Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26990
Total
2034
Critical
8144
High
8390
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-46316 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks … | Jun 09, 2026 |
| CVE-2026-2638 | UNKNOWN | — | A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race … | Jun 09, 2026 |
| CVE-2026-11764 | UNKNOWN | — | When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the … | Jun 09, 2026 |
| CVE-2017-20251 | CRITICAL | 9.8 | WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious … | Jun 09, 2026 |
| CVE-2017-20250 | HIGH | 7.5 | Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send … | Jun 09, 2026 |
| CVE-2017-20249 | HIGH | 8.2 | Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid … | Jun 09, 2026 |
| CVE-2017-20248 | HIGH | 7.5 | Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send … | Jun 09, 2026 |
| CVE-2017-20247 | HIGH | 8.2 | WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through … | Jun 09, 2026 |
| CVE-2017-20246 | HIGH | 8.2 | KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers … | Jun 09, 2026 |
| CVE-2017-20245 | HIGH | 8.2 | Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST … | Jun 09, 2026 |
| CVE-2017-20244 | HIGH | 8.2 | Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST … | Jun 09, 2026 |
| CVE-2017-20243 | HIGH | 8.2 | WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting … | Jun 09, 2026 |
| CVE-2016-20065 | HIGH | 8.2 | Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code … | Jun 09, 2026 |
| CVE-2016-20064 | MEDIUM | 6.2 | WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include … | Jun 09, 2026 |
| CVE-2016-20063 | HIGH | 7.1 | Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message … | Jun 09, 2026 |
| CVE-2016-20062 | HIGH | 8.2 | Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the … | Jun 09, 2026 |
| CVE-2026-49742 | UNKNOWN | — | Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. … | Jun 09, 2026 |
| CVE-2026-49741 | UNKNOWN | — | Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the … | Jun 09, 2026 |
| CVE-2026-49740 | UNKNOWN | — | TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the … | Jun 09, 2026 |
| CVE-2026-49738 | UNKNOWN | — | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be … | Jun 09, 2026 |
| CVE-2026-47352 | UNKNOWN | — | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted … | Jun 09, 2026 |
| CVE-2026-47351 | UNKNOWN | — | Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information … | Jun 09, 2026 |
| CVE-2026-47350 | UNKNOWN | — | Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions … | Jun 09, 2026 |
| CVE-2026-47349 | UNKNOWN | — | Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. … | Jun 09, 2026 |
| CVE-2026-47348 | UNKNOWN | — | Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index … | Jun 09, 2026 |