Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 561 - 580 of 34,822 CVEs
CVE-2026-52707 HIGH - 8.1

Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

Vendor: Mikado-Themes
Product: Kastell
Published: Jun 17, 2026
Source: NVD
CVE-2026-49268 CRITICAL - 9.1

A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: Jun 17, 2026
Source: NVD
CVE-2026-49108 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

Vendor: park_of_ideas
Product: Moderno
Published: Jun 17, 2026
Source: NVD
CVE-2026-40757 HIGH - 8.1

Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

Vendor: Mikado-Themes
Product: Château
Published: Jun 17, 2026
Source: NVD
CVE-2026-40756 HIGH - 8.1

Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

Vendor: Mikado-Themes
Product: Zoya
Published: Jun 17, 2026
Source: NVD
CVE-2026-40752 HIGH - 8.1

Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

Vendor: Select-Themes
Product: Manufaktur Solutions
Published: Jun 17, 2026
Source: NVD
CVE-2026-40738 HIGH - 8.1

Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

Vendor: Edge-Themes
Product: Eldon
Published: Jun 17, 2026
Source: NVD
CVE-2026-40733 HIGH - 8.1

Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.

Vendor: Mikado-Themes
Product: ShiftUp
Published: Jun 17, 2026
Source: NVD
CVE-2026-40720 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

Vendor: Royal Elementor Addons
Product: Royal Elementor Addons Pro
Published: Jun 17, 2026
Source: NVD
CVE-2026-39590 HIGH - 8.1

Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

Vendor: ThemeMove
Product: Atomlab
Published: Jun 17, 2026
Source: NVD
CVE-2026-39576 HIGH - 8.1

Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

Vendor: Elated-Themes
Product: SingleMalt
Published: Jun 17, 2026
Source: NVD
CVE-2026-39560 HIGH - 8.1

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

Vendor: Select-Themes
Product: Hiroshi
Published: Jun 17, 2026
Source: NVD
CVE-2026-39559 HIGH - 8.1

Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

Vendor: codesupplyco
Product: Uppercase
Published: Jun 17, 2026
Source: NVD
CVE-2026-39556 HIGH - 8.1

Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

Vendor: Elated-Themes
Product: Konsept
Published: Jun 17, 2026
Source: NVD
CVE-2026-39523 HIGH - 8.1

Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

Vendor: Elated-Themes
Product: Solene Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-39445 HIGH - 8.1

Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

Vendor: PressLayouts
Product: Alukas
Published: Jun 17, 2026
Source: NVD
CVE-2026-39442 HIGH - 8.1

Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

Vendor: PressLayouts
Product: PressMart
Published: Jun 17, 2026
Source: NVD
CVE-2026-10641 HIGH - 7.1

Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cind_handle(), which assigns a per-entry ...

Vendor: zephyrproject
Product: zephyr
Published: Jun 17, 2026
Source: NVD
CVE-2025-69189 HIGH - 7.3

Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.

Vendor: EMV
Product: JobBank
Published: Jun 17, 2026
Source: NVD
CVE-2025-69175 HIGH - 8.1

Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

Vendor: ThemeREX
Product: Line Agency
Published: Jun 17, 2026
Source: NVD