Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,941 - 1,960 of 35,345 CVEs
CVE-2026-54198 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.

Vendor: David Lingren
Product: Media LIbrary Assistant
Published: Jun 16, 2026
Source: NVD
CVE-2026-54197 MEDIUM - 6.5

Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

Vendor: Wpmet
Product: GetGenie
Published: Jun 16, 2026
Source: NVD
CVE-2026-54191 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.

Vendor: Pods Framework
Product: Pods
Published: Jun 16, 2026
Source: NVD
CVE-2026-54190 MEDIUM - 6.5

Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

Vendor: Awesomemotive
Product: Envira Photo Gallery
Published: Jun 16, 2026
Source: NVD
CVE-2026-52715 CRITICAL - 9.3

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

Vendor: Eyal Fitoussi
Product: GEO my WordPress
Published: Jun 16, 2026
Source: NVD
CVE-2026-52714 MEDIUM - 5.9

Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.

Vendor: SEO Squirrly
Product: SEO Plugin by Squirrly SEO
Published: Jun 16, 2026
Source: NVD
CVE-2026-52712 HIGH - 7.6

Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.

Vendor: tnomi
Product: Attendance Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-52711 HIGH - 7.5

Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

Vendor: kilbot
Product: WooCommerce POS
Published: Jun 16, 2026
Source: NVD
CVE-2026-49774 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.

Vendor: Filipe Nasc
Product: RD Station
Published: Jun 16, 2026
Source: NVD
CVE-2026-49772 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

Vendor: Liquid Web / StellarWP
Product: The Events Calendar
Published: Jun 16, 2026
Source: NVD
CVE-2026-40809 MEDIUM - 6.5

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.

Vendor: Rara Themes
Product: Metro Magazine
Published: Jun 16, 2026
Source: NVD
CVE-2026-39581 HIGH - 8.5

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

Vendor: activity-log.com
Product: WP Sessions Time Monitoring Full Automatic
Published: Jun 16, 2026
Source: NVD
CVE-2026-39574 CRITICAL - 9.3

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

Vendor: RealMag777
Product: InPost Gallery
Published: Jun 16, 2026
Source: NVD
CVE-2026-39490 HIGH - 7.5

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

Vendor: artbees
Product: JupiterX Core
Published: Jun 16, 2026
Source: NVD
CVE-2026-39437 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.

Vendor: WPFactory
Product: Min Max Step Quantity Limits Manager for WooCommerce
Published: Jun 16, 2026
Source: NVD
CVE-2026-2381 MEDIUM - 6.5

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when...

Published: Jun 16, 2026
Source: NVD

A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device reboot.

Vendor: Moxa
Product: NPort 6000-G2 Series
Published: Jun 16, 2026
Source: NVD
CVE-2025-68045 HIGH - 7.5

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

Vendor: Arraytics
Product: WP Event SOlution
Published: Jun 16, 2026
Source: NVD
CVE-2026-8444 HIGH - 8.8

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type ca...

Published: Jun 16, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the hint does not account for the runtime hea...

Vendor: Linux
Product: Linux
Published: Jun 16, 2026
Source: NVD