Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,881 - 1,900 of 34,868 CVEs
CVE-2026-5038 MEDIUM - 5.3

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underl...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD
CVE-2026-10634 MEDIUM - 4.8

Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connection callback a...

Vendor: zephyrproject
Product: zephyr
Published: Jun 15, 2026
Source: NVD
CVE-2025-15659 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.

Vendor: liseperu
Product: Elizaibots
Published: Jun 15, 2026
Source: NVD
CVE-2025-15658 MEDIUM - 5.9

Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.

Vendor: rewish
Product: WP Emmet
Published: Jun 15, 2026
Source: NVD

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub
CVE-2026-6517 MEDIUM - 6.3

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded to in the Mattermost Desktop App which allows any user on a server without the image proxy enabled to intercept other users credentials via embedding an image that ro...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD
CVE-2026-5242 HIGH - 8.8

Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5233 HIGH - 7.1

Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5230 HIGH - 7.1

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

Published: Jun 15, 2026
Source: NVD
CVE-2026-5079 HIGH - 7.5

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of dee...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD
CVE-2026-52704 CRITICAL - 10.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.

Vendor: Edgar Rojas
Product: WooCommerce PDF Invoice Builder
Published: Jun 15, 2026
Source: NVD
CVE-2026-49111 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

Vendor: ThemeGrill
Product: Masteriyo - LMS
Published: Jun 15, 2026
Source: NVD
CVE-2026-49064 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

Vendor: Stiofan
Product: GetPaid
Published: Jun 15, 2026
Source: NVD
CVE-2026-49062 HIGH - 8.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

Vendor: WP Engine
Product: Faust.js
Published: Jun 15, 2026
Source: NVD
CVE-2026-48969 MEDIUM - 6.5

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

Vendor: Really Simple Plugins B.V.
Product: Really Simple SSL
Published: Jun 15, 2026
Source: NVD
CVE-2025-64215 MEDIUM - 6.5

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.

Vendor: StylemixThemes
Product: MasterStudy LMS Pro
Published: Jun 15, 2026
Source: NVD
CVE-2019-25746 HIGH - 7.1

WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_inv...

Vendor: SlicedInvoices
Product: Sliced Invoices
Published: Jun 15, 2026
Source: NVD
CVE-2018-25437 HIGH - 7.5

WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management di...

Vendor: Cherryframework
Product: Cherry Framework Themes
Published: Jun 15, 2026
Source: NVD
CVE-2018-25436 CRITICAL - 9.8

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload ...

Vendor: Shipster
Product: Baggage Freight Shipping Australia
Published: Jun 15, 2026
Source: NVD
CVE-2016-20084 HIGH - 7.2

WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript i...

Vendor: dwbooster
Product: Booking Calendar Contact
Published: Jun 15, 2026
Source: NVD