Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,015
Quick preset (or use dates below)
Clear Filters
Showing 541 - 560 of 13,341 CVEs
CVE-2016-20070 MEDIUM - 6.4

WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscri...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20067 MEDIUM - 4.3

WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operations when administrators visit the page while logged in.

Vendor: dwbooster
Product: CP Polls
Published: Jun 15, 2026
Source: NVD
CVE-2026-44188 MEDIUM - 5.3

A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they c...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2
Published: Jun 15, 2026
Source: NVD
CVE-2026-9278 MEDIUM - 5.4

The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against an...

Published: Jun 15, 2026
Source: NVD
CVE-2026-8386 MEDIUM - 5.3

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address an...

Published: Jun 15, 2026
Source: NVD
CVE-2026-8385 MEDIUM - 5.3

The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, categ...

Published: Jun 15, 2026
Source: NVD
CVE-2026-12223 MEDIUM - 5.5

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection. The attack needs ...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12219 MEDIUM - 6.3

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. T...

Vendor: Yealink
Product: SIP-T46U
Published: Jun 15, 2026
Source: NVD
CVE-2026-12216 MEDIUM - 5.3

A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file duk_api_bytecode.c. Executing a manipulation of the argument count_instr can lead to memory corruption. The attack requires local access. The exploit has been made available to th...

Vendor: svaarala
Product: duktape
Published: Jun 15, 2026
Source: NVD
CVE-2026-12213 MEDIUM - 4.3

A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function getAccountInfo of the file server/account/src/operations.ts of the component User Information Handler. The manipulation results in improper authorization. The attack may be launched r...

Vendor: hcengineering
Product: Huly Platform
Published: Jun 15, 2026
Source: NVD
CVE-2026-12212 MEDIUM - 4.3

A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of the file server/account/src/operations.ts of the component RPC Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has ...

Vendor: hcengineering
Product: Huly Platform
Published: Jun 15, 2026
Source: NVD
CVE-2026-12210 MEDIUM - 6.3

A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an unknown function of the component utcp-gql/utcp-websocket. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be u...

Vendor: universal-tool-calling-protocol
Product: python-utcp
Published: Jun 15, 2026
Source: NVD
CVE-2026-12209 MEDIUM - 5.3

A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attributes. It is pos...

Vendor: RubyLouvre
Product: avalon
Published: Jun 15, 2026
Source: NVD
CVE-2026-12208 MEDIUM - 5.3

A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to ...

Vendor: jsonata-js
Product: jsonata
Published: Jun 15, 2026
Source: NVD
CVE-2026-12207 MEDIUM - 4.3

A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatientById of the file app\modules\medical\port\rest\controllers\PatientController.php of the component HTTP REST API. The manipulation of the argument ID resul...

Vendor: medkey-org
Product: medkey
Published: Jun 15, 2026
Source: NVD
CVE-2026-12206 MEDIUM - 6.3

A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/backend/app/models/grit/assays/data_table_entity.rb. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The ex...

Vendor: Grit42
Product: Grit
Published: Jun 15, 2026
Source: NVD
CVE-2026-12203 MEDIUM - 5.3

A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible....

Vendor: HKUDS
Product: AI-Trader
Published: Jun 15, 2026
Source: NVD
CVE-2026-12201 MEDIUM - 5.3

A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit has been published and may be used. The vendor was contacted...

Vendor: IObit
Product: Malware Fighter
Published: Jun 15, 2026
Source: NVD
CVE-2026-12190 MEDIUM - 5.3

A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. T...

Vendor: Genspark
Product: AI Workspace App
Published: Jun 14, 2026
Source: NVD
CVE-2026-12189 MEDIUM - 5.3

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper authorization in handler for custom url scheme. The attack can only be executed locally. The exploit has been publi...

Vendor: Moovit
Product: Bus & Public Transit App
Published: Jun 14, 2026
Source: NVD