Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 781 - 800 of 12,942 CVEs
CVE-2026-9019 MEDIUM - 6.4

The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping. T...

Published: Jun 10, 2026
Source: NVD
CVE-2026-8853 MEDIUM - 4.4

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and...

Published: Jun 10, 2026
Source: NVD
CVE-2026-8613 MEDIUM - 6.4

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

Published: Jun 10, 2026
Source: NVD
CVE-2025-8444 MEDIUM - 6.4

The Animation Addons for Elementor โ€“ GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. T...

Published: Jun 10, 2026
Source: NVD
CVE-2026-24720 MEDIUM - 6.5

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have...

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2026-24717 MEDIUM - 6.5

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the fol...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Jun 10, 2026
Source: NVD
CVE-2026-22899 MEDIUM - 6.5

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6....

Vendor: QNAP Systems Inc.
Product: File Station 5
Published: Jun 10, 2026
Source: NVD
CVE-2025-62851 MEDIUM - 4.4

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License C...

Vendor: QNAP Systems Inc.
Product: License Center
Published: Jun 10, 2026
Source: NVD
CVE-2026-46532 MEDIUM - 4.6

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd() in components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c). This issue has been ...

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-45160 MEDIUM - 6.5

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_options() in components/lwip/apps/dhcpserver/dhcpserver.c) shipped with ESP-IDF's lwIP component....

Vendor: espressif
Product: esp-idf
Published: Jun 10, 2026
Source: NVD
CVE-2026-53675 MEDIUM - 4.3

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_chec...

Vendor: BuddyPress
Product: BuddyPress
Published: Jun 10, 2026
Source: NVD
CVE-2026-47838 MEDIUM - 6.8

SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 ...

Vendor: Spring
Product: Spring Security
Published: Jun 10, 2026
Source: NVD
CVE-2026-46540 MEDIUM - 6.5

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a fork chain whose tip is a macro block (checkpoint or election), it only updates self.head but fails to update self.macro_h...

Vendor: nimiq
Product: core-rs-albatross
Published: Jun 10, 2026
Source: NVD
CVE-2026-46411 MEDIUM - 6.5

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of their write buffer and triggering an internal safe-guard exception. This exception was in a path that was not catchable, and there...

Vendor: halfgaar
Product: FlashMQ
Published: Jun 10, 2026
Source: NVD
CVE-2026-44505 MEDIUM - 5.3

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). Prior to version 1.4.0, when a peer returns a FoundRecord, the code verifies the recor...

Vendor: nimiq
Product: core-rs-albatross
Published: Jun 10, 2026
Source: NVD
CVE-2026-41837 MEDIUM - 5.3

Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.1...

Vendor: Spring
Product: Spring Data REST
Published: Jun 10, 2026
Source: NVD
CVE-2026-41730 MEDIUM - 5.3

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0...

Vendor: Spring
Product: Spring Data REST
Published: Jun 10, 2026
Source: NVD
CVE-2026-41727 MEDIUM - 6.5

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where th...

Vendor: Spring
Product: Spring for Apache Kafka
Published: Jun 10, 2026
Source: NVD
CVE-2026-41726 MEDIUM - 6.5

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0...

Vendor: Spring
Product: Spring for Apache Kafka
Published: Jun 10, 2026
Source: NVD
CVE-2026-41721 MEDIUM - 5.9

Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTTP request that causes the application to allocate lot...

Vendor: Spring
Product: Spring Data Commons
Published: Jun 10, 2026
Source: NVD