Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,410
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 561 - 580 of 33,519 CVEs
CVE-2016-20074 MEDIUM - 4.3

WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_adm...

Vendor: leethompson
Product: Lazy Content Slider Plugin
Published: Jun 15, 2026
Source: NVD
CVE-2016-20073 HIGH - 8.2

Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' POST parameter. Attackers can submit crafted SQL statements to the modal.php endpoint to e...

Vendor: mattkaye
Product: Answer My Question
Published: Jun 15, 2026
Source: NVD
CVE-2016-20072 HIGH - 8.2

BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the uid parameter. Attackers can craft requests to pages using the plugin's shortcode with UNION-based SQ...

Vendor: bbsetheme
Product: BBS e-Franchise
Published: Jun 15, 2026
Source: NVD
CVE-2016-20071 HIGH - 8.2

The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads ...

Vendor: 404-redirection-manager
Product: 404 Redirection Manager
Published: Jun 15, 2026
Source: NVD
CVE-2016-20070 MEDIUM - 6.4

WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscri...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20069 HIGH - 8.2

WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to exec...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20068 HIGH - 8.2

WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpo...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20067 MEDIUM - 4.3

WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operations when administrators visit the page while logged in.

Vendor: dwbooster
Product: CP Polls
Published: Jun 15, 2026
Source: NVD
CVE-2016-20066 HIGH - 7.2

WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers like onerror attributes to execute arbitrary Ja...

Vendor: dwbooster
Product: CP Polls
Published: Jun 15, 2026
Source: NVD

Responsive FileManager's allows an unauthenticatedĀ attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution.Ā  This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest releaseĀ ...

Published: Jun 15, 2026
Source: NVD

Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email address (an upsert on the email field, or a user-defined sign-...

Vendor: team-alembic
Product: ash_authentication
Published: Jun 15, 2026
Source: NVD

TheĀ Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch is created. The branch code is later used in multiple application functions, including filesystem path generation for uploaded files, profile pictures, and settings...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

TheĀ Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructure.Security.dll component. An attacker with access to the application files can reverse engineer the DLL and recover the hard-coded cryptographic key. This key...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated attacker can directly access HTTP endpoints to download files from locations such as /Resources/CompanyId_[ID]/Audio/ and /Sa...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and accepts the upload if ...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without sufficient validation, al...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from the HTTP X-Forwarded...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with minimal privileges can access endpoints that are not visible in the frontend but remain directly reachable. This allows t...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController WebMessageBroker. An authenticated attacker with valid low-privileged branch user credentials can manipulate WebSocket me...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)
Published: Jun 15, 2026
Source: NVD

TheĀ Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to protect communication. An attacker in an adversary-in-the-middle position can decrypt the data traffic. During reassessment, i...

Vendor: Wertheim GmbH
Product: Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)
Published: Jun 15, 2026
Source: NVD