Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1,961 - 1,980 of 35,345 CVEs
CVE-2026-10093 MEDIUM - 6.4

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Vendor: deepakkite
Product: Secure Client Portal and Private File Sharing Plugin – User Private Files
Published: Jun 16, 2026
Source: NVD
CVE-2025-9912 MEDIUM - 6.3

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

Published: Jun 16, 2026
Source: NVD
CVE-2026-9187 MEDIUM - 5.3

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_re...

Published: Jun 16, 2026
Source: NVD
CVE-2026-8443 HIGH - 8.8

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strin...

Published: Jun 16, 2026
Source: NVD
CVE-2026-6933 HIGH - 8.8

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processing user-supplied POST data, combined with th...

Published: Jun 16, 2026
Source: NVD
CVE-2026-5149 MEDIUM - 6.5

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it pos...

Published: Jun 16, 2026
Source: NVD
CVE-2026-50255 MEDIUM - 6.7

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges.

Vendor: Sony Corporation
Product: Optical Disc Archive Software for Windows
Published: Jun 16, 2026
Source: NVD
CVE-2026-10780 MEDIUM - 4.3

The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_...

Vendor: mohammadtanzilurrahman
Product: Static Block
Published: Jun 16, 2026
Source: NVD
CVE-2026-10635 MEDIUM - 6.3

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded inside the caller-owned struct k_mem_domain. When a domain is destroyed via k_mem_domain_de...

Vendor: zephyrproject
Product: zephyr
Published: Jun 16, 2026
Source: NVD
CVE-2025-10262 MEDIUM - 6.3

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privileges.

Vendor: Nokia
Product: SR Linux
Published: Jun 16, 2026
Source: NVD
CVE-2026-6964 MEDIUM - 5.3

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain the...

Published: Jun 16, 2026
Source: NVD
CVE-2026-7273 HIGH - 8.8

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions throughΒ 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Published: Jun 16, 2026
Source: NVD
CVE-2026-42014 MEDIUM - 6.6

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jun 16, 2026
Source: NVD
CVE-2026-1767 MEDIUM - 5.6

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calcula...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1766 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker co...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-1765 MEDIUM - 5.6

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Deni...

Published: Jun 16, 2026
Source: NVD
CVE-2026-1764 MEDIUM - 5.6

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attac...

Vendor: gnome
Product: localsearch
Published: Jun 16, 2026
Source: NVD
CVE-2026-12162 MEDIUM - 5.5

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-12161 HIGH - 8.8

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted altern...

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 16, 2026
Source: NVD
CVE-2026-9262 MEDIUM - 6.5

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Vendor: canon
Product: eos_network_setting_tool
Published: Jun 16, 2026
Source: NVD