Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 941 - 960 of 34,868 CVEs
CVE-2025-69109 HIGH - 8.1

Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions.

Vendor: ThemeREX
Product: Raider Spirit
Published: Jun 17, 2026
Source: NVD
CVE-2025-69108 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.

Vendor: ThemeREX
Product: Hot Coffee
Published: Jun 17, 2026
Source: NVD
CVE-2025-69107 HIGH - 8.1

Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions.

Vendor: ThemeREX
Product: Rosaleen
Published: Jun 17, 2026
Source: NVD
CVE-2025-69105 HIGH - 8.1

Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions.

Vendor: ThemeREX
Product: Modernee
Published: Jun 17, 2026
Source: NVD
CVE-2025-69104 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions.

Vendor: jkdevstudio
Product: Qreatix
Published: Jun 17, 2026
Source: NVD
CVE-2025-69103 HIGH - 7.5

Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.

Vendor: Utillz
Product: Brikk
Published: Jun 17, 2026
Source: NVD

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity

Vendor: HCL Software
Product: iControl
Published: Jun 17, 2026
Source: NVD
CVE-2025-60223 HIGH - 7.7

Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.

Vendor: QuantumCloud
Product: WPBot Pro Wordpress Chatbot
Published: Jun 17, 2026
Source: NVD
CVE-2025-60218 CRITICAL - 9.9

Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.

Vendor: WPLocker
Product: PT Luxa Addons
Published: Jun 17, 2026
Source: NVD
CVE-2025-60205 CRITICAL - 9.8

Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.

Vendor: ThemeREX
Product: ThemeREX Addons
Published: Jun 17, 2026
Source: NVD
CVE-2025-60085 HIGH - 8.1

Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.

Vendor: ThemeREX Group
Product: Learnify
Published: Jun 17, 2026
Source: NVD
CVE-2025-59872 MEDIUM - 4.3

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. ...

Vendor: HCL Software
Product: ZIE
Published: Jun 17, 2026
Source: NVD
CVE-2025-59563 HIGH - 8.8

Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

Vendor: SONAAR MUSIC
Product: Sonaar
Published: Jun 17, 2026
Source: NVD
CVE-2025-59560 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.

Vendor: SONAAR MUSIC
Product: Sonaar
Published: Jun 17, 2026
Source: NVD
CVE-2025-58954 HIGH - 8.1

Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.

Vendor: ThemeREX
Product: HomeRoofer
Published: Jun 17, 2026
Source: NVD
CVE-2025-58953 HIGH - 8.1

Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.

Vendor: ThemeREX
Product: Joly
Published: Jun 17, 2026
Source: NVD
CVE-2025-58952 HIGH - 8.1

Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.

Vendor: ThemeREX
Product: Neuronet
Published: Jun 17, 2026
Source: NVD
CVE-2025-58924 HIGH - 8.1

Unauthenticated Local File Inclusion in Geya <= 1.15 versions.

Vendor: ThemeREX Group
Product: Geya
Published: Jun 17, 2026
Source: NVD
CVE-2025-49403 HIGH - 7.5

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

Vendor: AA-Team
Product: Premium Age Verification / Restriction for WordPress
Published: Jun 17, 2026
Source: NVD
CVE-2025-48643 HIGH - 7.8

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD