Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 961 - 980 of 34,868 CVEs
CVE-2025-48640 HIGH - 8.0

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48617 HIGH - 7.8

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48571 MEDIUM - 4.3

In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-31013 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6.

Vendor: Themify
Product: Themify Folo
Published: Jun 17, 2026
Source: NVD

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,. * Pr...

Vendor: Netskope
Product: Netskope Client
Published: Jun 17, 2026
Source: NVD

Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti...

Vendor: Netskope
Product: Netskope Client
Published: Jun 17, 2026
Source: NVD
CVE-2024-52488 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

Vendor: Zidithemes
Product: Grip
Published: Jun 17, 2026
Source: NVD
CVE-2024-49269 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

Vendor: Mythemes
Product: my flatonica
Published: Jun 17, 2026
Source: NVD
CVE-2024-37496 MEDIUM - 4.3

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.

Vendor: Rara Themes
Product: Metro Magazine
Published: Jun 17, 2026
Source: NVD
CVE-2024-37210 MEDIUM - 6.5

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

Vendor: ali2woo
Product: AliNext
Published: Jun 17, 2026
Source: NVD
CVE-2024-35690 MEDIUM - 6.5

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.

Vendor: MarketingFire
Product: Widget Options
Published: Jun 17, 2026
Source: NVD
CVE-2024-35648 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.

Vendor: Andy Moyle
Product: Emergency Password Reset
Published: Jun 17, 2026
Source: NVD
CVE-2024-34810 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

Vendor: Extend Themes
Product: Skyline WP
Published: Jun 17, 2026
Source: NVD
CVE-2024-33909 MEDIUM - 5.3

Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.

Vendor: Avirtum
Product: iPages Flipbook
Published: Jun 17, 2026
Source: NVD
CVE-2024-33685 MEDIUM - 4.3

Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.

Vendor: Jegstudio
Product: Startupzy
Published: Jun 17, 2026
Source: NVD
CVE-2024-32949 HIGH - 8.3

Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8.

Vendor: Prince
Product: Integrate Google Drive
Published: Jun 17, 2026
Source: NVD
CVE-2024-32729 HIGH - 7.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.

Vendor: QuantumCloud
Product: Conversational Forms for ChatBot
Published: Jun 17, 2026
Source: NVD
CVE-2024-31435 MEDIUM - 4.3

: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6.

Vendor: Inisev
Product: Social Media & Share Icons
Published: Jun 17, 2026
Source: NVD
CVE-2024-24709 MEDIUM - 4.3

Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11.

Vendor: Shareaholic
Product: Shareaholic
Published: Jun 17, 2026
Source: NVD
CVE-2026-48776 MEDIUM - 4.2

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource ope...

Vendor: langchain-ai
Product: langchain-ai, langchain-sdk
Published: Jun 17, 2026
Source: NVD