Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,015
Quick preset (or use dates below)
Clear Filters
Showing 561 - 580 of 13,341 CVEs
CVE-2026-12188 MEDIUM - 6.3

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/controllers/concerns/grit/core/grit_entity_controller.rb of the component GritEntityController. Performing a manipulation results in sql injection. The ...

Vendor: Grit42
Product: Grit
Published: Jun 14, 2026
Source: NVD
CVE-2026-54411 MEDIUM - 5.9

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to reco...

Vendor: Linux-PAM
Product: Linux-PAM
Published: Jun 14, 2026
Source: NVD
CVE-2026-54421 MEDIUM - 6.8

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.

Vendor: OpenStack
Product: Ironic
Published: Jun 14, 2026
Source: NVD
CVE-2026-12176 MEDIUM - 4.3

A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely...

Vendor: SourceCodester
Product: CET Automated Grading System with AI Predictive Analytics
Published: Jun 14, 2026
Source: NVD
CVE-2026-12175 MEDIUM - 4.7

A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible....

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 13, 2026
Source: NVD
CVE-2026-1291 MEDIUM - 4.3

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-leve...

Published: Jun 13, 2026
Source: NVD
CVE-2026-9629 MEDIUM - 6.4

The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...

Published: Jun 13, 2026
Source: NVD
CVE-2026-3297 MEDIUM - 6.4

The Page Builder: Pagelayer โ€“ Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w...

Published: Jun 13, 2026
Source: NVD
CVE-2026-2470 MEDIUM - 4.3

The Page Builder: Pagelayer โ€“ Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users with basic post-edit capability to persist pagelayer_contact_te...

Published: Jun 13, 2026
Source: NVD
CVE-2026-9134 MEDIUM - 6.4

The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in the foogallery_sanitize_javascript() function, whi...

Published: Jun 13, 2026
Source: NVD

We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports loading dashboards & library panels using the jsonnet dat...

Vendor: Grafana
Product: Grafana Operator
Published: Jun 13, 2026
Source: NVD
CVE-2026-54231 MEDIUM - 5.5

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A lo...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
Published: Jun 13, 2026
Source: NVD
CVE-2026-12089 MEDIUM - 4.9

The LWS Optimize โ€“ All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 3.3.19. This is due to the combine_current_css() function trusting <link rel="stylesheet" href="..."> values harvested ...

Vendor: aurelienlws
Product: LWS Optimize โ€“ All-in-One Speed Booster & Cache Tools
Published: Jun 13, 2026
Source: NVD
CVE-2026-11443 MEDIUM - 4.6

Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User interaction is required to exploit this vulnerability in that the target must visit a malicious page ...

Vendor: Allegra
Product: Allegra
Published: Jun 13, 2026
Source: NVD
CVE-2026-11442 MEDIUM - 6.5

Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw exists within the exportRepor...

Vendor: Allegra
Product: Allegra
Published: Jun 13, 2026
Source: NVD
CVE-2026-53867 MEDIUM - 4.3

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.

Vendor: Cap-go
Product: capgo
Published: Jun 12, 2026
Source: NVD
CVE-2026-53839 MEDIUM - 6.5

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53835 MEDIUM - 4.3

OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploit this by leveraging the dynamic-agent binding fea...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53830 MEDIUM - 6.5

OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, poten...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53827 MEDIUM - 6.5

OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attackers can intercept Gateway tokens and action payloads by provid...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD