Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25897
Total
1938
Critical
7913
High
8158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13437 | MEDIUM | 6.5 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent … | Jun 29, 2026 |
| CVE-2026-57525 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jun 29, 2026 |
| CVE-2026-57523 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jun 29, 2026 |
| CVE-2026-57341 | MEDIUM | 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions. | Jun 29, 2026 |
| CVE-2026-57340 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. | Jun 29, 2026 |
| CVE-2026-57339 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. | Jun 29, 2026 |
| CVE-2026-57338 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | Jun 29, 2026 |
| CVE-2026-57337 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | Jun 29, 2026 |
| CVE-2026-57336 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions. | Jun 29, 2026 |
| CVE-2026-57335 | MEDIUM | 6.5 | Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions. | Jun 29, 2026 |
| CVE-2026-57334 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | Jun 29, 2026 |
| CVE-2026-57333 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. | Jun 29, 2026 |
| CVE-2026-57332 | HIGH | 7.1 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | Jun 29, 2026 |
| CVE-2026-57331 | CRITICAL | 9.9 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. | Jun 29, 2026 |
| CVE-2026-57330 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions. | Jun 29, 2026 |
| CVE-2026-57329 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions. | Jun 29, 2026 |
| CVE-2026-57328 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | Jun 29, 2026 |
| CVE-2026-57327 | MEDIUM | 6.3 | Subscriber Broken Access Control in MainWP <= 6.1.1 versions. | Jun 29, 2026 |
| CVE-2026-57326 | MEDIUM | 6.1 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | Jun 29, 2026 |
| CVE-2026-57320 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions. | Jun 29, 2026 |
| CVE-2026-56290 | UNKNOWN | — | The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | Jun 29, 2026 |
| CVE-2026-56124 | HIGH | 7.5 | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting … | Jun 29, 2026 |
| CVE-2026-55844 | HIGH | 7.5 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID … | Jun 29, 2026 |
| CVE-2026-55607 | UNKNOWN | — | Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees … | Jun 29, 2026 |
| CVE-2026-49049 | HIGH | 7.5 | The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template … | Jun 29, 2026 |