Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,386
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 81 - 100 of 3,181 CVEs
CVE-2026-38812 CRITICAL - 9.8

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.

Published: Jun 15, 2026
Source: NVD
CVE-2026-38329 CRITICAL - 9.8

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a malicious PHP script and ...

Published: Jun 15, 2026
Source: NVD
CVE-2026-38065 CRITICAL - 9.8

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

Published: Jun 15, 2026
Source: NVD
CVE-2026-38064 CRITICAL - 9.8

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.

Published: Jun 15, 2026
Source: NVD
CVE-2026-38063 CRITICAL - 9.8

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.

Published: Jun 15, 2026
Source: NVD
CVE-2026-38062 CRITICAL - 9.8

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.

Published: Jun 15, 2026
Source: NVD
CVE-2026-38061 CRITICAL - 9.8

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

Published: Jun 15, 2026
Source: NVD
CVE-2026-38060 CRITICAL - 9.8

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.

Published: Jun 15, 2026
Source: NVD
CVE-2026-36537 CRITICAL - 9.8

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote at...

Published: Jun 15, 2026
Source: NVD
CVE-2026-30121 CRITICAL - 9.1

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

Published: Jun 15, 2026
Source: NVD
CVE-2026-30120 CRITICAL - 9.8

remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.

Published: Jun 15, 2026
Source: NVD
CVE-2026-53633 CRITICAL - 9.8

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

Vendor: npm
Product: @vitest/browser
Published: Jun 15, 2026
Source: GitHub
CVE-2026-9862 CRITICAL - 9.8

Fortra'sย  Core Privileged Access Manager (BoKS)ย contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration proc...

Published: Jun 15, 2026
Source: NVD
CVE-2026-52704 CRITICAL - 10.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.

Vendor: Edgar Rojas
Product: WooCommerce PDF Invoice Builder
Published: Jun 15, 2026
Source: NVD
CVE-2018-25436 CRITICAL - 9.8

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload ...

Vendor: Shipster
Product: Baggage Freight Shipping Australia
Published: Jun 15, 2026
Source: NVD
CVE-2026-8935 CRITICAL - 9.8

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

Published: Jun 15, 2026
Source: NVD
CVE-2026-11526 CRITICAL - 9.8

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "c...

Vendor: RURBAN
Product: GD
Published: Jun 14, 2026
Source: NVD
CVE-2026-12183 CRITICAL - 9.8

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that suppli...

Vendor: Nefteprodukttekhnika LLC
Product: BUK TS-G Gas Station Automation System
Published: Jun 13, 2026
Source: NVD
CVE-2026-53838 CRITICAL - 9.8

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restriction...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53609 CRITICAL - 9.1

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.prototype` via the `$pullAll` patch operator...

Vendor: apostrophecms
Product: apostrophe
Published: Jun 12, 2026
Source: NVD