Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,958
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 101 - 120 of 12,906 CVEs
CVE-2026-12093 MEDIUM - 5.3

The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary ...

Vendor: wpinsider-1
Product: Simple Membership
Published: Jun 18, 2026
Source: NVD
CVE-2026-11784 MEDIUM - 4.3

The Optimole โ€“ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file function. This ma...

Vendor: optimole
Product: Optimole โ€“ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
Published: Jun 18, 2026
Source: NVD
CVE-2026-11777 MEDIUM - 4.9

The Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficie...

Vendor: 10web
Product: Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-11776 MEDIUM - 4.9

The Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of suff...

Vendor: 10web
Product: Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-11402 MEDIUM - 6.4

The Services Section Block โ€“ Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possib...

Vendor: bplugins
Product: Services Section Block โ€“ Showcase Service Details in Grid or Columns
Published: Jun 18, 2026
Source: NVD
CVE-2026-11360 MEDIUM - 4.9

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existi...

Vendor: algolplus
Product: Advanced Order Export For WooCommerce
Published: Jun 18, 2026
Source: NVD
CVE-2026-11358 MEDIUM - 4.4

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it po...

Vendor: themeisle
Product: Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
Published: Jun 18, 2026
Source: NVD
CVE-2026-11357 MEDIUM - 4.3

The Kadence Blocks โ€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with contributor-level access and above...

Vendor: stellarwp
Product: Kadence Blocks โ€” Page Builder Toolkit for Gutenberg Editor
Published: Jun 18, 2026
Source: NVD
CVE-2026-10736 MEDIUM - 4.9

The Tutor LMS โ€“ eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...

Vendor: themeum
Product: Tutor LMS โ€“ eLearning and online course solution
Published: Jun 18, 2026
Source: NVD
CVE-2026-10623 MEDIUM - 4.3

The PressPrimer Quiz โ€“ AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it po...

Vendor: pressprimer
Product: PressPrimer Quiz โ€“ AI Quiz Maker, Exam Builder & LMS Assessment Plugin
Published: Jun 18, 2026
Source: NVD
CVE-2026-10029 MEDIUM - 5.3

The Event Koi Lite โ€“ Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including v...

Vendor: eventkoi
Product: Event Koi Lite โ€“ Events Calendar, Event Management, RSVP, and Tickets
Published: Jun 18, 2026
Source: NVD
CVE-2026-10023 MEDIUM - 4.3

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ€“ Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_track...

Vendor: dokaninc
Product: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ€“ Build Your Own Amazon, eBay, Etsy
Published: Jun 18, 2026
Source: NVD
CVE-2026-50267 MEDIUM - 4.7

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors libra...

Vendor: SteeltoeOSS
Product: Steeltoe.Configuration.Abstractions
Published: Jun 17, 2026
Source: NVD
CVE-2026-50202 MEDIUM - 5.9

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentic...

Vendor: SteeltoeOSS
Product: Steeltoe.Security.Authentication.CloudFoundryBase, Steeltoe.Security.Authentication.JwtBearer, Steeltoe.Security.Authentication.OpenIdConnect
Published: Jun 17, 2026
Source: NVD
CVE-2026-50201 MEDIUM - 6.5

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPermiss...

Vendor: SteeltoeOSS
Product: Steeltoe.Management.Endpoint, Steeltoe.Management.EndpointBase
Published: Jun 17, 2026
Source: NVD
CVE-2026-12568 MEDIUM - 6.5

The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker t...

Vendor: Black Lantern Security
Product: BBOT
Published: Jun 17, 2026
Source: NVD
CVE-2026-12565 MEDIUM - 5.3

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extra...

Vendor: Black Lantern Security
Product: BBOT
Published: Jun 17, 2026
Source: NVD
CVE-2026-8049 MEDIUM - 5.3

In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly permissive default access control, allowing any authenticated local user to obtain a handle to the device and iss...

Published: Jun 17, 2026
Source: NVD
CVE-2026-54386 MEDIUM - 6.1

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Atta...

Vendor: marimo-team
Product: marimo
Published: Jun 17, 2026
Source: NVD
CVE-2026-48991 MEDIUM - 5.5

XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or state validation. Explo...

Vendor: XianYuLauncher
Product: XianYuLauncher
Published: Jun 17, 2026
Source: NVD