| CVE-2025-15658 |
WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability |
15.06.2026 |
5.9 |
| CVE-2025-15659 |
WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability |
15.06.2026 |
6.5 |
| CVE-2026-10634 |
Use-after-free in Zephyr native TCP net_tcp_foreach() due to dropping tcp_lock during the callback |
15.06.2026 |
4.8 |
| CVE-2026-5038 |
multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads |
15.06.2026 |
5.3 |
| CVE-2026-8683 |
Overly long URLs crash the Mattermost Desktop App |
15.06.2026 |
6.5 |
| CVE-2026-9595 |
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies |
15.06.2026 |
5.3 |
| CVE-2026-9862 |
Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability |
15.06.2026 |
9.8 |
| CVE-2026-9863 |
Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability |
15.06.2026 |
7.5 |
| CVE-2016-20066 |
WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting |
15.06.2026 |
|
| CVE-2016-20067 |
WordPress CP Polls 1.0.8 Cross-Site Request Forgery |
15.06.2026 |
|
| CVE-2016-20068 |
WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
15.06.2026 |
|
| CVE-2016-20069 |
WordPress Booking Calendar Contact Form 1.0.23 SQL Injection |
15.06.2026 |
|
| CVE-2016-20070 |
WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS |
15.06.2026 |
|
| CVE-2016-20071 |
WordPress 404 Redirection Manager Plugin 1.0 SQL Injection |
15.06.2026 |
|
| CVE-2016-20072 |
BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid |
15.06.2026 |
|
| CVE-2016-20073 |
Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php |
15.06.2026 |
|
| CVE-2016-20074 |
WordPress Lazy Content Slider Plugin 3.4 CSRF |
15.06.2026 |
|
| CVE-2016-20075 |
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE |
15.06.2026 |
|
| CVE-2016-20076 |
WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download |
15.06.2026 |
|
| CVE-2016-20077 |
WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php |
15.06.2026 |
|
| CVE-2016-20078 |
WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php |
15.06.2026 |
|
| CVE-2016-20079 |
WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php |
15.06.2026 |
|
| CVE-2016-20080 |
WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php |
15.06.2026 |
|
| CVE-2016-20081 |
WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download |
15.06.2026 |
|
| CVE-2016-20082 |
WordPress Plugin Abtest Local File Inclusion via abtest_admin.php |
15.06.2026 |
|
| CVE-2016-20083 |
WordPress More Fields Plugin 2.1 Cross-Site Request Forgery |
15.06.2026 |
|
| CVE-2016-20084 |
WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS |
15.06.2026 |
|
| CVE-2018-25436 |
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload |
15.06.2026 |
|
| CVE-2018-25437 |
WordPress CherryFramework Themes 3.1.4 Backup File Download |
15.06.2026 |
|
| CVE-2019-25746 |
WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter |
15.06.2026 |
|
| CVE-2025-64215 |
WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability |
15.06.2026 |
6.5 |
| CVE-2026-48969 |
WordPress Really Simple SSL plugin <= 9.5.9 - Broken Access Control vulnerability |
15.06.2026 |
6.5 |
| CVE-2026-49062 |
WordPress Faust.js plugin <= 1.8.7 - Broken Authentication vulnerability |
15.06.2026 |
8.8 |
| CVE-2026-49064 |
WordPress GetPaid plugin <= 2.8.49 - Sensitive Data Exposure vulnerability |
15.06.2026 |
7.5 |
| CVE-2026-49111 |
WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerability |
15.06.2026 |
8.8 |
| CVE-2026-52704 |
WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Remote Code Execution (RCE) vulnerability |
15.06.2026 |
10 |
| CVE-2026-5079 |
multer vulnerable to Denial of Service via deeply nested field names |
15.06.2026 |
7.5 |
| CVE-2026-5230 |
Improper Access Control in Mia Technologies' Pizzy Library |
15.06.2026 |
7.1 |
| CVE-2026-5233 |
Missing Rate Limiting in Mia Technologies' Pizzy Library |
15.06.2026 |
7.1 |
| CVE-2026-5242 |
Code Injection in Mia Technologies' Pizzy Library |
15.06.2026 |
8.8 |
| CVE-2026-6517 |
Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed |
15.06.2026 |
6.3 |
| CVE-2026-12057 |
DoS + Remote Code Execution via PDF JavaScript in Foxit AI |
15.06.2026 |
8.6 |
| CVE-2026-34021 |
Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay |
15.06.2026 |
|
| CVE-2026-34022 |
Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffic decryption |
15.06.2026 |
|
| CVE-2026-34023 |
Broken WebSocket authorization in Wertheim SafeController Software allows cross-branch access to restricted functions |
15.06.2026 |
|
| CVE-2026-34024 |
Missing authorization checks in Wertheim SafeController Software allow low-privileged users to access restricted functions |
15.06.2026 |
|
| CVE-2026-34025 |
IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations |
15.06.2026 |
|
| CVE-2026-34026 |
Path traversal in Wertheim SafeController Software allows authenticated users to download arbitrary files |
15.06.2026 |
|
| CVE-2026-34027 |
Upload restriction bypass in Wertheim SafeController Software allows authenticated users to upload arbitrary files |
15.06.2026 |
|
| CVE-2026-34028 |
Unauthenticated direct access to web data in Wertheim SafeController Software exposes files |
15.06.2026 |
|
| CVE-2026-34029 |
Hard-coded cryptographic key in Wertheim SafeController Software allows decryption of sensitive configuration data |
15.06.2026 |
|
| CVE-2026-34030 |
Improper branch-code validation in Wertheim SafeController Software allows file path manipulation |
15.06.2026 |
|
| CVE-2026-49757 |
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching |
15.06.2026 |
|
| CVE-2026-5482 |
Remote Code Execution via Unrestricted File Upload in Responsive FileManager |
15.06.2026 |
|
| CVE-2026-11860 |
Insecure Deserialisation via Plaintext HTTP leading to Remote Code Execution in Quick.CMS |
15.06.2026 |
|
| CVE-2026-44188 |
Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration |
15.06.2026 |
|
| CVE-2026-50100 |
|
15.06.2026 |
|
| CVE-2026-8385 |
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback |
15.06.2026 |
|
| CVE-2026-8386 |
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID |
15.06.2026 |
|
| CVE-2026-8935 |
Advanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation |
15.06.2026 |
|
| CVE-2026-9278 |
Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure |
15.06.2026 |
|
| CVE-2026-12218 |
Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflow |
15.06.2026 |
|
| CVE-2026-12219 |
Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection |
15.06.2026 |
|
| CVE-2026-12220 |
Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflow |
15.06.2026 |
|
| CVE-2026-12221 |
Yealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflow |
15.06.2026 |
|
| CVE-2026-12222 |
Yealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflow |
15.06.2026 |
|
| CVE-2026-12223 |
Yealink SIP-T46U Web FastCGI Service tftpuploadiperf mod_webd.TFTPUploadIperf command injection |
15.06.2026 |
|
| CVE-2026-12212 |
hcengineering Huly Platform RPC operations.ts getMailboxSecret access control |
15.06.2026 |
|
| CVE-2026-12213 |
hcengineering Huly Platform User Information operations.ts getAccountInfo improper authorization |
15.06.2026 |
|
| CVE-2026-12214 |
Qihoo 360 Total Security Nucleus Engine Monitoring Logic RpcStringBindingComposeW protection mechanism |
15.06.2026 |
|
| CVE-2026-12216 |
svaarala duktape duk_api_bytecode.c memory corruption |
15.06.2026 |
|
| CVE-2026-12217 |
DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management |
15.06.2026 |
|
| CVE-2026-12208 |
jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution |
15.06.2026 |
|
| CVE-2026-12209 |
RubyLouvre avalon Template Filter index.js prototype pollution |
15.06.2026 |
|
| CVE-2026-12210 |
universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery |
15.06.2026 |
|
| CVE-2026-12211 |
Intelbras iNVU 7016 FT Web syslog path traversal |
15.06.2026 |
|
| CVE-2026-12202 |
Intelliants Subrion CMS Blocks Endpoint cross site scripting |
15.06.2026 |
|
| CVE-2026-12203 |
HKUDS AI-Trader Research Export agents.csv information disclosure |
15.06.2026 |
|
| CVE-2026-12204 |
ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization |
15.06.2026 |
|
| CVE-2026-12206 |
Grit42 Grit data_table_entity.rb DataTableEntity sql injection |
15.06.2026 |
|
| CVE-2026-12207 |
medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource injection |
15.06.2026 |
|
| CVE-2026-12200 |
Ritlabs TinyWeb Server Header libeay32.dll.html stack-based overflow |
15.06.2026 |
|
| CVE-2026-12201 |
IObit Malware Fighter DLL permission |
15.06.2026 |
|
| CVE-2026-12197 |
Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection |
15.06.2026 |
|
| CVE-2026-12198 |
Microweber API Endpoint thumbnail_img userfiles_path path traversal |
15.06.2026 |
|
| CVE-2026-12192 |
GALAYOU Y4 Web Server buffer overflow |
14.06.2026 |
|
| CVE-2026-12193 |
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow |
15.06.2026 |
|
| CVE-2026-12190 |
Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme |
15.06.2026 |
|
| CVE-2026-12191 |
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization |
14.06.2026 |
|
| CVE-2026-12188 |
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection |
15.06.2026 |
|
| CVE-2026-12189 |
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme |
15.06.2026 |
|
| CVE-2026-12187 |
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection |
15.06.2026 |
|
| CVE-2026-12186 |
GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection |
14.06.2026 |
|