Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,013
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 461 - 480 of 35,345 CVEs

Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An attacker can enumerate valid email addresses and harvest sensitive user data including user IDs, nam...

Vendor: Flowise
Product: Flowise
Published: Jun 20, 2026
Source: NVD
CVE-2026-56235 MEDIUM - 5.3

Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role without enforcing org membership or permission checks. An unauthenticated attacker using only the publi...

Vendor: Cap-go
Product: capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56228 MEDIUM - 4.9

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum password length, making compliance impo...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56227 MEDIUM - 5.4

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these address...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56218 MEDIUM - 5.3

Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical location at capture time.

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2025-71331 MEDIUM - 6.1

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., <iframe src="javascript:alert(document.cookie)">...

Vendor: Flowise
Product: Flowise
Published: Jun 20, 2026
Source: NVD
CVE-2024-58351 CRITICAL - 9.8

Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by default with no allow-list of permitted variables and relies o...

Vendor: Flowise
Product: Flowise
Published: Jun 20, 2026
Source: NVD

Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in their managed secondary (non-default) group.

Vendor: liquidfiles
Product: liquidfiles
Published: Jun 20, 2026
Source: NVD
CVE-2022-50972 CRITICAL - 9.8

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values t...

Vendor: WooCommerce
Product: WooCommerce
Published: Jun 20, 2026
Source: NVD
CVE-2020-37255 HIGH - 7.5

WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies a...

Vendor: Wptimecapsule
Product: Time Capsule Plugin
Published: Jun 20, 2026
Source: NVD
CVE-2019-25763 CRITICAL - 9.8

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-s...

Vendor: Ultimatebeaver
Product: Ultimate Addons for Beaver Builder
Published: Jun 20, 2026
Source: NVD

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Vendor: icagenda.com
Product: iCagenda extension for Joomla
Published: Jun 20, 2026
Source: NVD

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

Vendor: joomshaper.net
Product: SP LMS extension for Joomla
Published: Jun 20, 2026
Source: NVD

A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.

Vendor: joomshaper.net
Product: SP Page Builder extension for Joomla
Published: Jun 20, 2026
Source: NVD
CVE-2026-12119 MEDIUM - 6.5

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level acce...

Vendor: eemitch
Product: Simple File List
Published: Jun 20, 2026
Source: NVD
CVE-2026-11912 HIGH - 7.5

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable...

Vendor: eemitch
Product: Simple File List
Published: Jun 20, 2026
Source: NVD
CVE-2026-11911 HIGH - 7.5

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, whic...

Vendor: eemitch
Product: Simple File List
Published: Jun 20, 2026
Source: NVD
CVE-2026-9843 HIGH - 8.1

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbit...

Published: Jun 20, 2026
Source: NVD
CVE-2026-9265 CRITICAL - 9.1

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen(...

Published: Jun 20, 2026
Source: NVD
CVE-2026-56216 HIGH - 8.8

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting empty limits. Attackers with a compromised app-limited key can create an unrestricted key with org-wide access to resources ...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD