Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,908
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 621 - 640 of 34,768 CVEs
CVE-2026-49072 MEDIUM - 6.5

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

Vendor: OPMC
Product: WooCommerce Anti-Fraud
Published: Jun 17, 2026
Source: NVD
CVE-2026-49071 MEDIUM - 6.5

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

Vendor: OPMC
Product: WooCommerce Dropshipping
Published: Jun 17, 2026
Source: NVD
CVE-2026-49058 CRITICAL - 9.8

Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

Vendor: LoginPress
Product: LoginPress Pro
Published: Jun 17, 2026
Source: NVD
CVE-2026-49057 HIGH - 7.5

Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.

Vendor: EyeCix Technologies
Product: JobSearch
Published: Jun 17, 2026
Source: NVD
CVE-2026-48967 HIGH - 8.5

Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.

Vendor: Dylan Kuhn
Product: Geo Mashup
Published: Jun 17, 2026
Source: NVD
CVE-2026-48929 HIGH - 7.5

Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentication. When called via an u...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Jun 17, 2026
Source: NVD
CVE-2026-48875 CRITICAL - 9.3

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

Vendor: Jetimpex Inc.
Product: JetSmartFilters
Published: Jun 17, 2026
Source: NVD
CVE-2026-48869 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

Vendor: Kriesi
Product: Enfold
Published: Jun 17, 2026
Source: NVD

Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and Hugging...

Vendor: mcp-tool-shop-org
Product: backpropagate, @mcptoolshop/backpropagate
Published: Jun 17, 2026
Source: NVD
CVE-2026-48788 HIGH - 8.2

Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing. The Remark42 image proxy fetches an arbitrary remote URL and re...

Vendor: umputun
Product: remark42
Published: Jun 17, 2026
Source: NVD
CVE-2026-48783 MEDIUM - 4.8

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose....

Vendor: gitroomhq
Product: postiz-app
Published: Jun 17, 2026
Source: NVD
CVE-2026-48782 MEDIUM - 6.8

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous fix, CVE-2026-46678, d...

Vendor: pydantic
Product: pydantic-ai, pydantic-ai-slim
Published: Jun 17, 2026
Source: NVD
CVE-2026-48781 CRITICAL - 9.9

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user fr...

Vendor: gitroomhq
Product: postiz-app
Published: Jun 17, 2026
Source: NVD
CVE-2026-48745 CRITICAL - 9.3

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The ap...

Vendor: traccar
Product: traccar-client
Published: Jun 17, 2026
Source: NVD
CVE-2026-48616 CRITICAL - 9.3

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not ve...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Jun 17, 2026
Source: NVD
CVE-2026-48055 CRITICAL - 10.0

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, ...

Vendor: truelockmc
Product: streambert
Published: Jun 17, 2026
Source: NVD
CVE-2026-47340 MEDIUM - 6.5

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-47277 MEDIUM - 6.5

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arbitrary file read through app-store logo symlinks. The path guard checks only the...

Vendor: runtipi
Product: runtipi
Published: Jun 17, 2026
Source: NVD
CVE-2026-45436 MEDIUM - 6.5

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

Vendor: Rain-Task Ltd.
Product: WPBakery Page Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-42629 HIGH - 8.8

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

Vendor: Powerpackelements
Product: PowerPack Pro for Elementor
Published: Jun 17, 2026
Source: NVD