Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,286
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,021 - 4,040 of 33,692 CVEs
CVE-2026-42679 MEDIUM - 6.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.

Vendor: Mamunur Rashid
Product: Classified Listing
Published: Jun 01, 2026
Source: NVD
CVE-2026-42678 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.

Vendor: Liquid Web / StellarWP
Product: GiveWP
Published: Jun 01, 2026
Source: NVD
CVE-2026-42677 HIGH - 7.5

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

Vendor: Ben Balter
Product: WP Document Revisions
Published: Jun 01, 2026
Source: NVD
CVE-2026-42676 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

Vendor: myCred
Product: myCred
Published: Jun 01, 2026
Source: NVD
CVE-2026-42675 HIGH - 7.3

Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.

Vendor: Themefic
Product: Hydra Booking
Published: Jun 01, 2026
Source: NVD
CVE-2026-42674 HIGH - 7.5

Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.

Vendor: AAM Plugin
Product: Advanced Access Manager
Published: Jun 01, 2026
Source: NVD
CVE-2026-42673 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logt...

Vendor: Logtivity Activity Logs
Product: Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
Published: Jun 01, 2026
Source: NVD
CVE-2026-42672 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

Vendor: Wp Directory Kit
Product: WP Directory Kit
Published: Jun 01, 2026
Source: NVD
CVE-2026-42671 MEDIUM - 6.5

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

Vendor: Paolo
Product: GeoDirectory
Published: Jun 01, 2026
Source: NVD
CVE-2026-38950 HIGH - 7.8

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.

Published: Jun 01, 2026
Source: NVD
CVE-2026-37227 HIGH - 7.5

FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port ...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37225 HIGH - 7.5

FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition field. The E42 layer decoder accepts this as valid, but the E2AP encoder asserts a non-empty constraint when forwarding the request. A remote unauthenticated attacker can crash the i...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37224 HIGH - 7.5

FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry enforces node ID uniqueness via assert() rather than graceful rejection. A remote unauthenticated attacker can crash the iApp process (port 36421) by sending two E2_SETUP_REQUESTs w...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37223 HIGH - 7.5

FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP messages against a 9-entry whitelist using assert(). A remote unauthenticated attacker can send any decodable E2AP PDU with a message type not in the whitelist to crash the iApp proce...

Published: Jun 01, 2026
Source: NVD
CVE-2026-37222 HIGH - 7.5

FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can send a valid E2AP PDU containing an unexpected number of IEs (e.g., an E2setupRequest with extra optional fields) to crash the near-RT RIC (port 36421)...

Published: Jun 01, 2026
Source: NVD
CVE-2026-10275 MEDIUM - 5.0

A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The complexity of an attac...

Product: OpenSC
Published: Jun 01, 2026
Source: NVD
CVE-2026-10274 MEDIUM - 6.3

A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This impacts the function getAssetMetadata of the file src/mcp-server.ts of the component Axios Request Flow. Executing a manipulation of the argument assetPath can lead to server-side ...

Vendor: indrasishbanerjee
Product: aem-mcp-server
Published: Jun 01, 2026
Source: NVD
CVE-2026-10273 HIGH - 7.3

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has ...

Product: php-censor
Published: Jun 01, 2026
Source: NVD
CVE-2026-10272 MEDIUM - 6.5

A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of the argument sid leads to improper authorization. It is possible to launch the attack re...

Vendor: a4m4
Product: Student-Management-System
Published: Jun 01, 2026
Source: NVD
CVE-2026-10271 MEDIUM - 6.3

A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the component Admin Endpoint. This manipulation of the argument uid causes execution after redirect. It is possible to initiate th...

Vendor: a4m4
Product: Student-Management-System
Published: Jun 01, 2026
Source: NVD