Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,921 - 4,940 of 34,601 CVEs
CVE-2026-45264 MEDIUM - 4.3

Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before 21.0.4, a user with READ and CREATE permission, but no UPDATE permission for a team folder can rename...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD

Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with access to an end-to-end encrypted files drop link was able to also drop files into other end-to-end ...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-45157 MEDIUM - 6.3

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could use this share token to also access the chunking upload directly and see temporar...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-45156 HIGH - 8.1

Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowed a malicious ID4me authority to identify as any user. This issue has been patched in versions 3.1.0,...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add unknown circles by their ID directly to other circles. Since circle IDs have 62^15 complexity by defau...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD

Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from the trashbin. This is...

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-45153 MEDIUM - 4.6

Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud Files app PIN. This issue has been patched in version 33.1.0.

Vendor: nextcloud
Product: security-advisories
Published: Jun 01, 2026
Source: NVD
CVE-2026-45132 CRITICAL - 10.0

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. T...

Vendor: CloudPirates-io
Product: helm-charts
Published: Jun 01, 2026
Source: NVD
CVE-2026-45131 CRITICAL - 10.0

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens witho...

Vendor: CloudPirates-io
Product: helm-charts
Published: Jun 01, 2026
Source: NVD
CVE-2026-42679 MEDIUM - 6.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.

Vendor: Mamunur Rashid
Product: Classified Listing
Published: Jun 01, 2026
Source: NVD
CVE-2026-42678 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.

Vendor: Liquid Web / StellarWP
Product: GiveWP
Published: Jun 01, 2026
Source: NVD
CVE-2026-42677 HIGH - 7.5

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

Vendor: Ben Balter
Product: WP Document Revisions
Published: Jun 01, 2026
Source: NVD
CVE-2026-42676 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

Vendor: myCred
Product: myCred
Published: Jun 01, 2026
Source: NVD
CVE-2026-42675 HIGH - 7.3

Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.

Vendor: Themefic
Product: Hydra Booking
Published: Jun 01, 2026
Source: NVD
CVE-2026-42674 HIGH - 7.5

Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.

Vendor: AAM Plugin
Product: Advanced Access Manager
Published: Jun 01, 2026
Source: NVD
CVE-2026-42673 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logt...

Vendor: Logtivity Activity Logs
Product: Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
Published: Jun 01, 2026
Source: NVD
CVE-2026-42672 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

Vendor: Wp Directory Kit
Product: WP Directory Kit
Published: Jun 01, 2026
Source: NVD
CVE-2026-42671 MEDIUM - 6.5

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

Vendor: Paolo
Product: GeoDirectory
Published: Jun 01, 2026
Source: NVD
CVE-2026-38950 HIGH - 7.8

An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.

Published: Jun 01, 2026
Source: NVD
CVE-2026-37227 HIGH - 7.5

FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port ...

Published: Jun 01, 2026
Source: NVD