Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,706
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 441 - 460 of 36,814 CVEs
CVE-2025-68063 HIGH - 7.5

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

Vendor: StylemixThemes
Product: Splash - Sport Club WordPress Theme for Basketball, Football, Hockey
Published: Jun 26, 2026
Source: NVD
CVE-2025-68052 HIGH - 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

Vendor: Eagle-Themes
Product: Eagle Booking
Published: Jun 26, 2026
Source: NVD
CVE-2025-66123 MEDIUM - 5.3

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

Vendor: About Envato
Product: BookPro
Published: Jun 26, 2026
Source: NVD
CVE-2025-64637 MEDIUM - 5.3

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

Vendor: Opal_WP
Product: Auros Core
Published: Jun 26, 2026
Source: NVD
CVE-2025-64636 MEDIUM - 5.3

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

Vendor: rhewlif
Product: Donation Thermometer
Published: Jun 26, 2026
Source: NVD
CVE-2025-63079 MEDIUM - 4.3

Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

Vendor: bdthemes
Product: Live Copy Paste for Elementor
Published: Jun 26, 2026
Source: NVD
CVE-2025-63078 MEDIUM - 4.3

Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.

Vendor: jetmonsters
Product: Restaurant Menu by MotoPress
Published: Jun 26, 2026
Source: NVD
CVE-2025-63041 MEDIUM - 5.4

Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

Vendor: Code Amp
Product: Forget About Shortcode Buttons
Published: Jun 26, 2026
Source: NVD

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any validation. An authenticated attacker with administrative privile...

Vendor: danpros
Product: HTMLy
Published: Jun 26, 2026
Source: NVD

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD
CVE-2026-57925 MEDIUM - 4.3

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD
CVE-2026-57924 MEDIUM - 4.3

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD
CVE-2026-57923 MEDIUM - 5.3

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD
CVE-2026-57921 MEDIUM - 4.3

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD
CVE-2026-53914 MEDIUM - 6.7

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Vendor: JetBrains
Product: Kotlin
Published: Jun 26, 2026
Source: NVD
CVE-2026-13426 MEDIUM - 5.4

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Adv...

Vendor: Mattermost
Product: github.com/mattermost/mattermost/server/public
Published: Jun 26, 2026
Source: NVD
CVE-2026-57920 HIGH - 7.7

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

Vendor: Peplink
Product: InControl
Published: Jun 26, 2026
Source: NVD
CVE-2026-57915 HIGH - 7.3

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache Kerby
Published: Jun 26, 2026
Source: NVD
CVE-2026-40711 HIGH - 8.0

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with re...

Vendor: Dell
Product: Container Storage Modules
Published: Jun 26, 2026
Source: NVD