Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,753
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 501 - 520 of 35,119 CVEs
CVE-2026-7547 MEDIUM - 4.9

The Woosa โ€“ Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name from the 'log_file...

Published: Jun 19, 2026
Source: NVD
CVE-2026-7515 CRITICAL - 9.8

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code ...

Published: Jun 19, 2026
Source: NVD
CVE-2026-56132 MEDIUM - 6.9

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

Vendor: libexpat project
Product: libexpat
Published: Jun 19, 2026
Source: NVD
CVE-2026-56131 MEDIUM - 4.9

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

Vendor: libexpat project
Product: libexpat
Published: Jun 19, 2026
Source: NVD
CVE-2026-54414 CRITICAL - 9.8

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename() and REGEX_FILE_NAME, which perm...

Vendor: error311
Product: FileRise
Published: Jun 19, 2026
Source: NVD
CVE-2026-4328 MEDIUM - 6.4

The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in t...

Published: Jun 19, 2026
Source: NVD
CVE-2026-1856 MEDIUM - 6.4

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-l...

Published: Jun 19, 2026
Source: NVD
CVE-2026-12644 MEDIUM - 5.3

Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken โ€” ...

Product: ts-deepmerge
Published: Jun 19, 2026
Source: NVD
CVE-2026-12430 MEDIUM - 4.4

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and ab...

Vendor: creativethemeshq
Product: Blocksy Companion
Published: Jun 19, 2026
Source: NVD
CVE-2026-12157 MEDIUM - 6.4

The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insuffi...

Vendor: wpdevteam
Product: BetterDocs โ€“ AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot
Published: Jun 19, 2026
Source: NVD
CVE-2026-11989 MEDIUM - 6.5

The Bit integrations โ€“ Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.7 via the upload_attachment. This makes it possible for unauthenticated attackers to make web re...

Vendor: bitpressadmin
Product: Bit integrations โ€“ Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation
Published: Jun 19, 2026
Source: NVD
CVE-2026-10779 MEDIUM - 4.3

The Classified Listing โ€“ Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler (action: rtcl_fb_gallery_i...

Vendor: techlabpro1
Product: Classified Listing โ€“ AI-Powered Classified ads & Business Directory
Published: Jun 19, 2026
Source: NVD

Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/mic...

Vendor: Canonical
Product: Microceph
Published: Jun 19, 2026
Source: NVD
CVE-2026-10034 MEDIUM - 5.3

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to supply an arbitr...

Vendor: legalweb
Product: WP DSGVO Tools (GDPR)
Published: Jun 19, 2026
Source: NVD
CVE-2025-7737 HIGH - 8.6

DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN...

Published: Jun 19, 2026
Source: NVD

Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication packets to th...

Published: Jun 19, 2026
Source: NVD

Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by rapidly establishing a large...

Published: Jun 19, 2026
Source: NVD
CVE-2026-11775 MEDIUM - 4.3

The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the useradminsimplifier_options_page function. This makes it possible for unauthenticated attackers to reset...

Vendor: adamsilverstein
Product: User Admin Simplifier
Published: Jun 19, 2026
Source: NVD
CVE-2026-52866 MEDIUM - 6.5

An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

Vendor: Apollo Pharmacy
Product: Blood Glucose Monitoring System (Model No. APG-01 BT)
Published: Jun 19, 2026
Source: NVD
CVE-2026-50034 MEDIUM - 6.5

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

Vendor: Apollo Pharmacy
Product: Blood Glucose Monitoring System (Model No. APG-01 BT)
Published: Jun 19, 2026
Source: NVD