Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48613 | MEDIUM | 5.9 | SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. … | Jun 12, 2026 |
| CVE-2026-48612 | HIGH | 8.0 | Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to … | Jun 12, 2026 |
| CVE-2026-48611 | CRITICAL | 9.8 | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations. | Jun 12, 2026 |
| CVE-2026-48610 | HIGH | 8.1 | Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS … | Jun 12, 2026 |
| CVE-2026-47370 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS … | Jun 12, 2026 |
| CVE-2026-47369 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS … | Jun 12, 2026 |
| CVE-2026-47368 | HIGH | 8.6 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from … | Jun 12, 2026 |
| CVE-2026-47367 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute … | Jun 12, 2026 |
| CVE-2026-47366 | HIGH | 7.2 | Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized … | Jun 12, 2026 |
| CVE-2026-47365 | CRITICAL | 9.9 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary … | Jun 12, 2026 |
| CVE-2026-20746 | UNKNOWN | — | Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled … | Jun 12, 2026 |
| CVE-2026-9125 | MEDIUM | 6.4 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and … | Jun 12, 2026 |
| CVE-2026-45170 | UNKNOWN | — | Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 | Jun 12, 2026 |
| CVE-2026-11933 | HIGH | 8.8 | A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is … | Jun 12, 2026 |
| CVE-2026-49482 | MEDIUM | 4.3 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters … | Jun 12, 2026 |
| CVE-2026-10676 | UNKNOWN | — | Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis determined that the addressed defect is not reachable in any … | Jun 12, 2026 |
| CVE-2026-47238 | MEDIUM | 6.5 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles … | Jun 11, 2026 |
| CVE-2026-45418 | HIGH | 8.8 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple … | Jun 11, 2026 |
| CVE-2026-45060 | CRITICAL | 9.8 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any … | Jun 11, 2026 |
| CVE-2026-42846 | CRITICAL | 9.8 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add … | Jun 11, 2026 |
| CVE-2026-6250 | UNKNOWN | — | An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is … | Jun 11, 2026 |
| CVE-2026-49060 | CRITICAL | 9.8 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4. | Jun 11, 2026 |
| CVE-2026-45174 | UNKNOWN | — | Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | Jun 11, 2026 |
| CVE-2026-45173 | UNKNOWN | — | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If … | Jun 11, 2026 |
| CVE-2026-45172 | UNKNOWN | — | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user … | Jun 11, 2026 |