Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
Showing 1,661 - 1,680 of 12,883 CVEs
CVE-2026-8901 HIGH - 7.2

The Integration for Freshsales โ€“ Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes i...

Published: Jun 06, 2026
Source: NVD
CVE-2026-8438 HIGH - 7.2

The All-In-One Security (AIOS) โ€“ Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output escaping in the column_default() method o...

Published: Jun 06, 2026
Source: NVD
CVE-2026-9290 HIGH - 7.5

The WP User Manager โ€“ User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php fi...

Published: Jun 06, 2026
Source: NVD
CVE-2026-7654 HIGH - 8.8

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` function, which pro...

Published: Jun 05, 2026
Source: NVD
CVE-2026-11416 HIGH - 8.1

MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured download directory with a filename taken directly from remote cloud API metadata without basename normali...

Vendor: jxxghp
Product: MoviePilot
Published: Jun 05, 2026
Source: NVD

Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points

Vendor: composer
Product: twig/twig
Published: Jun 05, 2026
Source: GitHub
CVE-2026-36785 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 05, 2026
Source: NVD
CVE-2026-11422 HIGH - 7.1

Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers c...

Vendor: shd101wyy
Product: Markdown Preview Enhanced, crossnote
Published: Jun 05, 2026
Source: NVD
CVE-2026-47743 HIGH - 8.7

Shopper: Multiple data integrity and disclosure issues in admin Livewire components

Vendor: composer
Product: shopper/framework
Published: Jun 05, 2026
Source: GitHub
CVE-2026-46493 HIGH - 7.5

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes the issue.

Vendor: haxtheweb
Product: haxcms-php
Published: Jun 05, 2026
Source: NVD
CVE-2026-11401 HIGH - 8.0

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the acto...

Vendor: AWS
Product: AWS Advanced Go Wrapper
Published: Jun 05, 2026
Source: NVD
CVE-2026-11400 HIGH - 8.0

An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the ac...

Vendor: AWS
Product: AWS Advanced JDBC Wrapper
Published: Jun 05, 2026
Source: NVD
CVE-2026-5415 HIGH - 8.8

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX handler relying solely on a nonce check (check_aja...

Published: Jun 05, 2026
Source: NVD
CVE-2026-5411 HIGH - 8.8

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability check in the save_ajax() function of the licensing module, com...

Published: Jun 05, 2026
Source: NVD
CVE-2026-46392 HIGH - 8.7

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...

Vendor: haxtheweb
Product: haxcms-php
Published: Jun 05, 2026
Source: NVD
CVE-2026-50733 HIGH - 8.8

Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll(...

Vendor: shd101wyy
Product: Markdown Preview Enhanced
Published: Jun 05, 2026
Source: NVD
CVE-2026-49493 HIGH - 8.8

Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled co...

Vendor: shd101wyy
Product: Markdown Preview Enhanced
Published: Jun 05, 2026
Source: NVD
CVE-2026-49492 HIGH - 8.8

Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - the diagram filename attribute, imported file paths, and the latex_engine code-chunk attribute. On Windows, a crafted mark...

Vendor: shd101wyy
Product: Markdown Preview Enhanced
Published: Jun 05, 2026
Source: NVD
CVE-2026-45749 HIGH - 8.1

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior to version 2.3.2 accept the account password as a sole authentication factor for MFA-critical ope...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45745 HIGH - 8.0

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacker to intercept and modify HTTPS traffic to the configured Te...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD