Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 681 - 700 of 34,822 CVEs
CVE-2026-48875 CRITICAL - 9.3

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

Vendor: Jetimpex Inc.
Product: JetSmartFilters
Published: Jun 17, 2026
Source: NVD
CVE-2026-48869 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

Vendor: Kriesi
Product: Enfold
Published: Jun 17, 2026
Source: NVD

Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and Hugging...

Vendor: mcp-tool-shop-org
Product: backpropagate, @mcptoolshop/backpropagate
Published: Jun 17, 2026
Source: NVD
CVE-2026-48788 HIGH - 8.2

Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing. The Remark42 image proxy fetches an arbitrary remote URL and re...

Vendor: umputun
Product: remark42
Published: Jun 17, 2026
Source: NVD
CVE-2026-48783 MEDIUM - 4.8

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose....

Vendor: gitroomhq
Product: postiz-app
Published: Jun 17, 2026
Source: NVD
CVE-2026-48782 MEDIUM - 6.8

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous fix, CVE-2026-46678, d...

Vendor: pydantic
Product: pydantic-ai, pydantic-ai-slim
Published: Jun 17, 2026
Source: NVD
CVE-2026-48781 CRITICAL - 9.9

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user fr...

Vendor: gitroomhq
Product: postiz-app
Published: Jun 17, 2026
Source: NVD
CVE-2026-48745 CRITICAL - 9.3

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The ap...

Vendor: traccar
Product: traccar-client
Published: Jun 17, 2026
Source: NVD
CVE-2026-48616 CRITICAL - 9.3

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not ve...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Jun 17, 2026
Source: NVD
CVE-2026-48055 CRITICAL - 10.0

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, ...

Vendor: truelockmc
Product: streambert
Published: Jun 17, 2026
Source: NVD
CVE-2026-47340 MEDIUM - 6.5

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-47277 MEDIUM - 6.5

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arbitrary file read through app-store logo symlinks. The path guard checks only the...

Vendor: runtipi
Product: runtipi
Published: Jun 17, 2026
Source: NVD
CVE-2026-45436 MEDIUM - 6.5

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

Vendor: Rain-Task Ltd.
Product: WPBakery Page Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-42629 HIGH - 8.8

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

Vendor: Powerpackelements
Product: PowerPack Pro for Elementor
Published: Jun 17, 2026
Source: NVD
CVE-2026-42385 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

Vendor: Cozmoslabs
Product: Profile Builder Pro
Published: Jun 17, 2026
Source: NVD
CVE-2026-42380 CRITICAL - 9.8

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

Vendor: jwsthemes
Product: AI Lab
Published: Jun 17, 2026
Source: NVD
CVE-2026-42357 MEDIUM - 6.5

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-41557 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.

Vendor: PressLayouts
Product: Kapee
Published: Jun 17, 2026
Source: NVD
CVE-2026-41280 MEDIUM - 4.9

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-40783 CRITICAL - 9.9

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

Vendor: Creative Themes
Product: Blocksy Companion Pro
Published: Jun 17, 2026
Source: NVD