Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 621 - 640 of 34,871 CVEs
CVE-2026-39560 HIGH - 8.1

Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

Vendor: Select-Themes
Product: Hiroshi
Published: Jun 17, 2026
Source: NVD
CVE-2026-39559 HIGH - 8.1

Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

Vendor: codesupplyco
Product: Uppercase
Published: Jun 17, 2026
Source: NVD
CVE-2026-39556 HIGH - 8.1

Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

Vendor: Elated-Themes
Product: Konsept
Published: Jun 17, 2026
Source: NVD
CVE-2026-39523 HIGH - 8.1

Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

Vendor: Elated-Themes
Product: Solene Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-39445 HIGH - 8.1

Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

Vendor: PressLayouts
Product: Alukas
Published: Jun 17, 2026
Source: NVD
CVE-2026-39442 HIGH - 8.1

Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

Vendor: PressLayouts
Product: PressMart
Published: Jun 17, 2026
Source: NVD
CVE-2026-10641 HIGH - 7.1

Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cind_handle(), which assigns a per-entry ...

Vendor: zephyrproject
Product: zephyr
Published: Jun 17, 2026
Source: NVD
CVE-2025-69189 HIGH - 7.3

Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.

Vendor: EMV
Product: JobBank
Published: Jun 17, 2026
Source: NVD
CVE-2025-69175 HIGH - 8.1

Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

Vendor: ThemeREX
Product: Line Agency
Published: Jun 17, 2026
Source: NVD
CVE-2025-69174 HIGH - 8.1

Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

Vendor: ThemeREX
Product: Etude
Published: Jun 17, 2026
Source: NVD
CVE-2025-69170 HIGH - 8.1

Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

Vendor: ThemeREX
Product: Eventicity
Published: Jun 17, 2026
Source: NVD
CVE-2025-69166 HIGH - 8.1

Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

Vendor: ThemeREX
Product: Gunslinger
Published: Jun 17, 2026
Source: NVD
CVE-2025-69164 HIGH - 8.1

Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.

Vendor: ThemeREX
Product: Skyward
Published: Jun 17, 2026
Source: NVD
CVE-2025-69158 HIGH - 8.1

Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

Vendor: ThemeREX
Product: Granola
Published: Jun 17, 2026
Source: NVD
CVE-2025-69157 HIGH - 8.1

Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

Vendor: ThemeREX
Product: Gamic
Published: Jun 17, 2026
Source: NVD
CVE-2025-69144 HIGH - 8.1

Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

Vendor: ThemeREX
Product: Preservation
Published: Jun 17, 2026
Source: NVD
CVE-2025-69140 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

Vendor: SeventhQueen
Product: SweetDate Core
Published: Jun 17, 2026
Source: NVD
CVE-2025-69130 HIGH - 8.8

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

Vendor: Themovation
Product: Entrepreneur - Booking for Small Businesses WordPress Theme
Published: Jun 17, 2026
Source: NVD
CVE-2025-69128 HIGH - 8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3.

Vendor: EMV
Product: JobCareer
Published: Jun 17, 2026
Source: NVD
CVE-2025-69127 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

Vendor: ThemeREX
Product: Plumbing
Published: Jun 17, 2026
Source: NVD