Total CVEs

136,950

Critical Severity

3,261

High Severity

12,142

Last 7 Days

1,875
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 33,355 CVEs

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial of service. HP is releasing software updates to mitigate these potential vulnerabilities.

Published: Jun 15, 2026
Source: NVD
CVE-2026-48714 CRITICAL - 9.1

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did n...

Vendor: i18next
Product: i18next-http-middleware
Published: Jun 15, 2026
Source: NVD
CVE-2026-48713 CRITICAL - 9.1

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configu...

Vendor: i18next
Product: i18next-fs-backend
Published: Jun 15, 2026
Source: NVD
CVE-2026-48157 MEDIUM - 6.1

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses HttpException::setTitle() and/or setDescription() to include untrusted/request-derived data in the error title or description (e.g. "No products fou...

Vendor: slimphp
Product: Slim
Published: Jun 15, 2026
Source: NVD

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-b...

Vendor: PEVANS
Product: Socket
Published: Jun 15, 2026
Source: NVD

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

Vendor: BIAFRA
Product: Dancer2::Plugin::Auth::OAuth
Published: Jun 15, 2026
Source: NVD
CVE-2026-9691 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

Published: Jun 15, 2026
Source: NVD
CVE-2026-52703 CRITICAL - 9.6

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

Vendor: Ninja Team
Product: FastDup
Published: Jun 15, 2026
Source: NVD
CVE-2026-52702 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

Vendor: wp-buy
Product: SEO Redirection
Published: Jun 15, 2026
Source: NVD
CVE-2026-52700 HIGH - 8.5

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

Vendor: WcMultishipping โ€“ Mondial Relay & Chronopost for Wooommerce
Product: WCMultiShipping
Published: Jun 15, 2026
Source: NVD
CVE-2026-52699 HIGH - 7.5

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

Vendor: e4jvikwp
Product: VikRentCar
Published: Jun 15, 2026
Source: NVD
CVE-2026-52697 HIGH - 8.5

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

Vendor: Taskbuilder
Product: Taskbuilder
Published: Jun 15, 2026
Source: NVD
CVE-2026-52695 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

Vendor: Al Monsor
Product: ABC Crypto Checkout
Published: Jun 15, 2026
Source: NVD
CVE-2026-52694 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

Vendor: WP E-Signature
Product: Signature Add-On for WooCommerce
Published: Jun 15, 2026
Source: NVD
CVE-2026-52693 CRITICAL - 9.3

Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

Vendor: impleCode
Product: eCommerce Product Catalog
Published: Jun 15, 2026
Source: NVD
CVE-2026-52692 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

Vendor: wp.insider
Product: Affiliates Manager
Published: Jun 15, 2026
Source: NVD
CVE-2026-49781 CRITICAL - 9.8

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

Vendor: Brainstorm Force
Product: OttoKit
Published: Jun 15, 2026
Source: NVD
CVE-2026-49780 HIGH - 8.8

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

Vendor: Dokan, Inc.
Product: Dokan
Published: Jun 15, 2026
Source: NVD
CVE-2026-49776 CRITICAL - 9.3

Unauthenticated SQL Injection in GPTranslate โ€“ Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.

Vendor: JExtensions Store
Product: GPTranslate โ€“ Multilingual AI Translation for WordPress: Automatically Translate Websites
Published: Jun 15, 2026
Source: NVD
CVE-2026-49775 MEDIUM - 6.5

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

Vendor: info@welcart
Product: Welcart e-Commerce
Published: Jun 15, 2026
Source: NVD