Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,015
Quick preset (or use dates below)
Clear Filters
Showing 521 - 540 of 13,341 CVEs

@angular/service-worker: Request Credential & Cache Policy Stripping

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub
CVE-2026-9595 MEDIUM - 5.3

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's...

Vendor: webpack.js
Product: webpack-dev-server
Published: Jun 15, 2026
Source: NVD
CVE-2026-8683 MEDIUM - 6.5

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD
CVE-2026-5038 MEDIUM - 5.3

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underl...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD
CVE-2026-10634 MEDIUM - 4.8

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connection callback a...

Vendor: zephyrproject
Product: zephyr
Published: Jun 15, 2026
Source: NVD
CVE-2025-15659 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

Vendor: liseperu
Product: Elizaibots
Published: Jun 15, 2026
Source: NVD
CVE-2025-15658 MEDIUM - 5.9

Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.

Vendor: rewish
Product: WP Emmet
Published: Jun 15, 2026
Source: NVD
CVE-2026-6517 MEDIUM - 6.3

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that ro...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD
CVE-2026-48969 MEDIUM - 6.5

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

Vendor: Really Simple Plugins B.V.
Product: Really Simple SSL
Published: Jun 15, 2026
Source: NVD
CVE-2025-64215 MEDIUM - 6.5

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.

Vendor: StylemixThemes
Product: MasterStudy LMS Pro
Published: Jun 15, 2026
Source: NVD
CVE-2016-20083 MEDIUM - 5.3

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes o...

Vendor: henrikmelin
Product: More Fields
Published: Jun 15, 2026
Source: NVD
CVE-2016-20082 MEDIUM - 6.2

WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and ...

Vendor: abtest
Product: Abtest
Published: Jun 15, 2026
Source: NVD
CVE-2016-20080 MEDIUM - 6.2

WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_ab...

Vendor: Brandfolder
Product: Brandfolder
Published: Jun 15, 2026
Source: NVD
CVE-2016-20079 MEDIUM - 6.2

WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway p...

Vendor: jamie
Product: Dharma Booking
Published: Jun 15, 2026
Source: NVD
CVE-2016-20078 MEDIUM - 6.2

WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.ph...

Vendor: Henrique Dias
Product: IMDb Profile Widget
Published: Jun 15, 2026
Source: NVD
CVE-2016-20077 MEDIUM - 6.2

WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in decode.php. Attackers can supply base64-encoded file paths in the 'id' parameter to the decode.php ...

Vendor: KaymeePhotography
Product: Photocart Link
Published: Jun 15, 2026
Source: NVD
CVE-2016-20074 MEDIUM - 4.3

WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_adm...

Vendor: leethompson
Product: Lazy Content Slider Plugin
Published: Jun 15, 2026
Source: NVD