIGH - 7.7

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Β Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerabl...

Vendor: HCLSoftware
Product: Traveler for Microsoft Outlook
Published: Jun 27, 2026
Source: NVD
CVE-2026-56414 HIGH - 7.2

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malforme...

Vendor: H.VIEW
Product: HV-500S6 IP Camera
Published: Jun 26, 2026
Source: NVD
CVE-2026-55975 HIGH - 7.2

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command ex...

Vendor: H.VIEW
Product: HV-500S6 IP Camera
Published: Jun 26, 2026
Source: NVD
CVE-2026-33560 HIGH - 7.1

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts...

Vendor: Daktronics
Product: VFC-DMP-5000, DMP-5000, DMP-8000
Published: Jun 26, 2026
Source: NVD
CVE-2026-31928 HIGH - 8.1

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.

Vendor: Daktronics
Product: VFC-DMP-5000, DMP-5000, DMP-8000
Published: Jun 26, 2026
Source: NVD
CVE-2026-28701 CRITICAL - 9.8

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

Vendor: Daktronics
Product: VFC-DMP-5000, DMP-5000, DMP-8000
Published: Jun 26, 2026
Source: NVD

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

Vendor: composer
Product: statamic/cms
Published: Jun 26, 2026
Source: GitHub
CVE-2026-54243 MEDIUM - 6.1

Statamic Vulnerable to CSV formula injection in form submission exports

Vendor: composer
Product: statamic/cms
Published: Jun 26, 2026
Source: GitHub
CVE-2026-54242 MEDIUM - 4.9

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Vendor: composer
Product: statamic/cms
Published: Jun 26, 2026
Source: GitHub
CVE-2026-50029 MEDIUM - 5.3

js-toml has silent type confusion via falsy-primitive duplicate-key bypass

Vendor: npm
Product: js-toml
Published: Jun 26, 2026
Source: GitHub