Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,750
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,781 - 1,800 of 13,055 CVEs
CVE-2026-46718 MEDIUM - 6.5

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Calcite
Published: Jun 02, 2026
Source: NVD
CVE-2026-41115 MEDIUM - 4.3

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This disc...

Vendor: Apache Software Foundation
Product: Apache Kafka
Published: Jun 02, 2026
Source: NVD
CVE-2025-53346 MEDIUM - 4.3

Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Core: from n/a through 2.3.3.

Vendor: ThimPress
Product: Thim Core
Published: Jun 02, 2026
Source: NVD
CVE-2025-53345 MEDIUM - 6.5

Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3.

Vendor: ThimPress
Product: Thim Core
Published: Jun 02, 2026
Source: NVD
CVE-2025-53302 MEDIUM - 5.3

Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Constructor: from n/a through 1.6.5.

Vendor: Anton Shevchuk
Product: Constructor
Published: Jun 02, 2026
Source: NVD
CVE-2025-52766 MEDIUM - 6.5

Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from n/a through 1.17.0.

Vendor: Printeers
Product: Printeers Print & Ship
Published: Jun 02, 2026
Source: NVD
CVE-2026-9730 MEDIUM - 4.3

The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9723 MEDIUM - 4.3

The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin&...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9722 MEDIUM - 4.3

The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update the plugin's set...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9599 MEDIUM - 4.3

The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, in...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9234 MEDIUM - 4.3

The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and o...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8885 MEDIUM - 6.4

The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'alig...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8422 MEDIUM - 4.3

The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated at...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4081 MEDIUM - 6.4

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'color�...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4080 MEDIUM - 6.4

The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_c...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4071 MEDIUM - 4.3

The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the ...

Published: Jun 02, 2026
Source: NVD
CVE-2026-3620 MEDIUM - 4.4

The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Admini...

Published: Jun 02, 2026
Source: NVD
CVE-2026-2425 MEDIUM - 6.1

The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

Published: Jun 02, 2026
Source: NVD
CVE-2026-2382 MEDIUM - 6.4

The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it...

Published: Jun 02, 2026
Source: NVD
CVE-2026-1451 MEDIUM - 6.1

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Published: Jun 02, 2026
Source: NVD