Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 701 - 720 of 12,942 CVEs
CVE-2026-40995 MEDIUM - 5.4

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring ...

Vendor: Spring
Product: Spring Web Services
Published: Jun 11, 2026
Source: NVD
CVE-2026-40992 MEDIUM - 5.0

Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; ...

Vendor: Spring
Product: Spring Boot
Published: Jun 11, 2026
Source: NVD
CVE-2026-40986 MEDIUM - 4.8

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected fro...

Vendor: Spring
Product: Spring Web Flow
Published: Jun 11, 2026
Source: NVD
CVE-2026-40985 MEDIUM - 6.4

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

Vendor: Spring
Product: Spring Web Flow
Published: Jun 11, 2026
Source: NVD
CVE-2026-2827 MEDIUM - 4.7

The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

Published: Jun 11, 2026
Source: NVD
CVE-2026-53465 MEDIUM - 6.2

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53464 MEDIUM - 4.0

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53463 MEDIUM - 4.3

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the distort operation a null pointer deference will occur. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-53462 MEDIUM - 5.9

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent this can result in a heap-use-after-free and result in a crash. This issue has been patched in versions 6.9.13-50 ...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-49219 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in v...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48994 MEDIUM - 5.9

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 an...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48734 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48733 MEDIUM - 4.7

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search operation can happen when using a crafted image. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2026-48724 MEDIUM - 5.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will cause a negative heap buffer over-write. This issue has been patched in version 7.1.2-24.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 10, 2026
Source: NVD
CVE-2024-21944 MEDIUM - 5.3

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrit...

Vendor: AMD
Product: AMD EPYCโ„ข 7003 Series Processors, AMD EPYCโ„ข 9004 Series Processor
Published: Jun 10, 2026
Source: NVD
CVE-2026-53742 MEDIUM - 5.4

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.

Vendor: quantumcloud
Product: Simple Link Directory
Published: Jun 10, 2026
Source: NVD
CVE-2026-53741 MEDIUM - 5.4

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.

Vendor: quantumcloud
Product: Simple Link Directory
Published: Jun 10, 2026
Source: NVD
CVE-2026-53740 MEDIUM - 5.4

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.

Vendor: Yoast
Product: Yoast Duplicate Post
Published: Jun 10, 2026
Source: NVD
CVE-2026-53739 MEDIUM - 4.3

Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressin...

Vendor: Yoast
Product: Yoast Duplicate Post
Published: Jun 10, 2026
Source: NVD
CVE-2026-53737 MEDIUM - 6.1

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes in an administrator's browser when the settings page loads.

Vendor: saas.group
Product: Juicer
Published: Jun 10, 2026
Source: NVD