Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,888
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 481 - 500 of 34,615 CVEs
CVE-2026-48745 CRITICAL - 9.3

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The ap...

Vendor: traccar
Product: traccar-client
Published: Jun 17, 2026
Source: NVD
CVE-2026-48616 CRITICAL - 9.3

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not ve...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Jun 17, 2026
Source: NVD
CVE-2026-48055 CRITICAL - 10.0

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, ...

Vendor: truelockmc
Product: streambert
Published: Jun 17, 2026
Source: NVD
CVE-2026-47340 MEDIUM - 6.5

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-47277 MEDIUM - 6.5

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arbitrary file read through app-store logo symlinks. The path guard checks only the...

Vendor: runtipi
Product: runtipi
Published: Jun 17, 2026
Source: NVD
CVE-2026-45436 MEDIUM - 6.5

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

Vendor: Rain-Task Ltd.
Product: WPBakery Page Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-42629 HIGH - 8.8

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

Vendor: Powerpackelements
Product: PowerPack Pro for Elementor
Published: Jun 17, 2026
Source: NVD
CVE-2026-42385 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

Vendor: Cozmoslabs
Product: Profile Builder Pro
Published: Jun 17, 2026
Source: NVD
CVE-2026-42380 CRITICAL - 9.8

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

Vendor: jwsthemes
Product: AI Lab
Published: Jun 17, 2026
Source: NVD
CVE-2026-42357 MEDIUM - 6.5

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-41557 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

Vendor: PressLayouts
Product: Kapee
Published: Jun 17, 2026
Source: NVD
CVE-2026-41280 MEDIUM - 4.9

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-40783 CRITICAL - 9.9

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

Vendor: Creative Themes
Product: Blocksy Companion Pro
Published: Jun 17, 2026
Source: NVD
CVE-2026-40768 HIGH - 7.3

Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

Vendor: Dimitri Grassi
Product: Salon booking system
Published: Jun 17, 2026
Source: NVD
CVE-2026-40765 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

Vendor: collectchat
Product: collectchat
Published: Jun 17, 2026
Source: NVD
CVE-2026-40761 HIGH - 8.1

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

Vendor: Edge-Themes
Product: Valeska
Published: Jun 17, 2026
Source: NVD
CVE-2026-40760 HIGH - 8.1

Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

Vendor: Edge-Themes
Product: Behold
Published: Jun 17, 2026
Source: NVD
CVE-2026-40759 HIGH - 8.1

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

Vendor: Mikado-Themes
Product: Esmée
Published: Jun 17, 2026
Source: NVD
CVE-2026-40758 HIGH - 8.1

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

Vendor: Elated-Themes
Product: Léonie
Published: Jun 17, 2026
Source: NVD
CVE-2026-40755 HIGH - 8.1

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

Vendor: Mikado-Themes
Product: TechLink
Published: Jun 17, 2026
Source: NVD