Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,007
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,261 - 1,280 of 13,004 CVEs
CVE-2026-9008 MEDIUM - 4.3

The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() function (the [pagelist_ext] / [pagelistext] shortcode) accepting attacker-controlled post_status, post_type, and show_meta_key att...

Published: Jun 06, 2026
Source: NVD
CVE-2026-9719 MEDIUM - 4.3

The LatePoint โ€“ Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the change_status function. This makes it possible for unauthentic...

Published: Jun 06, 2026
Source: NVD
CVE-2026-8976 MEDIUM - 4.3

The RSS Aggregator by Feedzy โ€“ Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action...

Published: Jun 06, 2026
Source: NVD
CVE-2026-8900 MEDIUM - 6.4

The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acces...

Published: Jun 06, 2026
Source: NVD
CVE-2026-8893 MEDIUM - 6.4

The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up to, and including, 1.28.0. This is due to insufficient input sanitization and output escaping on the shortcode attribut...

Published: Jun 06, 2026
Source: NVD
CVE-2026-8608 MEDIUM - 5.3

The Event Monster โ€“ Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusting c...

Published: Jun 06, 2026
Source: NVD
CVE-2026-7047 MEDIUM - 4.3

The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes it possible for unauthenticated attackers to trick a logged-in...

Published: Jun 06, 2026
Source: NVD
CVE-2026-6448 MEDIUM - 4.9

The Quiz and Survey Master (QSM) โ€“ Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...

Published: Jun 06, 2026
Source: NVD
CVE-2026-10038 MEDIUM - 4.3

The Charitable โ€“ Donation Plugin for WordPress โ€“ Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / Authorization Bypass leading to Arbitrary Attachment Deletion in versions up to, and including, 1.8.11.1 via the profile avatar up...

Vendor: smub
Product: Charitable โ€“ Donation Plugin for WordPress โ€“ Fundraising with Recurring Donations & More
Published: Jun 06, 2026
Source: NVD
CVE-2026-7523 MEDIUM - 4.3

The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and...

Published: Jun 05, 2026
Source: NVD
CVE-2026-46397 MEDIUM - 6.5

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary files on the server by manipulating the location field written int...

Vendor: haxtheweb
Product: haxcms-php, haxcms-nodejs
Published: Jun 05, 2026
Source: NVD
CVE-2026-45778 MEDIUM - 5.4

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD user profile and abuse the password reset functionality to email a link to an HTML page, which when visited by the victim,...

Vendor: ubccr
Product: xdmod
Published: Jun 05, 2026
Source: NVD
CVE-2026-45776 MEDIUM - 4.3

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request that sets a session variable used for authorization decisions. If an installation of Open XDMoD...

Vendor: ubccr
Product: xdmod
Published: Jun 05, 2026
Source: NVD
CVE-2026-25624 MEDIUM - 5.7

An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processi...

Vendor: Arista Networks
Product: Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Published: Jun 05, 2026
Source: NVD
CVE-2026-25623 MEDIUM - 6.0

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators can leverage this exposure to obtain underlying terminal script code processing execution permissions.

Vendor: Arista Networks
Product: Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Published: Jun 05, 2026
Source: NVD
CVE-2026-25622 MEDIUM - 6.0

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform she...

Vendor: Arista Networks
Product: Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Published: Jun 05, 2026
Source: NVD
CVE-2026-25621 MEDIUM - 6.0

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

Vendor: Arista Networks
Product: Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Published: Jun 05, 2026
Source: NVD
CVE-2026-25620 MEDIUM - 6.0

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

Vendor: Arista Networks
Product: Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Published: Jun 05, 2026
Source: NVD
CVE-2026-2379 MEDIUM - 5.9

On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security Associations, resulting ...

Published: Jun 05, 2026
Source: NVD
CVE-2026-11341 MEDIUM - 6.3

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.

Vendor: D-Link
Product: DWR-M920
Published: Jun 05, 2026
Source: NVD