Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,994
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,481 - 1,500 of 34,868 CVEs
CVE-2025-68045 HIGH - 7.5

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

Vendor: Arraytics
Product: WP Event SOlution
Published: Jun 16, 2026
Source: NVD
CVE-2026-8444 HIGH - 8.8

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type ca...

Published: Jun 16, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime hea...

Vendor: Linux
Product: Linux
Published: Jun 16, 2026
Source: NVD
CVE-2026-10093 MEDIUM - 6.4

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Vendor: deepakkite
Product: Secure Client Portal and Private File Sharing Plugin – User Private Files
Published: Jun 16, 2026
Source: NVD
CVE-2025-9912 MEDIUM - 6.3

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

Published: Jun 16, 2026
Source: NVD
CVE-2026-9187 MEDIUM - 5.3

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_re...

Published: Jun 16, 2026
Source: NVD
CVE-2026-8443 HIGH - 8.8

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strin...

Published: Jun 16, 2026
Source: NVD
CVE-2026-6933 HIGH - 8.8

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processing user-supplied POST data, combined with th...

Published: Jun 16, 2026
Source: NVD
CVE-2026-5149 MEDIUM - 6.5

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it pos...

Published: Jun 16, 2026
Source: NVD
CVE-2026-50255 MEDIUM - 6.7

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges.

Vendor: Sony Corporation
Product: Optical Disc Archive Software for Windows
Published: Jun 16, 2026
Source: NVD
CVE-2026-10780 MEDIUM - 4.3

The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_...

Vendor: mohammadtanzilurrahman
Product: Static Block
Published: Jun 16, 2026
Source: NVD
CVE-2026-10635 MEDIUM - 6.3

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded inside the caller-owned struct k_mem_domain. When a domain is destroyed via k_mem_domain_de...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2025-10262 MEDIUM - 6.3

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privileges.

Vendor: Nokia
Product: SR Linux
Published: Jun 16, 2026
Source: NVD
CVE-2026-6964 MEDIUM - 5.3

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the...

Published: Jun 16, 2026
Source: NVD
CVE-2026-7273 HIGH - 8.8

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions throughΒ 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Published: Jun 16, 2026
Source: NVD
CVE-2026-42014 MEDIUM - 6.6

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 16, 2026
Source: NVD
CVE-2026-1767 MEDIUM - 5.6

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calcula...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1766 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker co...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1765 MEDIUM - 5.6

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Deni...

Published: Jun 16, 2026
Source: NVD
CVE-2026-1764 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attac...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD