Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,624
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 141 - 160 of 35,133 CVEs

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verif...

Vendor: Apache Software Foundation
Product: Apache NiFi
Published: Jun 22, 2026
Source: NVD
CVE-2025-66336 HIGH - 8.1

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anony...

Vendor: Apache Software Foundation
Product: Apache Doris MCP Server
Published: Jun 22, 2026
Source: NVD
CVE-2025-62198 MEDIUM - 5.4

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Atlas
Published: Jun 22, 2026
Source: NVD
CVE-2026-8157 HIGH - 8.8

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.

Published: Jun 22, 2026
Source: NVD
CVE-2026-7859 MEDIUM - 5.3

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

Published: Jun 22, 2026
Source: NVD
CVE-2026-6858 HIGH - 7.1

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator

Published: Jun 22, 2026
Source: NVD
CVE-2026-4259 HIGH - 7.1

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Published: Jun 22, 2026
Source: NVD
CVE-2026-4110 MEDIUM - 6.1

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Published: Jun 22, 2026
Source: NVD
CVE-2026-10530 MEDIUM - 5.3

The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.

Vendor: Unknown
Product: Pie Register
Published: Jun 22, 2026
Source: NVD

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system uti...

Published: Jun 22, 2026
Source: NVD

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate Appย ' section on the ASUS Security ...

Published: Jun 22, 2026
Source: NVD

A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the ...

Vendor: LY Corporation
Product: Central Dogma
Published: Jun 22, 2026
Source: NVD

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper en...

Vendor: LY Corporation
Product: Central Dogma
Published: Jun 22, 2026
Source: NVD

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories.

Vendor: LY Corporation
Product: Central Dogma
Published: Jun 22, 2026
Source: NVD

A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may...

Product: Browserbase
Published: Jun 22, 2026
Source: NVD
CVE-2026-12822 MEDIUM - 5.3

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. The vendor was contacted early about this disclosure but did not respond in any...

Vendor: langflow-ai
Product: langflow
Published: Jun 22, 2026
Source: NVD
CVE-2026-12821 MEDIUM - 6.3

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack re...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 22, 2026
Source: NVD
CVE-2026-12815 MEDIUM - 6.3

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any w...

Vendor: coollabsio
Product: coolify
Published: Jun 22, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 21, 2026
Source: NVD
CVE-2026-12814 MEDIUM - 6.3

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endpoint. This manipulation of the argument destination causes os command injection. The attack is possible to be carried out...

Vendor: Comfast
Product: CF-WR631AX V3
Published: Jun 21, 2026
Source: NVD