Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,962
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 641 - 660 of 34,768 CVEs
CVE-2026-42385 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

Vendor: Cozmoslabs
Product: Profile Builder Pro
Published: Jun 17, 2026
Source: NVD
CVE-2026-42380 CRITICAL - 9.8

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

Vendor: jwsthemes
Product: AI Lab
Published: Jun 17, 2026
Source: NVD
CVE-2026-42357 MEDIUM - 6.5

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-41557 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

Vendor: PressLayouts
Product: Kapee
Published: Jun 17, 2026
Source: NVD
CVE-2026-41280 MEDIUM - 4.9

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-40783 CRITICAL - 9.9

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

Vendor: Creative Themes
Product: Blocksy Companion Pro
Published: Jun 17, 2026
Source: NVD
CVE-2026-40768 HIGH - 7.3

Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

Vendor: Dimitri Grassi
Product: Salon booking system
Published: Jun 17, 2026
Source: NVD
CVE-2026-40765 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.

Vendor: collectchat
Product: collectchat
Published: Jun 17, 2026
Source: NVD
CVE-2026-40761 HIGH - 8.1

Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.

Vendor: Edge-Themes
Product: Valeska
Published: Jun 17, 2026
Source: NVD
CVE-2026-40760 HIGH - 8.1

Unauthenticated PHP Object Injection in Behold <= 1.5 versions.

Vendor: Edge-Themes
Product: Behold
Published: Jun 17, 2026
Source: NVD
CVE-2026-40759 HIGH - 8.1

Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

Vendor: Mikado-Themes
Product: Esmée
Published: Jun 17, 2026
Source: NVD
CVE-2026-40758 HIGH - 8.1

Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.

Vendor: Elated-Themes
Product: Léonie
Published: Jun 17, 2026
Source: NVD
CVE-2026-40755 HIGH - 8.1

Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.

Vendor: Mikado-Themes
Product: TechLink
Published: Jun 17, 2026
Source: NVD
CVE-2026-40754 HIGH - 8.1

Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.

Vendor: Elated-Themes
Product: Roisin
Published: Jun 17, 2026
Source: NVD
CVE-2026-40753 HIGH - 8.1

Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.

Vendor: Mikado-Themes
Product: EasyMeals
Published: Jun 17, 2026
Source: NVD
CVE-2026-40751 HIGH - 8.1

Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.

Vendor: Mikado-Themes
Product: Ashtanga
Published: Jun 17, 2026
Source: NVD
CVE-2026-40749 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

Vendor: themagnifico52
Product: Charity Zone
Published: Jun 17, 2026
Source: NVD
CVE-2026-40748 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

Vendor: themagnifico52
Product: Kids Gift Shop
Published: Jun 17, 2026
Source: NVD
CVE-2026-40747 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

Vendor: themagnifico52
Product: Ecommerce Zone
Published: Jun 17, 2026
Source: NVD
CVE-2026-40746 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

Vendor: themagnifico52
Product: Restaurant Zone
Published: Jun 17, 2026
Source: NVD