Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 701 - 720 of 34,768 CVEs
CVE-2026-34893 HIGH - 8.1

Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.

Vendor: WebGeniusLab
Product: Thegov Core
Published: Jun 17, 2026
Source: NVD
CVE-2026-34888 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

Vendor: Bricksforge
Product: Bricksforge
Published: Jun 17, 2026
Source: NVD
CVE-2026-32967 CRITICAL - 9.1

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-32966 CRITICAL - 9.8

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-2604 MEDIUM - 5.6

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modificat...

Published: Jun 17, 2026
Source: NVD
CVE-2026-28615 HIGH - 7.8

In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28587 MEDIUM - 5.5

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28576 MEDIUM - 5.5

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28575 MEDIUM - 5.5

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. Use...

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS)  payload into the 'Hostname' field of the c...

Vendor: Teldat
Product: Regesta Smart HD-PLC - TLDPH16D2
Published: Jun 17, 2026
Source: NVD

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, with a Slow Loris attack, cause Denial of Service (DoS) on the web interface of the device. This issue affects Regesta Smar...

Vendor: Teldat
Product: Regesta Smart HD-PLC - TLDPH16D2
Published: Jun 17, 2026
Source: NVD

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting i...

Vendor: Teldat
Product: Regesta Smart HD-PLC - TLDPH16D2
Published: Jun 17, 2026
Source: NVD
CVE-2026-27429 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

Vendor: BoldThemes
Product: Nifty
Published: Jun 17, 2026
Source: NVD
CVE-2026-27410 MEDIUM - 6.5

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

Vendor: VeronaLabs
Product: Slimstat Analytics
Published: Jun 17, 2026
Source: NVD
CVE-2026-27400 HIGH - 8.6

Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.

Vendor: Ovatheme
Product: BookPro
Published: Jun 17, 2026
Source: NVD
CVE-2026-27395 CRITICAL - 9.8

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

Vendor: Schiocco
Product: Support Board
Published: Jun 17, 2026
Source: NVD
CVE-2026-27041 CRITICAL - 9.9

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

Vendor: Studio Keren Aga LTD.
Product: Unlimited Elements for Elementor (Premium)
Published: Jun 17, 2026
Source: NVD
CVE-2026-25470 CRITICAL - 10.0

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.

Vendor: ACPT
Product: ACPT (Pro) - Custom Post Types Plugin for WordPress
Published: Jun 17, 2026
Source: NVD
CVE-2026-25446 CRITICAL - 9.9

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

Vendor: WishList Products, LLC.
Product: WishList Member X
Published: Jun 17, 2026
Source: NVD
CVE-2026-25439 HIGH - 8.1

Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.

Vendor: fs-code
Product: Booknetic
Published: Jun 17, 2026
Source: NVD