Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,007
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,081 - 1,100 of 34,990 CVEs
CVE-2025-49403 HIGH - 7.5

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

Vendor: AA-Team
Product: Premium Age Verification / Restriction for WordPress
Published: Jun 17, 2026
Source: NVD
CVE-2025-48643 HIGH - 7.8

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48640 HIGH - 8.0

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48617 HIGH - 7.8

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-48571 MEDIUM - 4.3

In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2025-31013 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6.

Vendor: Themify
Product: Themify Folo
Published: Jun 17, 2026
Source: NVD

Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,. * Pr...

Vendor: Netskope
Product: Netskope Client
Published: Jun 17, 2026
Source: NVD

Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti...

Vendor: Netskope
Product: Netskope Client
Published: Jun 17, 2026
Source: NVD
CVE-2024-52488 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

Vendor: Zidithemes
Product: Grip
Published: Jun 17, 2026
Source: NVD
CVE-2024-49269 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

Vendor: Mythemes
Product: my flatonica
Published: Jun 17, 2026
Source: NVD
CVE-2024-37496 MEDIUM - 4.3

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.

Vendor: Rara Themes
Product: Metro Magazine
Published: Jun 17, 2026
Source: NVD
CVE-2024-37210 MEDIUM - 6.5

Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

Vendor: ali2woo
Product: AliNext
Published: Jun 17, 2026
Source: NVD
CVE-2024-35690 MEDIUM - 6.5

Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.

Vendor: MarketingFire
Product: Widget Options
Published: Jun 17, 2026
Source: NVD
CVE-2024-35648 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.

Vendor: Andy Moyle
Product: Emergency Password Reset
Published: Jun 17, 2026
Source: NVD
CVE-2024-34810 MEDIUM - 4.3

Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

Vendor: Extend Themes
Product: Skyline WP
Published: Jun 17, 2026
Source: NVD
CVE-2024-33909 MEDIUM - 5.3

Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.

Vendor: Avirtum
Product: iPages Flipbook
Published: Jun 17, 2026
Source: NVD
CVE-2024-33685 MEDIUM - 4.3

Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.

Vendor: Jegstudio
Product: Startupzy
Published: Jun 17, 2026
Source: NVD
CVE-2024-32949 HIGH - 8.3

Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8.

Vendor: Prince
Product: Integrate Google Drive
Published: Jun 17, 2026
Source: NVD
CVE-2024-32729 HIGH - 7.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.

Vendor: QuantumCloud
Product: Conversational Forms for ChatBot
Published: Jun 17, 2026
Source: NVD
CVE-2024-31435 MEDIUM - 4.3

: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6.

Vendor: Inisev
Product: Social Media & Share Icons
Published: Jun 17, 2026
Source: NVD