Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 641 - 660 of 36,708 CVEs
CVE-2026-54829 HIGH - 7.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.

Vendor: Jacob N. Breetvelt
Product: WP Photo Album Plus
Published: Jun 25, 2026
Source: NVD
CVE-2026-54828 HIGH - 7.5

Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

Vendor: StylemixThemes
Product: Motors
Published: Jun 25, 2026
Source: NVD
CVE-2026-54823 CRITICAL - 9.9

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

Vendor: MarketingFire
Product: Widget Options
Published: Jun 25, 2026
Source: NVD
CVE-2026-54822 HIGH - 8.5

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

Vendor: SALESmanago
Product: SALESmanago & Leadoo
Published: Jun 25, 2026
Source: NVD
CVE-2026-54821 HIGH - 7.4

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

Vendor: Bootstrapped Ventures
Product: Visual Link Preview
Published: Jun 25, 2026
Source: NVD
CVE-2026-52690 MEDIUM - 5.9

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

Vendor: PowerDNS
Product: Recursor
Published: Jun 25, 2026
Source: NVD
CVE-2026-4526 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-49506 HIGH - 7.2

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

Vendor: Dell
Product: Wyse Management Suite
Published: Jun 25, 2026
Source: NVD
CVE-2026-47154 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. ...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47153 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47152 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47151 HIGH - 7.1

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cl...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47150 HIGH - 7.1

In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IA...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47149 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices ...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47148 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Onl...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47147 HIGH - 7.1

In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network...

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47146 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-47145 MEDIUM - 6.5

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

Vendor: silabs
Product: emberznet
Published: Jun 25, 2026
Source: NVD
CVE-2026-46734 HIGH - 7.3

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

Vendor: Dell
Product: Display and Peripheral Manager
Published: Jun 25, 2026
Source: NVD
CVE-2026-46733 HIGH - 7.8

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

Vendor: Dell
Product: Display and Peripheral Manager
Published: Jun 25, 2026
Source: NVD