Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
Showing 621 - 640 of 12,797 CVEs
CVE-2026-39581 HIGH - 8.5

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

Vendor: activity-log.com
Product: WP Sessions Time Monitoring Full Automatic
Published: Jun 16, 2026
Source: NVD
CVE-2026-39490 HIGH - 7.5

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

Vendor: artbees
Product: JupiterX Core
Published: Jun 16, 2026
Source: NVD
CVE-2026-39437 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.

Vendor: WPFactory
Product: Min Max Step Quantity Limits Manager for WooCommerce
Published: Jun 16, 2026
Source: NVD
CVE-2025-68045 HIGH - 7.5

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

Vendor: Arraytics
Product: WP Event SOlution
Published: Jun 16, 2026
Source: NVD
CVE-2026-8444 HIGH - 8.8

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type ca...

Published: Jun 16, 2026
Source: NVD
CVE-2026-8443 HIGH - 8.8

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strin...

Published: Jun 16, 2026
Source: NVD
CVE-2026-6933 HIGH - 8.8

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processing user-supplied POST data, combined with th...

Published: Jun 16, 2026
Source: NVD
CVE-2026-7273 HIGH - 8.8

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions throughย 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Published: Jun 16, 2026
Source: NVD
CVE-2026-12161 HIGH - 8.8

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted altern...

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-48723 HIGH - 7.8

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a sh...

Vendor: browserstack
Product: browserstack-cypress-cli
Published: Jun 15, 2026
Source: NVD
CVE-2026-52702 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

Vendor: wp-buy
Product: SEO Redirection
Published: Jun 15, 2026
Source: NVD
CVE-2026-52700 HIGH - 8.5

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

Vendor: WcMultishipping โ€“ Mondial Relay & Chronopost for Wooommerce
Product: WCMultiShipping
Published: Jun 15, 2026
Source: NVD
CVE-2026-52699 HIGH - 7.5

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

Vendor: e4jvikwp
Product: VikRentCar
Published: Jun 15, 2026
Source: NVD
CVE-2026-52697 HIGH - 8.5

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

Vendor: Taskbuilder
Product: Taskbuilder
Published: Jun 15, 2026
Source: NVD
CVE-2026-52695 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

Vendor: Al Monsor
Product: ABC Crypto Checkout
Published: Jun 15, 2026
Source: NVD
CVE-2026-52694 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

Vendor: WP E-Signature
Product: Signature Add-On for WooCommerce
Published: Jun 15, 2026
Source: NVD
CVE-2026-52692 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

Vendor: wp.insider
Product: Affiliates Manager
Published: Jun 15, 2026
Source: NVD
CVE-2026-49780 HIGH - 8.8

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

Vendor: Dokan, Inc.
Product: Dokan
Published: Jun 15, 2026
Source: NVD
CVE-2026-49112 HIGH - 7.5

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

Vendor: Tammersoft
Product: Shared Files
Published: Jun 15, 2026
Source: NVD
CVE-2026-49110 HIGH - 7.5

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

Vendor: WP Swings
Product: Upsell Order Bump Offer for WooCommerce
Published: Jun 15, 2026
Source: NVD