Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26990
Total
2034
Critical
8144
High
8390
Medium
CVE ID Severity Score Description Published
CVE-2026-46316 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks … Jun 09, 2026
CVE-2026-2638 UNKNOWN A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race … Jun 09, 2026
CVE-2026-11764 UNKNOWN When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the … Jun 09, 2026
CVE-2017-20251 CRITICAL 9.8 WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious … Jun 09, 2026
CVE-2017-20250 HIGH 7.5 Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send … Jun 09, 2026
CVE-2017-20249 HIGH 8.2 Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid … Jun 09, 2026
CVE-2017-20248 HIGH 7.5 Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send … Jun 09, 2026
CVE-2017-20247 HIGH 8.2 WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through … Jun 09, 2026
CVE-2017-20246 HIGH 8.2 KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers … Jun 09, 2026
CVE-2017-20245 HIGH 8.2 Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST … Jun 09, 2026
CVE-2017-20244 HIGH 8.2 Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST … Jun 09, 2026
CVE-2017-20243 HIGH 8.2 WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting … Jun 09, 2026
CVE-2016-20065 HIGH 8.2 Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code … Jun 09, 2026
CVE-2016-20064 MEDIUM 6.2 WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include … Jun 09, 2026
CVE-2016-20063 HIGH 7.1 Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message … Jun 09, 2026
CVE-2016-20062 HIGH 8.2 Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the … Jun 09, 2026
CVE-2026-49742 UNKNOWN Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. … Jun 09, 2026
CVE-2026-49741 UNKNOWN Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the … Jun 09, 2026
CVE-2026-49740 UNKNOWN TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the … Jun 09, 2026
CVE-2026-49738 UNKNOWN The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be … Jun 09, 2026
CVE-2026-47352 UNKNOWN Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted … Jun 09, 2026
CVE-2026-47351 UNKNOWN Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information … Jun 09, 2026
CVE-2026-47350 UNKNOWN Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions … Jun 09, 2026
CVE-2026-47349 UNKNOWN Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. … Jun 09, 2026
CVE-2026-47348 UNKNOWN Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index … Jun 09, 2026