Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 481 - 500 of 36,556 CVEs
CVE-2026-54845 HIGH - 8.1

Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

Vendor: PluginUs.Net
Product: MDTF
Published: Jun 25, 2026
Source: NVD
CVE-2026-54844 HIGH - 7.5

Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.

Vendor: CheckView
Product: CheckView Automated Testing
Published: Jun 25, 2026
Source: NVD
CVE-2026-54843 CRITICAL - 9.3

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

Vendor: PluginUs.Net
Product: MDTF
Published: Jun 25, 2026
Source: NVD
CVE-2026-54842 HIGH - 8.1

Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.

Vendor: Royal Plugins
Product: Royal MCP
Published: Jun 25, 2026
Source: NVD
CVE-2026-54841 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.

Vendor: Appsbd
Product: Vitepos
Published: Jun 25, 2026
Source: NVD
CVE-2026-54838 HIGH - 8.5

Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

Vendor: Rymera Web Co
Product: WC Vendors Marketplace
Published: Jun 25, 2026
Source: NVD
CVE-2026-54836 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.

Vendor: YMC
Product: YMC Filter
Published: Jun 25, 2026
Source: NVD
CVE-2026-54830 HIGH - 7.5

Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

Vendor: Etoile Web Design Incorporated
Product: Five Star Restaurant Reservations
Published: Jun 25, 2026
Source: NVD
CVE-2026-54829 HIGH - 7.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.

Vendor: Jacob N. Breetvelt
Product: WP Photo Album Plus
Published: Jun 25, 2026
Source: NVD
CVE-2026-54828 HIGH - 7.5

Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

Vendor: StylemixThemes
Product: Motors
Published: Jun 25, 2026
Source: NVD
CVE-2026-54823 CRITICAL - 9.9

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

Vendor: MarketingFire
Product: Widget Options
Published: Jun 25, 2026
Source: NVD
CVE-2026-54822 HIGH - 8.5

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

Vendor: SALESmanago
Product: SALESmanago & Leadoo
Published: Jun 25, 2026
Source: NVD
CVE-2026-54821 HIGH - 7.4

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

Vendor: Bootstrapped Ventures
Product: Visual Link Preview
Published: Jun 25, 2026
Source: NVD
CVE-2026-52690 MEDIUM - 5.9

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-4526 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-49506 HIGH - 7.2

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

Vendor: Dell
Product: Wyse Management Suite
Published: Jun 25, 2026
Source: NVD
CVE-2026-47154 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. ...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47153 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47152 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47151 HIGH - 7.1

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cl...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD