Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,872
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 161 - 180 of 12,881 CVEs
CVE-2026-49071 MEDIUM - 6.5

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

Vendor: OPMC
Product: WooCommerce Dropshipping
Published: Jun 17, 2026
Source: NVD
CVE-2026-48783 MEDIUM - 4.8

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose....

Vendor: gitroomhq
Product: postiz-app
Published: Jun 17, 2026
Source: NVD
CVE-2026-48782 MEDIUM - 6.8

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous fix, CVE-2026-46678, d...

Vendor: pydantic
Product: pydantic-ai, pydantic-ai-slim
Published: Jun 17, 2026
Source: NVD
CVE-2026-47340 MEDIUM - 6.5

Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-47277 MEDIUM - 6.5

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arbitrary file read through app-store logo symlinks. The path guard checks only the...

Vendor: runtipi
Product: runtipi
Published: Jun 17, 2026
Source: NVD
CVE-2026-45436 MEDIUM - 6.5

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

Vendor: Rain-Task Ltd.
Product: WPBakery Page Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-42357 MEDIUM - 6.5

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-41280 MEDIUM - 4.9

Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

Vendor: apache
Product: dolphinscheduler
Published: Jun 17, 2026
Source: NVD
CVE-2026-40724 MEDIUM - 6.5

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

Vendor: Client Portal Ltd.
Product: Client Portal (Pro)
Published: Jun 17, 2026
Source: NVD
CVE-2026-40723 MEDIUM - 4.3

Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.

Vendor: Bricks
Product: Bricks Builder
Published: Jun 17, 2026
Source: NVD
CVE-2026-40722 MEDIUM - 5.5

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.

Vendor: Yoast BV
Product: Yoast SEO Premium
Published: Jun 17, 2026
Source: NVD
CVE-2026-39595 MEDIUM - 4.7

Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.

Vendor: BoldGrid
Product: W3 Total Cache
Published: Jun 17, 2026
Source: NVD
CVE-2026-39578 MEDIUM - 5.5

Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.

Vendor: Elated-Themes
Product: Valiance
Published: Jun 17, 2026
Source: NVD
CVE-2026-39577 MEDIUM - 5.5

Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.

Vendor: Elated-Themes
Product: Playroom
Published: Jun 17, 2026
Source: NVD
CVE-2026-39433 MEDIUM - 6.5

Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.

Vendor: mojoomla
Product: WPAMS
Published: Jun 17, 2026
Source: NVD
CVE-2026-2604 MEDIUM - 5.6

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modificat...

Published: Jun 17, 2026
Source: NVD
CVE-2026-28587 MEDIUM - 5.5

In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28576 MEDIUM - 5.5

In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-28575 MEDIUM - 5.5

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. Use...

Vendor: google
Product: android
Published: Jun 17, 2026
Source: NVD
CVE-2026-27410 MEDIUM - 6.5

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

Vendor: VeronaLabs
Product: Slimstat Analytics
Published: Jun 17, 2026
Source: NVD