Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26391
Total
1955
Critical
7971
High
8223
Medium
CVE ID Severity Score Description Published
CVE-2026-39581 HIGH 8.5 Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. Jun 16, 2026
CVE-2026-39574 CRITICAL 9.3 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. Jun 16, 2026
CVE-2026-39490 HIGH 7.5 Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions. Jun 16, 2026
CVE-2026-39437 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions. Jun 16, 2026
CVE-2026-2381 MEDIUM 6.5 The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function … Jun 16, 2026
CVE-2026-10825 UNKNOWN A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially … Jun 16, 2026
CVE-2025-68045 HIGH 7.5 Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. Jun 16, 2026
CVE-2026-8444 HIGH 8.8 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up … Jun 16, 2026
CVE-2026-46331 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range … Jun 16, 2026
CVE-2026-10093 MEDIUM 6.4 The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all … Jun 16, 2026
CVE-2025-9912 MEDIUM 6.3 Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands … Jun 16, 2026
CVE-2026-9187 MEDIUM 5.3 The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due … Jun 16, 2026
CVE-2026-8443 HIGH 8.8 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in … Jun 16, 2026
CVE-2026-6933 HIGH 8.8 The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is … Jun 16, 2026
CVE-2026-5149 MEDIUM 6.5 The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX … Jun 16, 2026
CVE-2026-50255 MEDIUM 6.7 Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed … Jun 16, 2026
CVE-2026-10780 MEDIUM 4.3 The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to … Jun 16, 2026
CVE-2026-10635 MEDIUM 6.3 On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded … Jun 16, 2026
CVE-2025-10262 MEDIUM 6.3 Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user … Jun 16, 2026
CVE-2026-6964 MEDIUM 5.3 The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to … Jun 16, 2026
CVE-2026-7273 HIGH 8.8 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the … Jun 16, 2026
CVE-2026-42014 MEDIUM 6.6 A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when … Jun 16, 2026
CVE-2026-1767 MEDIUM 5.6 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow … Jun 16, 2026
CVE-2026-1766 MEDIUM 5.6 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when … Jun 16, 2026
CVE-2026-1765 MEDIUM 5.6 A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially … Jun 16, 2026