Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 681 - 700 of 12,942 CVEs
CVE-2026-11561 MEDIUM - 5.3

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6...

Vendor: Soagen Informatics Technologies Software and Consulting Inc.
Product: Apinizer
Published: Jun 11, 2026
Source: NVD
CVE-2026-53723 MEDIUM - 5.8

Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model structures. Versions prior ro 1.5.4 do not safely serialize scalar XML element values containing the...

Vendor: composer
Product: guzzlehttp/guzzle-services
Published: Jun 11, 2026
Source: GitHub
CVE-2026-9204 MEDIUM - 5.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources du...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-6277 MEDIUM - 4.3

GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when t...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-6269 MEDIUM - 5.4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect author...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-1500 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a s...

Vendor: gitlab
Product: gitlab
Published: Jun 11, 2026
Source: NVD
CVE-2026-10733 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization.

Vendor: GitLab
Product: GitLab
Published: Jun 11, 2026
Source: NVD
CVE-2023-32959 MEDIUM - 4.3

Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.

Vendor: Sparkle WP
Product: MetroStore
Published: Jun 11, 2026
Source: NVD
CVE-2023-25969 MEDIUM - 5.4

Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Contact Form & Lead Form Elementor Builder: from n/a through 1.8.4.

Vendor: ThemeHunk
Product: Contact Form & Lead Form Elementor Builder
Published: Jun 11, 2026
Source: NVD
CVE-2022-47150 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10.

Vendor: weDevs
Product: WooCommerce Conversion Tracking
Published: Jun 11, 2026
Source: NVD
CVE-2022-45813 MEDIUM - 5.4

Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3.

Vendor: BeRocket
Product: Advanced AJAX Product Filters
Published: Jun 11, 2026
Source: NVD
CVE-2026-11850 MEDIUM - 5.0

An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 11, 2026
Source: NVD
CVE-2025-7064 MEDIUM - 6.6

Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.

Published: Jun 11, 2026
Source: NVD
CVE-2022-44630 MEDIUM - 4.6

Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery. This issue affects YITH WooCommerce Product Slider Carousel: from n/a through 1.16.0.

Vendor: YITH
Product: YITH WooCommerce Product Slider Carousel
Published: Jun 11, 2026
Source: NVD
CVE-2022-42479 MEDIUM - 5.4

Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Soledad: from n/a through 8.2.5.

Vendor: TemplateHouse
Product: Soledad
Published: Jun 11, 2026
Source: NVD
CVE-2024-32110 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.

Vendor: Magepeople inc.
Product: WpEvently
Published: Jun 11, 2026
Source: NVD
CVE-2023-40200 MEDIUM - 5.3

Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6.

Vendor: Essential Plugin
Product: WP Logo Showcase Responsive Slider and Carousel
Published: Jun 11, 2026
Source: NVD
CVE-2026-41001 MEDIUM - 5.3

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or place a symlink before the application st...

Vendor: Spring
Product: Spring Boot
Published: Jun 11, 2026
Source: NVD
CVE-2026-40997 MEDIUM - 5.3

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote at...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD
CVE-2026-40996 MEDIUM - 4.8

Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the fla...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD