Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,875
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,561 - 4,580 of 34,481 CVEs

LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.

Vendor: Yandex
Product: Yandex Database
Published: Jun 02, 2026
Source: NVD
CVE-2025-53346 MEDIUM - 4.3

Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Core: from n/a through 2.3.3.

Vendor: ThimPress
Product: Thim Core
Published: Jun 02, 2026
Source: NVD
CVE-2025-53345 MEDIUM - 6.5

Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3.

Vendor: ThimPress
Product: Thim Core
Published: Jun 02, 2026
Source: NVD
CVE-2025-53302 MEDIUM - 5.3

Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Constructor: from n/a through 1.6.5.

Vendor: Anton Shevchuk
Product: Constructor
Published: Jun 02, 2026
Source: NVD
CVE-2025-53209 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.

Vendor: Themeisle
Product: Masteriyo LMS PRO
Published: Jun 02, 2026
Source: NVD
CVE-2025-52766 MEDIUM - 6.5

Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from n/a through 1.17.0.

Vendor: Printeers
Product: Printeers Print & Ship
Published: Jun 02, 2026
Source: NVD
CVE-2025-52759 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a through 2.2.1.

Vendor: UnboundStudio
Product: Accordion FAQ
Published: Jun 02, 2026
Source: NVD
CVE-2026-9730 MEDIUM - 4.3

The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9723 MEDIUM - 4.3

The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin&...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9722 MEDIUM - 4.3

The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update the plugin's set...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9599 MEDIUM - 4.3

The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, in...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9234 MEDIUM - 4.3

The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and o...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8885 MEDIUM - 6.4

The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'alig...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8422 MEDIUM - 4.3

The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated at...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4081 MEDIUM - 6.4

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'color�...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4080 MEDIUM - 6.4

The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_c...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4071 MEDIUM - 4.3

The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the ...

Published: Jun 02, 2026
Source: NVD
CVE-2026-3620 MEDIUM - 4.4

The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Admini...

Published: Jun 02, 2026
Source: NVD
CVE-2026-3514 HIGH - 7.5

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication ...

Vendor: prefect
Product: prefect
Published: Jun 02, 2026
Source: NVD
CVE-2026-2425 MEDIUM - 6.1

The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

Published: Jun 02, 2026
Source: NVD