Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 921 - 940 of 34,822 CVEs
CVE-2024-52488 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

Vendor: Zidithemes
Product: Grip
Published: Jun 17, 2026
Source: NVD
CVE-2024-49269 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

Vendor: Mythemes
Product: my flatonica
Published: Jun 17, 2026
Source: NVD
CVE-2024-37496 MEDIUM - 4.3

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.

Vendor: Rara Themes
Product: Metro Magazine
Published: Jun 17, 2026
Source: NVD
CVE-2024-37210 MEDIUM - 6.5

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

Vendor: ali2woo
Product: AliNext
Published: Jun 17, 2026
Source: NVD
CVE-2024-35690 MEDIUM - 6.5

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.

Vendor: MarketingFire
Product: Widget Options
Published: Jun 17, 2026
Source: NVD
CVE-2024-35648 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.

Vendor: Andy Moyle
Product: Emergency Password Reset
Published: Jun 17, 2026
Source: NVD
CVE-2024-34810 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

Vendor: Extend Themes
Product: Skyline WP
Published: Jun 17, 2026
Source: NVD
CVE-2024-33909 MEDIUM - 5.3

Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.

Vendor: Avirtum
Product: iPages Flipbook
Published: Jun 17, 2026
Source: NVD
CVE-2024-33685 MEDIUM - 4.3

Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.

Vendor: Jegstudio
Product: Startupzy
Published: Jun 17, 2026
Source: NVD
CVE-2024-32949 HIGH - 8.3

Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8.

Vendor: Prince
Product: Integrate Google Drive
Published: Jun 17, 2026
Source: NVD
CVE-2024-32729 HIGH - 7.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.

Vendor: QuantumCloud
Product: Conversational Forms for ChatBot
Published: Jun 17, 2026
Source: NVD
CVE-2024-31435 MEDIUM - 4.3

: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6.

Vendor: Inisev
Product: Social Media & Share Icons
Published: Jun 17, 2026
Source: NVD
CVE-2024-24709 MEDIUM - 4.3

Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11.

Vendor: Shareaholic
Product: Shareaholic
Published: Jun 17, 2026
Source: NVD
CVE-2026-48776 MEDIUM - 4.2

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource ope...

Vendor: langchain-ai
Product: langchain-ai, langchain-sdk
Published: Jun 17, 2026
Source: NVD
CVE-2026-48294 HIGH - 8.2

Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in...

Vendor: adobe
Product: acrobat
Published: Jun 17, 2026
Source: NVD
CVE-2026-46979 MEDIUM - 6.5

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise People...

Published: Jun 17, 2026
Source: NVD
CVE-2026-46978 CRITICAL - 10.0

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Solaris. While the vulnerabi...

Published: Jun 17, 2026
Source: NVD

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromis...

Vendor: oracle
Product: vm_virtualbox
Published: Jun 17, 2026
Source: NVD
CVE-2026-46976 HIGH - 7.2

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public S...

Vendor: oracle
Product: public_sector_payroll
Published: Jun 17, 2026
Source: NVD
CVE-2026-46974 HIGH - 7.5

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracl...

Vendor: oracle
Product: vm_virtualbox
Published: Jun 17, 2026
Source: NVD