Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 441 - 460 of 34,868 CVEs
CVE-2026-11777 MEDIUM - 4.9

The Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficie...

Vendor: 10web
Product: Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-11776 MEDIUM - 4.9

The Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of suff...

Vendor: 10web
Product: Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-11402 MEDIUM - 6.4

The Services Section Block โ€“ Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possib...

Vendor: bplugins
Product: Services Section Block โ€“ Showcase Service Details in Grid or Columns
Published: Jun 18, 2026
Source: NVD
CVE-2026-11360 MEDIUM - 4.9

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existi...

Vendor: algolplus
Product: Advanced Order Export For WooCommerce
Published: Jun 18, 2026
Source: NVD
CVE-2026-11358 MEDIUM - 4.4

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it po...

Vendor: themeisle
Product: Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
Published: Jun 18, 2026
Source: NVD
CVE-2026-11357 MEDIUM - 4.3

The Kadence Blocks โ€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with contributor-level access and above...

Vendor: stellarwp
Product: Kadence Blocks โ€” Page Builder Toolkit for Gutenberg Editor
Published: Jun 18, 2026
Source: NVD
CVE-2026-10736 MEDIUM - 4.9

The Tutor LMS โ€“ eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...

Vendor: themeum
Product: Tutor LMS โ€“ eLearning and online course solution
Published: Jun 18, 2026
Source: NVD
CVE-2026-10623 MEDIUM - 4.3

The PressPrimer Quiz โ€“ AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it po...

Vendor: pressprimer
Product: PressPrimer Quiz โ€“ AI Quiz Maker, Exam Builder & LMS Assessment Plugin
Published: Jun 18, 2026
Source: NVD
CVE-2026-10029 MEDIUM - 5.3

The Event Koi Lite โ€“ Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including v...

Vendor: eventkoi
Product: Event Koi Lite โ€“ Events Calendar, Event Management, RSVP, and Tickets
Published: Jun 18, 2026
Source: NVD
CVE-2026-12505 HIGH - 7.8

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4
Published: Jun 18, 2026
Source: NVD
CVE-2026-12407 HIGH - 8.8

The E2Pdf โ€“ Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.32.26. This is due to the screen_action() function lacking a dedicated capability check and nonce verification โ€” when invoked via the ?action=screen routing path ...

Vendor: oleksandrz
Product: E2Pdf โ€“ Export Pdf Tool for WordPress
Published: Jun 18, 2026
Source: NVD
CVE-2026-10023 MEDIUM - 4.3

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ€“ Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_track...

Vendor: dokaninc
Product: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ€“ Build Your Own Amazon, eBay, Etsy
Published: Jun 18, 2026
Source: NVD

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.ย  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windch...

Vendor: PTC
Product: Windchill PDMLink, FlexPLM
Published: Jun 18, 2026
Source: NVD
CVE-2026-48768 CRITICAL - 9.3

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a result, any anonymous...

Vendor: baptisteArno
Product: typebot.io
Published: Jun 18, 2026
Source: NVD
CVE-2026-48764 HIGH - 8.2

TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether the resolved IP belongs to a forbidden range allowing for DNS rebinding bypass. The root cause is a time-of-check to time-of-use gap in the SSRF guard. The...

Vendor: baptisteArno
Product: typebot.io
Published: Jun 18, 2026
Source: NVD

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers that are allowed to run...

Vendor: vantage6
Product: vantage6
Published: Jun 17, 2026
Source: NVD

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin righ...

Vendor: vantage6
Product: vantage6
Published: Jun 17, 2026
Source: NVD
CVE-2026-53676 HIGH - 7.2

ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).

Vendor: ThingsBoard
Product: ThingsBoard
Published: Jun 17, 2026
Source: NVD

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transforma...

Vendor: SteeltoeOSS
Product: Steeltoe.Configuration.Encryption
Published: Jun 17, 2026
Source: NVD
CVE-2026-50267 MEDIUM - 4.7

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors libra...

Vendor: SteeltoeOSS
Product: Steeltoe.Configuration.Abstractions
Published: Jun 17, 2026
Source: NVD