--===============8762863052863791975==
Content-Type: multipart/alternative; boundary="===============1754896695755606665=="
MIME-Version: 1.0
--===============1754896695755606665==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Cybersecurity and Infrastructure Security Agency (CISA)
You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrast= ructure Security Agency. This information has recently been updated and is = now available.
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities t= hat have been recorded in the past week. In some cases, the vulnerabilities=
in the bulletin may not yet have assigned CVSS scores.
Vulnerabilities are based on the=C2=A0Common Vulnerabilities and Exposures =
[
https://www.cve.org/ ]=C2=A0(CVE) vulnerability naming standard and are o= rganized according to severity, determined by the=C2=A0Common Vulnerability=
Scoring System [
https://www.cve.org/about/relatedefforts ]=C2=A0(CVSS) st= andard. The division of high, medium, and low severities correspond to the = following scores:
* *High*: vulnerabilities with a CVSS base score of 7.0=E2=80=9310.0=20
* *Medium*: vulnerabilities with a CVSS base score of 4.0=E2=80=936.9=20
* *Low*: vulnerabilities with a CVSS base score of 0.0=E2=80=933.9=20
Entries may include additional information provided by organizations and ef= forts sponsored by CISA. This information may include identifying informati= on, values, definitions, and related links. Patch information is provided w= hen available. Please note that some of the information in the bulletin is = compiled from external, open-source reports and is not a direct result of C= ISA analysis.
=C2=A0
Vulnerability Summary for the Week of June 15, 2026 [
https://www.cisa.gov/= news-events/bulletins/sb26-173 ] 06/22/2026 03:30 PM EDT=20
High Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info 10Web--Form = Maker by 10Web Unauthenticated SQL Injection in Form Maker by 10Web <=3D 1.= 15.38 versions. 2026-06-15 9.3 CVE-2026-39502 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-39502 ] 404-redirection-manager--404 Redirection Manager T=
he 404 Redirection Manager plugin version 1.0 for WordPress contains an una= uthenticated SQL injection vulnerability that allows remote attackers to ex= ecute arbitrary SQL queries by injecting malicious code through unsanitized=
user input. Attackers can craft GET requests with SQL injection payloads t=
o manipulate database queries and extract sensitive information from the Wo= rdPress database. 2026-06-15 8.2 CVE-2016-20071 [
https://www.cve.org/CVERe= cord?id=3DCVE-2016-20071 ] A WP Life--Webenvo Subscriber Arbitrary File Upl= oad in Webenvo <=3D 0.0.6 versions. 2026-06-17 9.9 CVE-2026-39589 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-39589 ] AA-Team--Premium Age Verificat= ion / Restriction for WordPress Unauthenticated Arbitrary File Download in = Premium Age Verification / Restriction for WordPress <=3D 3.0.2 versions. 2= 026-06-17 7.5 CVE-2025-49403 [
https://www.cve.org/CVERecord?id=3DCVE-2025-= 49403 ] ACPT--ACPT (Pro) - Custom Post Types Plugin for WordPress Improper = Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT=
(Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusio=
n. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: = from n/a through 2.0.47. 2026-06-16 10 CVE-2026-25470 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-25470 ] activity-log.com--WP Sessions Time Monitor= ing Full Automatic Subscriber SQL Injection in WP Sessions Time Monitoring = Full Automatic <=3D 1.1.4 versions. 2026-06-16 8.5 CVE-2026-39581 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-39581 ] Adobe--Adobe Acrobat PDF Exten= sion (Chrome) Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and ea= rlier are affected by a UXSS-class cross-origin data disclosure vulnerabili= ty. An attacker could exploit this vulnerability to gain access to data reg= arding the victim's session. Exploitation of this issue requires user inter= action in that a victim must visit a maliciously crafted URL or interact wi=
th a compromised web page. Scope is changed. 2026-06-16 7.4 CVE-2026-48294 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-48294 ] Adobe--DNG SDK DNG SD=
K versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overf= low vulnerability that could result in arbitrary code execution in the cont= ext of the current user. Exploitation of this issue requires user interacti=
on in that a victim must open a malicious file. 2026-06-16 7.8 CVE-2026-479=
64 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47964 ] Advanced Ads GmbH-= -Advanced Ads Tracking Unauthenticated SQL Injection in Advanced Ads - Trac= king < 3.0.7 versions. 2026-06-17 9.3 CVE-2025-59554 [
https://www.cve.org/= CVERecord?id=3DCVE-2025-59554 ] aguilatechnologies--WP Customer Area Custom=
role Path Traversal in WP Customer Area <=3D 8.3.4 versions. 2026-06-15 8.=
8 CVE-2026-42661 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42661 ] Ahma= d--GeekyBot Unauthenticated Arbitrary File Upload in GeekyBot <=3D 1.2.2 ve= rsions. 2026-06-15 10 CVE-2026-40772 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-40772 ] Ahmad--GeekyBot Unauthenticated SQL Injection in GeekyBot <= =3D 1.2.0 versions. 2026-06-15 9.3 CVE-2026-39519 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-39519 ] Ahmad--JS Help Desk Unauthenticated SQL Inject= ion in JS Help Desk <=3D 3.0.9 versions. 2026-06-15 9.3 CVE-2026-48886 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-48886 ] AivahThemes--Car Zone Una= uthenticated Arbitrary File Deletion in Car Zone <=3D 3.7 versions. 2026-06= -16 8.6 CVE-2025-69139 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69139 =
] Al Monsor--ABC Crypto Checkout Unauthenticated Sensitive Data Exposure in=
ABC Crypto Checkout <=3D 1.8.2 versions. 2026-06-15 7.5 CVE-2026-52695 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-52695 ] Alberto Hornero--Clean L= ogin Unauthenticated Insecure Direct Object References (IDOR) in Clean Logi=
n <=3D 1.15 versions. 2026-06-17 8.2 CVE-2026-54184 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-54184 ] Aman--FunnelKit Automations Subscriber Broke=
n Authentication in FunnelKit Automations <=3D 3.7.3 versions. 2026-06-15 7=
.1 CVE-2026-39450 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39450 ] Any= desk--AnyDesk AnyDesk 2.5.0 contains an unquoted service path vulnerability=
that allows local users to execute arbitrary code with SYSTEM privileges b=
y exploiting the service installation. Attackers can insert malicious execu= tables in the system root path that execute with elevated privileges during=
application startup or system reboot. 2026-06-19 7.8 CVE-2016-20094 [ http= s://www.cve.org/CVERecord?id=3DCVE-2016-20094 ] AOMEI--Backupper A vulnerab= ility was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown=
function in the library amwrtdrv.sys of the component Kernel Driver. Execu= ting a manipulation can lead to improper access controls. The attack needs =
to be launched locally. The exploit has been publicly disclosed and may be = utilized. The vendor was contacted early about this disclosure but did not = respond in any way. 2026-06-21 7.8 CVE-2026-12780 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-12780 ] AOMEI--Dynamic Disk Manager A vulnerability wa=
s found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects som=
e unknown processing in the library ddmdrv.sys of the component Kernel Driv= er. Performing a manipulation results in improper access controls. The atta=
ck must be initiated from a local position. The exploit has been made publi=
c and could be used. The vendor was contacted early about this disclosure b=
ut did not respond in any way. 2026-06-21 7.8 CVE-2026-12779 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-12779 ] AOMEI--Partition Assistant A vulner= ability has been found in AOMEI Partition Assistant up to 10.10.1. This vul= nerability affects unknown code in the library ampa10.sys of the component = Kernel Driver. Such manipulation leads to improper access controls. The att= ack must be carried out locally. The exploit has been disclosed to the publ=
ic and may be used. The vendor was contacted early about this disclosure bu=
t did not respond in any way. 2026-06-21 7.8 CVE-2026-12778 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-12778 ] Archetyped--Favicon Rotator Unauthen= ticated Cross Site Scripting (XSS) in Favicon Rotator <=3D 1.2.11 versions.=
2026-06-15 7.1 CVE-2026-42649 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-42649 ] ArrayHQ--Okay Toolkit Unauthenticated Cross Site Scripting (XSS) =
in Okay Toolkit <=3D 2.3 versions. 2026-06-15 7.1 CVE-2025-68851 [
https://= www.cve.org/CVERecord?id=3DCVE-2025-68851 ] Arraytics--WP Event SOlution Un= authenticated Broken Access Control in WP Event SOlution <=3D 4.1.12 versio= ns. 2026-06-16 7.5 CVE-2025-68045 [
https://www.cve.org/CVERecord?id=3DCVE-= 2025-68045 ] Arraytics--WP Event SOlution Unauthenticated Broken Access Con= trol in WP Event SOlution <=3D 4.1.8 versions. 2026-06-15 7.5 CVE-2026-4077=
6 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40776 ] artbees--JupiterX C= ore Unauthenticated Broken Access Control in JupiterX Core <=3D 4.14.1 vers= ions. 2026-06-16 7.5 CVE-2026-39490 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-39490 ] Artio--Joomla! com_booking component Joomla com_booking comp= onent 2.4.9 contains an information disclosure vulnerability that allows un= authenticated attackers to enumerate user accounts by exploiting the getUse= rData function in the customer controller. Attackers can send GET requests =
to index.php with option=3Dcom_booking, controller=3Dcustomer, task=3DgetUs= erData, and an id parameter to retrieve user names, usernames, and email ad= dresses through brute force enumeration. 2026-06-19 7.5 CVE-2023-54357 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2023-54357 ] Avast--AVAST Antivirus AV= AST Antivirus 25.11 contains an unquoted service path vulnerability in the = SecureLine service that allows local non-privileged users to execute code w= ith elevated SYSTEM privileges. Attackers can exploit the unquoted binary p= ath in the service configuration to inject malicious executables that execu=
te with high-level system permissions. 2026-06-19 7.8 CVE-2025-71326 [ http= s://www.cve.org/CVERecord?id=3DCVE-2025-71326 ] AVer--PTC500S Improper inpu=
t validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allo=
w a remote, unauthenticated attacker to achieve arbitrary code execution vi=
a a specially crafted web request. 2026-06-18 9.8 CVE-2026-40624 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-40624 ] AVideo--AVideo AVideo through 2= 9.0 contains an authorization bypass vulnerability in the Meet plugin's upl= oadRecordedVideo.json.php endpoint that derives the target users_id from th=
e uploaded filename without verification. An attacker with knowledge of the=
Meet shared secret can craft a malicious file upload with a filename conta= ining an arbitrary users_id to invoke passwordless User->login() and establ= ish an authenticated session as any user including admin. Attackers can obt= ain the Meet shared secret through path-traversal vulnerabilities or timing=
attacks against checkToken.json.php, then POST a crafted file to uploadRec= ordedVideo.json.php with a filename like '1-anything.mp4' to hijack admin s= essions and gain full account takeover. 2026-06-20 8.1 CVE-2026-56345 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-56345 ] AVideo--AVideo AVideo thro= ugh version 26.0 contains multiple unauthenticated list.json.php endpoints =
in payment plugins lacking authorization checks, exposing PayPal tokens, Au= thorize.Net webhooks, and Bitcoin transaction records. Unauthenticated atta= ckers can retrieve all payment transaction data including agreement IDs, us=
er financial records, and API responses via direct GET requests to vulnerab=
le endpoints. 2026-06-20 7.5 CVE-2026-56341 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-56341 ] Awesomemotive--Contact Form by WPForms Unauthenticat=
ed Broken Access Control in Contact Form by WPForms <=3D 1.10.0.4 versions.=
2026-06-15 7.5 CVE-2026-48835 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-48835 ] Awesomemotive--Easy Digital Downloads Unauthenticated Broken Acce=
ss Control in Easy Digital Downloads <=3D 3.6.5 versions. 2026-06-15 7.5 CV= E-2026-39503 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39503 ] AWS--bed= rock-agentcore Improper neutralization of argument delimiters in the instal= l_packages() method in AWS Bedrock AgentCore Python SDK versions >=3D 1.1.3=
and < 1.6.1 might allow a remote authenticated user to execute arbitrary c= ommands within the Code Interpreter sandbox via crafted package name argume= nts. To mitigate this issue, users should upgrade to version 1.6.1. 2026-06= -17 7.3 CVE-2026-12530 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12530 =
] AxiomThemes--Promo Unauthenticated Local File Inclusion in Promo <=3D 1.3=
.0 versions. 2026-06-17 8.1 CVE-2026-22325 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-22325 ] AxiomThemes--Reprizo Unauthenticated Local File Inclu= sion in Reprizo <=3D 1.0.8 versions. 2026-06-17 8.1 CVE-2026-22326 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-22326 ] Ays Pro--Popup box Unauthenti= cated Cross Site Scripting (XSS) in Popup box <=3D 6.2.9 versions. 2026-06-=
17 7.1 CVE-2026-54192 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54192 ]=
Azuriom--Azuriom CMS Missing Authorization in the server management routes=
(routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms a= llows an authenticated attacker with the admin.access permission to create = AzLink server tokens and take over non-admin user accounts by changing thei=
r passwords and email addresses via crafted HTTP requests to /admin/servers= /create and the AzLink API endpoints (/api/azlink/password, /api/azlink/ema= il, /api/azlink/user/{id}). 2026-06-17 8.1 CVE-2026-54415 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-54415 ] baptisteArno--typebot.io TypeBot is a = chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file= -input/v3/generate-upload-url is unauthenticated and uses unsanitized fileN= ame input to construct public/ S3 object keys, while issuing presigned PUT = URLs that do not bind Content-Type. As a result, any anonymous visitor to a=
published bot with a file input can upload attacker-controlled HTML, SVG, =
or JS to attacker-chosen subpaths, including other tenants' publicly served=
result paths, enabling arbitrary content hosting and potential stored XSS =
on the storage origin. ../ traversal is blocked by S3/MinIO canonicalizatio=
n (signature mismatch), but forward-slash path injection is exploitable. Th=
is issue has been fixed in version 3.17.0. 2026-06-17 9.3 CVE-2026-48768 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-48768 ] baptisteArno--typebot.i=
o TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF vali= dation is implemented by resolving a hostname once and checking whether the=
resolved IP belongs to a forbidden range allowing for DNS rebinding bypass=
. The root cause is a time-of-check to time-of-use gap in the SSRF guard. T=
he validator resolves the hostname and approves it, but the later request p= ath performs a fresh resolution and connects to whatever IP the hostname ma=
ps to at that moment. The actual outbound request is then performed later u= sing the original hostname, without pinning the validated IP to the network=
connection. An attacker who can supply a URL to a public bot that performs=
a server-side HTTP Request block or server-side script fetch can use DNS r= ebinding to pass the initial validation and still force the server to conne=
ct to a private or metadata address during the real request. This enables s= erver-side access to private network services, cloud metadata endpoints, an=
d other internal HTTP targets that the validator was intended to block. The=
exact downstream impact depends on the reachable internal services. Concre=
te consequences include metadata disclosure, access to internal admin panel=
s, credential theft from metadata services, and further compromise through = internal-only HTTP interfaces. This issue has been fixed in version 3.17.2.=
2026-06-17 8.2 CVE-2026-48764 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-48764 ] baptisteArno--typebot.io TypeBot is a chatbot builder tool. Versi= ons 3.15.2 and below have an Insecure Direct Object Reference vulnerability=
through cross-workspace Theme Template modification and deletion. The hand= leSaveThemeTemplate and handleDeleteThemeTemplate handlers validate that th=
e authenticated user is a non-guest member of the provided workspaceId, but=
then operate on themeTemplateId via Prisma queries that do NOT include wor= kspaceId in the WHERE clause. This allows any authenticated user to modify =
or delete theme templates belonging to any other workspace and may expose T= emplate IDs via shared typebots or network traffic. This issue has been fix=
ed in version 3.16.0. 2026-06-17 7.1 CVE-2026-48759 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-48759 ] Barn2 Media Ltd--WooCommerce Product Filters=
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.=
6 versions. 2026-06-17 9.8 CVE-2026-40725 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-40725 ] bbsetheme--BBS e-Franchise BBS e-Franchise 1.1.1 plugi=
n for WordPress contains an SQL injection vulnerability that allows unauthe= nticated attackers to execute arbitrary SQL queries by injecting malicious = code through the uid parameter. Attackers can craft requests to pages using=
the plugin's shortcode with UNION-based SQL injection in the uid parameter=
to extract sensitive data from the WordPress database including user infor= mation and taxonomy terms. 2026-06-15 8.2 CVE-2016-20072 [
https://www.cve.= org/CVERecord?id=3DCVE-2016-20072 ] BdThemes--Element Pack Pro Contributor = Local File Inclusion in Element Pack Pro <=3D 9.0.6 versions. 2026-06-17 7.=
5 CVE-2026-40721 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40721 ] BDth= emes--SigmaForms Pro AI Generated Forms Unauthenticated Arbitrary File Uplo=
ad in SigmaForms Pro - AI Generated Forms <=3D 1.4.5 versions. 2026-06-17 9=
CVE-2026-52705 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52705 ] Berri= AI--litellm A weakness has been identified in BerriAI litellm up to 1.59.8.=
Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experim= ental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. = Executing a manipulation can lead to improper authentication. The attack ma=
y be launched remotely. The exploit has been made available to the public a=
nd could be used for attacks. The vendor was contacted early about this dis= closure. 2026-06-21 7.3 CVE-2026-12773 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12773 ] BerriAI--litellm A vulnerability was determined in Berr= iAI litellm up to 1.82.2. This affects the function json.dumps of the file = litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flo=
w. Executing a manipulation can lead to missing authentication. The attack = can be executed remotely. The exploit has been publicly disclosed and may b=
e utilized. The vendor was contacted early about this disclosure. 2026-06-2=
1 7.3 CVE-2026-12795 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12795 ] = betterdocs--BetterDocs Pro The BetterDocs Pro plugin for WordPress is vulne= rable to Local File Inclusion in versions up to, and including, 3.8.0 via t=
he `doc_style` parameter. This makes it possible for unauthenticated attack= ers to include and execute arbitrary .php files on the server, allowing the=
execution of any PHP code in those files. This can be used to bypass acces=
s controls, obtain sensitive data, or achieve code execution in cases where=
.php file types can be uploaded and included. 2026-06-19 9.8 CVE-2026-7515=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-7515 ] bgermann--CformsII Un= authenticated Cross Site Scripting (XSS) in CformsII <=3D 15.1.3 versions. = 2026-06-15 7.1 CVE-2026-39435 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -39435 ] Bhavin Thummar--Product Filter Widget for Elementor Unauthenticate=
d Cross Site Scripting (XSS) in Product Filter Widget for Elementor <=3D 1.= 0.6 versions. 2026-06-15 7.1 CVE-2026-45437 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-45437 ] Binisoft--Windows Firewall Control Windows Firewall = Control 4.8.6.0 contains an unquoted service path vulnerability that allows=
local attackers to escalate privileges by inserting malicious executables =
in the service path. Attackers can place executable files in unquoted path = directories that the wfcs.exe service will execute with LocalSystem privile= ges upon service restart or system reboot. 2026-06-19 7.8 CVE-2016-20091 [ =
https://www.cve.org/CVERecord?id=3DCVE-2016-20091 ] Bitnami--bitnami/cassan= dra Bitnami Cassandra container images are affected by a retained default s= uperuser vulnerability. When a custom administrator account is configured v=
ia the CASSANDRA_USER environment variable, the container initialization sc= ript creates the new superuser account but fails to drop the built-in cassa= ndra account in certain scenarios. This leaves the default cassandra:cassan= dra superuser active as an unintended access path. Affected versions - Cont= ainer image: 4.0.x prior to 4.0.20-photon-5-r7; 4.1.x prior to 4.1.11-photo= n-5-r7; 5.0.x prior to 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3. 2026-06-18 9=
.8 CVE-2026-47846 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47846 ] Blu= brry Podcasting--PowerPress Podcasting Contributor SQL Injection in PowerPr= ess Podcasting <=3D 11.15.10 versions. 2026-06-15 8.5 CVE-2026-24637 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-24637 ] BoldThemes--Nifty Unauthent= icated PHP Object Injection in Nifty <=3D 1.4.1 versions. 2026-06-16 9.8 CV= E-2026-27429 [
https://www.cve.org/CVERecord?id=3DCVE-2026-27429 ] Bookly--= Bookly Unauthenticated Sensitive Data Exposure in Bookly <=3D 27.4 versions=
. 2026-06-15 7.5 CVE-2026-42667 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-42667 ] bPlugins--B Blocks Contributor Privilege Escalation in B Blocks = <=3D 2.0.31 versions. 2026-06-15 8.8 CVE-2026-39579 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-39579 ] Brainstorm Force--OttoKit Unauthenticated PH=
P Object Injection in OttoKit <=3D 1.1.27 versions. 2026-06-15 9.8 CVE-2026= -49781 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49781 ] Brainstorm For= ce--SureDash Improper Neutralization of Special Elements used in an SQL Com= mand ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Bl= ind SQL Injection. This issue affects SureDash: from n/a through 1.8.0. 202= 6-06-17 8.5 CVE-2026-54813 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54= 813 ] Brainstorm Force--WooCommerce Cart Abandonment Recovery Shop manager = Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versi= ons. 2026-06-15 7.2 CVE-2026-39470 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-39470 ] Bricksforge--Bricksforge Unauthenticated Sensitive Data Expos= ure in Bricksforge <=3D 3.1.8.4 versions. 2026-06-17 7.5 CVE-2026-34888 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-34888 ] Brother--SAPSprint Broth=
er SAPSprint 7.60 contains an unquoted service path vulnerability in the SA= PSprint service binary that allows local attackers to escalate privileges. = Attackers can place a malicious executable in the Program Files directory p= ath to be executed with LocalSystem privileges when the service starts auto= matically. 2026-06-19 7.8 CVE-2021-47985 [
https://www.cve.org/CVERecord?id= =3DCVE-2021-47985 ] browserstack--browserstack-cypress-cli The browserstack= -cypress-cli is BrowserStack's CLI which allows users to run Cypress tests =
on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command inje= ction via the cypress_config_file configuration parameter. In readCypressCo= nfigUtil.js, the loadJsFile() function constructs a shell command by interp= olating the user-controlled cypress_config_filepath value into a template l= iteral, then executes it via child_process.execSync(). Shell metacharacters=
in the config path (specifically " and ;) allow breaking out of the quoted=
argument and injecting arbitrary commands. This issue has been fixed in ve= rsion 1.36.6. 2026-06-15 7.8 CVE-2026-48723 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-48723 ] bytecodealliance--wasmtime Wasmtime is a runtime for=
WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a file= system preopen is given DirPerms::all() and FilePerms::READ without FilePer= ms::WRITE, this access control mechanism can be bypassed via the wasip2 des= criptor.open-at or wasip1 path_open interfaces by opening a file with only = the OpenFlags::TRUNCATE oflag. The root cause is that the clause handling O= penFlags::TRUNCATE in crates/wasi/src/filesystem.rs (Dir::open_at, lines 96= 7-969) did not set open_mode |=3D OpenMode::WRITE;, which is later used for=
the access control check against FilePerms to determine whether opening th=
e file is permitted; the single-line fix adds that missing assignment, afte=
r which the affected calls correctly fail with error-code.not-permitted and=
ERRNO_PERM respectively. Only wasmtime-wasi embeddings that combine DirPer= ms::MUTATE with FilePerms::READ are affected by this bug. In particular, th=
e Wasmtime project's wasmtime-cli's use of wasmtime-wasi is not affected, b= ecause it always sets FilePerms::all() for all preopens. This issue has bee=
n fixed in versions 24.0.9, 36.0.10 and44.0.2. 2026-06-15 7.5 CVE-2026-4726=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47261 ] CactusThemes--Truem=
ag Unauthenticated Local File Inclusion in Truemag <=3D 4.3.14.2 versions. = 2026-06-16 8.1 CVE-2025-69178 [
https://www.cve.org/CVERecord?id=3DCVE-2025= -69178 ] Cap-go--capgo Cap-go before 12.128.2 contains an authentication by= pass vulnerability in OTP verification that allows attackers to bypass emai=
l verification by modifying server responses. Attackers can intercept OTP v= erification requests and manipulate HTTP responses to falsely mark verifica= tion successful, enabling unauthorized 2FA enablement and account takeover.=
2026-06-19 9.4 CVE-2026-56073 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-56073 ] Cap-go--capgo Cap-go before 12.128.2 contains an authentication l= ogic flaw that lets an attacker register and control an account bound to a = victim's email address before that email is verified. By enabling two-facto=
r authentication on the pre-registered account, the attacker gains control = over the account claimed under the victim's identity, allowing them to read=
and modify its state and enforce organization-level policies, while the le= gitimate user is denied access to the account tied to their own email. 2026= -06-19 9.1 CVE-2026-56081 [
https://www.cve.org/CVERecord?id=3DCVE-2026-560=
81 ] Cap-go--capgo Capgo (Cap-go/capgo) before 12.128.2 contains an imprope=
r access control vulnerability in the SECURITY DEFINER PostgREST RPC functi=
on public.record_build_time, which is granted to the anon role and callable=
with only the public Supabase publishable (sb_publishable_*) anon key. An = unauthenticated attacker can insert rows into public.build_logs for arbitra=
ry organizations and, because the function uses ON CONFLICT (build_id, org_= id) DO UPDATE, can overwrite existing usage/billing records by reusing the = same build_id for a target org. This enables cross-tenant tampering of bill= ing build logs and financial-impact denial of service by inflating billable=
build time. 2026-06-19 7.5 CVE-2026-56082 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-56082 ] Capgo--Capgo Capgo before 12.128.12 allows authentica= ted users to modify their mutable public.users.email to arbitrary addresses=
, which the SSO provisioning endpoint trusts as an account-merge key. Attac= kers can pre-position their account with a victim's corporate SSO email, ca= using the provision-user endpoint to merge the victim's SSO identity into t=
he attacker-controlled account. 2026-06-20 8.3 CVE-2026-56215 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-56215 ] Capgo--Capgo Capgo before 12.128.2=
contains a scope escalation vulnerability in the POST /functions/v1/apikey=
endpoint that allows app-limited API keys to mint unrestricted keys by set= ting empty limits. Attackers with a compromised app-limited key can create =
an unrestricted key with org-wide access to resources like app listings and=
other protected endpoints. 2026-06-20 8.8 CVE-2026-56216 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-56216 ] Capgo--Capgo Capgo before 12.128.2 con= tains an information disclosure vulnerability in Supabase PostgREST RPC end= points is_trial_org and is_paying_org that allows unauthenticated attackers=
to enumerate organizations and disclose billing status using the public sb= _publishable key. Attackers can invoke these endpoints to determine organiz= ation existence via distinguishable return values and identify paying custo= mers for targeted profiling. 2026-06-20 7.5 CVE-2026-56214 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-56214 ] Capgo--Capgo Capgo before 12.128.2 co= ntains a potential privilege escalation vulnerability in the public.apply_u= sage_overage SECURITY DEFINER function, which performs sensitive billing op= erations without enforcing internal authorization checks (no validation of = auth.uid(), org membership, or check_min_rights). Because the function runs=
with the owner's privileges, it bypasses Row Level Security. If EXECUTE pe= rmission is available to the authenticated or anon roles (explicitly or via=
default privileges), an authenticated user could invoke it via Supabase RP=
C to manipulate billing data for arbitrary organizations, including unautho= rized credit depletion and fraudulent overage event insertion. 2026-06-21 7=
.6 CVE-2026-56239 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56239 ] Cap= go--Capgo Capgo before 12.128.2 contains an unauthenticated security define=
r RPC function get_identity_apikey_only that returns the owning user_id for=
supplied API keys, creating an API key validity oracle and user identity d= isclosure primitive. Attackers can call this endpoint with valid or invalid=
API keys to confirm key validity and map keys to user identifiers, then ch= ain results into other exposed RPCs like get_orgs_v6 to retrieve organizati=
on membership and management email PII. 2026-06-21 7.5 CVE-2026-56242 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-56242 ] Capgo--Capgo Capgo before = 12.128.2 contains an improper access control vulnerability in the public.ge= t_org_members RPC function that allows unauthenticated attackers to enumera=
te organization members. Attackers can invoke the endpoint using only the p= ublic sb_publishable_* key and an organization UUID to retrieve sensitive m= ember information including email addresses, user IDs, roles, and pending i= nvitations. 2026-06-21 7.5 CVE-2026-56253 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-56253 ] Cargo RD--Cargo Shipping Location for WooCommerce Impr= oper Neutralization of Special Elements used in an SQL Command ('SQL Inject= ion') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce all= ows Blind SQL Injection. This issue affects Cargo Shipping Location for Woo= Commerce: from n/a through 5.6. 2026-06-17 9.3 CVE-2026-54815 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-54815 ] Chatway Live Chat--Chatway Live Ch=
at =E2=80=9C AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service =
& Chat Buttons Subscriber Sensitive Data Exposure in Chatway Live Chat R= 11; AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service &=
Chat Buttons <=3D 1.4.8 versions. 2026-06-15 7.4 CVE-2026-49082 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-49082 ] Cherryframework--Cherry Framewo=
rk Themes WordPress CherryFramework Themes 3.1.4 contains an information di= sclosure vulnerability that allows unauthenticated attackers to download se= nsitive backup files by accessing the download_backup.php endpoint. Attacke=
rs can directly access the download_backup.php script in the admin/data_man= agement directory to obtain ZIP archives containing the entire wp-content/t= hemes directory contents. 2026-06-15 7.5 CVE-2018-25437 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2018-25437 ] ChrisHurst--Simple Backup WordPress Simp= le-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticat=
ed attackers to delete arbitrary files and download sensitive files by mani= pulating the delete_backup_file and download_backup_file parameters in tool= s.php. Attackers can exploit insufficient input validation using directory = traversal techniques to access wp-config.php, database dumps, and other sen= sitive files, or delete critical files .htaccess to expose backup directori= es. 2026-06-15 7.5 CVE-2016-20076 [
https://www.cve.org/CVERecord?id=3DCVE-= 2016-20076 ] Cisco--Cisco Identity Services Engine Software A vulnerability=
in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to = execute arbitrary commands on the underlying operating system of an affecte=
d device. To exploit this vulnerability, the attacker must have valid admin= istrative credentials. This vulnerability is due to insufficient validation=
of user-supplied input. An attacker could exploit this vulnerability by se= nding a crafted HTTP request to an affected device. A successful exploit co= uld allow the attacker to obtain user-level access to the underlying operat= ing system and then elevate privileges to root. In single-node deployments,=
successful exploitation of this vulnerability could cause the affected ISE=
node to become unavailable, resulting in a denial of service (DoS) conditi= on. In that condition, endpoints that have not already authenticated would =
be unable to access the network until the node is restored. 2026-06-17 9.1 = CVE-2026-20181 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20181 ] Cisco-= -Cisco Identity Services Engine Software A vulnerability in Cisco ISE and I= SE-PIC could allow an unauthenticated, remote attacker to view sensitive in= formation on an affected device. This vulnerability is due to improper auth= orization checks when a resource is accessed. An attacker could exploit thi=
s vulnerability by sending crafted traffic to an affected device. A success= ful exploit could allow the attacker to gain access to sensitive informatio=
n, including hashed credentials that could be used in future attacks. 2026-= 06-17 7.5 CVE-2026-20190 [
https://www.cve.org/CVERecord?id=3DCVE-2026-2019=
0 ] claudiopizzillo--PIAF-HMS claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hote=
l Management System; no released versions, latest commit 389d2633441b65ced1= c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vul= nerabilities. The application has no authentication mechanism and passes us= er-supplied HTTP parameters directly into deprecated mysql_query() calls vi=
a string concatenation, without sanitization, escaping, or parameterization=
. Affected sinks include rooms.php (DELETE FROM Rooms WHERE ID =3D $_GET['I= D'], unquoted numeric context), checkuser.php (WHERE Ext =3D '$_GET["Ext"]'=
), ec.php (date/extension parameters in a WHERE), checkin.php and wakeup.ph=
p ($_POST values into INSERT statements), bills.php ($_POST fields built in=
to a WHERE clause), and rates.php and checkout.php. A remote, unauthenticat=
ed attacker can inject arbitrary SQL to read, modify, or delete arbitrary r= ecords in the backing database (e.g. rooms.php?ID=3D1 OR 1=3D1 deletes all = room records). Note: queries run via the legacy mysql_* extension, which do=
es not permit stacked statements. 2026-06-18 9.8 CVE-2026-54419 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-54419 ] CMSJunkie WordPress Business Dir= ectory Plugins--WP-BusinessDirectory Subscriber Arbitrary File Upload in WP= -BusinessDirectory <=3D 4.0.0 versions. 2026-06-15 9.9 CVE-2026-39591 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-39591 ] Cmsjunkie--ClassifiedsMana= ger Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection v= ulnerability that allows unauthenticated attackers to execute arbitrary SQL=
queries by injecting malicious code through POST parameters. Attackers can=
submit crafted SQL payloads in the categorySearch, adType, and citySearch = parameters to the displayads component to extract sensitive database inform= ation including usernames, databases, and version details. 2026-06-19 8.2 C= VE-2019-25751 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25751 ] Cmsjunk= ie--J-BusinessDirectory Joomla! Component J-BusinessDirectory 4.9.7 contain=
s an SQL injection vulnerability that allows unauthenticated attackers to e= xecute arbitrary SQL queries by injecting malicious code through the type p= arameter. Attackers can send GET requests to index.php with the option=3Dco= m_jbusinessdirectory&task=3Dcategories.getCategories parameters and inject = UNION-based SQL statements in the type parameter to extract database inform= ation including schema names and sensitive data. 2026-06-19 8.2 CVE-2019-25= 752 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25752 ] Cmsjunkie--J-Crui= sePortal Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerabilit=
y that allows authenticated attackers to execute arbitrary SQL queries by i= njecting malicious code through the guest_adult parameter. Attackers can se=
nd POST requests to the cruises endpoint with crafted SQL payloads in the g= uest_adult parameter to extract sensitive database information or manipulat=
e database records. 2026-06-19 7.1 CVE-2019-25749 [
https://www.cve.org/CVE= Record?id=3DCVE-2019-25749 ] Cmsjunkie--JHotelReservation Joomla JHotelRese= rvation 6.0.7 contains an SQL injection vulnerability that allows unauthent= icated attackers to execute arbitrary SQL queries by injecting malicious co=
de through the rooms parameter. Attackers can send POST requests to the sea= rch-hotels endpoint with crafted SQL payloads in the rooms parameter to ext= ract sensitive database information including version details. 2026-06-19 8=
.2 CVE-2019-25748 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25748 ] Cms= junkie--MultipleHotelReservation Joomla Component J-MultipleHotelReservatio=
n 6.0.7 contains an SQL injection vulnerability that allows unauthenticated=
attackers to execute arbitrary SQL queries by injecting malicious code thr= ough the hotel_id parameter. Attackers can send POST requests to the search= -hotels endpoint with crafted SQL UNION SELECT statements to extract sensit= ive database information including table names and column data. 2026-06-19 = 8.2 CVE-2019-25750 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25750 ] co= depeople--WP Time Slots Booking Form Subscriber SQL Injection in WP Time Sl= ots Booking Form <=3D 1.2.50 versions. 2026-06-15 8.5 CVE-2026-48882 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-48882 ] codepeople--WP Time Slots B= ooking Form Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Boo= king Form <=3D 1.2.46 versions. 2026-06-15 7.1 CVE-2026-40791 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-40791 ] codesupplyco--Uppercase Unauthenti= cated Local File Inclusion in Uppercase < 1.2.2 versions. 2026-06-17 8.1 CV= E-2026-39559 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39559 ] collectc= hat--collectchat Unauthenticated Cross Site Scripting (XSS) in collectchat = <=3D 2.4.9 versions. 2026-06-17 7.1 CVE-2026-40765 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-40765 ] cometd--cometd CometD is a scalable comet imp= lementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 thro= ugh 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 through 8.0.8, bad clients that=
always send a fixed batch value when the server is using the acknowledgeme=
nt extension may cause the unacknowledged message queue to grow indefinitel=
y, eventually causing an `OutOfMemoryError`. Versions 5.0.23, 6.0.19, 7.0.1=
9, and 8.0.9 patch the issue. As a workaround, disable the acknowledgement = extension. 2026-06-18 7.5 CVE-2025-53114 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-53114 ] Comodo--Chromodo Browser Comodo Chromodo Browser 52.15.= 25.664 contains an unquoted service path vulnerability in the ChromodoUpdat=
er service that runs with SYSTEM privileges. A local attacker can insert a = malicious executable in the service path and execute arbitrary code with el= evated privileges upon service restart or system reboot. 2026-06-19 7.8 CVE= -2016-20088 [
https://www.cve.org/CVERecord?id=3DCVE-2016-20088 ] Comodo--D= ragon Browser Comodo Dragon Browser versions up to 52.15.25.663 contain a p= rivilege escalation vulnerability in the DragonUpdater service due to an un= quoted service path running with SYSTEM privileges. A local attacker can in= sert a malicious executable in the service path and execute arbitrary code = with elevated privileges upon service restart or system reboot. 2026-06-19 = 7.8 CVE-2016-20090 [
https://www.cve.org/CVERecord?id=3DCVE-2016-20090 ] co= nda-forge--conda-smithy conda-smithy is a tool for combining a conda recipe=
with configurations to build using freely hosted CI services into a single=
repository. Prior to version 3.61.0, a vulnerability in the conda-forge au= tomated webservices allowed unintended write access to feedstock repositori=
es through GitHub username takeover. The root cause is the use of mutable G= itHub usernames as identifiers for repository invitation routing, rather th=
an stable, immutable GitHub user IDs. Version 3.61.0 fixes the issue. 2026-= 06-18 7.6 CVE-2026-46699 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4669=
9 ] Conekta Group--Conekta Payment Gateway Unauthenticated Sensitive Data E= xposure in Conekta Payment Gateway <=3D 6.0.0 versions. 2026-06-15 7.5 CVE-= 2026-49066 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49066 ] contest-ga= llery--Contest Gallery Upload & Vote Photos, Media, Sell with PayPal & Stri=
pe The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & St= ripe plugin for WordPress is vulnerable to Privilege Escalation in all vers= ions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. Thi=
s is due to the plugin's admin menu being registered at the `edit_posts` ca= pability level - granting Contributor-level users access to the plugin's ad= min pages and a valid `cg_admin` nonce - while the option-saving handler in=
`change-options-and-sizes.php` performs no `current_user_can()` capability=
check beyond `check_admin_referer('cg_admin')`, and the `RegistryUserRole`=
value is processed only through `sanitize_text_field()` and `htmlentities(=
)` without restriction to an allowlist of permitted role names. This makes =
it possible for authenticated attackers, with author-level access and above=
, to overwrite the plugin's stored `RegistryUserRole` option with `administ= rator`, which the `cg_create_wp_user_from_google_user` function then reads = back from the `contest_gal1ery_registry_and_login_options` database table w= ithout any allowlist validation and passes directly to `wp_update_user()`, = effectively promoting a newly registered Google sign-in account to Administ= rator. 2026-06-17 8.8 CVE-2026-12165 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-12165 ] Cotonti--Cotonti Cotonti 1.0.0 (master branch, commit f43f1= fc3) is vulnerable to Cross-Site Request Forgery in the administration righ=
ts handler. In system/admin/admin.rights.php, the rights update action ('a= =3Dupdate') modifies group access rights (including via cot_auth_add_group)=
without calling cot_check_xg() to validate the anti-CSRF token. A remote a= ttacker who lures an authenticated administrator into visiting a malicious = page can force the browser to submit a forged request that grants elevated = permissions to an attacker-controlled group, escalating privileges to admin= istrator. Because Cotonti administrators can modify templates and configura= tion, this can be further leveraged toward remote code execution. 2026-06-1=
8 9.6 CVE-2026-55742 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55742 ] = Cotonti--Cotonti Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerab=
le to Cross-Site Request Forgery in the administration configuration handle=
r. In system/admin/admin.config.php, the configuration update action ('a=3D= update') processes POST data via cot_config_update_options() without callin=
g cot_check_xg() to validate the anti-CSRF token (the 'x' parameter), unlik=
e other admin handlers (e.g. admin.structure.php, admin.cache.php). A remot=
e attacker who lures an authenticated administrator into visiting a malicio=
us page can force the browser to submit a forged request that modifies arbi= trary core, module, or plugin configuration options, which can be leveraged=
to weaken security or enable further compromise. 2026-06-18 8.8 CVE-2026-5= 5741 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55741 ] Cotonti--Cotonti=
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site=
Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/= inc/pfs.main.php, the file upload action ('a=3Dupload') processes uploaded = files without calling cot_check_xg() to validate the anti-CSRF token, even = though sibling actions such as 'delete' (line 272) do. A remote attacker wh=
o lures an authenticated user into visiting a malicious page can force the = browser to submit a forged multipart request that uploads arbitrary files i= nto the victim's PFS storage. 2026-06-18 8.1 CVE-2026-55744 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-55744 ] Cotonti--Cotonti Cotonti 1.0.0 (mast=
er branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in=
the Personal File Storage (PFS) module. A folder title (pff_title) is impo= rted with the 'TXT' filter, which does not strip or encode HTML (the tag ch= eck in cot_import is disabled), so an authenticated user can store HTML/Jav= aScript in a folder title. In modules/pfs/inc/pfs.main.php the title is ass= igned to the template variable PFF_ROW_TITLE without htmlspecialchars(), an=
d modules/pfs/tpl/pfs.tpl outputs {PFF_ROW_TITLE} unescaped. When the folde=
r listing is viewed (including by other users for public folders), the inje= cted script executes in the victim's browser. 2026-06-18 7.6 CVE-2026-55746=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-55746 ] coturn--coturn Cotur=
n is a free open source implementation of TURN and STUN Server. Versions pr= ior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). =
A uint16_t nonce_len field read from an attacker-supplied OAuth access toke=
n (0-65535) is passed directly to memcpy() as the copy length into a 256-by=
te stack buffer (oauth_encrypted_block.nonce[256]) without bounds checking.=
The overflow occurs before AES-GCM authentication is verified, the attacke=
r does not need to know the OAuth key or produce a valid AES-GCM token. Up =
to 735 bytes of attacker-controlled data are written past the buffer, may c= orrupt adjacent stack data, including control-flow data depending on compil= er, ABI, and mitigations. Requires --oauth mode (non-default). This may pro= vide a plausible RCE primitive depending on exploit mitigations; because co= turn is widely deployed for WebRTC TURN/STUN and --oauth is commonly recomm= ended, impact can be broad. This issue has been fixed in version 4.10.0. 20= 26-06-18 8.1 CVE-2026-43994 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 3994 ] Cozmoslabs--Paid Member Subscriptions Unauthenticated Cross Site Scr= ipting (XSS) in Paid Member Subscriptions <=3D 2.17.3 versions. 2026-06-15 = 7.1 CVE-2026-39514 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39514 ] Co= zmoslabs--Profile Builder Pro Unauthenticated Cross Site Scripting (XSS) in=
Profile Builder Pro <=3D 3.15.0 versions. 2026-06-17 7.1 CVE-2026-42385 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-42385 ] Cozy Vision Technologie=
s Pvt. Ltd.--SMS Alert Order Notifications Subscriber Privilege Escalation =
in SMS Alert Order Notifications <=3D 3.9.4 versions. 2026-06-17 9.8 CVE-20= 26-54803 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54803 ] Cozy Vision = Technologies Pvt. Ltd.--SMS Alert Order Notifications Unauthenticated Broke=
n Authentication in SMS Alert Order Notifications <=3D 3.9.3 versions. 2026= -06-17 7.5 CVE-2026-54802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-548=
02 ] craftcms--cms Craft CMS (composer package craftcms/cms) versions >=3D = 5.5.0 and <=3D 5.9.13 contain a remote code execution vulnerability in the = FieldsController::actionRenderCardPreview() method, which passes the fieldL= ayoutConfig POST parameter directly to Fields::createLayout() without calli=
ng Component::cleanseConfig(). An authenticated admin user can inject Yii2 = event handlers (e.g., 'on init' keys) via the fieldLayoutConfig parameter t=
o execute arbitrary PHP code and disclose sensitive information (such as en= vironment variables containing database credentials and CRAFT_SECURITY_KEY)=
. The issue is fixed in version 5.9.14. 2026-06-21 7.2 CVE-2026-56382 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-56382 ] Crawl4AI--Crawl4AI Crawl4A=
I before 0.8.7 contains an authentication bypass vulnerability due to a har= dcoded default JWT signing key in the Docker API server. Attackers who know=
the default key can forge valid authentication tokens for any user, bypass= ing authentication and gaining full access to protected functionality. 2026= -06-21 9.8 CVE-2026-56265 [
https://www.cve.org/CVERecord?id=3DCVE-2026-562=
65 ] Creative Themes--Blocksy Companion Pro Unauthenticated SQL Injection i=
n Blocksy Companion Pro < 2.1.29 versions. 2026-06-17 9.3 CVE-2026-39596 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-39596 ] Creative Themes--Blocks=
y Companion Pro Contributor Remote Code Execution (RCE) in Blocksy Companio=
n Pro <=3D 2.1.37 versions. 2026-06-17 9.9 CVE-2026-40783 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-40783 ] CRM Perks--Integration for ActiveCampa= ign and Contact Form 7, WPForms, Elementor, Ninja Forms Unauthenticated PHP=
Object Injection in Integration for ActiveCampaign and Contact Form 7, WPF= orms, Elementor, Ninja Forms <=3D 1.1.1 versions. 2026-06-15 9.8 CVE-2026-9= 691 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9691 ] CRM Perks--Integra= tion for Contact Form 7 and Constant Contact Unauthenticated PHP Object Inj= ection in Integration for Contact Form 7 and Constant Contact <=3D 1.1.6 ve= rsions. 2026-06-15 9.8 CVE-2026-49106 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-49106 ] CRM Perks--Integration for Contact Form 7 HubSpot Unauthen= ticated PHP Object Injection in Integration for Contact Form 7 HubSpot <=3D=
1.3.7 versions. 2026-06-15 9.8 CVE-2026-49763 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-49763 ] CRM Perks--Integration for Keap/infusionsoft and = Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Unauthenticated=
PHP Object Injection in Integration for Keap/infusionsoft and Contact Form=
7, WPForms, Elementor, Formidable, Ninja Forms <=3D 1.2.1 versions. 2026-0= 6-15 9.8 CVE-2026-49104 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49104=
] CRM Perks--Integration for Mailchimp and Contact Form 7, WPForms, Elemen= tor, Ninja Forms Unauthenticated PHP Object Injection in Integration for Ma= ilchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <=3D 1.1.8 vers= ions. 2026-06-15 9.8 CVE-2026-49765 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-49765 ] crm perks--Integration for Salesforce and Contact Form 7, WP= Forms, Elementor, Formidable, Ninja Forms Unauthenticated PHP Object Inject= ion in Integration for Salesforce and Contact Form 7, WPForms, Elementor, F= ormidable, Ninja Forms <=3D 1.4.3 versions. 2026-06-15 9.8 CVE-2026-49109 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-49109 ] CRM Perks--WP Insightl=
y for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Unauth= enticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms,=
Elementor, Formidable and Ninja Forms <=3D 1.1.4 versions. 2026-06-15 9.8 = CVE-2026-49085 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49085 ] CRM Pe= rks--WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninj=
a Forms Unauthenticated PHP Object Injection in WP Zendesk for Contact Form=
7, WPForms, Elementor, Formidable and Ninja Forms <=3D 1.1.4 versions. 202= 6-06-15 9.8 CVE-2026-49105 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49= 105 ] crmperks--Database for Contact Form 7, WPforms, Elementor forms The D= atabase for Contact Form 7, WPforms, Elementor forms plugin for WordPress i=
s vulnerable to arbitrary file deletion due to insufficient file path valid= ation in the view_page function in all versions up to, and including, 1.5.1=
. This makes it possible for unauthenticated attackers to delete arbitrary = files on the server, which can easily lead to remote code execution when th=
e right file is deleted (such as wp-config.php). Successful exploitation re= quires an administrator to view or edit the poisoned form entry, at which p= oint PHP's bracket parser reshapes the attacker-crafted JSON key to bypass = the stored-path isset check and trigger deletion of the traversal-specified=
file. 2026-06-20 8.1 CVE-2026-9843 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-9843 ] Crocoblock--JetEngine The JetEngine plugin for WordPress is v= ulnerable to SQL injection in all versions up to and including 3.8.10.1. Th=
e listing_load_more AJAX handler accepts a filtered_query parameter that is=
intentionally excluded from the HMAC query signature check to support fron= t-end filter integration. However, meta_query row values within filtered_qu= ery are not sanitized before being merged into SQL construction. This makes=
it possible for unauthenticated attackers to perform time-based or boolean=
blind SQL injection by appending a malicious meta_query value to a Load Mo=
re AJAX request captured from any public Listing Grid page. 2026-06-17 7.5 = CVE-2026-12360 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12360 ] CurlyT= hemes--Events Schedule - WordPress Events Calendar Plugin Subscriber SQL In= jection in Events Schedule - WordPress Events Calendar Plugin <=3D 2.7.2 ve= rsions. 2026-06-17 8.5 CVE-2025-69135 [
https://www.cve.org/CVERecord?id=3D= CVE-2025-69135 ] Dassault Systmes--SOLIDWORKS Visualize A Path Traversal vu= lnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release = 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to wri=
te arbitrary files on the server. 2026-06-17 9.8 CVE-2026-10094 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-10094 ] Datalogics--Datalogics Ecommerce=
Delivery Unauthenticated Privilege Escalation in Datalogics Ecommerce Deli= very <=3D 2.6.62 versions. 2026-06-15 9.8 CVE-2026-39583 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-39583 ] David Lingren--Media LIbrary Assistant = Improper Neutralization of Special Elements used in an SQL Command ('SQL In= jection') vulnerability in David Lingren Media LIbrary Assistant allows Bli=
nd SQL Injection. This issue affects Media LIbrary Assistant: from n/a thro= ugh 3.35. 2026-06-18 8.5 CVE-2026-56012 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56012 ] David Lingren--Media LIbrary Assistant Unauthenticated = Cross Site Scripting (XSS) in Media LIbrary Assistant <=3D 3.35 versions. 2= 026-06-16 7.1 CVE-2026-54198 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 54198 ] dbgate--dbgate DbGate is cross-platform database manager. In versio=
ns 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accept=
s a functionName parameter that is directly interpolated into a JavaScript = code template without any sanitization or validation. An authenticated user=
(with basic access, no special permissions required) can inject arbitrary = JavaScript code that executes on the server with full process privileges, b= ypassing the require=3Dnull sandbox restriction. An authenticated user with=
basic access (no admin role, no run-shell-script permission required) can:=
execute arbitrary OS commands on the DbGate server with the privileges of = the Node.js process, read/write any file accessible to the process, pivot t=
o connected databases by reading connection credentials from DbGate's stora= ge, and compromise the host system - in Docker deployments, this typically = means root access within the container. 2026-06-15 8.8 CVE-2026-48017 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-48017 ] deepstreamIO--deepstream.i=
o deepstream is a server that allows clients and backend services to sync d= ata, send messages and make rpcs at scale. Versions prior to 10.0.5 are vul= nerable to Prototype Pollution. Exploitation can lead to potential privileg=
e escalation from any authenticated user with write permission to any recor=
d. This issue has been fixed in version 10.0.5. 2026-06-18 9.9 CVE-2026-492=
52 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49252 ] Dell--AIOps Dell A= IOps Collector versions prior to 1.18.3 contain a "Use of Default Credentia= ls" vulnerability. A low privileged attacker with console access could pote= ntially exploit this vulnerability to gain Filesystem access. This vulnerab= ility only affects fresh installations of Collector versions earlier than 1= .18.3. Systems that have been upgraded (either manually or automatically) t=
o version 1.18.3 or later are not impacted, even if they were originally in= stalled on an earlier version. 2026-06-17 7.8 CVE-2026-32652 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-32652 ] Dell--Dell EMC VxRail Appliance upd= ate_disk_psu_baseline.sh requires password in plain text 2026-06-16 7.4 CVE= -2024-39575 [
https://www.cve.org/CVERecord?id=3DCVE-2024-39575 ] Dell--EMC=
VxRail Appliance api-gateway container running with root privilege would a= llow an attacker to escape the container and access host system to perform = unintended actions. 2026-06-16 7 CVE-2024-38487 [
https://www.cve.org/CVERe= cord?id=3DCVE-2024-38487 ] Dell--OpenManage Dell OpenManage Integration wit=
h Microsoft Windows Admin Center contains a Remote Code Execution vulnerabi= lity in the gateway plugin. A remote authenticated user could potentially e= xploit this vulnerability to escalate privileges. The malicious user may ga=
in the ability to run arbitrary code remotely. This is a high severity vuln= erability so Dell recommends customers to upgrade at the earliest opportuni= ty. 2026-06-16 8.8 CVE-2024-24909 [
https://www.cve.org/CVERecord?id=3DCVE-= 2024-24909 ] Dell--PowerFlex Dell PowerFlex Manager, version(s) [Versions],=
contain(s) an Improper Authentication vulnerability. An unauthenticated at= tacker with adjacent network access could potentially exploit this vulnerab= ility, leading to Unauthorized access. 2026-06-17 8.1 CVE-2026-32804 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-32804 ] Dell--PowerFlex Dell PowerF= lex Manager, version(s) [Versions], contain(s) a Missing Authentication for=
Critical Function vulnerability. An unauthenticated attacker with adjacent=
network access could potentially exploit this vulnerability, leading to Co=
de execution, Denial of service, Information disclosure, Information tamper= ing, Remote execution, Script injection, and Unauthorized access. 2026-06-1=
7 8.8 CVE-2026-35065 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35065 ] = Dell--PowerFlex Dell PowerFlex Manager, version(s) Version prior to 4.8, co= ntain(s) an Inclusion of Functionality from Untrusted Control Sphere vulner= ability. An unauthenticated attacker with remote access could potentially e= xploit this vulnerability, leading to Information disclosure. 2026-06-17 7.=
5 CVE-2026-22283 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22283 ] Dell= --PowerFlex Dell PowerFlex Manager, version(s) [Versions], contain(s) an Im= proper Access Control vulnerability. A low privileged attacker with remote = access could potentially exploit this vulnerability, leading to denial of s= ervice. 2026-06-17 7.1 CVE-2026-35066 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-35066 ] Dell--PowerFlex Dell PowerFlex Manager, version(s) [Versio= ns], contain(s) an Improper Authentication vulnerability. An unauthenticate=
d attacker with adjacent network access could potentially exploit this vuln= erability, leading to Information disclosure, Information tampering, and Un= authorized access. 2026-06-17 7.4 CVE-2026-49502 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-49502 ] Dell--Server Hardware Manager Dell Server Hardw= are Manager, versions prior to 3.2.2, contains an Improper Access Control v= ulnerability. A low privileged attacker with local access could potentially=
exploit this vulnerability, leading to Elevation of privileges. 2026-06-19=
7.8 CVE-2026-46461 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46461 ] D= ev4Press--GD Rating System Unauthenticated SQL Injection in GD Rating Syste=
m <=3D 3.6.2 versions. 2026-06-15 9.3 CVE-2026-42639 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-42639 ] Dimitri Grassi--Salon booking system Unauth= enticated Insecure Direct Object References (IDOR) in Salon booking system = <=3D 10.30.24 versions. 2026-06-17 7.3 CVE-2026-40768 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-40768 ] Dimitri Grassi--Salon booking system Unaut= henticated Broken Access Control in Salon booking system <=3D 10.30.25 vers= ions. 2026-06-15 7.5 CVE-2026-42666 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-42666 ] Discuz!--Discuz! X5.0 Discuz! X5.0 releases 20260320 through=
20260501 contains an authentication bypass vulnerability that allows unaut= henticated remote attackers to gain unauthorized access to database backup = and restore functionality by exploiting a shared cryptographic key between = UCenter integration and the database backup API exposed by dbbak.php. Attac= kers can inject a crafted payload through the username parameter during log=
in to abuse the encryption oracle in logging_ctl::logging_more(), obtain a = legitimately signed token, and use it to bypass authorization for database = export and import operations, with the additional ability to trigger a race=
condition to impersonate arbitrary users. 2026-06-15 9.1 CVE-2026-49952 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-49952 ] Discuz!--Discuz! X5.0 D= iscuz! X5.0 releases 20260320 through 20260610 contain a local file inclusi=
on vulnerability that allows authenticated administrators to execute arbitr= ary code by importing a specially crafted plugin configuration containing p= ath traversal sequences in the directory attribute. Attackers can trigger a=
n exception during plugin installation to bypass sanitization routines, cau= sing malicious paths to be stored unsanitized and subsequently passed to in= clude(), which combined with file upload functionality escalates to arbitra=
ry code execution in the context of the web server user. 2026-06-15 7.2 CVE= -2026-49954 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49954 ] Dokan, In= c.--Dokan Customer Privilege Escalation in Dokan <=3D 5.0.2 versions. 2026-= 06-15 8.8 CVE-2026-49780 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4978=
0 ] doobidoo--mcp-memory-service mcp-memory-service is a semantic memory la= yer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC en= dpoint at `/mcp` requires only OAuth `read` scope for all requests, then di= spatches `tools/call` directly to handlers that include mutating tools. A r= ead-only OAuth client can call `store_memory` and `delete_memory` through M=
CP even though the corresponding REST endpoints require `write` scope. Vers= ion 10.65.3 patches the issue. 2026-06-19 8.1 CVE-2026-49291 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-49291 ] DVDFab--Virtual Drive A security vu= lnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is =
an unknown function in the library dvdfabio.sys of the component Signed Ker= nel Driver. The manipulation leads to improper privilege management. An att= ack has to be approached locally. The exploit has been disclosed publicly a=
nd may be used. The vendor was contacted early about this disclosure but di=
d not respond in any way. 2026-06-15 7.8 CVE-2026-12217 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-12217 ] dwbooster--Booking Calendar Contact Word= Press appointment-booking-calendar 1.1.24 contains multiple privilege escal= ation vulnerabilities that allow unauthenticated attackers to modify calend=
ar settings and inject persistent cross-site scripting payloads through the=
admin.php page parameters. Attackers can inject malicious JavaScript into = the 'ict' and 'ics' options or the calendar 'name' parameter via GET reques=
ts to execute arbitrary scripts when the calendar is displayed or accessed =
in the administration interface. 2026-06-15 7.2 CVE-2016-20084 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2016-20084 ] dwbooster--Booking Calendar Conta=
ct Form WordPress Booking Calendar Contact Form version 1.0.23 contains an = unauthenticated blind SQL injection vulnerability that allows remote attack= ers to execute arbitrary SQL queries by injecting malicious code through th=
e 'id' parameter. Attackers can send requests to the admin-ajax.php endpoin=
t with the action parameter set to 'dex_bccf_calendar_ajaxevent' and supply=
crafted SQL commands in the 'id' parameter to extract sensitive database i= nformation. 2026-06-15 8.2 CVE-2016-20068 [
https://www.cve.org/CVERecord?i= d=3DCVE-2016-20068 ] dwbooster--Booking Calendar Contact Form WordPress Boo= king Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL inj= ection vulnerability in the shortcode function that fails to sanitize the c= alendar parameter before using it in database queries. Attackers can inject=
SQL commands through the calendar shortcode parameter to execute arbitrary=
SQL queries and extract sensitive database information. 2026-06-15 8.2 CVE= -2016-20069 [
https://www.cve.org/CVERecord?id=3DCVE-2016-20069 ] dwbooster= --CP Polls WordPress CP Polls 1.0.8 contains a persistent cross-site script= ing vulnerability that allows attackers to inject malicious scripts through=
unsanitized file upload functionality. Attackers can upload files containi=
ng script payloads with event handlers like onerror attributes to execute a= rbitrary JavaScript in the browsers of users viewing the affected content. = 2026-06-15 7.2 CVE-2016-20066 [
https://www.cve.org/CVERecord?id=3DCVE-2016= -20066 ] Dylan Kuhn--Geo Mashup Subscriber SQL Injection in Geo Mashup <=3D=
1.13.19 versions. 2026-06-17 8.5 CVE-2026-48967 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-48967 ] e107inc--e107 e107 is a content management syst=
em (CMS). Versions 2.3.5 and earlier contain a command injection vulnerabil= ity in the ImageMagick resize destination path. In resize_image(), the sour=
ce path is escaped with escapeshellarg(), but the destination path is inser= ted inside raw double quotes in the convert command; in the submit-news upl= oad flow, that destination filename includes the first six characters of us= er-controlled news title input. Because the title filter removes literal sp= aces but not tab characters, and shell expansions such as $(...) and backti= cks can survive into the quoted destination argument, /bin/sh -c may evalua=
te attacker-controlled input. Exploitation is possible only when all of the=
following non-default settings are enabled: resize_method=3DImageMagick, s= ubnews_attach=3D1, upload_enabled=3D1, subnews_resize is numeric between 30=
and 5000, and the attacker is a non-admin in classes permitted by both sub= news_class and upload_class. This issue has been fixed in version 2.3.6. 20= 26-06-17 7.1 CVE-2026-48997 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 8997 ] e4jvikwp--VikRentCar Unauthenticated Insecure Direct Object Referenc=
es (IDOR) in VikRentCar <=3D 1.4.5 versions. 2026-06-15 7.5 CVE-2026-52699 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-52699 ] EaseUS--Partition Mas= ter A vulnerability was identified in EaseUS Partition Master up to 14.5. T=
he affected element is an unknown function in the library epmntdrv.sys of t=
he component Kernel Driver. The manipulation leads to improper access contr= ols. The attack needs to be performed locally. The exploit is publicly avai= lable and might be used. You should upgrade the affected component. The ven= dor explains: "We have confirmed that this issue was present only in older = versions of the product. Our product has since been updated, and the issue = has been resolved in the latest version, so it no longer exists." 2026-06-2=
1 7.8 CVE-2026-12781 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12781 ] = EaseUS--Partition Master A security flaw has been discovered in EaseUS Part= ition Master up to 14.5. The impacted element is an unknown function in the=
library EUEDKEPM.sys of the component Kernel Driver. The manipulation resu= lts in improper access controls. The attack requires a local approach. The = exploit has been released to the public and may be used for attacks. The af= fected component should be upgraded. The vendor explains: "We have confirme=
d that this issue was present only in older versions of the product. Our pr= oduct has since been updated, and the issue has been resolved in the latest=
version, so it no longer exists." 2026-06-21 7.8 CVE-2026-12782 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-12782 ] Easy Appointments--Easy Appoint= ments Unauthenticated Broken Access Control in Easy Appointments <=3D 3.12.=
21 versions. 2026-06-15 7.5 CVE-2026-39513 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-39513 ] Eclipse Foundation--Eclipse ThreadX - NetX Duo The se= curity fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error ha= ndling in the HTTP server PUT process to use a shared cleanup label, but th=
is unified cleanup path unconditionally calls=C2=A0fx_file_close()=C2=A0eve=
n when the file was never successfully opened. Multiple error branches jump=
to the shared cleanup label before any file open operation has occurred, c= ausing=C2=A0fx_file_close()=C2=A0to operate on an uninitialized file handle=
, leading to undefined behavior, double-close issues, or memory corruption.=
2026-06-19 7.5 CVE-2026-11576 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-11576 ] Edgar Rojas--WooCommerce PDF Invoice Builder Improper Control of = Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooComme= rce PDF Invoice Builder allows Remote Code Inclusion. This issue affects Wo= oCommerce PDF Invoice Builder: from n/a through 2.0.8. 2026-06-15 10 CVE-20= 26-52704 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52704 ] Edge-Themes-= -Alloggio - Hotel Booking Unauthenticated PHP Object Injection in Alloggio =
- Hotel Booking <=3D 2.1.2 versions. 2026-06-16 8.1 CVE-2026-39539 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-39539 ] Edge-Themes--Behold Unauthent= icated PHP Object Injection in Behold <=3D 1.5 versions. 2026-06-16 8.1 CVE= -2026-40760 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40760 ] Edge-Them= es--Eldon Unauthenticated PHP Object Injection in Eldon <=3D 1.4.1 versions=
. 2026-06-17 8.1 CVE-2026-40738 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-40738 ] Edge-Themes--Laurits Unauthenticated PHP Object Injection in Lau= rits <=3D 1.5.1 versions. 2026-06-16 8.1 CVE-2026-40736 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-40736 ] Edge-Themes--Reina Unauthenticated PHP O= bject Injection in Reina <=3D 2.1 versions. 2026-06-17 8.1 CVE-2026-40735 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-40735 ] Edge-Themes--Valeska U= nauthenticated PHP Object Injection in Valeska <=3D 1.2.2 versions. 2026-06= -16 8.1 CVE-2026-40761 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40761 =
] Edimax--BR-6478AC V2 A vulnerability has been found in Edimax BR-6478AC V=
2 1.23. The impacted element is the function formWlSiteSurvey of the file /= goform/formWlSiteSurvey of the component POST Request Handler. The manipula= tion of the argument selSSID leads to buffer overflow. It is possible to in= itiate the attack remotely. The exploit has been disclosed to the public an=
d may be used. The vendor was contacted early about this disclosure but did=
not respond in any way. 2026-06-21 8.8 CVE-2026-12806 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12806 ] eemitch--Simple File List The Simple File=
List plugin for WordPress is vulnerable to arbitrary file deletion due to = insufficient file path validation in the eeSFL_DeleteFile function in all v= ersions up to, and including, 6.3.7. This makes it possible for unauthentic= ated attackers to delete arbitrary files on the server, which can easily le=
ad to remote code execution when the right file is deleted (such as wp-conf= ig.php). The simplefilelist_edit_job AJAX action is registered via wp_ajax_= nopriv_, making it accessible without authentication, and the is_admin() gu= ard that would otherwise restrict access is bypassed because is_admin() alw= ays returns true for requests to the admin-ajax.php endpoint. 2026-06-20 7.=
5 CVE-2026-11911 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11911 ] eemi= tch--Simple File List The Simple File List plugin for WordPress is vulnerab=
le to arbitrary file modification due to insufficient authorization checks =
in all versions up to, and including, 6.3.7. This makes it possible for una= uthenticated attackers to delete and modify files on the serve. This vulner= ability is exploitable even when the administrator has not enabled the Allo= wFrontManage setting, because the is_admin() check unconditionally short-ci= rcuits the guard before that setting is evaluated. 2026-06-20 7.5 CVE-2026-= 11912 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11912 ] Elated-Themes--= Aperitif Unauthenticated Local File Inclusion in Aperitif <=3D 1.5 versions=
. 2026-06-16 8.1 CVE-2026-39549 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-39549 ] Elated-Themes--Fidalgo Unauthenticated PHP Object Injection in F= idalgo <=3D 1.2.2 versions. 2026-06-16 8.1 CVE-2026-39554 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-39554 ] Elated-Themes--Konsept Unauthenticated=
PHP Object Injection in Konsept <=3D 1.9 versions. 2026-06-17 8.1 CVE-2026= -39556 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39556 ] Elated-Themes-= -Lonie Unauthenticated PHP Object Injection in L=C3=83=C2=A9onie <=3D 1.2.1=
versions. 2026-06-16 8.1 CVE-2026-40758 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-40758 ] Elated-Themes--Malm Unauthenticated Local File Inclusio=
n in Malm=C3=83=C2=B6 <=3D 2.2 versions. 2026-06-17 8.1 CVE-2026-39558 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-39558 ] Elated-Themes--Mr. SEO Un= authenticated Local File Inclusion in Mr. SEO <=3D 2.0 versions. 2026-06-16=
8.1 CVE-2026-39568 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39568 ] E= lated-Themes--NeoBeat Unauthenticated PHP Object Injection in NeoBeat <=3D = 1.7 versions. 2026-06-16 8.1 CVE-2026-39557 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-39557 ] Elated-Themes--Playroom Unauthenticated PHP Object I= njection in Playroom <=3D 1.4.1 versions. 2026-06-16 8.1 CVE-2026-39577 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-39577 ] Elated-Themes--Roisin Un= authenticated PHP Object Injection in Roisin <=3D 1.4 versions. 2026-06-16 = 8.1 CVE-2026-40754 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40754 ] El= ated-Themes--SingleMalt Unauthenticated PHP Object Injection in SingleMalt = <=3D 1.5 versions. 2026-06-17 8.1 CVE-2026-39576 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-39576 ] Elated-Themes--Solene Unauthenticated Local Fil=
e Inclusion in Solene <=3D 3.4 versions. 2026-06-16 8.1 CVE-2026-39522 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-39522 ] Elated-Themes--Solene Cor=
e Unauthenticated Local File Inclusion in Solene Core <=3D 2.3.2 versions. = 2026-06-17 8.1 CVE-2026-39523 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -39523 ] Elated-Themes--Valiance Unauthenticated PHP Object Injection in Va= liance <=3D 1.2 versions. 2026-06-16 8.1 CVE-2026-39578 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-39578 ] ELEXtensions--ELEX WordPress HelpDesk & = Customer Ticketing System Subscriber SQL Injection in ELEX WordPress HelpDe=
sk & Customer Ticketing System <=3D 3.3.6 versions. 2026-06-15 8.5 CVE-2026= -48964 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48964 ] Eli Scheetz--A= nti-Malware Security and Brute-Force Firewall Contributor PHP Object Inject= ion in Anti-Malware Security and Brute-Force Firewall <=3D 4.23.87 versions=
. 2026-06-15 8.8 CVE-2026-39478 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-39478 ] Eli--Eli's WordCents adSense Widget with Analytics Unauthenticat=
ed Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with A= nalytics <=3D 1.3.03.27 versions. 2026-06-15 7.1 CVE-2025-68872 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2025-68872 ] Emraan Cheema--ListingPro Unauth= enticated SQL Injection in ListingPro <=3D 2.9.10 versions. 2026-06-16 9.3 = CVE-2026-39438 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39438 ] EMV--C= reatify Deserialization of Untrusted Data vulnerability in EMV Creatify all= ows Object Injection. This issue affects Creatify: from n/a through 1.5. 20= 26-06-17 9.8 CVE-2025-60236 [
https://www.cve.org/CVERecord?id=3DCVE-2025-6= 0236 ] EMV--JobBank Missing Authorization vulnerability in EMV JobBank allo=
ws Exploiting Incorrectly Configured Access Control Security Levels. This i= ssue affects JobBank: from n/a through 1.2.3. 2026-06-17 7.3 CVE-2025-69189=
[
https://www.cve.org/CVERecord?id=3DCVE-2025-69189 ] EMV--JobCareer Impro= per Limitation of a Pathname to a Restricted Directory ('Path Traversal') v= ulnerability in EMV JobCareer allows Path Traversal. This issue affects Job= Career: from n/a through 7.3. 2026-06-17 8.6 CVE-2025-69128 [
https://www.c= ve.org/CVERecord?id=3DCVE-2025-69128 ] EMV--The Hospital Deserialization of=
Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object=
Injection. This issue affects The Hospital: from n/a through 1.8.1. 2026-0= 6-17 9.8 CVE-2025-60231 [
https://www.cve.org/CVERecord?id=3DCVE-2025-60231=
] envoyproxy--envoy Envoy is an open source edge and service proxy designe=
d for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3,=
and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processin=
g allows an unauthenticated remote client to trigger excessive memory consu= mption, potentially resulting in OOM termination of the Envoy process and d= enial of service. The issue arises from the combination of two behaviors. F= irst, cookie header bytes are not fully accounted for during request header=
size validation in Envoy. Second, HPACK header block limits in oghttp2/qui= che are enforced on encoded bytes without a corresponding limit on total de= coded header size. Together, these behaviors allow a malicious client to ca= use large decoded header allocations while bypassing the intended request h= eader size protections. Versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1 contai=
n a fix. No complete workaround is known short of applying a fix. Possible = temporary mitigations include disabling downstream HTTP/2 where operational=
ly feasible; enforcing stricter request header and cookie limits before tra= ffic reaches Envoy; and monitoring Envoy memory usage for abnormal growth u= nder HTTP/2 traffic. 2026-06-17 7.5 CVE-2026-47774 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-47774 ] error311--FileRise FileRise before 3.16.0 is = vulnerable to path traversal in the shared-folder upload endpoint (/api/fol= der/uploadToSharedFolder.php), leading to arbitrary file write and administ= rator account takeover. The upload filename is validated by FolderControlle=
r with basename() and REGEX_FILE_NAME, which permit URL-encoded sequences (= the regex blocks / and \ but not %). The raw filename is then passed to Upl= oadModel::handleUpload, where it is reconstructed as trim(urldecode(basenam= e($fileName))), re-introducing path separators after validation (e.g. ..%2f= users%2fusers.txt becomes ../users/users.txt). UploadNamePolicy::isAllowedF= orWrite() applies basename() internally and therefore only evaluates the fi= nal component (users.txt), allowing the traversal sequence to pass the exte= nsion policy. The destination path is then used directly in move_uploaded_f= ile() with no realpath containment check, allowing a write outside the inte= nded upload directory. An attacker who possesses a valid, non-expired, uplo= ad-enabled shared-folder link/token (which are designed to be shared public= ly) can overwrite users/users.txt to create an administrator account, resul= ting in unauthenticated admin takeover and, depending on configuration, rem= ote code execution. Exploitation requires possession of a valid, non-expire=
d, upload-enabled shared-folder link/token. This issue is fixed in 3.16.0, = which URL-decodes before validation and rejects any path separators in the = upload filename. 2026-06-19 9.8 CVE-2026-54414 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-54414 ] Etoilewebdesign--Ultimate Product Catalog WordPre=
ss Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnera= bility that allows authenticated users with contributor, editor, author, or=
administrator roles to upload malicious files by exploiting the custom fie= lds functionality. Attackers can upload PHP shells through the Products tab=
custom file field and access them via the upcp-product-file-uploads direct= ory to execute arbitrary code on the server. 2026-06-15 8.8 CVE-2016-20075 =
[
https://www.cve.org/CVERecord?id=3DCVE-2016-20075 ] EventPrime--EventPrim=
e Unauthenticated PHP Object Injection in EventPrime <=3D 4.3.2.1 versions.=
2026-06-15 8.1 CVE-2026-42687 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-42687 ] EventPrime--EventPrime Subscriber Insecure Direct Object Referenc=
es (IDOR) in EventPrime <=3D 4.3.0.0 versions. 2026-06-15 7.1 CVE-2026-3951=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39518 ] EventPrime--EventPr= ime Subscriber Cross Site Scripting (XSS) in EventPrime <=3D 4.3.2.1 versio= ns. 2026-06-15 7.1 CVE-2026-42686 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-42686 ] ExpressTech--Quiz And Survey Master Unauthenticated Cross Site=
Scripting (XSS) in Quiz And Survey Master <=3D 11.0.0 versions. 2026-06-15=
7.1 CVE-2026-40787 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40787 ] E= xpressTech--Quiz And Survey Master Unauthenticated Cross Site Scripting (XS=
S) in Quiz And Survey Master <=3D 11.1.2 versions. 2026-06-15 7.1 CVE-2026-= 48867 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48867 ] Extendons--Word= Press & WooCommerce Scraper Plugin, Import Data from Any Site Unauthenticat=
ed Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import = Data from Any Site <=3D 1.0.7 versions. 2026-06-17 10 CVE-2025-69129 [ http= s://www.cve.org/CVERecord?id=3DCVE-2025-69129 ] extendons--WordPress & WooC= ommerce Scraper Plugin, Import Data from Any Site Unauthenticated Arbitrary=
File Download in WordPress & WooCommerce Scraper Plugin, Import Data from = Any Site <=3D 1.0.7 versions. 2026-06-16 7.5 CVE-2025-69131 [
https://www.c= ve.org/CVERecord?id=3DCVE-2025-69131 ] Extensions--Joomla Payage Joomla Pay= age 2.05 contains an SQL injection vulnerability that allows unauthenticate=
d attackers to manipulate database queries by injecting SQL code through th=
e aid parameter. Attackers can send GET requests to index.php with maliciou=
s aid values in the make_payment task to extract sensitive database informa= tion using boolean-based blind or time-based blind techniques. 2026-06-19 8=
.2 CVE-2017-20279 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20279 ] Ext= ro--RPC Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL in= jection vulnerability that allows unauthenticated attackers to execute arbi= trary SQL queries by injecting malicious code through the id parameter. Att= ackers can send GET requests to index.php with option=3Dcom_pofos&view=3Dpo= fo&id=3D[SQL] to extract sensitive database information. 2026-06-19 8.2 CVE= -2017-20258 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20258 ] Eyal Fito= ussi--GEO my WordPress Unauthenticated SQL Injection in GEO my WordPress <=
=3D 4.5.5 versions. 2026-06-16 9.3 CVE-2026-52715 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-52715 ] EyeCix Technologies--JobSearch Unauthenticated=
Broken Access Control in JobSearch <=3D 3.2.7 versions. 2026-06-16 7.5 CVE= -2026-49057 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49057 ] eyecix--J= obSearch Unauthenticated SQL Injection in JobSearch <=3D 3.2.9 versions. 20= 26-06-17 9.3 CVE-2026-54186 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 4186 ] Ezbsystems--UltraISO Premium Edition A vulnerability has been found =
in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue i=
s some unknown functionality in the library bootpt64.sys of the component K= ernel Driver. The manipulation leads to improper access controls. Local acc= ess is required to approach this attack. The exploit has been disclosed to = the public and may be used. The vendor was contacted early about this discl= osure but did not respond in any way. 2026-06-21 7.8 CVE-2026-12786 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-12786 ] F5--NGINX Gateway Fabric Whe=
n NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an i= njection vulnerability exists in the NGINX configuration generator componen=
t of NGINX Gateway Fabric. User-supplied string values from the NginxProxy= =C2=A0Custom Resource Definition serverTokens=C2=A0field and the Authentica= tionFilter=C2=A0Custom Resource Definition extraAuthArgs=C2=A0field are ren= dered directly into NGINX configuration templates without sanitization or e= scaping. An authenticated attacker with permission to create or modify thes=
e Custom Resource Definitions may craft values that inject arbitrary NGINX = configuration directives. This is a control plane issue; there is no data p= lane exposure from the vulnerability trigger itself. Note: Software version=
s which have reached End of Technical Support (EoTS) are not evaluated. 202= 6-06-17 8.1 CVE-2026-11311 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11= 311 ] F5--NGINX Gateway Fabric When NGINX Plus or NGINX Open Source is conf= igured as the data plane for NGINX Gateway Fabric, an injection vulnerabili=
ty exists in the NGINX configuration generator component of NGINX Gateway F= abric. User-supplied string values from the NginxProxy=C2=A0Custom Resource=
Definition (CRD) access log format setting are rendered directly into NGIN=
X configuration templates without sanitization or escaping. An authenticate=
d attacker with permission to create or modify these CRDs may craft values = that inject arbitrary NGINX configuration directives. This is a control pla=
ne issue; there is no data plane exposure from the vulnerability trigger it= self. Note: Software versions which have reached End of Technical Support (= EoTS) are not evaluated. 2026-06-17 8.1 CVE-2026-50107 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-50107 ] F5--NGINX Open Source NGINX Plus and NGIN=
X Open Source have a vulnerability in the ngx_http_proxy_v2_module=C2=A0and=
ngx_http_grpc_module=C2=A0modules. This vulnerability exists when the prox= y_http_version to 2=C2=A0or grpc_pass=C2=A0directives are used to proxy HTT= P/2 traffic, the ignore_invalid_headers=C2=A0directive is set to off, and t=
he large_client_header_buffers=C2=A0directive size is larger than 2 megabyt= es. A remote, unauthenticated attacker, along with conditions beyond their = control, could send large headers while creating an upstream request. This = may cause a heap-based buffer overflow in the NGINX worker process leading =
to a restart. Additionally, attackers can execute code on systems with Addr= ess Space Layout Randomization (ASLR) disabled or when the attacker can byp= ass ASLR. Note: Software versions which have reached End of Technical Suppo=
rt (EoTS) are not evaluated. 2026-06-17 8.1 CVE-2026-42055 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-42055 ] F5--NGINX Open Source NGINX Open Sour=
ce has a vulnerability in the ngx_http_v3_module=C2=A0module. When NGINX Op=
en Source is configured to use the HTTP/3 QUIC module, a remote unauthentic= ated attacker along with conditions beyond their control can use a speciall=
y crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a=
Use-after-Free in the NGINX worker process leading to a restart. Additiona= lly, attackers can execute code on systems with Address Space Layout Random= ization (ASLR) disabled or when the attacker can bypass ASLR. Note: Softwar=
e versions which have reached End of Technical Support (EoTS) are not evalu= ated. 2026-06-17 8.1 CVE-2026-42530 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-42530 ] Faboba--Ultimate Property Listing Joomla Ultimate Property L= isting 1.0.2 contains an SQL injection vulnerability that allows unauthenti= cated attackers to execute arbitrary SQL queries by injecting malicious cod=
e through the sf_selectuser_id parameter. Attackers can send GET requests t=
o index.php with the option=3Dcom_upl and view=3Dpropertylisting parameters=
to extract sensitive database information including table names and column=
structures. 2026-06-19 8.2 CVE-2017-20272 [
https://www.cve.org/CVERecord?= id=3DCVE-2017-20272 ] FFmpeg--FFmpeg An out-of-bounds write vulnerability i=
n FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows=
denial-of-service and, in some cases, can be exploited for remote code exe= cution. This vulnerability is associated with the file libavcodec/magicyuv.=
C. This issue affects FFmpeg before version 8.1.2. 2026-06-18 8.8 CVE-2026-= 8461 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8461 ] fgmacedo--python-= statemachine Python StateMachine versions 3.0.0 before 3.2.0 contains a rem= ote code execution vulnerability that allows attackers to execute arbitrary=
code by supplying malicious SCXML documents containing crafted `<data expr= =3D"...">` attributes evaluated unsafely. The SCXMLProcessor passes attacke= r-controlled expression strings through a call chain ending in Python's bui= lt-in eval() without sandboxing, enabling arbitrary code execution in the c= ontext of the hosting process. 2026-06-17 9.8 CVE-2026-47103 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-47103 ] Filipe Nasc--RD Station Improper Co= ntrol of Generation of Code ('Code Injection') vulnerability in Filipe Nasc=
RD Station allows Remote Code Inclusion. This issue affects RD Station: fr=
om n/a through 5.6.0. 2026-06-16 9.9 CVE-2026-49774 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-49774 ] Flipper Code WordPress Development Company--=
WP Maps Unauthenticated SQL Injection in WP Maps <=3D 4.9.1 versions. 2026-= 06-15 9.3 CVE-2026-39492 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3949=
2 ] Flowise--Flowise Flowise before 2.1.4 allows configuration to be inject=
ed into the Chainflow during execution via the overrideConfig option, suppo= rted in both the frontend web integration and the backend Prediction API. B= ecause this feature is enabled by default with no allow-list of permitted v= ariables and relies on vm2 for sandboxing, an attacker can abuse it to achi= eve remote code execution and sandbox escape, denial of service by crashing=
the server, server-side request forgery, prompt injection, and server vari= able and data exfiltration. These issues are self-targeted and do not persi=
st to other users. 2026-06-20 9.8 CVE-2024-58351 [
https://www.cve.org/CVER= ecord?id=3DCVE-2024-58351 ] Focalpointx--FocalPoint Pro / Free Joomla! Comp= onent FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability tha=
t allows unauthenticated attackers to execute arbitrary SQL queries by inje= cting malicious code through the id parameter. Attackers can send GET reque= sts to index.php with option=3Dcom_focalpoint, view=3Dlocation, and a craft=
ed id parameter containing SQL commands to extract sensitive database infor= mation. 2026-06-19 8.2 CVE-2017-20263 [
https://www.cve.org/CVERecord?id=3D= CVE-2017-20263 ] forem--forem Forem is open source software for building co= mmunities. Prior to commit a2ab6d4, a maliciously crafted email address cou=
ld allow an attacker to bypass domain allowlist or denylist restrictions an=
d gain access to invite-only forem deployments. The issue is patched as of = `a2ab6d4`. As a workaround, some SMTP servers and email delivery providers = may drop or refuse to send maliciously crafted email addresses. 2026-06-16 = 8.2 CVE-2026-48780 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48780 ] Fo= rtra--Core Privileged Access Manager (BoKS) Fortra's=C2=A0 Core Privileged = Access Manager (BoKS)=C2=A0contains an OS command injection vulnerability i=
n the boks_autoregisterd service. A remote attacker with network access to = the service may be able to cause commands to be executed with the privilege=
s of the service during the autoregistration processing. 2026-06-15 9.8 CVE= -2026-9862 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9862 ] Fortra--Cor=
e Privileged Access Manager (BoKS) Fortra BoKS Manager contains an OS comma=
nd injection vulnerability in the client upgrade and patch tooling for lega=
cy tar-based client installations. A malicious or compromised legacy tar-in= stalled client selected for upgrade or patching may be able to cause comman=
ds to be executed on the BoKS Master during client version handling. 2026-0= 6-15 7.5 CVE-2026-9863 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9863 ]=
Foxit Software Inc.--Foxit AI When the application executes the JavaScript=
script embedded in the PDF within the sandbox, it fails to intercept some = dangerous interfaces, which allows remote scripts to be loaded, resulting i=
n arbitrary code execution. 2026-06-15 8.6 CVE-2026-12057 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12057 ] fs-code--Booknetic Unauthenticated Bro= ken Authentication in Booknetic <=3D 4.8.5 versions. 2026-06-17 8.1 CVE-202= 6-25439 [
https://www.cve.org/CVERecord?id=3DCVE-2026-25439 ] FunnelKit--Fu= nnel Builder by FunnelKit Unauthenticated SQL Injection in Funnel Builder b=
y FunnelKit <=3D 3.15.0.1 versions. 2026-06-15 9.3 CVE-2026-42381 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-42381 ] FunnelKit--Funnel Builder by F= unnelKit Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by Fu= nnelKit <=3D 3.15.0.2 versions. 2026-06-15 7.1 CVE-2026-48966 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-48966 ] Gegabyte--My Projects Joomla! Comp= onent My Projects 2.0 contains an SQL injection vulnerability that allows u= nauthenticated attackers to execute arbitrary SQL queries by injecting mali= cious code through the VerAyari parameter. Attackers can craft requests to = the component endpoint with SQL injection payloads to extract sensitive dat= abase information including credentials and system data. 2026-06-19 8.2 CVE= -2017-20253 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20253 ] Gegabyte-= -User Bench Joomla! Component User Bench 1.0 contains an SQL injection vuln= erability that allows unauthenticated attackers to execute arbitrary SQL qu= eries by injecting malicious code through the userid parameter. Attackers c=
an send GET requests to index.php with the option=3Dcom_userbench&view=3Dde= tail&userid parameter containing SQL injection payloads to extract sensitiv=
e database information including credentials and configuration data. 2026-0= 6-19 8.2 CVE-2017-20254 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20254=
] geoserver--org.geoserver.extension:gs-db2 GeoServer is an open source se= rver that allows users to share and edit geospatial data. Prior to version = 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perfo=
rm a JNDI attack through specially crafted DB2 jdbc url leading to to Remot=
e Code Execution (RCE). Version 2.27.0 fixes the issue. 2026-06-18 7.2 CVE-= 2025-27511 [
https://www.cve.org/CVERecord?id=3DCVE-2025-27511 ] geoserver-= -org.geoserver.web:gs-web-app GeoServer is an open source server that allow=
s users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2= 7.3, a vulnerability exists that allows an authenticated administrator with=
access to GeoServer's security system to pass arbitrary file names to the = Master Password Dump web page and create files containing the master passwo=
rd in plaintext. The provided file name must be an absolute path to the tar= get file, the target file can not already exist and all parent directories = must already exist. Versions 2.26.4 and 2.27.3 contain a fix. GeoServer ins= tallations where the web interface is either disabled or completely removed=
are not affected since the vulnerability exists in one of the web pages. 2= 026-06-18 7.2 CVE-2025-52465 [
https://www.cve.org/CVERecord?id=3DCVE-2025-= 52465 ] gitroomhq--postiz-app Postiz is an AI social media scheduling tool.=
In versions prior to 2.21.8, the Skool integration callback signed an atta= cker-controlled JSON blob into a session-shape JWT using the application's = JWT_SECRET, and the auth middleware trusted every claim in that JWT without=
re-resolving the user from the database. Any authenticated Postiz user cou=
ld forge a SUPERADMIN session and impersonate arbitrary organizations. This=
allowed Full Access to the following: all parts of Postiz, including users=
registered to the specific instance and the ability to post in the name of=
the victim's social media channels added to that Postiz instance. This iss=
ue has been fixed in version 2.21.8. 2026-06-16 9.9 CVE-2026-48781 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-48781 ] Glen Don Mongaya--Drag and Dr=
op Multiple File Upload Contact Form 7 Unauthenticated Cross Site Scripting=
(XSS) in Drag and Drop Multiple File Upload - Contact Form 7 <=3D 1.3.9.7 = versions. 2026-06-15 7.1 CVE-2026-49055 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49055 ] Government Accountability Office--Electronic Protest Do= cketing System (EPDS) The U.S. Government Accountability Office (GAO) Elect= ronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeal=
s (CBCA) Electronic Docketing System (EDS) does not authenticate password c= hange requests to the '/update-profile/N' API endpoint. A remote, unauthent= icated attacker could change an arbitrary user's password. 2026-06-18 9.8 C= VE-2026-54103 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54103 ] Governm= ent Accountability Office--Electronic Protest Docketing System (EPDS) The U= .S. Government Accountability Office (GAO) Electronic Protest Docketing Sys= tem (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketi=
ng System (EDS) trusts client-provided values for the 'epds_role_id' parame= ter without verification, allowing a remote, authenticated attacker to esca= late their own privileges. 2026-06-18 8.8 CVE-2026-54104 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-54104 ] Groundhogg--Groundhogg Sales Representa= tive Arbitrary File Deletion in Groundhogg <=3D 4.4 versions. 2026-06-15 7.=
7 CVE-2026-40727 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40727 ] Grou= ndhogg--HollerBox Unauthenticated Cross Site Scripting (XSS) in HollerBox <= =3D 2.3.10.1 versions. 2026-06-15 7.1 CVE-2026-48885 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-48885 ] Hakan Ozevin--WP BASE Booking Unauthenticat=
ed Privilege Escalation in WP BASE Booking <=3D 5.9.0 versions. 2026-06-15 = 8.1 CVE-2026-39587 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39587 ] Ha= ppyforms--Happyforms Unauthenticated PHP Object Injection in Happyforms <=
=3D 1.26.13 versions. 2026-06-15 9.8 CVE-2026-49768 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-49768 ] haproxy--haproxy HAProxy through 3.4.0, fixe=
d in commit 5985276, contains an integer overflow vulnerability in the fcgi= _conn structure's drl field that allows buffer misparse as new FCGI record = headers. When contentLength is 65535 and paddingLength is 1 or more, the dr=
l field wraps to 0, causing incorrect record consumption and allowing malic= ious FastCGI backends to desynchronize the FCGI framing parser, potentially=
causing request routing errors, response smuggling, or memory safety issue=
s. 2026-06-18 7.5 CVE-2026-55203 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-55203 ] haproxy--haproxy HAProxy through 3.4.0, fixed in commit 9a6d1fe=
, contains a null pointer dereference vulnerability in hpack_dht_insert() w= ithin src/hpack-tbl.c that fails to validate the return value of hpack_dht_= defrag() when the memory pool is exhausted. An attacker can trigger HPACK d= ynamic table insertions under memory pressure to dereference a NULL pointer=
and crash HAProxy worker processes, causing denial of service. 2026-06-18 = 7.5 CVE-2026-55204 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55204 ] ha= rttle--liquidjs LiquidJS is a Shopify/GitHub Pages compatible template engi=
ne written in pure JavaScript. In versions 10.25.7 and below, the date filt= er's strftime implementation parses width specifiers like %9999999d and for= wards the captured width unchecked into pad()/padStart(), leading to memory=
and render limit bypass. In src/util/underscore.ts, the pad loop performs = unbounded string concatenation without consulting the Context's memoryLimit=
or renderLimit, so a single small template ({{ x | date: '%5000000d' }}) p= roduces megabytes of output and unbounded CPU. The memoryLimit and renderLi= mit options the docs (src/liquid-options.ts:87-92) advertise as DoS control=
s - and which the docstring explicitly mentions for strftime - are entirely=
bypassed. Exploitation can cause large memory allocations, high CPU usage,=
or OOM crashes per render. This issue has been fixed in version 10.26.0. 2= 026-06-17 7.5 CVE-2026-45357 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 45357 ] harttle--liquidjs LiquidJS is a Shopify/GitHub Pages compatible tem= plate engine written in pure JavaScript. In versions 10.25.7 and below, the=
built-in strip_html filter uses a regex containing four flawed lazy-quanti= fied alternatives, leading to ReDoS via quadratic backtracking. When the in= put contains many <script, <style, or <!-- opener tokens without matching c= losers, the V8 regex engine performs O(N=C3=82=C2=B2) backtracking, blockin=
g the Node.js event loop. A single ~350 KB request ('<script'.repeat(50000)=
) stalls the process for ~10 seconds; cost grows quadratically with input s= ize. The default memoryLimit: Infinity does not bound regex CPU, and even w= hen configured strip_html only charges str.length to the limit - the regex = itself runs unbounded. A single unauthenticated request containing crafted = untrusted input can cause severe event-loop blocking and CPU amplification = that saturates Node.js workers while bypassing memoryLimit protections. Thi=
s issue has been fixed in version 10.26.0. 2026-06-17 7.5 CVE-2026-45617 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-45617 ] Henryschorradt--Bridge = Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability = that allows unauthenticated attackers to execute arbitrary SQL queries by i= njecting malicious code through the id parameter. Attackers can send GET re= quests to index.php with option=3Dcom_phpbridge&view=3Dphpview parameters a=
nd inject SQL code in the id parameter to extract database information incl= uding table and column names. 2026-06-19 8.2 CVE-2017-20275 [
https://www.c= ve.org/CVERecord?id=3DCVE-2017-20275 ] hermes-webui--hermes-webui Hermes We= bUI before 0.51.409 contains an authentication bypass vulnerability in pass= key registration endpoints that allows unauthenticated remote attackers to = register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=3D1 is enabled with =
no existing credentials, POST /api/auth/passkey/register/options and POST /= api/auth/passkey/register endpoints are accessible without authentication, = allowing attackers to claim the first passkey and gain permanent administra= tive control. 2026-06-17 9.1 CVE-2026-55196 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-55196 ] hippooo--Hippoo Mobile App for WooCommerce Unauthent= icated Broken Access Control in Hippoo Mobile App for WooCommerce <=3D 1.9.=
5 versions. 2026-06-15 8.2 CVE-2026-49065 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-49065 ] Hitachi--Hitachi Virtual Storage Platform E990, E1090,=
E1090H DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage=
Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090,=
E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, = before DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DK= CMAIN Ver.93-06-82-80/00-06, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver= .93-06-63-80/00-04, CHB(iSCSI) Ver.88-01-02-04; Hitachi Virtual Storage Pla= tform E390, E590, E790, E390H, E590H, E790H: before DKCMAIN Ver.93-07-21-x0= /00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-x0/00-07, C= HB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-82-x0/00-06, CHB(iSCSI)=
Ver.88-01-02-04, before DKCMAIN Ver.93-06-63-x0/00-04, CHB(iSCSI) Ver.88-0= 1-02-04, before DKCMAIN Ver.93-07-24-x0/00-02, CHB(iSCSI) Ver.88-01-02-04, = before DKCMAIN Ver.93-07-02-x0/00-02, CHB(iSCSI) Ver.88-01-02-04; Hitachi V= irtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F70=
0, F900: before DKCMAIN Ver.88-08-10-x0/00-05, CHB(iSCSI) Ver.88-01-02-04; = Hitachi Virtual Storage Platform G100, G200, G400, G600, G800, F400, F600, = F800: before DKCMAIN Ver.83-06-20-x0/00-05, CHB(iSCSI) Ver.83-01-01-29; Hit= achi Virtual Storage Platform VX8, 5100, 5500, 5100H, 5500H, 5200, 5600, 52= 00H, 5600H: before DKCMAIN Ver.90-09-01-00/01-01, CHB(iSCSI) Ver.90-01-01-0=
7, before DKCMAIN Ver.90-08-83-00/01-01, CHB(iSCSI) Ver.90-01-01-07, before=
DKCMAIN Ver.90-08-63-00/01-01, CHB(iSCSI) Ver.90-01-01-07; Hitachi Virtual=
Storage Platform VX7, G1000, G1500, F1500: before DKCMAIN Ver.80-06-93-00/= 00-04, ISFC Ver.80-01-17. 2026-06-19 8.6 CVE-2025-7737 [
https://www.cve.or= g/CVERecord?id=3DCVE-2025-7737 ] HKUDS--nanobot nanobot is a personal AI as= sistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/s= rc/whatsapp.ts constructs a filesystem path using the fileName field from a=
n incoming WhatsApp document message without sanitization. The WhatsApp bri= dge downloads media attachments and writes them to disk using a filename de= rived from the sender's message via documentMessage.fileName, which is conc= atenated with a prefix and its raw value is passed directly to path.join(me= diaDir, outFilename). Node.js path.join resolves .. components, allowing an=
attacker to escape the intended media/ directory by sending a document wit=
h a crafted fileName such as ../../../.ssh/authorized_keys. Because the att= acker also controls the file content (the downloaded buffer), this is a wri= te-anywhere primitive - both path and content are attacker-controlled. A fi=
x for this issue is planned for version 0.1.5.post4. 2026-06-18 8.7 CVE-202= 6-48716 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48716 ]
https://wprev= iewslider.com/--WP Review Slider Pro The WP Review Slider Pro plugin for Wo= rdPress is vulnerable to Arbitrary File Deletion in versions up to and incl= uding 12.6.8. This is due to missing authorization checks on the wpfb_hide_= review and wprp_save_review_admin AJAX handlers combined with insufficient = path validation in the wpfb_hidereview_ajax() function, which uses strpos()=
to check that a stored media URL starts with the expected prefix but fails=
to sanitize path traversal sequences in the remaining relative path before=
passing it to unlink(). This makes it possible for authenticated attackers=
, with subscriber-level access and above, to delete arbitrary files on the = affected site's server which may make remote code execution possible. 2026-= 06-16 8.1 CVE-2026-8442 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8442 =
]
https://wpreviewslider[.]com/--WP Review Slider Pro The WP Review Slider = Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' an=
d 'slocations' parameters of the wppro_get_overall_chart_data AJAX action i=
n versions up to, and including, 12.6.8. This is due to the use of stripsla= shes() on user-supplied JSON strings prior to json_decode(), which removes = the escaping applied by WordPress's wp_magic_quotes; the resulting decoded = array values are then concatenated directly into SQL WHERE clauses without = parameterization, and the constructed query is executed via $wpdb->get_resu= lts() without $wpdb->prepare(). This makes it possible for authenticated at= tackers, with Subscriber-level access and above, to append additional SQL q= ueries into already existing queries that can be used to extract sensitive = information from the database. The handler also returns the executed SQL st= ring in its JSON response, which simplifies oracle construction for blind e= xploitation. 2026-06-16 8.8 CVE-2026-8443 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-8443 ]
https://wpreviewslider[.]com/--WP Review Slider Pro The=
WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection v=
ia the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in ver= sions up to, and including, 12.6.8. This is due to the handler reading $_PO= ST['curselrevs'] raw with no sanitization or type casting, then concatenati=
ng each array element directly into a `WHERE id IN ( ... )` clause without = quoting and executing via $wpdb->get_results() without $wpdb->prepare(). Th=
is makes it possible for authenticated attackers, with Subscriber-level acc= ess and above, to append additional SQL queries into already existing queri=
es that can be used to extract sensitive information from the database. 202= 6-06-16 8.8 CVE-2026-8444 [
https://www.cve.org/CVERecord?id=3DCVE-2026-844=
4 ] Husain--HB Audio Gallery Lite WordPress Plugin HB Audio Gallery Lite 1.= 0.0 contains a path traversal vulnerability that allows unauthenticated att= ackers to download arbitrary files by manipulating the file_path parameter.=
Attackers can send requests to the audio-download.php endpoint with direct= ory traversal sequences to access sensitive files like wp-config.php outsid=
e the intended gallery directory. 2026-06-15 7.5 CVE-2016-20081 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2016-20081 ] i18next--i18next-fs-backend Vers= ions prior to 2.6.6 are vulnerable to prototype pollution via crafted missi= ng-key strings when used to persist missing translation keys (e.g. via i18n= ext-http-middleware's missingKeyHandler exposed to untrusted input). Backen= d.writeFile() splits each queued missing-key string on the configured keySe= parator (default .) before calling the internal setPath() walker. The walke=
r (getLastOfPath in lib/utils.js) did not guard against unsafe segments, so=
a key like "__proto__.polluted" was split into ["__proto__", "polluted"] a=
nd walked straight into Object.prototype, allowing an attacker to write arb= itrary properties onto the global object prototype. Depending on the host a= pplication, polluted prototype properties may cause crashes, corrupted tran= slation behaviour, configuration poisoning, or bypasses of property-based s= ecurity checks. Applications are affected only if the missingKeyHandler (or=
another route that forwards untrusted request bodies to i18next.t(..., { .=
.. }) with saveMissing: true) is reachable by untrusted users and the defau=
lt behaviour of splitting missing-key strings on keySeparator is in use (i.=
e. keySeparator is not false). Apps that do not expose missing-key persiste= nce to untrusted input are not directly affected through this attack path. = This issue has been fixed in version 2.6.6. If developers using the library=
are unable to upgrade immediately, they should take the following precauti= ons: do not expose i18next-http-middleware's missingKeyHandler to untrusted=
users (mount it behind authentication, or remove the route), disable missi= ng-key persistence (saveMissing: false, or no backend.create implementation=
) when accepting writes from untrusted input, and set keySeparator: false i=
n their i18next options to disable backend key splitting (note: this also d= isables nested translation keys). 2026-06-15 9.1 CVE-2026-48713 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-48713 ] i18next--i18next-http-middleware=
i18next-http-middleware is a middleware to be used with Node.js web framew= orks like express or Fastify and also for Deno. In versions prior to 3.9.7,=
the missingKeyHandler blocked the literal request-body keys __proto__, con= structor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did = not reject dotted variants such as "__proto__.polluted". Downstream backend=
s that split the missing-key string on a configured keySeparator (notably i= 18next-fs-backend =C3=A2=E2=80=B0=C2=A4 2.6.5) hand these keys to an unguar= ded setPath() walker that writes to Object.prototype. Applications that exp= ose missingKeyHandler to untrusted input AND use i18next-fs-backend =C3=A2= =E2=80=B0=C2=A4 2.6.5 are directly exploitable for remote prototype polluti= on. Other downstream backends that split the missing-key string the same wa=
y may be similarly affected. Depending on the host application, polluted pr= ototype properties may cause crashes, corrupted translation behaviour, conf= iguration poisoning, or bypasses of property-based security checks. This is= sue has been fixed in version 3.9.7. If developers cannot upgrade immediate= ly, they should do the following: do not expose missingKeyHandler to untrus= ted users (mount it behind authentication, or remove the route), add a requ= est-body filter ahead of the handler that rejects any top-level key contain= ing __proto__, constructor, or prototype after splitting on their configure=
d keySeparator, and disable missing-key persistence (saveMissing: false) wh=
en accepting writes from untrusted input. 2026-06-15 9.1 CVE-2026-48714 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-48714 ] iba--ibaPDA A remote, un= authenticated attacker may exploit a deserialization of untrusted data vuln= erability in ibaPDA or ibaDatCoordinator to gain full access to the affecte=
d systems. 2026-06-18 9.8 CVE-2026-8024 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-8024 ] IDPay--IDPay Payment Gateway for Woocommerce Unauthentic= ated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <=3D = 2.2.5 versions. 2026-06-15 7.5 CVE-2026-34891 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-34891 ] IM-Magic--Partition Resizer A weakness has been id= entified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown=
function in the library MDA_NTDRV.sys of the component Kernel Driver. This=
manipulation causes improper access controls. The attack requires local ac= cess. The exploit has been made available to the public and could be used f=
or attacks. The vendor was contacted early about this disclosure but did no=
t respond in any way. 2026-06-21 7.8 CVE-2026-12784 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-12784 ] impleCode--eCommerce Product Catalog Unauthe= nticated SQL Injection in eCommerce Product Catalog <=3D 3.5.5 versions. 20= 26-06-15 9.3 CVE-2026-52693 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 2693 ] Inisev--Backup Migration Unauthenticated Sensitive Data Exposure in = Backup Migration <=3D 2.1.1 versions. 2026-06-15 7.5 CVE-2026-39480 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-39480 ] Iperiusremote--Iperius Remot=
e Iperius Remote 1.7.0 contains an unquoted service path vulnerability that=
allows local users to execute arbitrary code with SYSTEM privileges by exp= loiting the service installation path. When installed from directories cont= aining spaces, attackers can place malicious executables in the path to be = executed with elevated privileges during service startup or system reboot. = 2026-06-19 7.8 CVE-2016-20089 [
https://www.cve.org/CVERecord?id=3DCVE-2016= -20089 ] IT Path Solutions--Contact Form to Any API Unauthenticated Cross S= ite Scripting (XSS) in Contact Form to Any API <=3D 3.0.3 versions. 2026-06= -15 7.1 CVE-2026-39449 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39449 =
] Jacob N. Breetvelt--WP Photo Album Plus Unauthenticated SQL Injection in =
WP Photo Album Plus <=3D 9.1.08.001 versions. 2026-06-15 9.3 CVE-2026-39511=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-39511 ] JetBrains--GoLand In=
JetBrains GoLand before 2026.1.3 remote code execution was possible via un= trusted project configuration 2026-06-19 7.1 CVE-2026-53915 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-53915 ] JetBrains--Hub In JetBrains Hub befo=
re 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430=
, 2024.2.148429 authentication bypass via direct database access leading to=
administrative access was possible 2026-06-19 10 CVE-2026-50242 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-50242 ] JetBrains--Hub In JetBrains Hub=
before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.1= 48430, 2024.2.148429 account takeover via predictable restore codes was pos= sible 2026-06-19 9.8 CVE-2026-56141 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-56141 ] JetBrains--Hub In JetBrains Hub before 2026.1.13757, 2025.3.= 148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg=
e escalation by attaching authentication details to accounts was possible 2= 026-06-19 9.6 CVE-2026-56142 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 56142 ] Jetimpex Inc.--JetBlog Unauthenticated Sensitive Data Exposure in J= etBlog <=3D 2.4.8 versions. 2026-06-17 7.5 CVE-2026-52696 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-52696 ] Jetimpex Inc.--JetEngine Contributor P=
HP Object Injection in JetEngine <=3D 3.8.9.1 versions. 2026-06-17 9.8 CVE-= 2026-49075 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49075 ] Jetimpex I= nc.--JetEngine Unauthenticated SQL Injection in JetEngine <=3D 3.8.9.1 vers= ions. 2026-06-17 9.3 CVE-2026-49076 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-49076 ] Jetimpex Inc.--JetEngine Unauthenticated SQL Injection in Je= tEngine < 3.8.9.1 versions. 2026-06-17 9.3 CVE-2026-49084 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-49084 ] Jetimpex Inc.--JetEngine Unauthenticat=
ed PHP Object Injection in JetEngine <=3D 3.8.10 versions. 2026-06-17 9.8 C= VE-2026-52706 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52706 ] Jetimpe=
x Inc.--JetEngine Unauthenticated SQL Injection in JetEngine <=3D 3.8.10.1 = versions. 2026-06-17 9.3 CVE-2026-54187 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-54187 ] Jetimpex Inc.--JetEngine Unauthenticated Cross Site Scr= ipting (XSS) in JetEngine <=3D 3.8.9.1 versions. 2026-06-17 7.1 CVE-2026-49= 074 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49074 ] Jetimpex Inc.--Je= tEngine Unauthenticated Cross Site Scripting (XSS) in JetEngine <=3D 3.8.10=
versions. 2026-06-17 7.1 CVE-2026-54188 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-54188 ] Jetimpex Inc.--JetEngine Unauthenticated Cross Site Scr= ipting (XSS) in JetEngine <=3D 3.8.10 versions. 2026-06-17 7.1 CVE-2026-541=
89 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54189 ] Jetimpex Inc.--Jet= Search Unauthenticated SQL Injection in JetSearch <=3D 3.5.17 versions. 202= 6-06-17 9.3 CVE-2026-49079 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49= 079 ] Jetimpex Inc.--JetSmartFilters Unauthenticated SQL Injection in JetSm= artFilters <=3D 3.8.1 versions. 2026-06-17 9.3 CVE-2026-48875 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-48875 ] Jetmonsters--JetFormBuilder Unauth= enticated Cross Site Scripting (XSS) in JetFormBuilder <=3D 3.6.0.1 version=
s. 2026-06-17 7.1 CVE-2026-54195 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-54195 ] JExtensions Store--GPTranslate Multilingual AI Translation for = WordPress: Automatically Translate Websites Unauthenticated SQL Injection i=
n GPTranslate - Multilingual AI Translation for WordPress: Automatically Tr= anslate Websites <=3D 2.32.6 versions. 2026-06-15 9.3 CVE-2026-49776 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-49776 ] jkdevstudio--Qreatix Unauth= enticated Cross Site Scripting (XSS) in Qreatix <=3D 1.9.4 versions. 2026-0= 6-16 7.1 CVE-2025-69104 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69104=
] Jobster Marketplace--WPJobster Unauthenticated SQL Injection in WPJobste=
r <=3D 6.3.5 versions. 2026-06-17 9.3 CVE-2026-22340 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-22340 ] Jobster Marketplace--WPJobster Unauthentica= ted Cross Site Scripting (XSS) in WPJobster <=3D 6.3.5 versions. 2026-06-17=
7.1 CVE-2026-22339 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22339 ] J= oombooking--JB Visa Joomla! Component JB Visa 1.0 contains an SQL injection=
vulnerability that allows unauthenticated attackers to execute arbitrary S=
QL queries by injecting malicious code through the visatype parameter. Atta= ckers can send GET requests to index.php with the option=3Dcom_bookpro and = view=3Dpopup parameters, injecting SQL commands in the visatype parameter t=
o extract sensitive database information including credentials and table co= ntents. 2026-06-19 8.2 CVE-2017-20255 [
https://www.cve.org/CVERecord?id=3D= CVE-2017-20255 ] Joomboost--JoomCRM Joomla! Component JoomCRM 1.1.1 contain=
s an SQL injection vulnerability that allows authenticated attackers to exe= cute arbitrary SQL queries by injecting malicious code through the deal_id = parameter. Attackers can send GET requests to index.php with option=3Dcom_j= oomcrm&view=3Dcontacts and inject SQL code in the deal_id parameter to extr= act sensitive database information including table names and schemas. 2026-= 06-19 7.1 CVE-2019-25761 [
https://www.cve.org/CVERecord?id=3DCVE-2019-2576=
1 ] Joomboost--Joomla JoomRecipe Joomla JoomRecipe 1.0.4 component contains=
a blind SQL injection vulnerability in the search_author parameter on the = search results page. Attackers can inject SQL code through POST requests to=
the search endpoint to extract database information using boolean-based bl= ind SQL injection techniques. 2026-06-19 8.2 CVE-2017-20277 [
https://www.c= ve.org/CVERecord?id=3DCVE-2017-20277 ] Joomboost--JoomProject Joomla! Compo= nent JoomProject 1.1.3.2 contains an information disclosure vulnerability t= hat allows unauthenticated attackers to access sensitive user data by explo= iting the projects endpoint. Attackers can send requests to index.php with = option=3Dcom_jpprojects&view=3Dprojects&tmpl=3Dcomponent&format=3Djson para= meters to retrieve user IDs, names, and email addresses in JSON format. 202= 6-06-19 7.5 CVE-2019-25762 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25= 762 ] Joomboost--JoomRecipe Joomla Component JoomRecipe 1.0.3 contains an S=
QL injection vulnerability that allows unauthenticated attackers to manipul= ate database queries by injecting SQL code through the category parameter. = Attackers can send GET requests to the all-recipes endpoint with malicious = SQL payloads in the category path segment to extract sensitive database inf= ormation. 2026-06-19 8.2 CVE-2017-20278 [
https://www.cve.org/CVERecord?id= =3DCVE-2017-20278 ] Joomlaboat--Extra Search Joomla! Component Extra Search=
2.2.8 contains an SQL injection vulnerability that allows unauthenticated = attackers to manipulate database queries by injecting SQL code through the = establename parameter. Attackers can send GET requests to index.php with th=
e option=3Dcom_extrasearch parameter and malicious SQL in the establename f= ield to extract sensitive database information. 2026-06-19 8.2 CVE-2017-202=
81 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20281 ] Joomlashack--OSDow= nloads Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability tha=
t allows unauthenticated attackers to execute arbitrary SQL queries by inje= cting malicious code through the id parameter. Attackers can send GET reque= sts to index.php with option=3Dcom_osdownloads&view=3Ditem&id=3D[SQL] to ex= tract sensitive database information including credentials and configuratio=
n data. 2026-06-19 8.2 CVE-2017-20259 [
https://www.cve.org/CVERecord?id=3D= CVE-2017-20259 ] Joomlashowroom--Event Registration Pro Calendar Joomla Eve=
nt Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability = that allows unauthenticated attackers to execute arbitrary SQL queries by i= njecting malicious code through the id parameter. Attackers can send GET re= quests to index.php with option=3Dcom_registrationpro&view=3Dcategory&id pa= rameter containing SQL injection payloads to extract sensitive database inf= ormation. 2026-06-19 8.2 CVE-2017-20273 [
https://www.cve.org/CVERecord?id= =3DCVE-2017-20273 ] Joomlathat--Calendar Planner Joomla! Component Calendar=
Planner 1.0.1 contains an SQL injection vulnerability that allows unauthen= ticated attackers to inject SQL commands through the category_id parameter.=
Attackers can send GET requests to the events view with malicious SQL code=
in the category_id parameter to extract sensitive database information. 20= 26-06-19 8.2 CVE-2017-20267 [
https://www.cve.org/CVERecord?id=3DCVE-2017-2= 0267 ] Joomplace--Quiz Deluxe Joomla! Component Quiz Deluxe 3.7.4 contains =
an SQL injection vulnerability that allows unauthenticated attackers to exe= cute arbitrary SQL commands through the ajaxaction.flag_question task. Atta= ckers can inject malicious SQL code via the stu_quiz_id or flag_quest param= eters to manipulate database queries and extract sensitive information. 202= 6-06-19 8.2 CVE-2017-20257 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20= 257 ] Joomplace--Survey Force Deluxe Joomla Survey Force Deluxe 3.2.4 conta= ins an SQL injection vulnerability that allows unauthenticated attackers to=
execute arbitrary SQL queries by injecting malicious code through the invi=
te parameter. Attackers can send GET requests to the component with crafted=
SQL payloads in the invite parameter to extract sensitive database informa= tion. 2026-06-19 8.2 CVE-2017-20256 [
https://www.cve.org/CVERecord?id=3DCV= E-2017-20256 ] Joomshaper--SP Movie Database Joomla SP Movie Database 1.3 c= ontains an SQL injection vulnerability that allows unauthenticated attacker=
s to execute arbitrary SQL queries by injecting malicious code through the = searchword parameter. Attackers can send GET requests to the searchresults = view with crafted SQL payloads in the searchword parameter to extract sensi= tive database information. 2026-06-19 8.2 CVE-2017-20266 [
https://www.cve.= org/CVERecord?id=3DCVE-2017-20266 ] Joomunited--WP Media folder Addon Unaut= henticated Arbitrary File Download in WP Media folder Addon <=3D 4.0.1 vers= ions. 2026-06-17 7.5 CVE-2026-9690 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-9690 ] Jose Conti--Redsys for WooCommerce Light Unauthenticated Broke=
n Access Control in Redsys for WooCommerce Light <=3D 7.0.0 versions. 2026-= 06-15 7.5 CVE-2026-40741 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4074=
1 ] Jovancoding--Network-AI Network-AI is a TypeScript/Node.js multi-agent = orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unau= thenticated cross-origin MCP tool invocation due to an empty default secret=
. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by = closing the CORS flaw (with Access-Control-Allow-Origin now set only for lo= calhost origins), but the empty-default-secret flaw described in the title = remained: the SSE MCP server still defaulted to an empty secret, _isAuthori= zed() still returned true when the secret was empty, and a non-loopback bin=
d only produced a warning. As a result, the server still ran fully unauthen= ticated by default. Any non-browser caller (for example, curl, SSRF, or a 0= .0.0.0 bind) could invoke all 22 MCP tools (config_set, agent_spawn, blackb= oard_write, token_*) with no credentials. This issue was fixed in version 5= .7.2. 2026-06-17 9.1 CVE-2026-48814 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-48814 ] Jthemes--Genemy Subscriber Privilege Escalation in Genemy <=
=3D 1.6.6 versions. 2026-06-17 8.8 CVE-2025-69138 [
https://www.cve.org/CVE= Record?id=3DCVE-2025-69138 ] JTL Software--JTL Shop JTL Shop versions 5.2.0=
through 5.7.1 contains a server-side template injection vulnerability that=
allows unauthenticated attackers to inject malicious template syntax due t=
o unsanitized user-supplied input passed to the Smarty template engine. Att= ackers can exploit this flaw to read sensitive server-side values such as d= atabase credentials and encryption keys, and on versions 5.4.0 through 5.7.=
1, leverage registered Smarty modifiers including unserialize and file_get_= contents to write a webshell to the web root and execute arbitrary commands=
as the web server user. 2026-06-18 9.8 CVE-2026-54390 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-54390 ] jwsthemes--AI Lab Unauthenticated PHP Obj= ect Injection in AI Lab < 5.4.2 versions. 2026-06-17 9.8 CVE-2026-42380 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-42380 ] kilbot--WooCommerce POS = Unauthenticated Broken Access Control in WooCommerce POS <=3D 1.8.14 versio= ns. 2026-06-16 7.5 CVE-2026-52711 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-52711 ] King-products--LMS King Professional Joomla LMS King Professio= nal 3.2.4.0 contains an SQL injection vulnerability that allows unauthentic= ated attackers to manipulate database queries by injecting SQL code through=
the cp_id parameter. Attackers can send GET requests to index.php with the=
option=3Dcom_lmsking, view=3Dlmsking, layout=3Dlearningpath, and task=3Dle= arningPath parameters to extract sensitive database information. 2026-06-19=
8.2 CVE-2017-20274 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20274 ] K= ludex--starlette Starlette is a lightweight ASGI framework/toolkit. In vers= ions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UN=
C path such as \attacker.com\share can cause os.path.realpath to initiate a=
n outbound SMB connection before the path is rejected, exposing the service=
account's NTLMv2 credentials for offline cracking or relay even though the=
HTTP response is only a 404. The issue affects default follow_symlink=3DFa= lse deployments, including frameworks built on Starlette such as FastAPI; P= OSIX systems and follow_symlink=3DTrue are unaffected. The issue is fixed i=
n 1.1.0. 2026-06-17 7.5 CVE-2026-48818 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-48818 ] Knit Pay--Knit Pay Unauthenticated Broken Access Contro=
l in Knit Pay <=3D 9.4.0.0 versions. 2026-06-15 7.5 CVE-2026-49070 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-49070 ] Kodezen LLC--Academy LMS Pro = Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LL=
C Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue aff= ects Academy LMS Pro: from n/a before 3.5.2. 2026-06-16 8 CVE-2026-39598 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-39598 ] Kriesi--Enfold Unauthen= ticated Cross Site Scripting (XSS) in Enfold <=3D 7.1.4 versions. 2026-06-1=
6 7.1 CVE-2026-48869 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48869 ] = LatePoint--LatePoint Contributor Privilege Escalation in LatePoint <=3D 5.5=
.1 versions. 2026-06-15 7.5 CVE-2026-49083 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-49083 ] latepoint--LatePoint Calendar Booking Plugin for Appo= intments and Events The LatePoint - Calendar Booking Plugin for Appointment=
s and Events plugin for WordPress is vulnerable to Privilege Escalation to = Administrator in versions up to, and including, 5.5.1. The plugin chains th= ree independent flaws that together allow an authenticated Agent (Agent+) t=
o overwrite a WordPress Administrator's password without ever invoking an A= dministrator-only API. This makes it possible for authenticated attackers, = with Agent access and above, to elevate their privileges to Administrator. = 2026-06-16 7.5 CVE-2026-8176 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 8176 ] leejet--stable-diffusion.cpp stable-diffusion.cpp is a pure C/C++ li= brary for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image,=
Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the=
pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vuln= erability in the BINUNICODE opcode handler. The issue was caused by sign co= nfusion on the opcode length field. A crafted .ckpt file could trigger memc=
py with a very large length derived from a negative signed value, causing i= mmediate heap corruption. The issue has been resolved in version master-584= -0a7ae07. If developers are unable to immediately update their applications=
they can work around this issue by only loading .ckpt checkpoint files fro=
m trusted sources and preferring trusted model sources and safer formats su=
ch as .safetensors where possible. 2026-06-16 7.8 CVE-2026-47747 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-47747 ] leejet--stable-diffusion.cpp st= able-diffusion.cpp is a pure C/C++ library for running diffusion model (Sta= ble Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Version=
s prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHO= RT_BINUNICODE parsing for PyTorch checkpoint files. The pickle .ckpt parser=
in src/model.cpp contained a heap buffer overflow vulnerability in the SHO= RT_BINUNICODE opcode handler. The issue was caused by sign confusion on the=
opcode length field. A crafted .ckpt file could trigger memcpy with a very=
large length derived from a negative signed value, causing immediate heap = corruption. Any application using affected stable-diffusion.cpp releases to=
load untrusted .ckpt model files could be vulnerable. A malicious checkpoi=
nt file could cause heap corruption through memcpy with an attacker-control= led length. This may lead to process crash and could potentially be leverag=
ed for code execution depending on heap layout. The attack requires the vic= tim or application to load a .ckpt file from an untrusted source, such as a=
downloaded model from a model sharing site. The issue has been resolved in=
version master-584-0a7ae07. If developers are unable to immediately update=
their applications they can work around this issue by not loading .ckpt ch= eckpoint files from untrusted sources, and referring to trusted model sourc=
es and safer formats such as .safetensors where possible. 2026-06-16 7.8 CV= E-2026-47749 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47749 ] leejet--= stable-diffusion.cpp stable-diffusion.cpp is a pure C/C++ library for runni=
ng diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and m= ore) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt p= arser in src/model.cpp contained a heap buffer overflow vulnerability in th=
e GLOBAL opcode handler. The issue was caused by missing validation when se= arching for newline-delimited fields. A crafted .ckpt file without the expe= cted newline could cause the parser to use -1 as a copy length, resulting i=
n immediate heap corruption. The attack requires the victim or application =
to load a .ckpt file from an untrusted source, such as a downloaded model f= rom a model sharing site. The issue has been resolved in version master-584= -0a7ae07. If developers are unable to immediately update their applications=
they can work around this issue by following these instructions: do not lo=
ad .ckpt checkpoint files from untrusted sources, and prefer trusted model = sources and safer formats such as .safetensors where possible. 2026-06-16 7=
.8 CVE-2026-47750 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47750 ] lib= ssh2--libssh2 libssh2 through 1.11.1, fixed in commit 7acf3df contains an o= ut-of-bounds write vulnerability in ssh2_transport_read() that fails to enf= orce upper bounds on packet_length field. Remote attackers can send crafted=
SSH packets with excessively large packet_length values to corrupt heap me= mory and achieve remote code execution. 2026-06-17 8.1 CVE-2026-55200 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-55200 ] Liquid Web / StellarWP--Gi= veWP Unauthenticated Cross Site Scripting (XSS) in GiveWP <=3D 4.14.2 versi= ons. 2026-06-15 7.1 CVE-2026-34900 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-34900 ] Liquid Web / StellarWP--The Events Calendar Improper Neutrali= zation of Special Elements used in an SQL Command ('SQL Injection') vulnera= bility in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injec= tion. This issue affects The Events Calendar: from 6.15.12 through 6.16.2. = 2026-06-16 9.3 CVE-2026-49772 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -49772 ] LoginPress--LoginPress Pro Unauthenticated Privilege Escalation in=
LoginPress Pro <=3D 6.2.2 versions. 2026-06-17 9.8 CVE-2026-49058 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-49058 ] Magepeople inc.--WpEvently Un= authenticated Other Vulnerability Type in WpEvently <=3D 5.3.3 versions. 20= 26-06-15 7.5 CVE-2026-45441 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 5441 ] Magepeople inc.--WpTravelly Unauthenticated Bypass Vulnerability in = WpTravelly <=3D 2.1.7 versions. 2026-06-15 7.5 CVE-2026-27089 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-27089 ] Malwarebytes--Malwarebytes Malware= bytes 4.5 contains an unquoted service path vulnerability in the MBAMServic=
e executable that allows local attackers to escalate privileges by injectin=
g malicious code into the system root path. Attackers can place executable = files in unquoted path directories that execute with LocalSystem privileges=
during service startup or system reboot. 2026-06-19 7.8 CVE-2022-50971 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2022-50971 ] Mamunur Rashid--Classifi=
ed Listing Unauthenticated Cross Site Scripting (XSS) in Classified Listing=
<=3D 5.3.8 versions. 2026-06-15 7.1 CVE-2026-42658 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-42658 ] ManageWP--ManageWP Worker Unauthenticated Cr= oss Site Scripting (XSS) in ManageWP Worker <=3D 4.9.31 versions. 2026-06-1=
5 7.1 CVE-2026-39463 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39463 ] = MantraBrain--Easy Invoice Unauthenticated Remote Code Execution (RCE) in Ea=
sy Invoice <=3D 2.1.19 versions. 2026-06-15 10 CVE-2026-48836 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-48836 ] mariovalney--CF7 to Webhook The CF=
7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forg= ery in all versions up to, and including, 5.0.0 via the pull_the_trigger. T= his makes it possible for unauthenticated attackers to make web requests to=
arbitrary locations originating from the web application and can be used t=
o query and modify information from internal services. Exploitation require=
s that the admin-configured webhook URL contains a Contact Form 7 field pla= ceholder in the host segment of the URL, and that the affected form is publ= icly accessible. 2026-06-18 7.2 CVE-2026-11395 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-11395 ] markbeljaars--iRobots.txt SEO Unauthenticated Cro=
ss Site Scripting (XSS) in iRobots.txt SEO <=3D 1.1.2 versions. 2026-06-15 = 7.1 CVE-2025-68840 [
https://www.cve.org/CVERecord?id=3DCVE-2025-68840 ] ma= stodon--mastodon Mastodon is a free, open-source social network server base=
d on ActivityPub. In versions there is a missing condition in the check if = remote accounts consented to be featured in a remote Collection could lead =
to attackers bypassing the check and faking consent. An attacker could forg=
e the FeatureAuthorization object that is used to verify consent to be feat= ured in a Collection and thus make it appear as if an account is allowed to=
be in a Collection when it actually is not. While the FeatureAuthorization=
must reside on the same domain as the object it is for, a check is missing=
to make sure said object is actually the same as in the Collection item. T= his allows an attacker to forge the authorization. Mastodon servers are aff= ected only if running the main branch or nightly builds who have opted into=
testing the experimental "Collections" feature by setting the environment = variable EXPERIMENTAL_FEATURES to a value including collections. This has b= een patched in version 4.6.0-beta.1. 2026-06-15 7.5 CVE-2026-47777 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-47777 ] Matrix42--Matrix42 Remote Con= trol Host Matrix42 Remote Control Host 3.20.0031 contains an unquoted servi=
ce path vulnerability in the FastViewerRemoteService and FastViewerRemotePr= oxy services that allows local users to execute arbitrary code with SYSTEM = privileges. Attackers can place a malicious executable in the Program Files=
directory with a crafted name to be executed by the service during startup=
, gaining elevated privileges. 2026-06-19 7.8 CVE-2016-20095 [
https://www.= cve.org/CVERecord?id=3DCVE-2016-20095 ] mattkaye--Answer My Question Answer=
My Question 1.3 plugin for WordPress contains an SQL injection vulnerabili=
ty that allows unauthenticated attackers to execute arbitrary SQL queries b=
y injecting malicious code through the 'id' POST parameter. Attackers can s= ubmit crafted SQL statements to the modal.php endpoint to extract sensitive=
database information including WordPress terms and configuration data. 202= 6-06-15 8.2 CVE-2016-20073 [
https://www.cve.org/CVERecord?id=3DCVE-2016-20= 073 ] Melapress--WP Activity Log Unauthenticated PHP Object Injection in WP=
Activity Log <=3D 5.6.3.1 versions. 2026-06-17 9.8 CVE-2026-54806 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-54806 ] melhorenvio--Melhor Envio Sub= scriber Broken Authentication in Melhor Envio <=3D 2.16.3 versions. 2026-06= -17 7.6 CVE-2026-54804 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54804 =
] Meow Apps--AI Engine Editor Privilege Escalation in AI Engine <=3D 3.4.9 = versions. 2026-06-15 7.2 CVE-2026-27407 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-27407 ] Metagauss--RegistrationMagic Unauthenticated Broken Aut= hentication in RegistrationMagic <=3D 6.0.8.6 versions. 2026-06-15 9.8 CVE-= 2026-49764 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49764 ] metaphorcr= eations--Post Duplicator Contributor PHP Object Injection in Post Duplicato=
r <=3D 3.0.10 versions. 2026-06-15 8.8 CVE-2026-39474 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-39474 ] MetaSlider--Responsive Slider by MetaSlide=
r Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <=
=3D 3.106.0 versions. 2026-06-15 9.1 CVE-2026-39465 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-39465 ] MIA Technology Inc.--Pizzy Library Improper = neutralization of formula elements in a CSV file vulnerability in MIA Techn= ology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Li= brary: from 1.0.0.26250 before 1.3.9.26250. 2026-06-15 8.8 CVE-2026-5242 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-5242 ] MIA Technology Inc.--Piz=
zy Library Improper Access Control, Missing Authorization vulnerability in = MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured = Access Control Security Levels. This issue affects Pizzy Library: from 1.0.= 0.26250 before 1.3.9.26250. 2026-06-15 7.1 CVE-2026-5230 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-5230 ] MIA Technology Inc.--Pizzy Library Impro= per Control of Interaction Frequency vulnerability in MIA Technology Inc. P= izzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.= 26250 before 1.3.9.26250. 2026-06-15 7.1 CVE-2026-5233 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-5233 ] Microsoft--Azure Active Directory Improper=
authentication in Azure Active Directory allows an unauthorized attacker t=
o elevate privileges over a network. 2026-06-19 10 CVE-2026-45480 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-45480 ] Microsoft--Azure AI Bot Servic=
e Improper authentication in Azure Bot Service allows an authorized attacke=
r to elevate privileges over a network. 2026-06-18 7.7 CVE-2026-32174 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-32174 ] Microsoft--Azure Synapse E= xecution with unnecessary privileges in Azure Synapse allows an authorized = attacker to elevate privileges over a network. 2026-06-19 9.9 CVE-2026-4858=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48584 ] Microsoft--Microsof=
t 365 Copilot Missing authentication for critical function in M365 Copilot = allows an unauthorized attacker to disclose information over a network. 202= 6-06-18 9.8 CVE-2026-54130 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54= 130 ] Microsoft--Microsoft 365 Copilot Url redirection to untrusted site ('= open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthor= ized attacker to elevate privileges over a network. 2026-06-19 8.8 CVE-2026= -47645 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47645 ] Microsoft--Mic= rosoft Cost Management Exposure of sensitive information to an unauthorized=
actor in Cost Management Interactive Experiences allows an unauthorized at= tacker to disclose information over a network. 2026-06-18 7.5 CVE-2026-4763=
3 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47633 ] Microsoft--Microsof=
t Dynamics 365 Improper access control in Microsoft Dynamics 365 allows an = authorized attacker to elevate privileges over a network. 2026-06-18 9.9 CV= E-2026-47647 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47647 ] Microsof= t--Microsoft Edge (Chromium-based) Improper neutralization of input during = web page generation ('cross-site scripting') in Microsoft Edge (Chromium-ba= sed) allows an authorized attacker to perform spoofing over a network. 2026= -06-19 8.8 CVE-2026-32208 [
https://www.cve.org/CVERecord?id=3DCVE-2026-322=
08 ] Microsoft--Microsoft Exchange Online Missing authorization in Microsof=
t Exchange Online allows an authorized attacker to elevate privileges over =
a network. 2026-06-19 9.6 CVE-2026-48582 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-48582 ] Microsoft--Microsoft Malware Protection Engine Microsof=
t is aware of an elevation of privilege in the Microsoft Malware Protection=
Engine in Microsoft Defender publicly referred to as "RoguePlanet &qu= ot;. We are working to provide a high quality security update that addresse=
s this vulnerability. We will provide information in this CVE when the upda=
te is available. 2026-06-16 7.8 CVE-2026-50656 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-50656 ] Microweber--Microweber A weakness has been identi= fied in Microweber up to 2.0.20. This affects the function userfiles_path o=
f the file /api_nosession/thumbnail_img of the component API Endpoint. Exec= uting a manipulation of the argument cache_path_relative can lead to path t= raversal. It is possible to launch the attack remotely. The exploit has bee=
n made available to the public and could be used for attacks. The vendor wa=
s contacted early about this disclosure but did not respond in any way. 202= 6-06-15 7.3 CVE-2026-12198 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12= 198 ] Mikado-Themes--Ashtanga Unauthenticated PHP Object Injection in Ashta= nga <=3D 1.2 versions. 2026-06-16 8.1 CVE-2026-40751 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-40751 ] Mikado-Themes--ChapterOne Unauthenticated L= ocal File Inclusion in ChapterOne <=3D 1.7 versions. 2026-06-17 8.1 CVE-202= 6-40731 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40731 ] Mikado-Themes= --Chteau Unauthenticated PHP Object Injection in Ch=C3=83=C2=A2teau <=3D 1.= 2.1 versions. 2026-06-17 8.1 CVE-2026-40757 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-40757 ] Mikado-Themes--EasyMeals Unauthenticated PHP Object = Injection in EasyMeals <=3D 1.5.1 versions. 2026-06-17 8.1 CVE-2026-40753 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-40753 ] Mikado-Themes--Esme Un= authenticated PHP Object Injection in Esm=C3=83=C2=A9e <=3D 1.4 versions. 2= 026-06-16 8.1 CVE-2026-40759 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 40759 ] Mikado-Themes--Kastell Unauthenticated Local File Inclusion in Kast= ell <=3D 2.0 versions. 2026-06-17 8.1 CVE-2026-52707 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-52707 ] Mikado-Themes--LuxeDrive Unauthenticated PH=
P Object Injection in LuxeDrive <=3D 1.4 versions. 2026-06-16 8.1 CVE-2026-= 40739 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40739 ] Mikado-Themes--= Mikado Core Unauthenticated Local File Inclusion in Mikado Core <=3D 1.6 ve= rsions. 2026-06-17 8.1 CVE-2026-39537 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-39537 ] Mikado-Themes--ShiftUp Unauthenticated PHP Object Injectio=
n in ShiftUp <=3D 1.3 versions. 2026-06-17 8.1 CVE-2026-40733 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-40733 ] Mikado-Themes--TechLink Unauthenti= cated PHP Object Injection in TechLink <=3D 1.3 versions. 2026-06-16 8.1 CV= E-2026-40755 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40755 ] Mikado-T= hemes--Zoya Unauthenticated PHP Object Injection in Zoya <=3D 1.4 versions.=
2026-06-17 8.1 CVE-2026-40756 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-40756 ] Monetizemore--Advanced Ads Improper Control of Generation of Code=
('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remot=
e Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.=
2026-06-17 7.5 CVE-2026-54816 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-54816 ] Montodel--House-Rental-Management A vulnerability was detected in=
Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a= 33863. Affected by this issue is some unknown functionality of the file /lo= gin.php. The manipulation of the argument Username results in sql injection=
. The attack can be executed remotely. The exploit is now public and may be=
used. This product implements a rolling release for ongoing delivery, whic=
h means version information for affected or updated releases is unavailable=
. The vendor was contacted early about this disclosure but did not respond =
in any way. 2026-06-21 7.3 CVE-2026-12775 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-12775 ] Montonio--Montonio for WooCommerce Unauthenticated Bro= ken Access Control in Montonio for WooCommerce <=3D 10.1.2 versions. 2026-0= 6-15 7.5 CVE-2026-48873 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48873=
] Motive Commerce Search--AI Product Search for WooCommerce Motive Commerc=
e Search Unauthenticated Broken Access Control in AI Product Search for Woo= Commerce – Motive Commerce Search <=3D 1.38.2 versions. 2026-06-15 8.=
2 CVE-2026-42664 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42664 ] mra1=
3 / Team Tips and Tricks HQ--Simple Shopping Cart Unauthenticated Insecure = Direct Object References (IDOR) in Simple Shopping Cart <=3D 5.2.9 versions=
. 2026-06-15 7.5 CVE-2026-48868 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-48868 ] multer--multer Impact: multer versions 1.0.0 through 2.1.1 and 3= .0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field = names in multipart form data. The append-field dependency parses bracket no= tation in field names with no limit on nesting depth, allowing an attacker =
to force allocation of deeply nested object structures that consume CPU and=
memory. A single HTTP request with a crafted multipart body is sufficient =
to exploit this. Patches: Users should upgrade to multer 2.2.0 (2.x line) o=
r 3.0.0-alpha.2 (3.x prerelease) and configure the new limits.fieldNestingD= epth option to the minimum depth their application requires. Workarounds: S=
et limits.fields to a reasonable value to reduce the number of fields an at= tacker can send per request. This does not fully mitigate the issue but lim= its the impact. 2026-06-15 7.5 CVE-2026-5079 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-5079 ] Myportfolio--Myportfolio Joomla Component Myportfoli=
o 3.0.2 contains an SQL injection vulnerability that allows unauthenticated=
attackers to manipulate database queries by injecting SQL code through the=
pid parameter. Attackers can send GET requests to index.php with malicious=
pid values in the task=3Dproject&view=3Dgrid endpoint to extract sensitive=
database information. 2026-06-19 8.2 CVE-2017-20280 [
https://www.cve.org/= CVERecord?id=3DCVE-2017-20280 ] Mythemes--my flatonica Unauthenticated Cros=
s Site Scripting (XSS) in my flatonica <=3D 0.0.8 versions. 2026-06-17 7.1 = CVE-2024-49269 [
https://www.cve.org/CVERecord?id=3DCVE-2024-49269 ] Naked = Cat Plugins (by Webdados)--Feed KuantoKusta for WooCommerce Free Unauthenti= cated SQL Injection in Feed KuantoKusta for WooCommerce - Free <=3D 5.3 ver= sions. 2026-06-15 9.3 CVE-2026-39441 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-39441 ] NCEAS--metacat Metacat is data repository software that hel=
ps researchers preserve, share, and discover data. Versions 2.0.0 and and a= bove contain an unauthenticated SQL injection in the /harvesterRegistration=
endpoint. HarvesterRegistration.dbInsert() builds an INSERT against HARVES= T_SITE_SCHEDULE via string concatenation, using a quoteString() helper that=
performs raw single-quote wrapping without escaping. Three request paramet= ers reach the sink: unit, contactEmail, and documentListURL. The servlet do=
es not verify a real LDAP identity. Allowing the vulnerable insert to proce= ed. Since the PostgreSQL backend permits stacked queries via Statement.exec= uteUpdate(), this vulnerability allows full read/write/execute access in th=
e Metacat database context. The vulnerability was remediated in Metacat 3.0= .0. 2026-06-15 9.8 CVE-2026-48114 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-48114 ] nesquena--hermes-webui Hermes WebUI before 0.51.368 contains a=
n authorization bypass vulnerability in the get_profile_cookie() function t= hat accepts unauthenticated profile names from the hermes_profile cookie. A=
n authenticated attacker can forge the hermes_profile cookie value to bypas=
s profile-scoped authorization checks and access sessions, files, and resou= rces across different profiles. 2026-06-17 8.1 CVE-2026-53871 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-53871 ] Netdrive--NetDrive NetDrive 2.6.12=
contains an unquoted service path vulnerability in the Netdrive2_Service_N= etdrive2 service that allows local users to execute arbitrary code with SYS= TEM privileges. Attackers can insert malicious executables in the system ro=
ot path that will be executed during service startup or system reboot, resu= lting in privilege escalation. 2026-06-19 7.8 CVE-2016-20092 [
https://www.= cve.org/CVERecord?id=3DCVE-2016-20092 ] Network-Inventory-Advisor--Network = Inventory Advisor Network Inventory Advisor 5.0.26.0 installs the niaservic=
e service with an unquoted binary path that allows local attackers to escal= ate privileges by placing malicious executables in intermediate directories=
. Attackers can exploit the unquoted path in the service configuration to e= xecute arbitrary code with LocalSystem privileges when the service starts o=
r restarts. 2026-06-19 7.8 CVE-2019-25747 [
https://www.cve.org/CVERecord?i= d=3DCVE-2019-25747 ] Networkdls--Fortitude HTTP Fortitude HTTP 1.0.4.0 cont= ains an unquoted service path vulnerability that allows local users to exec= ute arbitrary code with elevated privileges by exploiting the service binar=
y path. Attackers can insert malicious executables in the system root path = that execute with SYSTEM privileges during service startup or system reboot=
. 2026-06-19 7.8 CVE-2016-20087 [
https://www.cve.org/CVERecord?id=3DCVE-20= 16-20087 ] Nexi Payments--Nexi XPay Missing Authorization vulnerability in = Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Con= trol Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1.=
2026-06-17 7.5 CVE-2026-54810 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-54810 ] nextgeneditor--NextGen Editor Joomla NextGen Editor 2.1.0 contain=
s an SQL injection vulnerability that allows unauthenticated attackers to e= xecute arbitrary SQL commands through the plname parameter. Attackers can s= end GET requests to index.php with option=3Dcom_nge&view=3Dconfig and injec=
t malicious SQL code in the plname parameter to extract sensitive database = information. 2026-06-19 8.2 CVE-2017-20252 [
https://www.cve.org/CVERecord?= id=3DCVE-2017-20252 ] NI--grpc-device There is an untrusted pointer derefer= ence vulnerability in the NI grpc-device sideband streaming API that may al= low an attacker to cause an arbitrary memory dereference, potentially resul= ting in remote code execution.=C2=A0 Successful exploitation requires an at= tacker=C2=A0 to supply a specially crafted=C2=A0Moniker protobuf message.= =C2=A0 This affects NI grpc-device 2.17.0 and prior versions. 2026-06-19 9.=
1 CVE-2026-48137 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48137 ] NI--= grpc-device There is an insecure default credentials vulnerability in NI gr= pc-device when TLS configuration is not present and the server is bound bey= ond loopback.=C2=A0 This may allow an unauthenticated user access to the se= rver on the local network.=C2=A0 This affects NI grpc-device 2.17.0 and pri=
or versions. 2026-06-19 9.1 CVE-2026-9142 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-9142 ] NI--grpc-device There is an out-of-bounds read vulnerab= ility in the NI grpc-device streaming API due to a missing bounds check tha=
t may result in a denial of service. Successful exploitation requires an at= tacker to supply a specially crafted write request. This affects NI grpc-de= vice 2.17.0 and prior versions. 2026-06-19 7.5 CVE-2026-48138 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-48138 ] NI--grpc-device There is a NULL po= inter dereference vulnerability in NI grpc-device in the data moniker servi=
ce that may allow an attacker to cause a denial of service by triggering a = crash.=C2=A0 Successful exploitation requires an attacker to provide an unk= nown=C2=A0value to the data moniker service. This affects NI grpc-device 2.= 17.0 and prior versions. 2026-06-19 7.5 CVE-2026-48139 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-48139 ] Ninja Team--FastDup Unauthenticated Path = Traversal in FastDup <=3D 2.7.2 versions. 2026-06-15 9.6 CVE-2026-52703 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-52703 ] Nordmograph--StreetGuess=
r Game Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerabili=
ty that allows unauthenticated attackers to execute arbitrary SQL queries b=
y injecting malicious code through the catid parameter. Attackers can send = GET requests to index.php with the option=3Dcom_streetguess&view=3Dmaps par= ameters and inject SQL code in the catid parameter to extract sensitive dat= abase information including version and database names. 2026-06-19 8.2 CVE-= 2017-20271 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20271 ] NousResear= ch--hermes-agent Hermes Agent before 0.16.0 contains a DNS rebinding vulner= ability in WebSocket endpoints that allows remote attackers to bypass Host = and Origin validation. FastAPI HTTP middleware does not execute for WebSock=
et upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoin= ts, enabling attackers to exploit DNS rebinding and inject malicious comman=
ds or read terminal output. 2026-06-17 7.5 CVE-2026-53869 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-53869 ] NSquared--Simply Schedule Appointments=
Unauthenticated SQL Injection in Simply Schedule Appointments <=3D 1.6.9.2=
7 versions. 2026-06-15 9.3 CVE-2026-39493 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-39493 ] NSquared--Simply Schedule Appointments Unauthenticated=
Cross Site Scripting (XSS) in Simply Schedule Appointments <=3D 1.6.10.6 v= ersions. 2026-06-15 7.1 CVE-2026-39447 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-39447 ] NSquared--Simply Schedule Appointments Unauthenticated = Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions=
. 2026-06-15 7.5 CVE-2026-42384 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-42384 ] Nur-Alam39--bus-ticket Nur-Alam39 bus-ticket (no released versio= ns; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an una= uthenticated SQL injection vulnerability in bus_info.php. The busid paramet=
er received via HTTP POST is concatenated directly into a MySQL query (sele=
ct * from bus_info where id=3D$busid) without sanitization, escaping, or pa= rameterization, and in a numeric (unquoted) context. A remote, unauthentica= ted attacker can inject arbitrary SQL - for example a UNION-based payload s= uch as busid=3D-1 UNION SELECT 1,2,3,4,5,6 - to read arbitrary data from th=
e bus_service database. The application connects to the database as the MyS=
QL root account with an empty password, increasing the potential impact. Th=
e query is executed via mysqli_query(), which does not permit stacked (semi= colon-separated) statements. 2026-06-18 9.8 CVE-2026-55740 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-55740 ] nv-tlabs--GEN3C NVIDIA Spatial Intell= igence Lab's (SIL) GEN3C contains an unauthenticated remote code execution = vulnerability in the inference API server where the /request-inference and = /seed-model endpoints deserialize raw HTTP request bodies using Python's pi= ckle.loads() without authentication or input validation. Attackers can supp=
ly a crafted payload containing a __reduce__ gadget to the inference API po=
rt to achieve remote code execution as the inference process. 2026-06-17 9.=
8 CVE-2026-53805 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53805 ] NVID= IA--NeMo Framework NVIDIA NeMo Framework for all platforms contains a code = injection vulnerability. A successful exploit of this vulnerability might l= ead to code execution, escalation of privileges, information disclosure, an=
d data tampering. 2026-06-16 7.8 CVE-2026-24155 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-24155 ] NVIDIA--NeMo Framework NVIDIA NeMo Framework for=
Linux contains a vulnerability where an attacker may cause deserialization=
of untrusted data. A successful exploit of this vulnerability may lead to = code execution, escalation of privileges, data tampering, and information d= isclosure. 2026-06-16 7.8 CVE-2026-24228 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-24228 ] oleksandrz--E2Pdf Export Pdf Tool for WordPress The E2P=
df - Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Mi= ssing Authorization in versions up to, and including, 1.32.26. This is due =
to the screen_action() function lacking a dedicated capability check and no= nce verification - when invoked via the ?action=3Dscreen routing path the c= ontroller's index_action() nonce gate is bypassed entirely - while reading =
an attacker-controlled option name and value from $_POST['wp_screen_options=
'] and passing them directly to update_option() with no allowlist, relying = solely on the page-level e2pdf_templates capability which the plugin's own = Permissions UI allows administrators to grant to any role including Subscri= ber, Contributor, Author, or Editor. This makes it possible for authenticat=
ed attackers, with a custom role that has been granted the e2pdf_templates = capability, to overwrite arbitrary WordPress options such as default_role a=
nd thereby escalate their privileges to administrator. 2026-06-18 8.8 CVE-2= 026-12407 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12407 ] OliveTin--O= liveTin OliveTin gives access to predefined shell commands from a web inter= face. In versions 3000.0.0 and prior, the template engine uses a single sha= red text/template.Template instance (tpl package-level variable in service/= internal/tpl/templates.go) across all goroutines. Every action execution ca= lls tpl.Parse(source) followed by t.Execute() on this shared instance with =
no synchronization. When two or more actions execute concurrently (which is=
the normal case - each ExecRequest spawns a goroutine), a race condition o= ccurs: one goroutine's Parse overwrites the template tree while another gor= outine is calling Execute, causing cross-user command contamination, Go run= time panic, and incorrect command execution. This issue has been resolved i=
n version 3000.13.0. 2026-06-15 7.5 CVE-2026-48708 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-48708 ] Omnisend--Email Marketing for WooCommerce by = Omnisend Unauthenticated Broken Authentication in Email Marketing for WooCo= mmerce by Omnisend <=3D 1.18.0 versions. 2026-06-15 7.5 CVE-2026-42668 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-42668 ] open-webui--open-webui Op=
en WebUI is a self-hosted artificial intelligence platform designed to oper= ate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in = `backend/open_webui/routers/terminals.py` does not fully confine the user-c= ontrolled `path` segment before forwarding it to an admin-configured termin=
al server. An authenticated user who has been granted access to a terminal = server can craft `path` values containing encoded `../` traversal sequences=
that escape the intended path (or policy) scope on that server, reaching u= nintended endpoints and files on the terminal-server host. Where the termin=
al server fans requests out to internal services, this also gives SSRF-styl=
e reach into those services. This is a separate code path from the `/api/v1= /retrieval/process/web` SSRF (GHSA-c6xv-rcvw-v685), with its own input. Two=
distinct vectors are consolidated here: first, raw path forwarding / singl= e-encoded traversal (original report); and second, a bypass of the subseque= ntly-added `_sanitize_proxy_path` mitigation using double-encoded dots (`%2= 52e%252e`). The attacker-controlled input is the request `path`, supplied b=
y the non-admin user, not anything an administrator configures, so this is = not an admin-trust / Rule-9 situation. Version 0.9.6 fixes the issue. 2026-= 06-18 7.7 CVE-2026-54017 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5401=
7 ] OpenClaw--OpenClaw OpenClaw before 2026.5.26 contains an authorization = bypass vulnerability where a surviving pairing-scoped device session can re= -establish node token authority after revocation. Attackers with a paired d= evice can regain WebSocket node-level access without renewed approval, weak= ening revocation controls and maintaining unauthorized access longer than i= ntended. 2026-06-16 8.8 CVE-2026-53843 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-53843 ] OpenClaw--OpenClaw OpenClaw before 2026.5.7 contains a = privilege escalation vulnerability where the allowFrom feature improperly v= alidates Discord account identity using mutable display names instead of im= mutable user IDs. Attackers with Discord accounts can change their display = name to match a policy entry and gain unauthorized agent access intended fo=
r another Discord identity. 2026-06-16 8.1 CVE-2026-53849 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-53849 ] OpenClaw--OpenClaw OpenClaw before 202= 6.5.12 contains an argument pattern validation bypass in the exec allowlist=
that allows attackers to execute disallowed arguments for allowlisted exec= utables on Linux and macOS systems. Attackers can bypass configured argPatt= ern restrictions by directly invoking allowlisted executables with unrestri= cted arguments, potentially enabling unauthorized file access, network acce= ss, or command execution. 2026-06-16 8.3 CVE-2026-53853 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-53853 ] OpenClaw--OpenClaw OpenClaw before 2026.= 4.2 contains an inline-eval bypass vulnerability allowing authenticated ope= rators to weaken strict allowlist checks via shell positional parameters. A= ttackers can combine allowlisted tools with shell positional arguments to p= lace inline-eval content in shell carriers outside intended allowlist rules=
, enabling execution of unapproved shell-provided content. 2026-06-16 8.1 C= VE-2026-53855 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53855 ] OpenCla= w--OpenClaw OpenClaw before 2026.5.3 contains a policy enforcement vulnerab= ility where Zalo contacts with mutable display metadata could match allowFr=
om policy entries through display name changes. Attackers with mutable disp= lay names could receive agent responses intended for different Zalo identit= ies when the feature is enabled. 2026-06-16 8.1 CVE-2026-53857 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-53857 ] OpenClaw--OpenClaw OpenClaw befor=
e 2026.5.26 contains an insufficient sanitization vulnerability in the host=
environment sanitizer that allows Node.js control variables to bypass vali= dation. Attackers with access to workspace .env files, tool environment ove= rrides, or skill environment blocks can pass malicious Node.js control vari= ables to influence child processes or coverage output paths. 2026-06-16 8.1=
CVE-2026-53864 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53864 ] OpenC= law--OpenClaw OpenClaw before 2026.5.12 contains an allowlist bypass vulner= ability in shell inline-command parsing that allows authenticated operators=
to execute unapproved commands. A command request using shell inline-comma=
nd forms could route through a parser case missing the expected allowlist d= ecision, enabling shell content execution without intended approval prompts=
. 2026-06-16 8.1 CVE-2026-53866 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-53866 ] OpenClaw--OpenClaw OpenClaw before 2026.5.12 contains an informa= tion disclosure vulnerability in streamable-http MCP servers that forwards = operator-configured custom headers during cross-origin redirects. Attackers=
controlling or compromising an MCP endpoint can redirect requests to exfil= trate sensitive headers like API keys or tenant-routing credentials to atta= cker-controlled origins. 2026-06-16 7.1 CVE-2026-53840 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-53840 ] OpenClaw--OpenClaw OpenClaw before 2026.5=
.2 contains an environment variable injection vulnerability allowing worksp= ace .env files to influence Python runtime selection through CLOUDSDK_PYTHO=
N during Gmail setup gcloud execution. Attackers with repository access can=
manipulate the CLOUDSDK_PYTHON variable to execute setup through unintende=
d local Python paths, potentially enabling arbitrary code execution. 2026-0= 6-16 7.1 CVE-2026-53842 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53842=
] OpenClaw--OpenClaw OpenClaw before 2026.4.29 contains a path traversal v= ulnerability in the install helper that allows workspace .env files to over= ride the npm_execpath configuration used for bundled runtime dependency ins= tallation. Attackers with workspace access can execute unintended local pac= kage-manager executables during dependency setup to compromise the build en= vironment. 2026-06-16 7.1 CVE-2026-53846 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-53846 ] OpenClaw--OpenClaw OpenClaw before 2026.5.2 contains an=
environment variable injection vulnerability where workspace .env STATE_DI= RECTORY could influence bundled runtime dependency roots. Attackers can man= ipulate the STATE_DIRECTORY variable to load runtime dependencies from unin= tended local paths, potentially executing malicious code during dependency = resolution. 2026-06-16 7.1 CVE-2026-53858 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-53858 ] OpenClaw--OpenClaw OpenClaw before 2026.4.25 contains =
an input validation vulnerability in tool group policy callers that accept = unvalidated group IDs. Attackers who can supply a group ID to the policy re= solver could trigger incorrect group-policy decisions for tool invocations,=
potentially bypassing intended access controls. 2026-06-16 7.1 CVE-2026-53= 863 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53863 ] OpenClaw--OpenCla=
w OpenClaw before 2026.5.2 contains a path traversal vulnerability in maint= enance task execution that allows workspace-derived service paths to influe= nce trash command selection. Attackers can execute unintended local executa= bles from operator-unintended paths during maintenance operations by manipu= lating workspace-derived environment paths. 2026-06-16 7.1 CVE-2026-53865 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-53865 ] Oracle Corporation--AP=
M - Application Performance Management Vulnerability in the APM - Applicati=
on Performance Management product of Oracle Enterprise Manager (component: = JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 2= 4.1. Easily exploitable vulnerability allows unauthenticated attacker with = network access via HTTP to compromise APM - Application Performance Managem= ent. Successful attacks of this vulnerability can result in unauthorized cr= eation, deletion or modification access to critical data or all APM - Appli= cation Performance Management accessible data and unauthorized ability to c= ause a hang or frequently repeatable crash (complete DOS) of APM - Applicat= ion Performance Management. CVSS 3.1 Base Score 9.1 (Integrity and Availabi= lity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).=
2026-06-16 9.1 CVE-2026-46858 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-46858 ] Oracle Corporation--Identity Manager Vulnerability in the Identit=
y Manager product of Oracle Fusion Middleware (component: Core). Supported = versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitabl=
e vulnerability allows low privileged attacker with network access via T3, = IIOP to compromise Identity Manager. While the vulnerability is in Identity=
Manager, attacks may significantly impact additional products (scope chang= e). Successful attacks of this vulnerability can result in takeover of Iden= tity Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Avail= ability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:= H). 2026-06-16 9.9 CVE-2026-35268 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-35268 ] Oracle Corporation--Identity Manager Vulnerability in the Iden= tity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI)=
. Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easil=
y exploitable vulnerability allows unauthenticated attacker with network ac= cess via T3, IIOP to compromise Identity Manager. Successful attacks of thi=
s vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base S= core 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-4= 6807 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46807 ] Oracle Corporati= on--Identity Manager Vulnerability in the Identity Manager product of Oracl=
e Fusion Middleware (component: Security). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Identit=
y Manager. Successful attacks of this vulnerability can result in takeover =
of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity an=
d Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H= /I:H/A:H). 2026-06-16 8.8 CVE-2026-35265 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-35265 ] Oracle Corporation--Identity Manager Vulnerability in t=
he Identity Manager product of Oracle Fusion Middleware (component: REST We= bServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.= 1.0. Easily exploitable vulnerability allows low privileged attacker with n= etwork access via HTTP to compromise Identity Manager. Successful attacks o=
f this vulnerability can result in takeover of Identity Manager. CVSS 3.1 B= ase Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS V= ector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2= 026-35267 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35267 ] Oracle Corp= oration--Identity Manager Vulnerability in the Identity Manager product of = Oracle Fusion Middleware (component: REST WebServices). Supported versions = that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnera= bility allows unauthenticated attacker with network access via HTTP to comp= romise Identity Manager. Successful attacks of this vulnerability can resul=
t in unauthorized creation, deletion or modification access to critical dat=
a or all Identity Manager accessible data. CVSS 3.1 Base Score 7.5 (Integri=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). 2= 026-06-16 7.5 CVE-2026-35269 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 35269 ] Oracle Corporation--Identity Manager Connector Vulnerability in the=
Identity Manager Connector product of Oracle Fusion Middleware (component:=
Mainframe Connectors). Supported versions that are affected are 12.2.1.4.0=
and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged att= acker with network access via HTTP to compromise Identity Manager Connector=
. While the vulnerability is in Identity Manager Connector, attacks may sig= nificantly impact additional products (scope change). Successful attacks of=
this vulnerability can result in takeover of Identity Manager Connector. C= VSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts=
). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 = 9.9 CVE-2026-35294 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35294 ] Or= acle Corporation--Identity Manager Connector Vulnerability in the Identity = Manager Connector product of Oracle Fusion Middleware (component: Generic U= nix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.= 1.2.1.0. Easily exploitable vulnerability allows low privileged attacker wi=
th network access via HTTP to compromise Identity Manager Connector. While = the vulnerability is in Identity Manager Connector, attacks may significant=
ly impact additional products (scope change). Successful attacks of this vu= lnerability can result in takeover of Identity Manager Connector. CVSS 3.1 = Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS = Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-= 2026-46792 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46792 ] Oracle Cor= poration--Identity Manager Connector Vulnerability in the Identity Manager = Connector product of Oracle Fusion Middleware (component: Database User). S= upported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily e= xploitable vulnerability allows low privileged attacker with network access=
via HTTP to compromise Identity Manager Connector. While the vulnerability=
is in Identity Manager Connector, attacks may significantly impact additio= nal products (scope change). Successful attacks of this vulnerability can r= esult in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (C= onfidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1= /AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46793 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-46793 ] Oracle Corporation--Identit=
y Manager Connector Vulnerability in the Identity Manager Connector product=
of Oracle Fusion Middleware (component: Generic Unix Connector). Supported=
versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitab=
le vulnerability allows low privileged attacker with network access via SSH=
to compromise Identity Manager Connector. While the vulnerability is in Id= entity Manager Connector, attacks may significantly impact additional produ= cts (scope change). Successful attacks of this vulnerability can result in = takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidenti= ality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:= L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46794 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-46794 ] Oracle Corporation--JD Edwards Enter= priseOne Accounts Payable Vulnerability in the JD Edwards EnterpriseOne Acc= ounts Payable product of Oracle JD Edwards (component: Accounts Payable). T=
he supported version that is affected is 9.2. Easily exploitable vulnerabil= ity allows low privileged attacker with network access via HTTP to compromi=
se JD Edwards EnterpriseOne Accounts Payable. While the vulnerability is in=
JD Edwards EnterpriseOne Accounts Payable, attacks may significantly impac=
t additional products (scope change). Successful attacks of this vulnerabil= ity can result in takeover of JD Edwards EnterpriseOne Accounts Payable. CV=
SS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts)=
. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9=
.9 CVE-2026-46908 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46908 ] Ora= cle Corporation--JD Edwards EnterpriseOne Accounts Payable Vulnerability in=
the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards=
(component: Accounts Payable). The supported version that is affected is 9= .2. Easily exploitable vulnerability allows low privileged attacker with ne= twork access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payab= le. Successful attacks of this vulnerability can result in unauthorized cre= ation, deletion or modification access to critical data or all JD Edwards E= nterpriseOne Accounts Payable accessible data as well as unauthorized acces=
s to critical data or complete access to all JD Edwards EnterpriseOne Accou= nts Payable accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and I= ntegrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :N). 2026-06-16 8.1 CVE-2026-46891 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-46891 ] Oracle Corporation--JD Edwards EnterpriseOne General Ledger V= ulnerability in the JD Edwards EnterpriseOne General Ledger product of Orac=
le JD Edwards (component: E1 Foundation). The supported version that is aff= ected is 9.2. Easily exploitable vulnerability allows low privileged attack=
er with network access via SMB to compromise JD Edwards EnterpriseOne Gener=
al Ledger. While the vulnerability is in JD Edwards EnterpriseOne General L= edger, attacks may significantly impact additional products (scope change).=
Successful attacks of this vulnerability can result in takeover of JD Edwa= rds EnterpriseOne General Ledger. CVSS 3.1 Base Score 9.9 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46893 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-46893 ] Oracle Corporation--JD Edwards EnterpriseO=
ne Human Resources Management Vulnerability in the JD Edwards EnterpriseOne=
Human Resources Management product of Oracle JD Edwards (component: Human = Resources). The supported version that is affected is 9.2. Easily exploitab=
le vulnerability allows unauthenticated attacker with network access via HT=
TP to compromise JD Edwards EnterpriseOne Human Resources Management. Succe= ssful attacks of this vulnerability can result in unauthorized creation, de= letion or modification access to critical data or all JD Edwards Enterprise= One Human Resources Management accessible data as well as unauthorized acce=
ss to critical data or complete access to all JD Edwards EnterpriseOne Huma=
n Resources Management accessible data. CVSS 3.1 Base Score 9.1 (Confidenti= ality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:= U/C:H/I:H/A:N). 2026-06-16 9.1 CVE-2026-46892 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-46892 ] Oracle Corporation--JD Edwards EnterpriseOne Order=
Promising Vulnerability in the JD Edwards EnterpriseOne Order Promising pr= oduct of Oracle JD Edwards (component: Order Promising Integration). The su= pported version that is affected is 9.2. Easily exploitable vulnerability a= llows low privileged attacker with network access via HTTP to compromise JD=
Edwards EnterpriseOne Order Promising. While the vulnerability is in JD Ed= wards EnterpriseOne Order Promising, attacks may significantly impact addit= ional products (scope change). Successful attacks of this vulnerability can=
result in takeover of JD Edwards EnterpriseOne Order Promising. CVSS 3.1 B= ase Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS V= ector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2= 026-46907 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46907 ] Oracle Corp= oration--JD Edwards EnterpriseOne Project Costing Vulnerability in the JD E= dwards EnterpriseOne Project Costing product of Oracle JD Edwards (componen=
t: Job Costing). The supported version that is affected is 9.2. Easily expl= oitable vulnerability allows low privileged attacker with network access vi=
a JDENET to compromise JD Edwards EnterpriseOne Project Costing. While the = vulnerability is in JD Edwards EnterpriseOne Project Costing, attacks may s= ignificantly impact additional products (scope change). Successful attacks =
of this vulnerability can result in unauthorized creation, deletion or modi= fication access to critical data or all JD Edwards EnterpriseOne Project Co= sting accessible data as well as unauthorized access to critical data or co= mplete access to all JD Edwards EnterpriseOne Project Costing accessible da= ta. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS V= ector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). 2026-06-16 9.6 CVE-2= 026-46911 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46911 ] Oracle Corp= oration--JD Edwards EnterpriseOne Tools Vulnerability in the JD Edwards Ent= erpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infras= tructure Security). Supported versions that are affected are 9.2.0.0-9.2.26= .2. Easily exploitable vulnerability allows unauthenticated attacker with n= etwork access via JDENET to compromise JD Edwards EnterpriseOne Tools. Succ= essful attacks of this vulnerability can result in takeover of JD Edwards E= nterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and=
Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/= I:H/A:H). 2026-06-16 9.8 CVE-2026-46878 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46878 ] Oracle Corporation--JD Edwards EnterpriseOne Tools Vuln= erability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edward=
s (component: Enterprise Infrastructure Security). Supported versions that = are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows = unauthenticated attacker with network access via JDENET to compromise JD Ed= wards EnterpriseOne Tools. Successful attacks of this vulnerability can res= ult in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 = (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3= .1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46879 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-46879 ] Oracle Corporation--JD Ed= wards EnterpriseOne Tools Vulnerability in the JD Edwards EnterpriseOne Too=
ls product of Oracle JD Edwards (component: Enterprise Infrastructure Secur= ity). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exp= loitable vulnerability allows unauthenticated attacker with network access = via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks=
of this vulnerability can result in takeover of JD Edwards EnterpriseOne T= ools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability = impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026= -06-16 9.8 CVE-2026-46880 [
https://www.cve.org/CVERecord?id=3DCVE-2026-468=
80 ] Oracle Corporation--JD Edwards EnterpriseOne Tools Vulnerability in th=
e JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E= nterprise Infrastructure Security). Supported versions that are affected ar=
e 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated=
attacker with network access via JDENET to compromise JD Edwards Enterpris= eOne Tools. Successful attacks of this vulnerability can result in takeover=
of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentialit=
y, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR= :N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46881 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-46881 ] Oracle Corporation--JD Edwards Enterpris= eOne Tools Vulnerability in the JD Edwards EnterpriseOne Tools product of O= racle JD Edwards (component: Enterprise Infrastructure Security). Supported=
versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulner= ability allows unauthenticated attacker with network access via JDENET to c= ompromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulner= ability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 = Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS = Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-= 2026-46882 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46882 ] Oracle Cor= poration--JD Edwards EnterpriseOne Tools Vulnerability in the JD Edwards En= terpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infra= structure Security). Supported versions that are affected are 9.2.0.0-9.2.2= 6.2. Easily exploitable vulnerability allows unauthenticated attacker with = network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Suc= cessful attacks of this vulnerability can result in takeover of JD Edwards = EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity an=
d Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H= /I:H/A:H). 2026-06-16 9.8 CVE-2026-46883 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46883 ] Oracle Corporation--JD Edwards EnterpriseOne Tools Vuln= erability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edward=
s (component: Enterprise Infrastructure Security). Supported versions that = are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows = unauthenticated attacker with network access via JDENET to compromise JD Ed= wards EnterpriseOne Tools. Successful attacks of this vulnerability can res= ult in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 = (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3= .1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46904 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-46904 ] Oracle Corporation--JD Ed= wards EnterpriseOne Tools Vulnerability in the JD Edwards EnterpriseOne Too=
ls product of Oracle JD Edwards (component: Web Runtime Security). Supporte=
d versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulne= rability allows unauthenticated attacker with network access via HTTP to co= mpromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnera= bility can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 B= ase Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS V= ector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2= 026-46905 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46905 ] Oracle Corp= oration--JD Edwards EnterpriseOne Tools Vulnerability in the JD Edwards Ent= erpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infras= tructure Security). Supported versions that are affected are 9.2.0.0-9.2.26= .2. Easily exploitable vulnerability allows low privileged attacker with ne= twork access via HTTP to compromise JD Edwards EnterpriseOne Tools. While t=
he vulnerability is in JD Edwards EnterpriseOne Tools, attacks may signific= antly impact additional products (scope change). Successful attacks of this=
vulnerability can result in unauthorized creation, deletion or modificatio=
n access to critical data or all JD Edwards EnterpriseOne Tools accessible = data as well as unauthorized access to critical data or complete access to = all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.6=
(Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/= PR:L/UI:N/S:C/C:H/I:H/A:N). 2026-06-16 9.6 CVE-2026-46906 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-46906 ] Oracle Corporation--JD Edwards Enterpr= iseOne Tools Vulnerability in the JD Edwards EnterpriseOne Tools product of=
Oracle JD Edwards (component: Enterprise Infrastructure Security). Support=
ed versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vuln= erability allows unauthenticated attacker with network access via HTTP to c= ompromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulner= ability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 = Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS = Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-= 2026-46909 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46909 ] Oracle Cor= poration--JD Edwards EnterpriseOne Tools Vulnerability in the JD Edwards En= terpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infra= structure Security). Supported versions that are affected are 9.2.0.0-9.2.2= 6.2. Easily exploitable vulnerability allows unauthenticated attacker with = network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Succe= ssful attacks of this vulnerability can result in unauthorized access to cr= itical data or complete access to all JD Edwards EnterpriseOne Tools access= ible data and unauthorized ability to cause a hang or frequently repeatable=
crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Scor=
e 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV= :N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H). 2026-06-16 9.1 CVE-2026-46910 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-46910 ] Oracle Corporation--JD Edwards=
EnterpriseOne Tools Vulnerability in the JD Edwards EnterpriseOne Tools pr= oduct of Oracle JD Edwards (component: Web Runtime Security). Supported ver= sions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerabil= ity allows unauthenticated attacker with network access via HTTP to comprom= ise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edward=
s EnterpriseOne Tools, attacks may significantly impact additional products=
(scope change). Successful attacks of this vulnerability can result in una= uthorized access to critical data or complete access to all JD Edwards Ente= rpriseOne Tools accessible data as well as unauthorized update, insert or d= elete access to some of JD Edwards EnterpriseOne Tools accessible data. CVS=
S 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: = (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N). 2026-06-16 9.3 CVE-2026-469=
12 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46912 ] Oracle Corporation= --JD Edwards EnterpriseOne Tools Vulnerability in the JD Edwards Enterprise= One Tools product of Oracle JD Edwards (component: Installation Security). = Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitab=
le vulnerability allows unauthenticated attacker with logon to the infrastr= ucture where JD Edwards EnterpriseOne Tools executes to compromise JD Edwar=
ds EnterpriseOne Tools. While the vulnerability is in JD Edwards Enterprise= One Tools, attacks may significantly impact additional products (scope chan= ge). Successful attacks of this vulnerability can result in takeover of JD = Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.3 (Confidentiality, Inte= grity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N= /S:C/C:H/I:H/A:H). 2026-06-16 9.3 CVE-2026-46913 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-46913 ] Oracle Corporation--JD Edwards EnterpriseOne To= ols Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Business Logic Infrastructure Security). Supported ve= rsions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerabi= lity allows low privileged attacker with network access via HTTP to comprom= ise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerabilit=
y can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base S= core 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-4= 6903 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46903 ] Oracle Corporati= on--MySQL NDB Cluster Vulnerability in the MySQL NDB Cluster product of Ora= cle MySQL (component: Cluster: NDB Operator). Supported versions that are a= ffected are 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable = vulnerability allows low privileged attacker with network access via HTTP t=
o compromise MySQL NDB Cluster. While the vulnerability is in MySQL NDB Clu= ster, attacks may significantly impact additional products (scope change). = Successful attacks of this vulnerability can result in unauthorized creatio=
n, deletion or modification access to critical data or all MySQL NDB Cluste=
r accessible data as well as unauthorized access to critical data or comple=
te access to all MySQL NDB Cluster accessible data. CVSS 3.1 Base Score 9.6=
(Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/= PR:L/UI:N/S:C/C:H/I:H/A:N). 2026-06-16 9.6 CVE-2026-46861 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-46861 ] Oracle Corporation--MySQL Router Vulne= rability in the MySQL Router product of Oracle MySQL (component: Router: Ge= neral). Supported versions that are affected are 9.0.0-9.7.0. Easily exploi= table vulnerability allows unauthenticated attacker with network access via=
HTTP to compromise MySQL Router. Successful attacks of this vulnerability = can result in takeover of MySQL Router. CVSS 3.1 Base Score 9.8 (Confidenti= ality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:= L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46860 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-46860 ] Oracle Corporation--MySQL Router Vul= nerability in the MySQL Router product of Oracle MySQL (component: Router: = General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.= 7.0. Easily exploitable vulnerability allows unauthenticated attacker with = network access via TLS to compromise MySQL Router. Successful attacks of th=
is vulnerability can result in unauthorized ability to cause a hang or freq= uently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score=
7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U= /C:N/I:N/A:H). 2026-06-16 7.5 CVE-2026-46862 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-46862 ] Oracle Corporation--MySQL Server Vulnerability in t=
he MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: = Connection Handling). Supported versions that are affected are MySQL Server=
: 8.4.0-8.4.9, 9.0.0-9.7.0; MySQL Cluster: 8.0.11-8.0.46, 8.4.0-8.4.9 and 9= .0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacke=
r with network access via multiple protocols to compromise MySQL Server, My= SQL Cluster. Successful attacks of this vulnerability can result in unautho= rized ability to cause a hang or frequently repeatable crash (complete DOS)=
of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impa= cts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). 2026-06-=
16 7.5 CVE-2026-46863 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46863 ]=
Oracle Corporation--MySQL Shell Vulnerability in the MySQL Shell product o=
f Oracle MySQL (component: Shell for VS Code). The supported version that i=
s affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low p= rivileged attacker with network access via HTTP to compromise MySQL Shell. = While the vulnerability is in MySQL Shell, attacks may significantly impact=
additional products (scope change). Successful attacks of this vulnerabili=
ty can result in takeover of MySQL Shell. CVSS 3.1 Base Score 9.9 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46850 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-46850 ] Oracle Corporation--MySQL Shell Vu= lnerability in the MySQL Shell product of Oracle MySQL (component: Shell fo=
r VS Code). The supported version that is affected is 2026.2.0+9.6.1. Diffi= cult to exploit vulnerability allows low privileged attacker with network a= ccess via multiple protocols to compromise MySQL Shell. While the vulnerabi= lity is in MySQL Shell, attacks may significantly impact additional product=
s (scope change). Successful attacks of this vulnerability can result in ta= keover of MySQL Shell. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C= :H/I:H/A:H). 2026-06-16 8.5 CVE-2026-46870 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-46870 ] Oracle Corporation--Oracle Access Manager Vulnerabili=
ty in the Oracle Access Manager product of Oracle Fusion Middleware (compon= ent: Authentication Engine). Supported versions that are affected are 12.2.= 1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privilege=
d attacker with network access via HTTP to compromise Oracle Access Manager=
. While the vulnerability is in Oracle Access Manager, attacks may signific= antly impact additional products (scope change). Successful attacks of this=
vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Ba=
se Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Ve= ctor: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-20= 26-35313 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35313 ] Oracle Corpo= ration--Oracle Access Manager Vulnerability in the Oracle Access Manager pr= oduct of Oracle Fusion Middleware (component: Web Server Plugin). Supported=
versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitab=
le vulnerability allows unauthenticated attacker with network access via HT=
TP to compromise Oracle Access Manager. Successful attacks of this vulnerab= ility can result in unauthorized update, insert or delete access to some of=
Oracle Access Manager accessible data as well as unauthorized read access =
to a subset of Oracle Access Manager accessible data and unauthorized abili=
ty to cause a partial denial of service (partial DOS) of Oracle Access Mana= ger. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability i= mpacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). 2026-= 06-16 7.3 CVE-2026-35314 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3531=
4 ] Oracle Corporation--Oracle Advanced Outbound Telephony Vulnerability in=
the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite = (component: Internal Operations). Supported versions that are affected are = 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated att= acker with network access via HTTP to compromise Oracle Advanced Outbound T= elephony. Successful attacks of this vulnerability can result in unauthoriz=
ed creation, deletion or modification access to critical data or all Oracle=
Advanced Outbound Telephony accessible data as well as unauthorized access=
to critical data or complete access to all Oracle Advanced Outbound Teleph= ony accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity=
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). 202= 6-06-16 9.1 CVE-2026-46949 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46= 949 ] Oracle Corporation--Oracle Advanced Outbound Telephony Vulnerability =
in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suit=
e (component: Internal Operations). Supported versions that are affected ar=
e 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged at= tacker with network access via HTTP to compromise Oracle Advanced Outbound = Telephony. Successful attacks of this vulnerability can result in takeover =
of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentia= lity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L= /PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46947 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-46947 ] Oracle Corporation--Oracle Advanced O= utbound Telephony Vulnerability in the Oracle Advanced Outbound Telephony p= roduct of Oracle E-Business Suite (component: Internal Operations). Support=
ed versions that are affected are 12.2.3-12.2.15. Easily exploitable vulner= ability allows low privileged attacker with network access via HTTP to comp= romise Oracle Advanced Outbound Telephony. Successful attacks of this vulne= rability can result in takeover of Oracle Advanced Outbound Telephony. CVSS=
3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). = CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8=
CVE-2026-46950 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46950 ] Oracl=
e Corporation--Oracle Agile PLM Vulnerability in the Oracle Agile PLM produ=
ct of Oracle Supply Chain (component: Security). The supported version that=
is affected is 9.3.6. Easily exploitable vulnerability allows unauthentica= ted attacker with network access via HTTP to compromise Oracle Agile PLM. S= uccessful attacks of this vulnerability can result in takeover of Oracle Ag= ile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2= 026-06-16 9.8 CVE-2026-46859 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 46859 ] Oracle Corporation--Oracle Application Development Framework (ADF) = Vulnerability in the Oracle Application Development Framework (ADF) product=
of Oracle Fusion Middleware (component: ADF Shared Components). Supported = versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl=
e vulnerability allows high privileged attacker with network access via HTT=
P to compromise Oracle Application Development Framework (ADF). Successful = attacks of this vulnerability can result in takeover of Oracle Application = Development Framework (ADF). CVSS 3.1 Base Score 7.2 (Confidentiality, Inte= grity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N= /S:U/C:H/I:H/A:H). 2026-06-16 7.2 CVE-2026-46769 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-46769 ] Oracle Corporation--Oracle Applications Manager=
Vulnerability in the Oracle Applications Manager product of Oracle E-Busin= ess Suite (component: Internal Operations). Supported versions that are aff= ected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle Applicatio=
ns Manager. While the vulnerability is in Oracle Applications Manager, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in takeover of Oracle Application=
s Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabi= lity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).=
2026-06-16 9.9 CVE-2026-46933 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-46933 ] Oracle Corporation--Oracle Coherence Vulnerability in the Oracle = Coherence product of Oracle Fusion Middleware (component: Core). Supported = versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.= 1.0.0. Easily exploitable vulnerability allows unauthenticated attacker wit=
h network access via HTTP to compromise Oracle Coherence. While the vulnera= bility is in Oracle Coherence, attacks may significantly impact additional = products (scope change). Successful attacks of this vulnerability can resul=
t in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentialit=
y, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR= :N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10 CVE-2026-35307 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-35307 ] Oracle Corporation--Oracle Coherence Vuln= erability in the Oracle Coherence product of Oracle Fusion Middleware (comp= onent: Centralized Third Party Jars). Supported versions that are affected = are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable v= ulnerability allows unauthenticated attacker with network access via HTTP t=
o compromise Oracle Coherence. While the vulnerability is in Oracle Coheren= ce, attacks may significantly impact additional products (scope change). Su= ccessful attacks of this vulnerability can result in takeover of Oracle Coh= erence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). 2= 026-06-16 10 CVE-2026-35308 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3= 5308 ] Oracle Corporation--Oracle Coherence Vulnerability in the Oracle Coh= erence product of Oracle Fusion Middleware (component: Core). Supported ver= sions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0= .0. Easily exploitable vulnerability allows unauthenticated attacker with n= etwork access via HTTPS to compromise Oracle Coherence. Successful attacks =
of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 = Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS = Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-= 2026-35304 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35304 ] Oracle Cor= poration--Oracle Coherence Vulnerability in the Oracle Coherence product of=
Oracle Fusion Middleware (component: Centralized Third Party Jars). The su= pported version that is affected is 15.1.1.0.0. Easily exploitable vulnerab= ility allows unauthenticated attacker with network access via HTTP to compr= omise Oracle Coherence. While the vulnerability is in Oracle Coherence, att= acks may significantly impact additional products (scope change). Successfu=
l attacks of this vulnerability can result in unauthorized access to critic=
al data or complete access to all Oracle Coherence accessible data as well =
as unauthorized update, insert or delete access to some of Oracle Coherence=
accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N). 2026-0= 6-16 9.3 CVE-2026-35305 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35305=
] Oracle Corporation--Oracle Coherence Vulnerability in the Oracle Coheren=
ce product of Oracle Fusion Middleware (component: Centralized Third Party = Jars). The supported version that is affected is 15.1.1.0.0. Easily exploit= able vulnerability allows unauthenticated attacker with network access via = HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle C= oherence, attacks may significantly impact additional products (scope chang= e). Successful attacks of this vulnerability can result in unauthorized acc= ess to critical data or complete access to all Oracle Coherence accessible = data as well as unauthorized update, insert or delete access to some of Ora= cle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and=
Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L= /A:N). 2026-06-16 9.3 CVE-2026-35306 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-35306 ] Oracle Corporation--Oracle Coherence Vulnerability in the O= racle Coherence product of Oracle Fusion Middleware (component: Centralized=
Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14= .1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allow=
s unauthenticated attacker with network access via HTTP to compromise Oracl=
e Coherence. Successful attacks of this vulnerability can result in takeove=
r of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C= :H/I:H/A:H). 2026-06-16 9.8 CVE-2026-35309 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-35309 ] Oracle Corporation--Oracle Coherence Vulnerability in=
the Oracle Coherence product of Oracle Fusion Middleware (component: Core)=
. Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0=
.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle Coherence. Succe= ssful attacks of this vulnerability can result in takeover of Oracle Cohere= nce. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability i= mpacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-= 06-16 9.8 CVE-2026-35310 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3531=
0 ] Oracle Corporation--Oracle Complex Maintenance, Repair and Overhaul Vul= nerability in the Oracle Complex Maintenance, Repair and Overhaul product o=
f Oracle E-Business Suite (component: Production). Supported versions that = are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows = low privileged attacker with network access via HTTP to compromise Oracle C= omplex Maintenance, Repair and Overhaul. While the vulnerability is in Orac=
le Complex Maintenance, Repair and Overhaul, attacks may significantly impa=
ct additional products (scope change). Successful attacks of this vulnerabi= lity can result in takeover of Oracle Complex Maintenance, Repair and Overh= aul. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability i= mpacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-= 06-16 8.5 CVE-2026-46915 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4691=
5 ] Oracle Corporation--Oracle Complex Maintenance, Repair and Overhaul Vul= nerability in the Oracle Complex Maintenance, Repair and Overhaul product o=
f Oracle E-Business Suite (component: Internal Operations). Supported versi= ons that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerabilit=
y allows low privileged attacker with network access via HTTP to compromise=
Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of thi=
s vulnerability can result in takeover of Oracle Complex Maintenance, Repai=
r and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Ava= ilability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/= A:H). 2026-06-16 7.5 CVE-2026-46934 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-46934 ] Oracle Corporation--Oracle Complex Maintenance, Repair and O= verhaul Vulnerability in the Oracle Complex Maintenance, Repair and Overhau=
l product of Oracle E-Business Suite (component: Internal Operations). Supp= orted versions that are affected are 12.2.3-12.2.15. Difficult to exploit v= ulnerability allows low privileged attacker with network access via HTTP to=
compromise Oracle Complex Maintenance, Repair and Overhaul. Successful att= acks of this vulnerability can result in takeover of Oracle Complex Mainten= ance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integr= ity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S= :U/C:H/I:H/A:H). 2026-06-16 7.5 CVE-2026-46935 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-46935 ] Oracle Corporation--Oracle Configure to Order Vul= nerability in the Oracle Configure to Order product of Oracle E-Business Su= ite (component: Supply to Order Workbench). Supported versions that are aff= ected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle Configure =
to Order. Successful attacks of this vulnerability can result in unauthoriz=
ed creation, deletion or modification access to critical data or all Oracle=
Configure to Order accessible data as well as unauthorized access to criti= cal data or complete access to all Oracle Configure to Order accessible dat=
a. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Ve= ctor: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). 2026-06-16 8.1 CVE-20= 26-46939 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46939 ] Oracle Corpo= ration--Oracle Cost Management Vulnerability in the Oracle Cost Management = product of Oracle E-Business Suite (component: Cost Planning). Supported ve= rsions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabili=
ty allows low privileged attacker with network access via HTTP to compromis=
e Oracle Cost Management. Successful attacks of this vulnerability can resu=
lt in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46929 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-46929 ] Oracle Corporation--Oracle Cost Ma= nagement Vulnerability in the Oracle Cost Management product of Oracle E-Bu= siness Suite (component: Cost Planning). Supported versions that are affect=
ed are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileg=
ed attacker with network access via HTTP to compromise Oracle Cost Manageme= nt. Successful attacks of this vulnerability can result in takeover of Orac=
le Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and=
Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/= I:H/A:H). 2026-06-16 8.8 CVE-2026-46940 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46940 ] Oracle Corporation--Oracle Cost Management Vulnerabilit=
y in the Oracle Cost Management product of Oracle E-Business Suite (compone= nt: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15=
. Easily exploitable vulnerability allows high privileged attacker with net= work access via HTTP to compromise Oracle Cost Management. Successful attac=
ks of this vulnerability can result in takeover of Oracle Cost Management. = CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impact= s). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). 2026-06-16=
7.2 CVE-2026-46938 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46938 ] O= racle Corporation--Oracle Data Integrator Vulnerability in the Oracle Data = Integrator product of Oracle Fusion Middleware (component: Market Place). S= upported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily e= xploitable vulnerability allows low privileged attacker with network access=
via HTTP to compromise Oracle Data Integrator. Successful attacks of this = vulnerability can result in unauthorized creation, deletion or modification=
access to critical data or all Oracle Data Integrator accessible data as w= ell as unauthorized access to critical data or complete access to all Oracl=
e Data Integrator accessible data and unauthorized ability to cause a parti=
al denial of service (partial DOS) of Oracle Data Integrator. CVSS 3.1 Base=
Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vect= or: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L). 2026-06-16 8.3 CVE-2026= -35262 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35262 ] Oracle Corpora= tion--Oracle Enterprise Asset Management Vulnerability in the Oracle Enterp= rise Asset Management product of Oracle E-Business Suite (component: Intern=
al Operations). Supported versions that are affected are 12.2.6-12.2.15. Ea= sily exploitable vulnerability allows low privileged attacker with network = access via HTTP to compromise Oracle Enterprise Asset Management. Successfu=
l attacks of this vulnerability can result in takeover of Oracle Enterprise=
Asset Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and = Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I= :H/A:H). 2026-06-16 8.8 CVE-2026-46931 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46931 ] Oracle Corporation--Oracle Enterprise Asset Management = Vulnerability in the Oracle Enterprise Asset Management product of Oracle E= -Business Suite (component: Internal Operations). Supported versions that a=
re affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low=
privileged attacker with network access via HTTP to compromise Oracle Ente= rprise Asset Management. Successful attacks of this vulnerability can resul=
t in unauthorized access to critical data or complete access to all Oracle = Enterprise Asset Management accessible data and unauthorized ability to cau=
se a partial denial of service (partial DOS) of Oracle Enterprise Asset Man= agement. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts)=
. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L). 2026-06-16 7=
.1 CVE-2026-46932 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46932 ] Ora= cle Corporation--Oracle Enterprise Command Center Framework Vulnerability i=
n the Oracle Enterprise Command Center Framework product of Oracle E-Busine=
ss Suite (component: Core). Supported versions that are affected are V15 an=
d V16. Easily exploitable vulnerability allows low privileged attacker with=
network access via HTTP to compromise Oracle Enterprise Command Center Fra= mework. While the vulnerability is in Oracle Enterprise Command Center Fram= ework, attacks may significantly impact additional products (scope change).=
Successful attacks of this vulnerability can result in takeover of Oracle = Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiali= ty, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/P= R:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46895 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-46895 ] Oracle Corporation--Oracle Enterprise C= ommand Center Framework Vulnerability in the Oracle Enterprise Command Cent=
er Framework product of Oracle E-Business Suite (component: Core). Supporte=
d versions that are affected are V15 and V16. Easily exploitable vulnerabil= ity allows high privileged attacker with network access via HTTP to comprom= ise Oracle Enterprise Command Center Framework. While the vulnerability is =
in Oracle Enterprise Command Center Framework, attacks may significantly im= pact additional products (scope change). Successful attacks of this vulnera= bility can result in takeover of Oracle Enterprise Command Center Framework=
. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impa= cts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-=
16 9.1 CVE-2026-46896 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46896 ]=
Oracle Corporation--Oracle Enterprise Command Center Framework Vulnerabili=
ty in the Oracle Enterprise Command Center Framework product of Oracle E-Bu= siness Suite (component: Core). Supported versions that are affected are V1=
5 and V16. Easily exploitable vulnerability allows low privileged attacker = with network access via HTTP to compromise Oracle Enterprise Command Center=
Framework. While the vulnerability is in Oracle Enterprise Command Center = Framework, attacks may significantly impact additional products (scope chan= ge). Successful attacks of this vulnerability can result in unauthorized cr= eation, deletion or modification access to critical data or all Oracle Ente= rprise Command Center Framework accessible data as well as unauthorized acc= ess to critical data or complete access to all Oracle Enterprise Command Ce= nter Framework accessible data and unauthorized ability to cause a partial = denial of service (partial DOS) of Oracle Enterprise Command Center Framewo= rk. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L). 2026-0= 6-16 9.9 CVE-2026-46897 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46897=
] Oracle Corporation--Oracle Enterprise Command Center Framework Vulnerabi= lity in the Oracle Enterprise Command Center Framework product of Oracle E-= Business Suite (component: Core). Supported versions that are affected are = V15 and V16. Easily exploitable vulnerability allows low privileged attacke=
r with network access via HTTP to compromise Oracle Enterprise Command Cent=
er Framework. While the vulnerability is in Oracle Enterprise Command Cente=
r Framework, attacks may significantly impact additional products (scope ch= ange). Successful attacks of this vulnerability can result in unauthorized = creation, deletion or modification access to critical data or all Oracle En= terprise Command Center Framework accessible data as well as unauthorized a= ccess to critical data or complete access to all Oracle Enterprise Command = Center Framework accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality = and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/= I:H/A:N). 2026-06-16 9.6 CVE-2026-46899 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46899 ] Oracle Corporation--Oracle Enterprise Command Center Fr= amework Vulnerability in the Oracle Enterprise Command Center Framework pro= duct of Oracle E-Business Suite (component: Core). Supported versions that = are affected are V15 and V16. Easily exploitable vulnerability allows low p= rivileged attacker with network access via HTTPS to compromise Oracle Enter= prise Command Center Framework. While the vulnerability is in Oracle Enterp= rise Command Center Framework, attacks may significantly impact additional = products (scope change). Successful attacks of this vulnerability can resul=
t in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base = Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vecto=
r: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-= 46900 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46900 ] Oracle Corporat= ion--Oracle Enterprise Command Center Framework Vulnerability in the Oracle=
Enterprise Command Center Framework product of Oracle E-Business Suite (co= mponent: Core). Supported versions that are affected are V15 and V16. Easil=
y exploitable vulnerability allows low privileged attacker with network acc= ess via HTTP to compromise Oracle Enterprise Command Center Framework. Whil=
e the vulnerability is in Oracle Enterprise Command Center Framework, attac=
ks may significantly impact additional products (scope change). Successful = attacks of this vulnerability can result in unauthorized creation, deletion=
or modification access to critical data or all Oracle Enterprise Command C= enter Framework accessible data as well as unauthorized access to critical = data or complete access to all Oracle Enterprise Command Center Framework a= ccessible data and unauthorized ability to cause a partial denial of servic=
e (partial DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Bas=
e Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vec= tor: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L). 2026-06-16 9.9 CVE-202= 6-46901 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46901 ] Oracle Corpor= ation--Oracle Enterprise Command Center Framework Vulnerability in the Orac=
le Enterprise Command Center Framework product of Oracle E-Business Suite (= component: Core). Supported versions that are affected are V15 and V16. Eas= ily exploitable vulnerability allows unauthenticated attacker with network = access via HTTPS to compromise Oracle Enterprise Command Center Framework. = Successful attacks of this vulnerability can result in takeover of Oracle E= nterprise Command Center Framework. CVSS 3.1 Base Score 9.8 (Confidentialit=
y, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR= :N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46902 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-46902 ] Oracle Corporation--Oracle Enterprise Co= mmand Center Framework Vulnerability in the Oracle Enterprise Command Cente=
r Framework product of Oracle E-Business Suite (component: Core). Supported=
versions that are affected are V15 and V16. Easily exploitable vulnerabili=
ty allows unauthenticated attacker with network access via HTTPS to comprom= ise Oracle Enterprise Command Center Framework. Successful attacks require = human interaction from a person other than the attacker. Successful attacks=
of this vulnerability can result in unauthorized creation, deletion or mod= ification access to critical data or all Oracle Enterprise Command Center F= ramework accessible data as well as unauthorized access to critical data or=
complete access to all Oracle Enterprise Command Center Framework accessib=
le data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). C= VSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). 2026-06-16 8.1 = CVE-2026-46898 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46898 ] Oracle=
Corporation--Oracle Enterprise Manager Base Platform Vulnerability in the = Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manage=
r (component: Discovery Framework). Supported versions that are affected ar=
e 13.5 and 24.1. Easily exploitable vulnerability allows low privileged att= acker with network access via HTTPS to compromise Oracle Enterprise Manager=
Base Platform. While the vulnerability is in Oracle Enterprise Manager Bas=
e Platform, attacks may significantly impact additional products (scope cha= nge). Successful attacks of this vulnerability can result in takeover of Or= acle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentia= lity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L= /PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46832 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-46832 ] Oracle Corporation--Oracle Enterprise=
Manager Base Platform Vulnerability in the Oracle Enterprise Manager Base = Platform product of Oracle Enterprise Manager (component: Metadata Plugin).=
Supported versions that are affected are 13.5 and 24.1. Easily exploitable=
vulnerability allows low privileged attacker with network access via HTTPS=
to compromise Oracle Enterprise Manager Base Platform. While the vulnerabi= lity is in Oracle Enterprise Manager Base Platform, attacks may significant=
ly impact additional products (scope change). Successful attacks of this vu= lnerability can result in takeover of Oracle Enterprise Manager Base Platfo= rm. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-0= 6-16 9.9 CVE-2026-46852 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46852=
] Oracle Corporation--Oracle Enterprise Manager Base Platform Vulnerabilit=
y in the Oracle Enterprise Manager Base Platform product of Oracle Enterpri=
se Manager (component: Metadata Plugin). Supported versions that are affect=
ed are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticat=
ed attacker with network access via HTTP to compromise Oracle Enterprise Ma= nager Base Platform. Successful attacks require human interaction from a pe= rson other than the attacker and while the vulnerability is in Oracle Enter= prise Manager Base Platform, attacks may significantly impact additional pr= oducts (scope change). Successful attacks of this vulnerability can result =
in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score=
9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). 2026-06-16 9.6 CVE-2026-46853=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46853 ] Oracle Corporation--= Oracle Enterprise Manager Base Platform Vulnerability in the Oracle Enterpr= ise Manager Base Platform product of Oracle Enterprise Manager (component: = Target Management). Supported versions that are affected are 13.5 and 24.1.=
Easily exploitable vulnerability allows low privileged attacker with netwo=
rk access via HTTP to compromise Oracle Enterprise Manager Base Platform. W= hile the vulnerability is in Oracle Enterprise Manager Base Platform, attac=
ks may significantly impact additional products (scope change). Successful = attacks of this vulnerability can result in takeover of Oracle Enterprise M= anager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity a=
nd Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:= H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46854 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-46854 ] Oracle Corporation--Oracle Enterprise Manager Base Pla= tform Vulnerability in the Oracle Enterprise Manager Base Platform product =
of Oracle Enterprise Manager (component: Metadata Plugin). Supported versio=
ns that are affected are 13.5 and 24.1. Easily exploitable vulnerability al= lows low privileged attacker with network access via HTTPS to compromise Or= acle Enterprise Manager Base Platform. While the vulnerability is in Oracle=
Enterprise Manager Base Platform, attacks may significantly impact additio= nal products (scope change). Successful attacks of this vulnerability can r= esult in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base=
Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vect= or: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026= -46855 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46855 ] Oracle Corpora= tion--Oracle Enterprise Manager Base Platform Vulnerability in the Oracle E= nterprise Manager Base Platform product of Oracle Enterprise Manager (compo= nent: Metadata Plugin). Supported versions that are affected are 13.5 and 2= 4.1. Easily exploitable vulnerability allows unauthenticated attacker with = network access via HTTP to compromise Oracle Enterprise Manager Base Platfo= rm. Successful attacks require human interaction from a person other than t=
he attacker and while the vulnerability is in Oracle Enterprise Manager Bas=
e Platform, attacks may significantly impact additional products (scope cha= nge). Successful attacks of this vulnerability can result in takeover of Or= acle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.6 (Confidentia= lity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L= /PR:N/UI:R/S:C/C:H/I:H/A:H). 2026-06-16 9.6 CVE-2026-46856 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-46856 ] Oracle Corporation--Oracle Enterprise=
Manager Base Platform Vulnerability in the Oracle Enterprise Manager Base = Platform product of Oracle Enterprise Manager (component: Oracle Management=
Service). Supported versions that are affected are 13.5 and 24.1. Easily e= xploitable vulnerability allows unauthenticated attacker with network acces=
s via HTTP to compromise Oracle Enterprise Manager Base Platform. Successfu=
l attacks of this vulnerability can result in takeover of Oracle Enterprise=
Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/= C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46857 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-46857 ] Oracle Corporation--Oracle Enterprise Manager Base P= latform Vulnerability in the Oracle Enterprise Manager Base Platform produc=
t of Oracle Enterprise Manager (component: Install). Supported versions tha=
t are affected are 13.5 and 24.1. Easily exploitable vulnerability allows h= igh privileged attacker with network access via HTTPS to compromise Oracle = Enterprise Manager Base Platform. While the vulnerability is in Oracle Ente= rprise Manager Base Platform, attacks may significantly impact additional p= roducts (scope change). Successful attacks of this vulnerability can result=
in unauthorized creation, deletion or modification access to critical data=
or all Oracle Enterprise Manager Base Platform accessible data as well as = unauthorized read access to a subset of Oracle Enterprise Manager Base Plat= form accessible data and unauthorized ability to cause a hang or frequently=
repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform=
. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impa= cts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H). 2026-06-=
16 9 CVE-2026-46872 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46872 ] O= racle Corporation--Oracle Enterprise Manager Base Platform Vulnerability in=
the Oracle Enterprise Manager Base Platform product of Oracle Enterprise M= anager (component: Deployment Library). Supported versions that are affecte=
d are 13.5 and 24.1. Easily exploitable vulnerability allows high privilege=
d attacker with network access via HTTPS to compromise Oracle Enterprise Ma= nager Base Platform. While the vulnerability is in Oracle Enterprise Manage=
r Base Platform, attacks may significantly impact additional products (scop=
e change). Successful attacks of this vulnerability can result in takeover =
of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confid= entiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N= /AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.1 CVE-2026-46875 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-46875 ] Oracle Corporation--Oracle Enter= prise Manager Base Platform Vulnerability in the Oracle Enterprise Manager = Base Platform product of Oracle Enterprise Manager (component: Agent Next G= en). Supported versions that are affected are 13.5 and 24.1. Easily exploit= able vulnerability allows low privileged attacker with network access via S=
SH to compromise Oracle Enterprise Manager Base Platform. Successful attack=
s of this vulnerability can result in takeover of Oracle Enterprise Manager=
Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Ava= ilability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/= A:H). 2026-06-16 8.8 CVE-2026-46864 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-46864 ] Oracle Corporation--Oracle Enterprise Manager Base Platform = Vulnerability in the Oracle Enterprise Manager Base Platform product of Ora= cle Enterprise Manager (component: Extensibility Framework). Supported vers= ions that are affected are 13.5 and 24.1. Easily exploitable vulnerability = allows high privileged attacker with logon to the infrastructure where Orac=
le Enterprise Manager Base Platform executes to compromise Oracle Enterpris=
e Manager Base Platform. While the vulnerability is in Oracle Enterprise Ma= nager Base Platform, attacks may significantly impact additional products (= scope change). Successful attacks of this vulnerability can result in takeo= ver of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.2 (Co= nfidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/= AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 8.2 CVE-2026-46865 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-46865 ] Oracle Corporation--Oracle E= nterprise Manager Base Platform Vulnerability in the Oracle Enterprise Mana= ger Base Platform product of Oracle Enterprise Manager (component: Agent Ne=
xt Gen). Supported versions that are affected are 13.5 and 24.1. Easily exp= loitable vulnerability allows unauthenticated attacker with network access = via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful=
attacks of this vulnerability can result in unauthorized ability to cause =
a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise M= anager Base Platform as well as unauthorized update, insert or delete acces=
s to some of Oracle Enterprise Manager Base Platform accessible data. CVSS = 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS= :3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). 2026-06-16 8.2 CVE-2026-46866 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-46866 ] Oracle Corporation--Ora= cle Enterprise Manager Base Platform Vulnerability in the Oracle Enterprise=
Manager Base Platform product of Oracle Enterprise Manager (component: Ext= ensibility Framework). Supported versions that are affected are 13.5 and 24= .1. Easily exploitable vulnerability allows high privileged attacker with n= etwork access via HTTPS to compromise Oracle Enterprise Manager Base Platfo= rm. Successful attacks of this vulnerability can result in takeover of Orac=
le Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiali= ty, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/P= R:H/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 7.2 CVE-2026-46867 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-46867 ] Oracle Corporation--Oracle Enterprise M= anager Base Platform Vulnerability in the Oracle Enterprise Manager Base Pl= atform product of Oracle Enterprise Manager (component: Extensibility Frame= work). Supported versions that are affected are 13.5 and 24.1. Easily explo= itable vulnerability allows high privileged attacker with network access vi=
a HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful a= ttacks of this vulnerability can result in takeover of Oracle Enterprise Ma= nager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity an=
d Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H= /I:H/A:H). 2026-06-16 7.2 CVE-2026-46868 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46868 ] Oracle Corporation--Oracle Financials for EMEA Vulnerab= ility in the Oracle Financials for EMEA product of Oracle E-Business Suite = (component: Internal Operations). Supported versions that are affected are = 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged att= acker with network access via HTTP to compromise Oracle Financials for EMEA=
. Successful attacks of this vulnerability can result in takeover of Oracle=
Financials for EMEA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity a=
nd Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:= H/I:H/A:H). 2026-06-16 7.2 CVE-2026-46969 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-46969 ] Oracle Corporation--Oracle HR Intelligence Vulnerabili=
ty in the Oracle HR Intelligence product of Oracle E-Business Suite (compon= ent: Internal Operations). Supported versions that are affected are 12.2.3-= 12.2.15. Easily exploitable vulnerability allows high privileged attacker w= ith network access via HTTP to compromise Oracle HR Intelligence. Successfu=
l attacks of this vulnerability can result in takeover of Oracle HR Intelli= gence. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability=
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). 202= 6-06-16 7.2 CVE-2026-46922 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46= 922 ] Oracle Corporation--Oracle HR Intelligence Vulnerability in the Oracl=
e HR Intelligence product of Oracle E-Business Suite (component: Internal O= perations). Supported versions that are affected are 12.2.3-12.2.15. Easily=
exploitable vulnerability allows high privileged attacker with network acc= ess via HTTP to compromise Oracle HR Intelligence. Successful attacks of th=
is vulnerability can result in takeover of Oracle HR Intelligence. CVSS 3.1=
Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS=
Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 7.2 CVE= -2026-46970 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46970 ] Oracle Co= rporation--Oracle HR Intelligence Vulnerability in the Oracle HR Intelligen=
ce product of Oracle E-Business Suite (component: Internal Operations). Sup= ported versions that are affected are 12.2.3-12.2.15. Difficult to exploit = vulnerability allows low privileged attacker with network access via HTTP t=
o compromise Oracle HR Intelligence. Successful attacks of this vulnerabili=
ty can result in takeover of Oracle HR Intelligence. CVSS 3.1 Base Score 7.=
5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS= :3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 7.5 CVE-2026-46971 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-46971 ] Oracle Corporation--Ora= cle HRMS (UK) Vulnerability in the Oracle HRMS (UK) product of Oracle E-Bus= iness Suite (component: UK Payroll). Supported versions that are affected a=
re 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged = attacker with network access via HTTP to compromise Oracle HRMS (UK). Succe= ssful attacks of this vulnerability can result in takeover of Oracle HRMS (= UK). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability i= mpacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). 2026-= 06-16 7.2 CVE-2026-46953 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4695=
3 ] Oracle Corporation--Oracle Human Resources Vulnerability in the Oracle = Human Resources product of Oracle E-Business Suite (component: Person). Sup= ported versions that are affected are 12.2.3-12.2.15. Difficult to exploit = vulnerability allows unauthenticated attacker with network access via HTTP =
to compromise Oracle Human Resources. Successful attacks require human inte= raction from a person other than the attacker. Successful attacks of this v= ulnerability can result in takeover of Oracle Human Resources. CVSS 3.1 Bas=
e Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vec= tor: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). 2026-06-16 7.5 CVE-202= 6-46955 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46955 ] Oracle Corpor= ation--Oracle In-Memory Cost Management for Discrete Industries Vulnerabili=
ty in the Oracle In-Memory Cost Management for Discrete Industries product =
of Oracle E-Business Suite (component: Internal Operations). Supported vers= ions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerabilit=
y allows unauthenticated attacker with network access via HTTPS to compromi=
se Oracle In-Memory Cost Management for Discrete Industries. Successful att= acks of this vulnerability can result in unauthorized creation, deletion or=
modification access to critical data or all Oracle In-Memory Cost Manageme=
nt for Discrete Industries accessible data as well as unauthorized access t=
o critical data or complete access to all Oracle In-Memory Cost Management = for Discrete Industries accessible data. CVSS 3.1 Base Score 9.1 (Confident= iality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S= :U/C:H/I:H/A:N). 2026-06-16 9.1 CVE-2026-46930 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-46930 ] Oracle Corporation--Oracle iSetup Vulnerability i=
n the Oracle iSetup product of Oracle E-Business Suite (component: General = Ledger Update Transform, Reports). Supported versions that are affected are=
12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged att= acker with network access via HTTP to compromise Oracle iSetup. Successful = attacks of this vulnerability can result in takeover of Oracle iSetup. CVSS=
3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). = CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8=
CVE-2026-46937 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46937 ] Oracl=
e Corporation--Oracle iSupplier Portal Vulnerability in the Oracle iSupplie=
r Portal product of Oracle E-Business Suite (component: Home Page). Support=
ed versions that are affected are 12.2.3-12.2.15. Easily exploitable vulner= ability allows low privileged attacker with network access via HTTPS to com= promise Oracle iSupplier Portal. Successful attacks require human interacti=
on from a person other than the attacker. Successful attacks of this vulner= ability can result in takeover of Oracle iSupplier Portal. CVSS 3.1 Base Sc= ore 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). 2026-06-16 8 CVE-2026-4689=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46894 ] Oracle Corporation-= -Oracle iSupplier Portal Vulnerability in the Oracle iSupplier Portal produ=
ct of Oracle E-Business Suite (component: Internal Operations). Supported v= ersions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerab= ility allows low privileged attacker with network access via HTTP to compro= mise Oracle iSupplier Portal. Successful attacks of this vulnerability can = result in takeover of Oracle iSupplier Portal. CVSS 3.1 Base Score 7.5 (Con= fidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/A= V:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 7.5 CVE-2026-46957 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-46957 ] Oracle Corporation--Oracle iS= upport Vulnerability in the Oracle iSupport product of Oracle E-Business Su= ite (component: Internal Operations). Supported versions that are affected = are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged=
attacker with network access via HTTP to compromise Oracle iSupport. While=
the vulnerability is in Oracle iSupport, attacks may significantly impact = additional products (scope change). Successful attacks of this vulnerabilit=
y can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confi= dentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:= N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.1 CVE-2026-46944 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-46944 ] Oracle Corporation--Oracle iSup= port Vulnerability in the Oracle iSupport product of Oracle E-Business Suit=
e (component: Internal Operations). Supported versions that are affected ar=
e 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged a= ttacker with network access via HTTP to compromise Oracle iSupport. While t=
he vulnerability is in Oracle iSupport, attacks may significantly impact ad= ditional products (scope change). Successful attacks of this vulnerability = can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confide= ntiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/= AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.1 CVE-2026-46945 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-46945 ] Oracle Corporation--Oracle iSuppo=
rt Vulnerability in the Oracle iSupport product of Oracle E-Business Suite = (component: Internal Operations). Supported versions that are affected are = 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged att= acker with network access via HTTP to compromise Oracle iSupport. While the=
vulnerability is in Oracle iSupport, attacks may significantly impact addi= tional products (scope change). Successful attacks of this vulnerability ca=
n result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confident= iality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC= :L/PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.1 CVE-2026-46946 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-46946 ] Oracle Corporation--Oracle Outsourc=
ed Mfg for Discrete Industries Vulnerability in the Oracle Outsourced Mfg f=
or Discrete Industries product of Oracle E-Business Suite (component: Inter= nal Operations). Supported versions that are affected are 12.2.3-12.2.15. E= asily exploitable vulnerability allows low privileged attacker with network=
access via HTTP to compromise Oracle Outsourced Mfg for Discrete Industrie=
s. Successful attacks of this vulnerability can result in takeover of Oracl=
e Outsourced Mfg for Discrete Industries. CVSS 3.1 Base Score 8.8 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46972 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-46972 ] Oracle Corporation--Oracle Outsour= ced Mfg for Discrete Industries Vulnerability in the Oracle Outsourced Mfg = for Discrete Industries product of Oracle E-Business Suite (component: Inte= rnal Operations). Supported versions that are affected are 12.2.3-12.2.15. = Easily exploitable vulnerability allows low privileged attacker with networ=
k access via HTTP to compromise Oracle Outsourced Mfg for Discrete Industri= es. Successful attacks of this vulnerability can result in takeover of Orac=
le Outsourced Mfg for Discrete Industries. CVSS 3.1 Base Score 8.8 (Confide= ntiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/= AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46973 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-46973 ] Oracle Corporation--Oracle Proces=
s Manufacturing Process Planning Vulnerability in the Oracle Process Manufa= cturing Process Planning product of Oracle E-Business Suite (component: Int= ernal Operations). Supported versions that are affected are 12.2.3-12.2.15.=
Easily exploitable vulnerability allows low privileged attacker with netwo=
rk access via HTTP to compromise Oracle Process Manufacturing Process Plann= ing. Successful attacks of this vulnerability can result in takeover of Ora= cle Process Manufacturing Process Planning. CVSS 3.1 Base Score 8.8 (Confid= entiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N= /AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46942 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-46942 ] Oracle Corporation--Oracle Proce=
ss Manufacturing Product Development Vulnerability in the Oracle Process Ma= nufacturing Product Development product of Oracle E-Business Suite (compone= nt: Internal Operations). Supported versions that are affected are 12.2.3-1= 2.2.15. Easily exploitable vulnerability allows low privileged attacker wit=
h network access via HTTP to compromise Oracle Process Manufacturing Produc=
t Development. While the vulnerability is in Oracle Process Manufacturing P= roduct Development, attacks may significantly impact additional products (s= cope change). Successful attacks of this vulnerability can result in takeov=
er of Oracle Process Manufacturing Product Development. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46918=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46918 ] Oracle Corporation--= Oracle Process Manufacturing Product Development Vulnerability in the Oracl=
e Process Manufacturing Product Development product of Oracle E-Business Su= ite (component: Quality Management Specs). Supported versions that are affe= cted are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privil= eged attacker with network access via HTTP to compromise Oracle Process Man= ufacturing Product Development. Successful attacks of this vulnerability ca=
n result in takeover of Oracle Process Manufacturing Product Development. C= VSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts=
). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 = 8.8 CVE-2026-46916 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46916 ] Or= acle Corporation--Oracle Project Portfolio Analysis Vulnerability in the Or= acle Project Portfolio Analysis product of Oracle E-Business Suite (compone= nt: Internal Operations). Supported versions that are affected are 12.2.3-1= 2.2.15. Easily exploitable vulnerability allows low privileged attacker wit=
h network access via HTTP to compromise Oracle Project Portfolio Analysis. = Successful attacks of this vulnerability can result in takeover of Oracle P= roject Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integr= ity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S= :U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46961 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-46961 ] Oracle Corporation--Oracle Project Portfolio Anal= ysis Vulnerability in the Oracle Project Portfolio Analysis product of Orac=
le E-Business Suite (component: Internal Operations). Supported versions th=
at are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = Project Portfolio Analysis. Successful attacks of this vulnerability can re= sult in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score = 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CV= SS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46962 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46962 ] Oracle Corporation--O= racle Project Portfolio Analysis Vulnerability in the Oracle Project Portfo= lio Analysis product of Oracle E-Business Suite (component: Internal Operat= ions). Supported versions that are affected are 12.2.3-12.2.15. Easily expl= oitable vulnerability allows high privileged attacker with network access v=
ia HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks=
of this vulnerability can result in takeover of Oracle Project Portfolio A= nalysis. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). 2= 026-06-16 7.2 CVE-2026-46960 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 46960 ] Oracle Corporation--Oracle Property Manager Vulnerability in the Or= acle Property Manager product of Oracle E-Business Suite (component: Intern=
al Operations). Supported versions that are affected are 12.2.3-12.2.15. Ea= sily exploitable vulnerability allows high privileged attacker with network=
access via HTTP to compromise Oracle Property Manager. Successful attacks =
of this vulnerability can result in takeover of Oracle Property Manager. CV=
SS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts)=
. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 7=
.2 CVE-2026-46956 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46956 ] Ora= cle Corporation--Oracle Public Sector Financials (International) Vulnerabil= ity in the Oracle Public Sector Financials (International) product of Oracl=
e E-Business Suite (component: Authorization). Supported versions that are = affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low pr= ivileged attacker with network access via HTTP to compromise Oracle Public = Sector Financials (International). Successful attacks of this vulnerability=
can result in takeover of Oracle Public Sector Financials (International).=
CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impac= ts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-1=
6 8.8 CVE-2026-46967 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46967 ] = Oracle Corporation--Oracle Public Sector Payroll Vulnerability in the Oracl=
e Public Sector Payroll product of Oracle E-Business Suite (component: Inte= rnal Operations). Supported versions that are affected are 12.2.3-12.2.15. = Easily exploitable vulnerability allows high privileged attacker with netwo=
rk access via HTTP to compromise Oracle Public Sector Payroll. Successful a= ttacks of this vulnerability can result in takeover of Oracle Public Sector=
Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). = 2026-06-16 7.2 CVE-2026-46976 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -46976 ] Oracle Corporation--Oracle Quality Vulnerability in the Oracle Qua= lity product of Oracle E-Business Suite (component: Internal Operations). S= upported versions that are affected are 12.2.3-12.2.15. Easily exploitable = vulnerability allows low privileged attacker with network access via HTTP t=
o compromise Oracle Quality. Successful attacks of this vulnerability can r= esult in takeover of Oracle Quality. CVSS 3.1 Base Score 8.8 (Confidentiali= ty, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/P= R:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46951 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-46951 ] Oracle Corporation--Oracle Quality Vuln= erability in the Oracle Quality product of Oracle E-Business Suite (compone= nt: Internal Operations). Supported versions that are affected are 12.2.3-1= 2.2.15. Easily exploitable vulnerability allows low privileged attacker wit=
h network access via HTTP to compromise Oracle Quality. Successful attacks =
of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Ba=
se Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Ve= ctor: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-20= 26-46952 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46952 ] Oracle Corpo= ration--Oracle Receivables Vulnerability in the Oracle Receivables product =
of Oracle E-Business Suite (component: Internal Operations). Supported vers= ions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerabili=
ty allows unauthenticated attacker with network access via SOAP to compromi=
se Oracle Receivables. Successful attacks of this vulnerability can result =
in takeover of Oracle Receivables. CVSS 3.1 Base Score 8.1 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:= N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.1 CVE-2026-46927 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-46927 ] Oracle Corporation--Oracle Solaris Vulner= ability in the Oracle Solaris product of Oracle Systems (component: Remote = Administration Daemon). The supported version that is affected is 11.4. Eas= ily exploitable vulnerability allows unauthenticated attacker with network = access via HTTPS to compromise Oracle Solaris. While the vulnerability is i=
n Oracle Solaris, attacks may significantly impact additional products (sco=
pe change). Successful attacks of this vulnerability can result in unauthor= ized creation, deletion or modification access to critical data or all Orac=
le Solaris accessible data as well as unauthorized access to critical data =
or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Sco=
re 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:= N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). 2026-06-16 10 CVE-2026-46978 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-46978 ] Oracle Corporation--Oracle Solar=
is Vulnerability in the Oracle Solaris product of Oracle Systems (component=
: Filesystem). The supported version that is affected is 11.4. Easily explo= itable vulnerability allows low privileged attacker with logon to the infra= structure where Oracle Solaris executes to compromise Oracle Solaris. Succe= ssful attacks of this vulnerability can result in unauthorized access to cr= itical data or complete access to all Oracle Solaris accessible data and un= authorized ability to cause a hang or frequently repeatable crash (complete=
DOS) of Oracle Solaris. CVSS 3.1 Base Score 7.1 (Confidentiality and Avail= ability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:= H). 2026-06-16 7.1 CVE-2026-46914 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-46914 ] Oracle Corporation--Oracle Spares Management Vulnerability in = the Oracle Spares Management product of Oracle E-Business Suite (component:=
Internal Operations). Supported versions that are affected are 12.2.3-12.2= .15. Easily exploitable vulnerability allows low privileged attacker with n= etwork access via HTTPS to compromise Oracle Spares Management. Successful = attacks of this vulnerability can result in takeover of Oracle Spares Manag= ement. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability=
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 202= 6-06-16 8.8 CVE-2026-46928 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46= 928 ] Oracle Corporation--Oracle Subledger Accounting Vulnerability in the = Oracle Subledger Accounting product of Oracle E-Business Suite (component: = Internal Operations). Supported versions that are affected are 12.2.3-12.2.= 15. Difficult to exploit vulnerability allows low privileged attacker with = network access via HTTP to compromise Oracle Subledger Accounting. Successf=
ul attacks of this vulnerability can result in takeover of Oracle Subledger=
Accounting. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availa= bility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H=
). 2026-06-16 7.5 CVE-2026-46958 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-46958 ] Oracle Corporation--Oracle Subledger Accounting Vulnerability i=
n the Oracle Subledger Accounting product of Oracle E-Business Suite (compo= nent: Internal Operations). Supported versions that are affected are 12.2.3= -12.2.15. Difficult to exploit vulnerability allows low privileged attacker=
with network access via HTTP to compromise Oracle Subledger Accounting. Su= ccessful attacks of this vulnerability can result in takeover of Oracle Sub= ledger Accounting. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and = Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I= :H/A:H). 2026-06-16 7.5 CVE-2026-46959 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46959 ] Oracle Corporation--Oracle Unified Directory Vulnerabil= ity in the Oracle Unified Directory product of Oracle Fusion Middleware (co= mponent: OUD Core). Supported versions that are affected are 12.2.1.4.0 and=
14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attack=
er with network access via LDAP to compromise Oracle Unified Directory. Suc= cessful attacks of this vulnerability can result in takeover of Oracle Unif= ied Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A= :H). 2026-06-16 9.8 CVE-2026-46773 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-46773 ] Oracle Corporation--Oracle Unified Directory Vulnerability in=
the Oracle Unified Directory product of Oracle Fusion Middleware (componen=
t: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.= 2.1.0. Easily exploitable vulnerability allows unauthenticated attacker wit=
h network access via RMI to compromise Oracle Unified Directory. Successful=
attacks of this vulnerability can result in takeover of Oracle Unified Dir= ectory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availabilit=
y impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 20= 26-06-16 9.8 CVE-2026-46774 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 6774 ] Oracle Corporation--Oracle Unified Directory Vulnerability in the Or= acle Unified Directory product of Oracle Fusion Middleware (component: OUD = Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. = Easily exploitable vulnerability allows unauthenticated attacker with netwo=
rk access via LDAP to compromise Oracle Unified Directory. Successful attac=
ks of this vulnerability can result in unauthorized creation, deletion or m= odification access to critical data or all Oracle Unified Directory accessi= ble data as well as unauthorized read access to a subset of Oracle Unified = Directory accessible data and unauthorized ability to cause a partial denia=
l of service (partial DOS) of Oracle Unified Directory. CVSS 3.1 Base Score=
8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L). 2026-06-16 8.6 CVE-2026-46776=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46776 ] Oracle Corporation--= Oracle Universal Work Queue Vulnerability in the Oracle Universal Work Queu=
e product of Oracle E-Business Suite (component: Work Provider Site Level A= dministration). Supported versions that are affected are 12.2.3-12.2.15. Ea= sily exploitable vulnerability allows low privileged attacker with network = access via HTTP to compromise Oracle Universal Work Queue. While the vulner= ability is in Oracle Universal Work Queue, attacks may significantly impact=
additional products (scope change). Successful attacks of this vulnerabili=
ty can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Sco=
re 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: = (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-469=
63 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46963 ] Oracle Corporation= --Oracle Universal Work Queue Vulnerability in the Oracle Universal Work Qu= eue product of Oracle E-Business Suite (component: Work Provider Site Level=
Administration). Supported versions that are affected are 12.2.3-12.2.15. = Easily exploitable vulnerability allows low privileged attacker with networ=
k access via HTTP to compromise Oracle Universal Work Queue. While the vuln= erability is in Oracle Universal Work Queue, attacks may significantly impa=
ct additional products (scope change). Successful attacks of this vulnerabi= lity can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base S= core 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-4= 6964 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46964 ] Oracle Corporati= on--Oracle Universal Work Queue Vulnerability in the Oracle Universal Work = Queue product of Oracle E-Business Suite (component: Work Provider Site Lev=
el Administration). Supported versions that are affected are 12.2.3-12.2.15=
. Easily exploitable vulnerability allows low privileged attacker with netw= ork access via HTTP to compromise Oracle Universal Work Queue. Successful a= ttacks of this vulnerability can result in takeover of Oracle Universal Wor=
k Queue. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2= 026-06-16 8.8 CVE-2026-46965 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 46965 ] Oracle Corporation--Oracle Universal Work Queue Vulnerability in th=
e Oracle Universal Work Queue product of Oracle E-Business Suite (component=
: Work Provider Site Level Administration). Supported versions that are aff= ected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low pri= vileged attacker with network access via HTTP to compromise Oracle Universa=
l Work Queue. Successful attacks of this vulnerability can result in takeov=
er of Oracle Universal Work Queue. CVSS 3.1 Base Score 7.5 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:= L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 7.5 CVE-2026-46966 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-46966 ] Oracle Corporation--Oracle Virtual Direct= ory Vulnerability in the Oracle Virtual Directory product of Oracle Fusion = Middleware (component: Virtual Directory Server). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via LDAP to compromise=
Oracle Virtual Directory. Successful attacks of this vulnerability can res= ult in takeover of Oracle Virtual Directory. CVSS 3.1 Base Score 9.8 (Confi= dentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:= N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-35312 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-35312 ] Oracle Corporation--Oracle VM V= irtualBox Vulnerability in the Oracle VM VirtualBox product of Oracle Virtu= alization (component: Shared Folders). The supported version that is affect=
ed is 7.2.8. Difficult to exploit vulnerability allows low privileged attac= ker with logon to the infrastructure where Oracle VM VirtualBox executes to=
compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM V= irtualBox, attacks may significantly impact additional products (scope chan= ge). Successful attacks of this vulnerability can result in unauthorized cr= eation, deletion or modification access to critical data or all Oracle VM V= irtualBox accessible data as well as unauthorized access to critical data o=
r complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Bas=
e Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1= /AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N). 2026-06-16 7.5 CVE-2026-35275 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-35275 ] Oracle Corporation--Oracle =
VM VirtualBox Vulnerability in the Oracle VM VirtualBox product of Oracle V= irtualization (component: VMSVGA device). The supported version that is aff= ected is 7.2.8. Difficult to exploit vulnerability allows high privileged a= ttacker with logon to the infrastructure where Oracle VM VirtualBox execute=
s to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle =
VM VirtualBox, attacks may significantly impact additional products (scope = change). Successful attacks of this vulnerability can result in takeover of=
Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C= :H/I:H/A:H). 2026-06-16 7.5 CVE-2026-46873 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-46873 ] Oracle Corporation--Oracle VM VirtualBox Vulnerabilit=
y in the Oracle VM VirtualBox product of Oracle Virtualization (component: = Core). The supported version that is affected is 7.2.8. Difficult to exploi=
t vulnerability allows high privileged attacker with logon to the infrastru= cture where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBo=
x. While the vulnerability is in Oracle VM VirtualBox, attacks may signific= antly impact additional products (scope change). Successful attacks of this=
vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Bas=
e Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vec= tor: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 7.5 CVE-202= 6-46974 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46974 ] Oracle Corpor= ation--Oracle WebCenter Content Vulnerability in the Oracle WebCenter Conte=
nt product of Oracle Fusion Middleware (component: Content Server). Support=
ed versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploit= able vulnerability allows high privileged attacker with network access via = HTTP to compromise Oracle WebCenter Content. While the vulnerability is in = Oracle WebCenter Content, attacks may significantly impact additional produ= cts (scope change). Successful attacks of this vulnerability can result in = takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.1 (Confidential= ity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/= PR:H/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.1 CVE-2026-35270 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-35270 ] Oracle Corporation--Oracle WebCenter C= ontent Vulnerability in the Oracle WebCenter Content product of Oracle Fusi=
on Middleware (component: Content Server). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
unauthenticated attacker with network access via HTTP to compromise Oracle=
WebCenter Content. Successful attacks of this vulnerability can result in = takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidential= ity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/= PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-35286 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-35286 ] Oracle Corporation--Oracle WebCenter C= ontent Vulnerability in the Oracle WebCenter Content product of Oracle Fusi=
on Middleware (component: Content Server). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = WebCenter Content. While the vulnerability is in Oracle WebCenter Content, = attacks may significantly impact additional products (scope change). Succes= sful attacks of this vulnerability can result in takeover of Oracle WebCent=
er Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availab= ility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)=
. 2026-06-16 9.9 CVE-2026-35316 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-35316 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in th=
e Oracle WebCenter Content product of Oracle Fusion Middleware (component: = Content Server). Supported versions that are affected are 12.2.1.4.0 and 14= .1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker = with network access via HTTP to compromise Oracle WebCenter Content. Succes= sful attacks of this vulnerability can result in takeover of Oracle WebCent=
er Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availab= ility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)=
. 2026-06-16 9.8 CVE-2026-35319 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-35319 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in th=
e Oracle WebCenter Content product of Oracle Fusion Middleware (component: = Content Server). Supported versions that are affected are 12.2.1.4.0 and 14= .1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacke=
r with network access via HTTP to compromise Oracle WebCenter Content. Whil=
e the vulnerability is in Oracle WebCenter Content, attacks may significant=
ly impact additional products (scope change). Successful attacks of this vu= lnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Ba=
se Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Ve= ctor: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9 CVE-2026= -35320 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35320 ] Oracle Corpora= tion--Oracle WebCenter Content Vulnerability in the Oracle WebCenter Conten=
t product of Oracle Fusion Middleware (component: Content Server). Supporte=
d versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploita= ble vulnerability allows low privileged attacker with network access via HT=
TP to compromise Oracle WebCenter Content. While the vulnerability is in Or= acle WebCenter Content, attacks may significantly impact additional product=
s (scope change). Successful attacks of this vulnerability can result in ta= keover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentialit=
y, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR= :L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-35321 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-35321 ] Oracle Corporation--Oracle WebCenter Con= tent Vulnerability in the Oracle WebCenter Content product of Oracle Fusion=
Middleware (component: Content Server). Supported versions that are affect=
ed are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows l=
ow privileged attacker with network access via HTTP to compromise Oracle We= bCenter Content. While the vulnerability is in Oracle WebCenter Content, at= tacks may significantly impact additional products (scope change). Successf=
ul attacks of this vulnerability can result in takeover of Oracle WebCenter=
Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). = 2026-06-16 9.9 CVE-2026-35323 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -35323 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the = Oracle WebCenter Content product of Oracle Fusion Middleware (component: Co= ntent Server). Supported versions that are affected are 12.2.1.4.0 and 14.1= .2.0.0. Easily exploitable vulnerability allows unauthenticated attacker wi=
th network access via HTTP to compromise Oracle WebCenter Content. Successf=
ul attacks of this vulnerability can result in takeover of Oracle WebCenter=
Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). = 2026-06-16 9.8 CVE-2026-46766 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -46766 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the = Oracle WebCenter Content product of Oracle Fusion Middleware (component: Co= ntent Server). Supported versions that are affected are 12.2.1.4.0 and 14.1= .2.0.0. Easily exploitable vulnerability allows unauthenticated attacker wi=
th network access via HTTP to compromise Oracle WebCenter Content. Successf=
ul attacks of this vulnerability can result in unauthorized creation, delet= ion or modification access to critical data or all Oracle WebCenter Content=
accessible data as well as unauthorized access to critical data or complet=
e access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Sco=
re 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N= /AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). 2026-06-16 9.1 CVE-2026-46777 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-46777 ] Oracle Corporation--Oracle WebCe= nter Content Vulnerability in the Oracle WebCenter Content product of Oracl=
e Fusion Middleware (component: Content Server). The supported version that=
is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthe= nticated attacker with network access via HTTP to compromise Oracle WebCent=
er Content. Successful attacks require human interaction from a person othe=
r than the attacker and while the vulnerability is in Oracle WebCenter Cont= ent, attacks may significantly impact additional products (scope change). S= uccessful attacks of this vulnerability can result in unauthorized creation=
, deletion or modification access to critical data or all Oracle WebCenter = Content accessible data as well as unauthorized access to critical data or = complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 B= ase Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3= .1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). 2026-06-16 9.3 CVE-2026-46785 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-46785 ] Oracle Corporation--Oracl=
e WebCenter Content Vulnerability in the Oracle WebCenter Content product o=
f Oracle Fusion Middleware (component: Content Server). The supported versi=
on that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows = unauthenticated attacker with network access via HTTP to compromise Oracle = WebCenter Content. Successful attacks require human interaction from a pers=
on other than the attacker and while the vulnerability is in Oracle WebCent=
er Content, attacks may significantly impact additional products (scope cha= nge). Successful attacks of this vulnerability can result in takeover of Or= acle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/= C:H/I:H/A:H). 2026-06-16 9.6 CVE-2026-46786 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-46786 ] Oracle Corporation--Oracle WebCenter Content Vulnera= bility in the Oracle WebCenter Content product of Oracle Fusion Middleware = (component: Content Server). The supported version that is affected is 14.1= .2.0.0. Easily exploitable vulnerability allows unauthenticated attacker wi=
th network access via HTTP to compromise Oracle WebCenter Content. Successf=
ul attacks require human interaction from a person other than the attacker = and while the vulnerability is in Oracle WebCenter Content, attacks may sig= nificantly impact additional products (scope change). Successful attacks of=
this vulnerability can result in takeover of Oracle WebCenter Content. CVS=
S 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).=
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). 2026-06-16 9.=
6 CVE-2026-46789 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46789 ] Orac=
le Corporation--Oracle WebCenter Content Vulnerability in the Oracle WebCen= ter Content product of Oracle Fusion Middleware (component: Content Server)=
. The supported version that is affected is 14.1.2.0.0. Easily exploitable = vulnerability allows unauthenticated attacker with network access via HTTP =
to compromise Oracle WebCenter Content. Successful attacks require human in= teraction from a person other than the attacker and while the vulnerability=
is in Oracle WebCenter Content, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in unauthorized creation, deletion or modification access to critical d= ata or all Oracle WebCenter Content accessible data as well as unauthorized=
access to critical data or complete access to all Oracle WebCenter Content=
accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). 2026-0= 6-16 9.3 CVE-2026-46795 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46795=
] Oracle Corporation--Oracle WebCenter Content Vulnerability in the Oracle=
WebCenter Content product of Oracle Fusion Middleware (component: Content = Server). The supported version that is affected is 14.1.2.0.0. Easily explo= itable vulnerability allows unauthenticated attacker with network access vi=
a HTTP to compromise Oracle WebCenter Content. Successful attacks require h= uman interaction from a person other than the attacker and while the vulner= ability is in Oracle WebCenter Content, attacks may significantly impact ad= ditional products (scope change). Successful attacks of this vulnerability = can result in unauthorized creation, deletion or modification access to cri= tical data or all Oracle WebCenter Content accessible data as well as unaut= horized access to critical data or complete access to all Oracle WebCenter = Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integ= rity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).=
2026-06-16 9.3 CVE-2026-46805 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-46805 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the=
Oracle WebCenter Content product of Oracle Fusion Middleware (component: C= ontent Server). Supported versions that are affected are 12.2.1.4.0 and 14.= 1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker w= ith network access via HTTP to compromise Oracle WebCenter Content. Success= ful attacks of this vulnerability can result in takeover of Oracle WebCente=
r Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availabi= lity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).=
2026-06-16 9.8 CVE-2026-46813 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-46813 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the=
Oracle WebCenter Content product of Oracle Fusion Middleware (component: C= ontent Server). Supported versions that are affected are 12.2.1.4.0 and 14.= 1.2.0.0. Easily exploitable vulnerability allows low privileged attacker wi=
th network access via HTTP to compromise Oracle WebCenter Content. Successf=
ul attacks of this vulnerability can result in takeover of Oracle WebCenter=
Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). = 2026-06-16 8.8 CVE-2026-35315 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -35315 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the = Oracle WebCenter Content product of Oracle Fusion Middleware (component: Co= ntent Server). Supported versions that are affected are 12.2.1.4.0 and 14.1= .2.0.0. Easily exploitable vulnerability allows low privileged attacker wit=
h network access via HTTP to compromise Oracle WebCenter Content. Successfu=
l attacks of this vulnerability can result in takeover of Oracle WebCenter = Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2= 026-06-16 8.8 CVE-2026-35317 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 35317 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the O= racle WebCenter Content product of Oracle Fusion Middleware (component: Con= tent Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.= 2.0.0. Easily exploitable vulnerability allows low privileged attacker with=
network access via HTTP to compromise Oracle WebCenter Content. Successful=
attacks of this vulnerability can result in takeover of Oracle WebCenter C= ontent. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availabilit=
y impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 20= 26-06-16 8.8 CVE-2026-35322 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3= 5322 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the Or= acle WebCenter Content product of Oracle Fusion Middleware (component: Cont= ent Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2= .0.0. Easily exploitable vulnerability allows low privileged attacker with = network access via HTTP to compromise Oracle WebCenter Content. Successful = attacks of this vulnerability can result in takeover of Oracle WebCenter Co= ntent. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability=
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 202= 6-06-16 8.8 CVE-2026-35324 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35= 324 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the Ora= cle WebCenter Content product of Oracle Fusion Middleware (component: Conte=
nt Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.= 0.0. Easily exploitable vulnerability allows low privileged attacker with n= etwork access via HTTP to compromise Oracle WebCenter Content. Successful a= ttacks of this vulnerability can result in takeover of Oracle WebCenter Con= tent. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability = impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026= -06-16 8.8 CVE-2026-35325 [
https://www.cve.org/CVERecord?id=3DCVE-2026-353=
25 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in the Orac=
le WebCenter Content product of Oracle Fusion Middleware (component: Conten=
t Server). The supported version that is affected is 14.1.2.0.0. Difficult =
to exploit vulnerability allows unauthenticated attacker with network acces=
s via HTTP to compromise Oracle WebCenter Content. Successful attacks requi=
re human interaction from a person other than the attacker and while the vu= lnerability is in Oracle WebCenter Content, attacks may significantly impac=
t additional products (scope change). Successful attacks of this vulnerabil= ity can result in unauthorized creation, deletion or modification access to=
critical data or all Oracle WebCenter Content accessible data as well as u= nauthorized access to critical data or complete access to all Oracle WebCen= ter Content accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and I= ntegrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A= :N). 2026-06-16 8 CVE-2026-46787 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-46787 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in t=
he Oracle WebCenter Content product of Oracle Fusion Middleware (component:=
Content Server). The supported version that is affected is 14.1.2.0.0. Eas= ily exploitable vulnerability allows high privileged attacker with network = access via HTTP to compromise Oracle WebCenter Content. Successful attacks = require human interaction from a person other than the attacker and while t=
he vulnerability is in Oracle WebCenter Content, attacks may significantly = impact additional products (scope change). Successful attacks of this vulne= rability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base = Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vecto=
r: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H). 2026-06-16 8.4 CVE-2026-= 46788 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46788 ] Oracle Corporat= ion--Oracle WebCenter Content Vulnerability in the Oracle WebCenter Content=
product of Oracle Fusion Middleware (component: Content Server). The suppo= rted version that is affected is 14.1.2.0.0. Easily exploitable vulnerabili=
ty allows low privileged attacker with network access via HTTP to compromis=
e Oracle WebCenter Content. Successful attacks require human interaction fr=
om a person other than the attacker and while the vulnerability is in Oracl=
e WebCenter Content, attacks may significantly impact additional products (= scope change). Successful attacks of this vulnerability can result in unaut= horized creation, deletion or modification access to critical data or all O= racle WebCenter Content accessible data as well as unauthorized access to c= ritical data or complete access to all Oracle WebCenter Content accessible = data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS=
Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). 2026-06-16 8.7 CVE= -2026-46804 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46804 ] Oracle Co= rporation--Oracle WebCenter Content Vulnerability in the Oracle WebCenter C= ontent product of Oracle Fusion Middleware (component: Content Server). The=
supported version that is affected is 14.1.2.0.0. Easily exploitable vulne= rability allows unauthenticated attacker with network access via HTTPS to c= ompromise Oracle WebCenter Content. Successful attacks require human intera= ction from a person other than the attacker and while the vulnerability is =
in Oracle WebCenter Content, attacks may significantly impact additional pr= oducts (scope change). Successful attacks of this vulnerability can result =
in unauthorized access to critical data or complete access to all Oracle We= bCenter Content accessible data as well as unauthorized update, insert or d= elete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 = Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:= 3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N). 2026-06-16 8.2 CVE-2026-46806 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-46806 ] Oracle Corporation--Orac=
le WebCenter Content Vulnerability in the Oracle WebCenter Content product =
of Oracle Fusion Middleware (component: Content Server). The supported vers= ion that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = WebCenter Content. Successful attacks require human interaction from a pers=
on other than the attacker and while the vulnerability is in Oracle WebCent=
er Content, attacks may significantly impact additional products (scope cha= nge). Successful attacks of this vulnerability can result in unauthorized c= reation, deletion or modification access to critical data or all Oracle Web= Center Content accessible data as well as unauthorized access to critical d= ata or complete access to all Oracle WebCenter Content accessible data. CVS=
S 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: = (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). 2026-06-16 8.7 CVE-2026-468=
08 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46808 ] Oracle Corporation= --Oracle WebCenter Content Vulnerability in the Oracle WebCenter Content pr= oduct of Oracle Fusion Middleware (component: Content Server). Supported ve= rsions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable = vulnerability allows high privileged attacker with network access via HTTP =
to compromise Oracle WebCenter Content. Successful attacks of this vulnerab= ility can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Sco=
re 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: = (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 7.2 CVE-2026-353=
26 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35326 ] Oracle Corporation= --Oracle WebCenter Content Vulnerability in the Oracle WebCenter Content pr= oduct of Oracle Fusion Middleware (component: Content Server). Supported ve= rsions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable = vulnerability allows low privileged attacker with network access via HTTPS =
to compromise Oracle WebCenter Content. Successful attacks require human in= teraction from a person other than the attacker and while the vulnerability=
is in Oracle WebCenter Content, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in unauthorized access to critical data or complete access to all Oracl=
e WebCenter Content accessible data as well as unauthorized update, insert =
or delete access to some of Oracle WebCenter Content accessible data. CVSS = 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). 2026-06-16 7.6 CVE-2026-35327=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-35327 ] Oracle Corporation--= Oracle WebCenter Content Vulnerability in the Oracle WebCenter Content prod= uct of Oracle Fusion Middleware (component: Content Server). The supported = version that is affected is 14.1.2.0.0. Easily exploitable vulnerability al= lows unauthenticated attacker with network access via HTTP to compromise Or= acle WebCenter Content. Successful attacks of this vulnerability can result=
in unauthorized access to critical data or complete access to all Oracle W= ebCenter Content accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality = impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). 2026= -06-16 7.5 CVE-2026-46791 [
https://www.cve.org/CVERecord?id=3DCVE-2026-467=
91 ] Oracle Corporation--Oracle WebCenter Enterprise Capture Vulnerability =
in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middlew= are (component: Client Bundle). Supported versions that are affected are 12= .2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenti= cated attacker with network access via RMI to compromise Oracle WebCenter E= nterprise Capture. While the vulnerability is in Oracle WebCenter Enterpris=
e Capture, attacks may significantly impact additional products (scope chan= ge). Successful attacks of this vulnerability can result in takeover of Ora= cle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.0 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10 CVE-2026-46778 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-46778 ] Oracle Corporation--Oracle WebCenter Enter= prise Capture Vulnerability in the Oracle WebCenter Enterprise Capture prod= uct of Oracle Fusion Middleware (component: Client Bundle). Supported versi= ons that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vul= nerability allows unauthenticated attacker with network access via RMI to c= ompromise Oracle WebCenter Enterprise Capture. While the vulnerability is i=
n Oracle WebCenter Enterprise Capture, attacks may significantly impact add= itional products (scope change). Successful attacks of this vulnerability c=
an result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base=
Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vec= tor: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10 CVE-2026= -46781 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46781 ] Oracle Corpora= tion--Oracle WebCenter Enterprise Capture Vulnerability in the Oracle WebCe= nter Enterprise Capture product of Oracle Fusion Middleware (component: Cli= ent Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2= .0.0. Easily exploitable vulnerability allows low privileged attacker with = network access via T3, IIOP to compromise Oracle WebCenter Enterprise Captu= re. While the vulnerability is in Oracle WebCenter Enterprise Capture, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in takeover of Oracle WebCenter E= nterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and = Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I= :H/A:H). 2026-06-16 9.9 CVE-2026-35280 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-35280 ] Oracle Corporation--Oracle WebCenter Enterprise Capture=
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle=
Fusion Middleware (component: Client Bundle). Supported versions that are = affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability al= lows low privileged attacker with network access via T3, IIOP to compromise=
Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle = WebCenter Enterprise Capture, attacks may significantly impact additional p= roducts (scope change). Successful attacks of this vulnerability can result=
in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.=
9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS= :3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-35281 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-35281 ] Oracle Corporation--Ora= cle WebCenter Enterprise Capture Vulnerability in the Oracle WebCenter Ente= rprise Capture product of Oracle Fusion Middleware (component: Client Bundl= e). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Eas= ily exploitable vulnerability allows low privileged attacker with network a= ccess via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While=
the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may s= ignificantly impact additional products (scope change). Successful attacks =
of this vulnerability can result in takeover of Oracle WebCenter Enterprise=
Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). = 2026-06-16 9.9 CVE-2026-35282 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -35282 ] Oracle Corporation--Oracle WebCenter Enterprise Capture Vulnerabil= ity in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Mid= dleware (component: Client Bundle). Supported versions that are affected ar=
e 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr= ivileged attacker with network access via T3, IIOP to compromise Oracle Web= Center Enterprise Capture. While the vulnerability is in Oracle WebCenter E= nterprise Capture, attacks may significantly impact additional products (sc= ope change). Successful attacks of this vulnerability can result in takeove=
r of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-35283 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-35283 ] Oracle Corporation--Oracle WebCent=
er Enterprise Capture Vulnerability in the Oracle WebCenter Enterprise Capt= ure product of Oracle Fusion Middleware (component: Client Bundle). Support=
ed versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploit= able vulnerability allows low privileged attacker with network access via T=
3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulner= ability is in Oracle WebCenter Enterprise Capture, attacks may significantl=
y impact additional products (scope change). Successful attacks of this vul= nerability can result in takeover of Oracle WebCenter Enterprise Capture. C= VSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts=
). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 = 9.9 CVE-2026-35284 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35284 ] Or= acle Corporation--Oracle WebCenter Enterprise Capture Vulnerability in the = Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (co= mponent: Client Bundle). Supported versions that are affected are 12.2.1.4.=
0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged at= tacker with network access via T3, IIOP to compromise Oracle WebCenter Ente= rprise Capture. While the vulnerability is in Oracle WebCenter Enterprise C= apture, attacks may significantly impact additional products (scope change)=
. Successful attacks of this vulnerability can result in takeover of Oracle=
WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, In= tegrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI= :N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-35285 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-35285 ] Oracle Corporation--Oracle WebCenter Enterpri=
se Capture Vulnerability in the Oracle WebCenter Enterprise Capture product=
of Oracle Fusion Middleware (component: Client Bundle). Supported versions=
that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulner= ability allows low privileged attacker with network access via T3 to compro= mise Oracle WebCenter Enterprise Capture. While the vulnerability is in Ora= cle WebCenter Enterprise Capture, attacks may significantly impact addition=
al products (scope change). Successful attacks of this vulnerability can re= sult in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Scor=
e 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-4677=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46779 ] Oracle Corporation-= -Oracle WebCenter Enterprise Capture Vulnerability in the Oracle WebCenter = Enterprise Capture product of Oracle Fusion Middleware (component: Client B= undle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0.=
Easily exploitable vulnerability allows low privileged attacker with netwo=
rk access via HTTP to compromise Oracle WebCenter Enterprise Capture. While=
the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may s= ignificantly impact additional products (scope change). Successful attacks =
of this vulnerability can result in takeover of Oracle WebCenter Enterprise=
Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). = 2026-06-16 9.9 CVE-2026-46782 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -46782 ] Oracle Corporation--Oracle WebCenter Portal Vulnerability in the O= racle WebCenter Portal product of Oracle Fusion Middleware (component: Secu= rity Framework). Supported versions that are affected are 12.2.1.4.0 and 14= .1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker = with network access via HTTP to compromise Oracle WebCenter Portal. While t=
he vulnerability is in Oracle WebCenter Portal, attacks may significantly i= mpact additional products (scope change). Successful attacks of this vulner= ability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Sc= ore 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10 CVE-2026-46= 803 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46803 ] Oracle Corporatio= n--Oracle WebCenter Portal Vulnerability in the Oracle WebCenter Portal pro= duct of Oracle Fusion Middleware (component: Security Framework). Supported=
versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitab=
le vulnerability allows unauthenticated attacker with network access via HT=
TP to compromise Oracle WebCenter Portal. While the vulnerability is in Ora= cle WebCenter Portal, attacks may significantly impact additional products = (scope change). Successful attacks of this vulnerability can result in take= over of Oracle WebCenter Portal. CVSS 3.1 Base Score 10.0 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N= /UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10 CVE-2026-46846 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-46846 ] Oracle Corporation--Oracle WebCenter Portal=
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Midd= leware (component: Composer). Supported versions that are affected are 12.2= .1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileg=
ed attacker with network access via HTTP to compromise Oracle WebCenter Por= tal. While the vulnerability is in Oracle WebCenter Portal, attacks may sig= nificantly impact additional products (scope change). Successful attacks of=
this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS=
3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). = CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9=
CVE-2026-46765 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46765 ] Oracl=
e Corporation--Oracle WebCenter Portal Vulnerability in the Oracle WebCente=
r Portal product of Oracle Fusion Middleware (component: Composer). Support=
ed versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploit= able vulnerability allows low privileged attacker with network access via H= TTP to compromise Oracle WebCenter Portal. While the vulnerability is in Or= acle WebCenter Portal, attacks may significantly impact additional products=
(scope change). Successful attacks of this vulnerability can result in tak= eover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46767 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-46767 ] Oracle Corporation--Oracle WebCenter Porta=
l Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Mid= dleware (component: Security Framework). Supported versions that are affect=
ed are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows l=
ow privileged attacker with network access via HTTP to compromise Oracle We= bCenter Portal. While the vulnerability is in Oracle WebCenter Portal, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in takeover of Oracle WebCenter P= ortal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability=
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 202= 6-06-16 9.9 CVE-2026-46802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46= 802 ] Oracle Corporation--Oracle WebCenter Portal Vulnerability in the Orac=
le WebCenter Portal product of Oracle Fusion Middleware (component: Securit=
y Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.= 2.0.0. Easily exploitable vulnerability allows low privileged attacker with=
network access via HTTP to compromise Oracle WebCenter Portal. While the v= ulnerability is in Oracle WebCenter Portal, attacks may significantly impac=
t additional products (scope change). Successful attacks of this vulnerabil= ity can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score = 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CV= SS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46814 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46814 ] Oracle Corporation--O= racle WebCenter Portal Vulnerability in the Oracle WebCenter Portal product=
of Oracle Fusion Middleware (component: Security Framework). Supported ver= sions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable v= ulnerability allows low privileged attacker with network access via HTTPS t=
o compromise Oracle WebCenter Portal. While the vulnerability is in Oracle = WebCenter Portal, attacks may significantly impact additional products (sco=
pe change). Successful attacks of this vulnerability can result in takeover=
of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Inte= grity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N= /S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46838 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-46838 ] Oracle Corporation--Oracle WebCenter Portal Vul= nerability in the Oracle WebCenter Portal product of Oracle Fusion Middlewa=
re (component: Security Framework). Supported versions that are affected ar=
e 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr= ivileged attacker with network access via HTTPS to compromise Oracle WebCen= ter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks = may significantly impact additional products (scope change). Successful att= acks of this vulnerability can result in takeover of Oracle WebCenter Porta=
l. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability imp= acts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06= -16 9.9 CVE-2026-46844 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46844 =
] Oracle Corporation--Oracle WebCenter Portal Vulnerability in the Oracle W= ebCenter Portal product of Oracle Fusion Middleware (component: Security Fr= amework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.=
0. Easily exploitable vulnerability allows unauthenticated attacker with ne= twork access via HTTPS to compromise Oracle WebCenter Portal. Successful at= tacks of this vulnerability can result in takeover of Oracle WebCenter Port= al. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-0= 6-16 9.8 CVE-2026-46845 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46845=
] Oracle Corporation--Oracle WebCenter Portal Vulnerability in the Oracle = WebCenter Portal product of Oracle Fusion Middleware (component: Runtime To= ols). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. E= asily exploitable vulnerability allows low privileged attacker with network=
access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerab= ility is in Oracle WebCenter Portal, attacks may significantly impact addit= ional products (scope change). Successful attacks of this vulnerability can=
result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Co= nfidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/= AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-2026-46847 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-46847 ] Oracle Corporation--Oracle W= ebCenter Sites Vulnerability in the Oracle WebCenter Sites product of Oracl=
e Fusion Middleware (component: WebCenter Sites). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via HTTP to compromise=
Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sit= es, attacks may significantly impact additional products (scope change). Su= ccessful attacks of this vulnerability can result in takeover of Oracle Web= Center Sites. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A= :H). 2026-06-16 10 CVE-2026-46798 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-46798 ] Oracle Corporation--Oracle WebCenter Sites Vulnerability in th=
e Oracle WebCenter Sites product of Oracle Fusion Middleware (component: We= bCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.= 1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker w= ith network access via HTTP to compromise Oracle WebCenter Sites. While the=
vulnerability is in Oracle WebCenter Sites, attacks may significantly impa=
ct additional products (scope change). Successful attacks of this vulnerabi= lity can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score = 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10 CVE-2026-46800 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46800 ] Oracle Corporation--O= racle WebCenter Sites Vulnerability in the Oracle WebCenter Sites product o=
f Oracle Fusion Middleware (component: WebCenter Sites). The supported vers= ion that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows=
unauthenticated attacker with network access via HTTP to compromise Oracle=
WebCenter Sites. Successful attacks of this vulnerability can result in ta= keover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N= /UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-35293 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-35293 ] Oracle Corporation--Oracle WebCenter Sites=
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middl= eware (component: WebCenter Sites). Supported versions that are affected ar=
e 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauth= enticated attacker with network access via HTTP to compromise Oracle WebCen= ter Sites. Successful attacks of this vulnerability can result in takeover =
of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integr= ity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S= :U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-35296 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-35296 ] Oracle Corporation--Oracle WebCenter Sites Vulner= ability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (= component: WebCenter Sites). Supported versions that are affected are 12.2.= 1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticat=
ed attacker with network access via HTTP to compromise Oracle WebCenter Sit= es. Successful attacks of this vulnerability can result in takeover of Orac=
le WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and=
Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/= I:H/A:H). 2026-06-16 9.8 CVE-2026-46797 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-46797 ] Oracle Corporation--Oracle WebCenter Sites Vulnerabilit=
y in the Oracle WebCenter Sites product of Oracle Fusion Middleware (compon= ent: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 = and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated att= acker with network access via HTTP to compromise Oracle WebCenter Sites. Su= ccessful attacks of this vulnerability can result in takeover of Oracle Web= Center Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Avail= ability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:= H). 2026-06-16 9.8 CVE-2026-46799 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-46799 ] Oracle Corporation--Oracle WebCenter Sites Vulnerability in th=
e Oracle WebCenter Sites product of Oracle Fusion Middleware (component: We= bCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.= 1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker w= ith network access via HTTP to compromise Oracle WebCenter Sites. Successfu=
l attacks of this vulnerability can result in takeover of Oracle WebCenter = Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability=
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 202= 6-06-16 9.8 CVE-2026-46801 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46= 801 ] Oracle Corporation--Oracle WebCenter Sites Vulnerability in the Oracl=
e WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter=
Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0=
. Easily exploitable vulnerability allows unauthenticated attacker with net= work access via HTTP to compromise Oracle WebCenter Sites. Successful attac=
ks of this vulnerability can result in unauthorized creation, deletion or m= odification access to critical data or all Oracle WebCenter Sites accessibl=
e data as well as unauthorized access to critical data or complete access t=
o all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 9.1 (Conf= identiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/U= I:N/S:U/C:H/I:H/A:N). 2026-06-16 9.1 CVE-2026-46809 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-46809 ] Oracle Corporation--Oracle WebCenter Sites V= ulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlew= are (component: WebCenter Sites). Supported versions that are affected are = 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low priv= ileged attacker with network access via HTTP to compromise Oracle WebCenter=
Sites. Successful attacks of this vulnerability can result in takeover of = Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/= C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-35318 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-35318 ] Oracle Corporation--Oracle WebCenter Sites Vulnerabi= lity in the Oracle WebCenter Sites product of Oracle Fusion Middleware (com= ponent: WebCenter Sites). Supported versions that are affected are 12.2.1.4=
.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged a= ttacker with network access via HTTP to compromise Oracle WebCenter Sites. = Successful attacks require human interaction from a person other than the a= ttacker. Successful attacks of this vulnerability can result in takeover of=
Oracle WebCenter Sites. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrit=
y and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U= /C:H/I:H/A:H). 2026-06-16 8 CVE-2026-46796 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-46796 ] Oracle Corporation--Oracle WebCenter Sites Vulnerabil= ity in the Oracle WebCenter Sites product of Oracle Fusion Middleware (comp= onent: WebCenter Sites). Supported versions that are affected are 12.2.1.4.=
0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged = attacker with network access via HTTP to compromise Oracle WebCenter Sites.=
Successful attacks of this vulnerability can result in takeover of Oracle = WebCenter Sites. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Av= ailability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H= /A:H). 2026-06-16 7.5 CVE-2026-35295 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-35295 ] Oracle Corporation--PeopleSoft Enterprise CS Campus Communi=
ty Vulnerability in the PeopleSoft Enterprise CS Campus Community product o=
f Oracle PeopleSoft (component: Security). The supported version that is af= fected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated=
attacker with network access via HTTP to compromise PeopleSoft Enterprise =
CS Campus Community. Successful attacks of this vulnerability can result in=
takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score=
8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.1 CVE-2026-46851=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46851 ] Oracle Corporation--= PeopleSoft Enterprise CS Student Financials Vulnerability in the PeopleSoft=
Enterprise CS Student Financials product of Oracle PeopleSoft (component: = Other). The supported version that is affected is 9.2.38. Easily exploitabl=
e vulnerability allows low privileged attacker with network access via HTTP=
to compromise PeopleSoft Enterprise CS Student Financials. Successful atta= cks of this vulnerability can result in unauthorized creation, deletion or = modification access to critical data or all PeopleSoft Enterprise CS Studen=
t Financials accessible data as well as unauthorized access to critical dat=
a or complete access to all PeopleSoft Enterprise CS Student Financials acc= essible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impact= s). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). 2026-06-16=
8.1 CVE-2026-46849 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46849 ] O= racle Corporation--PeopleSoft Enterprise PT PeopleTools Vulnerability in th=
e PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (compon= ent: Performance Monitor). Supported versions that are affected are 8.61 an=
d 8.62. Easily exploitable vulnerability allows unauthenticated attacker wi=
th network access via HTTP to compromise PeopleSoft Enterprise PT PeopleToo= ls. Successful attacks of this vulnerability can result in takeover of Peop= leSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N= /UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-35278 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-35278 ] Oracle Corporation--PeopleSoft Enterprise =
PT PeopleTools Vulnerability in the PeopleSoft Enterprise PT PeopleTools pr= oduct of Oracle PeopleSoft (component: Weblogic). Supported versions that a=
re affected are 8.61 and 8.62. Difficult to exploit vulnerability allows un= authenticated attacker with network access via HTTP to compromise PeopleSof=
t Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enter= prise PT PeopleTools, attacks may significantly impact additional products = (scope change). Successful attacks of this vulnerability can result in unau= thorized creation, deletion or modification access to critical data or all = PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorize=
d access to critical data or complete access to all PeopleSoft Enterprise P=
T PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and=
Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H= /A:N). 2026-06-16 8.7 CVE-2026-35271 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-35271 ] Oracle Corporation--PeopleSoft Enterprise PT PeopleTools Vu= lnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P= eopleSoft (component: Deployment Package). Supported versions that are affe= cted are 8.61 and 8.62. Easily exploitable vulnerability allows unauthentic= ated attacker with logon to the infrastructure where PeopleSoft Enterprise =
PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools.=
Successful attacks of this vulnerability can result in takeover of PeopleS= oft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.4 (Confidentiality, In= tegrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI= :N/S:U/C:H/I:H/A:H). 2026-06-16 8.4 CVE-2026-35272 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-35272 ] Oracle Corporation--PeopleSoft Enterprise PT = PeopleTools Vulnerability in the PeopleSoft Enterprise PT PeopleTools produ=
ct of Oracle PeopleSoft (component: Deployment Package). Supported versions=
that are affected are 8.61 and 8.62. Easily exploitable vulnerability allo=
ws unauthenticated attacker with network access via HTTP to compromise Peop= leSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability = can result in unauthorized access to critical data or complete access to al=
l PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthori= zed update, insert or delete access to some of PeopleSoft Enterprise PT Peo= pleTools accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Inte= grity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)=
. 2026-06-16 8.2 CVE-2026-35274 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-35274 ] Oracle Corporation--PeopleSoft Enterprise PT PeopleTools Vulnera= bility in the PeopleSoft Enterprise PT PeopleTools product of Oracle People= Soft (component: Application Server). Supported versions that are affected = are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticate=
d attacker with network access via HTTP to compromise PeopleSoft Enterprise=
PT PeopleTools. Successful attacks of this vulnerability can result in tak= eover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.1 (Con= fidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/A= V:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.1 CVE-2026-35276 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-35276 ] Oracle Corporation--PeopleSof=
t Enterprise PT PeopleTools Vulnerability in the PeopleSoft Enterprise PT P= eopleTools product of Oracle PeopleSoft (component: Performance Monitor). S= upported versions that are affected are 8.61 and 8.62. Difficult to exploit=
vulnerability allows unauthenticated attacker with network access via HTTP=
to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of = this vulnerability can result in takeover of PeopleSoft Enterprise PT Peopl= eTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availabilit=
y impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). 20= 26-06-16 8.1 CVE-2026-35279 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3= 5279 ] Oracle Corporation--PeopleSoft Enterprise PT PeopleTools Vulnerabili=
ty in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft=
(component: Deployment Package). Supported versions that are affected are = 8.61 and 8.62. Easily exploitable vulnerability allows high privileged atta= cker with logon to the infrastructure where PeopleSoft Enterprise PT People= Tools executes to compromise PeopleSoft Enterprise PT PeopleTools. While th=
e vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may sig= nificantly impact additional products (scope change). Successful attacks of=
this vulnerability can result in takeover of PeopleSoft Enterprise PT Peop= leTools. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). 2= 026-06-16 8.2 CVE-2026-35288 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 35288 ] Oracle Corporation--PeopleSoft Enterprise PT PeopleTools Vulnerabil= ity in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSof=
t (component: Deployment Package). Supported versions that are affected are=
8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated a= ttacker with network access via HTTPS to compromise PeopleSoft Enterprise P=
T PeopleTools. Successful attacks of this vulnerability can result in takeo= ver of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.1 (Confi= dentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:= N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.1 CVE-2026-35289 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-35289 ] Oracle Corporation--Siebel Apps=
- Marketing Vulnerability in the Siebel Apps - Marketing product of Oracle=
Siebel CRM (component: Marketing). Supported versions that are affected ar=
e 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attack=
er with network access via HTTP to compromise Siebel Apps - Marketing. Succ= essful attacks of this vulnerability can result in takeover of Siebel Apps =
- Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availa= bility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H=
). 2026-06-16 9.8 CVE-2026-46884 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-46884 ] Oracle Corporation--Siebel Apps - Marketing Vulnerability in th=
e Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketin= g). Supported versions that are affected are 17.0-26.5. Easily exploitable = vulnerability allows unauthenticated attacker with network access via HTTP =
to compromise Siebel Apps - Marketing. Successful attacks of this vulnerabi= lity can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score=
9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46887=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46887 ] Oracle Corporation--= Siebel Apps - Marketing Vulnerability in the Siebel Apps - Marketing produc=
t of Oracle Siebel CRM (component: Marketing). Supported versions that are = affected are 17.0-26.5. Easily exploitable vulnerability allows unauthentic= ated attacker with network access via HTTP to compromise Siebel Apps - Mark= eting. Successful attacks of this vulnerability can result in takeover of S= iebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/= C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46889 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-46889 ] Oracle Corporation--Siebel Apps - Marketing Vulnerab= ility in the Siebel Apps - Marketing product of Oracle Siebel CRM (componen=
t: Marketing). Supported versions that are affected are 17.0-26.5. Easily e= xploitable vulnerability allows unauthenticated attacker with network acces=
s via HTTP to compromise Siebel Apps - Marketing. Successful attacks of thi=
s vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1=
Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS=
Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE= -2026-46890 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46890 ] Oracle Co= rporation--Siebel Apps - Marketing Vulnerability in the Siebel Apps - Marke= ting product of Oracle Siebel CRM (component: Marketing). Supported version=
s that are affected are 17.0-26.5. Easily exploitable vulnerability allows = low privileged attacker with network access via HTTP to compromise Siebel A= pps - Marketing. Successful attacks of this vulnerability can result in tak= eover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46886 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-46886 ] Oracle Corporation--Siebel CRM Cloud Appli= cations Vulnerability in the Siebel CRM Cloud Applications product of Oracl=
e Siebel CRM (component: Siebel Cloud Manager). Supported versions that are=
affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenti= cated attacker with network access via HTTP to compromise Siebel CRM Cloud = Applications. Successful attacks of this vulnerability can result in takeov=
er of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.8 (Confidentiali= ty, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/P= R:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46919 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-46919 ] Oracle Corporation--Siebel CRM Cloud Ap= plications Vulnerability in the Siebel CRM Cloud Applications product of Or= acle Siebel CRM (component: Siebel Cloud Manager). Supported versions that = are affected are 17.0-26.5. Difficult to exploit vulnerability allows unaut= henticated attacker with network access via HTTP to compromise Siebel CRM C= loud Applications. Successful attacks of this vulnerability can result in t= akeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.1 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:H/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.1 CVE-2026-46920 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-46920 ] Oracle Corporation--Siebel CRM Clo=
ud Applications Vulnerability in the Siebel CRM Cloud Applications product =
of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions = that are affected are 17.0-26.5. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Siebel CRM=
Cloud Applications. Successful attacks of this vulnerability can result in=
takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confid= entiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N= /AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46921 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-46921 ] Oracle Corporation--Siebel CRM C= loud Applications Vulnerability in the Siebel CRM Cloud Applications produc=
t of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported version=
s that are affected are 17.0-26.5. Difficult to exploit vulnerability allow=
s unauthenticated attacker with access to the physical communication segmen=
t attached to the hardware where the Siebel CRM Cloud Applications executes=
to compromise Siebel CRM Cloud Applications. While the vulnerability is in=
Siebel CRM Cloud Applications, attacks may significantly impact additional=
products (scope change). Successful attacks of this vulnerability can resu=
lt in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.3 (C= onfidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1= /AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 8.3 CVE-2026-46925 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-46925 ] Oracle Corporation--Siebel = CRM Cloud Applications Vulnerability in the Siebel CRM Cloud Applications p= roduct of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported ve= rsions that are affected are 17.0-26.5. Easily exploitable vulnerability al= lows low privileged attacker with logon to the infrastructure where Siebel = CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications=
. While the vulnerability is in Siebel CRM Cloud Applications, attacks may = significantly impact additional products (scope change). Successful attacks=
of this vulnerability can result in takeover of Siebel CRM Cloud Applicati= ons. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability i= mpacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-= 06-16 8.8 CVE-2026-46926 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4692=
6 ] Oracle Corporation--Siebel CRM Deployment Vulnerability in the Siebel C=
RM Deployment product of Oracle Siebel CRM (component: Database Upgrade). S= upported versions that are affected are 17.0-26.5. Easily exploitable vulne= rability allows low privileged attacker with logon to the infrastructure wh= ere Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Suc= cessful attacks of this vulnerability can result in takeover of Siebel CRM = Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availab= ility impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)=
. 2026-06-16 7.8 CVE-2026-46888 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-46888 ] Oracle Corporation--Siebel CRM Integration Vulnerability in the = Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Suppo= rted versions that are affected are 17.0-26.5. Easily exploitable vulnerabi= lity allows low privileged attacker with network access via HTTP to comprom= ise Siebel CRM Integration. Successful attacks of this vulnerability can re= sult in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.8 (Confid= entiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N= /AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-2026-46885 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-46885 ] Oracle Corporation--WebCenter Co= ntent: Imaging Vulnerability in the WebCenter Content: Imaging product of O= racle Fusion Middleware (component: Core). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
unauthenticated attacker with network access via HTTP to compromise WebCen= ter Content: Imaging. Successful attacks of this vulnerability can result i=
n takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-46783 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-46783 ] Oracle Corporation--WebCenter Cont= ent: Imaging Vulnerability in the WebCenter Content: Imaging product of Ora= cle Fusion Middleware (component: Core). Supported versions that are affect=
ed are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows u= nauthenticated attacker with network access via HTTP to compromise WebCente=
r Content: Imaging. Successful attacks of this vulnerability can result in = unauthorized creation, deletion or modification access to critical data or = all WebCenter Content: Imaging accessible data as well as unauthorized acce=
ss to critical data or complete access to all WebCenter Content: Imaging ac= cessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impac= ts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). 2026-06-1=
6 9.1 CVE-2026-46784 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46784 ] = Oracle Corporation--WebCenter Content: Imaging Vulnerability in the WebCent=
er Content: Imaging product of Oracle Fusion Middleware (component: Core). = Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily = exploitable vulnerability allows low privileged attacker with network acces=
s via HTTP to compromise WebCenter Content: Imaging. Successful attacks of = this vulnerability can result in takeover of WebCenter Content: Imaging. CV=
SS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts)=
. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8=
.8 CVE-2026-46780 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46780 ] Ora= cle Corporation--WebLogic Server Vulnerability in the WebLogic Server produ=
ct of Oracle Fusion Middleware (component: Console). Supported versions tha=
t are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerabil= ity allows unauthenticated attacker with network access via HTTP to comprom= ise WebLogic Server. While the vulnerability is in WebLogic Server, attacks=
may significantly impact additional products (scope change). Successful at= tacks of this vulnerability can result in takeover of WebLogic Server. CVSS=
3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).=
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10=
CVE-2026-35292 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35292 ] Oracl=
e Corporation--WebLogic Server Vulnerability in the WebLogic Server product=
of Oracle Fusion Middleware (component: Console). Supported versions that = are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerabilit=
y allows unauthenticated attacker with network access via HTTP to compromis=
e WebLogic Server. While the vulnerability is in WebLogic Server, attacks m=
ay significantly impact additional products (scope change). Successful atta= cks of this vulnerability can result in takeover of WebLogic Server. CVSS 3=
.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). C= VSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 10 C= VE-2026-35301 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35301 ] Oracle = Corporation--WebLogic Server Vulnerability in the WebLogic Server product o=
f Oracle Fusion Middleware (component: Core). Supported versions that are a= ffected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability all= ows low privileged attacker with network access via HTTP to compromise WebL= ogic Server. While the vulnerability is in WebLogic Server, attacks may sig= nificantly impact additional products (scope change). Successful attacks of=
this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Bas=
e Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vec= tor: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). 2026-06-16 9.9 CVE-202= 6-35263 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35263 ] Oracle Corpor= ation--WebLogic Server Vulnerability in the WebLogic Server product of Orac=
le Fusion Middleware (component: Core). Supported versions that are affecte=
d are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable=
vulnerability allows high privileged attacker with network access via HTTP=
to compromise WebLogic Server. While the vulnerability is in WebLogic Serv= er, attacks may significantly impact additional products (scope change). Su= ccessful attacks of this vulnerability can result in takeover of WebLogic S= erver. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability=
impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). 202= 6-06-16 9.1 CVE-2026-35298 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35= 298 ] Oracle Corporation--WebLogic Server Vulnerability in the WebLogic Ser= ver product of Oracle Fusion Middleware (component: Core). Supported versio=
ns that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.=
Easily exploitable vulnerability allows unauthenticated attacker with netw= ork access via TCP to compromise WebLogic Server. Successful attacks of thi=
s vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 9.8 CVE-2026-35= 300 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35300 ] Oracle Corporatio= n--WebLogic Server Vulnerability in the WebLogic Server product of Oracle F= usion Middleware (component: Console). Supported versions that are affected=
are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low=
privileged attacker with network access via HTTPS to compromise WebLogic S= erver. Successful attacks require human interaction from a person other tha=
n the attacker and while the vulnerability is in WebLogic Server, attacks m=
ay significantly impact additional products (scope change). Successful atta= cks of this vulnerability can result in unauthorized creation, deletion or = modification access to critical data or all WebLogic Server accessible data=
as well as unauthorized access to critical data or complete access to all = WebLogic Server accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality a=
nd Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I= :H/A:N). 2026-06-16 8.7 CVE-2026-35258 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-35258 ] Oracle Corporation--WebLogic Server Vulnerability in th=
e WebLogic Server product of Oracle Fusion Middleware (component: Console).=
Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily=
exploitable vulnerability allows unauthenticated attacker with network acc= ess via HTTPS to compromise WebLogic Server. Successful attacks require hum=
an interaction from a person other than the attacker. Successful attacks of=
this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Bas=
e Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vec= tor: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-202= 6-35259 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35259 ] Oracle Corpor= ation--WebLogic Server Vulnerability in the WebLogic Server product of Orac=
le Fusion Middleware (component: Console). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise WebLogi=
c Server. Successful attacks of this vulnerability can result in takeover o=
f WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and = Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I= :H/A:H). 2026-06-16 8.8 CVE-2026-35299 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-35299 ] Oracle Corporation--WebLogic Server Vulnerability in th=
e WebLogic Server product of Oracle Fusion Middleware (component: Console).=
Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Diffic= ult to exploit vulnerability allows unauthenticated attacker with network a= ccess via HTTP to compromise WebLogic Server. Successful attacks require hu= man interaction from a person other than the attacker and while the vulnera= bility is in WebLogic Server, attacks may significantly impact additional p= roducts (scope change). Successful attacks of this vulnerability can result=
in takeover of WebLogic Server. CVSS 3.1 Base Score 8.3 (Confidentiality, = Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/= UI:R/S:C/C:H/I:H/A:H). 2026-06-16 8.3 CVE-2026-35302 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-35302 ] Oracle Corporation--WebLogic Server Vulnera= bility in the WebLogic Server product of Oracle Fusion Middleware (componen=
t: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1= .0.0. Easily exploitable vulnerability allows low privileged attacker with = network access via HTTP to compromise WebLogic Server. Successful attacks o=
f this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Ba=
se Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Ve= ctor: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). 2026-06-16 8.8 CVE-20= 26-35303 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35303 ] Oracle Corpo= ration--WebLogic Server Vulnerability in the WebLogic Server product of Ora= cle Fusion Middleware (component: Core). Supported versions that are affect=
ed are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows l=
ow privileged attacker with network access via HTTP to compromise WebLogic = Server. Successful attacks of this vulnerability can result in takeover of = WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Av= ailability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H= /A:H). 2026-06-16 8.8 CVE-2026-35311 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-35311 ] Oracle Corporation--WebLogic Server Vulnerability in the We= bLogic Server product of Oracle Fusion Middleware (component: Console). Sup= ported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exp= loitable vulnerability allows low privileged attacker with logon to the inf= rastructure where WebLogic Server executes to compromise WebLogic Server. S= uccessful attacks require human interaction from a person other than the at= tacker and while the vulnerability is in WebLogic Server, attacks may signi= ficantly impact additional products (scope change). Successful attacks of t= his vulnerability can result in unauthorized creation, deletion or modifica= tion access to critical data or all WebLogic Server accessible data as well=
as unauthorized access to critical data or complete access to all WebLogic=
Server accessible data. CVSS 3.1 Base Score 7.9 (Confidentiality and Integ= rity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).=
2026-06-16 7.9 CVE-2026-46848 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-46848 ] Ovatheme--BookPro Unauthenticated Arbitrary File Deletion in Book= Pro <=3D 1.1.0 versions. 2026-06-17 8.6 CVE-2026-27400 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-27400 ] Paolo--GeoDirectory Unauthenticated SQL I= njection in GeoDirectory <=3D 2.8.152 versions. 2026-06-15 9.3 CVE-2026-395=
12 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39512 ] park_of_ideas--Mod= erno Unauthenticated PHP Object Injection in Moderno < 1.43 versions. 2026-= 06-17 9.8 CVE-2026-49108 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4910=
8 ] Passionate Programmer Peter--WP Data Access Unauthenticated SQL Injecti=
on in WP Data Access <=3D 5.5.70 versions. 2026-06-15 9.3 CVE-2026-42665 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-42665 ] Paul--iControlWP Unauth= enticated Privilege Escalation in iControlWP <=3D 5.5.3 versions. 2026-06-1=
5 9.8 CVE-2026-34901 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34901 ] = PerryTS--perry Perry before 0.5.1166 contains a JWT validation vulnerabilit=
y that allows remote attackers to bypass token expiration by exploiting the=
unconditional setting of validate_exp =3D false in the verify_decode helpe=
r within the stdlib JWT verification path. Attackers in possession of a pre= viously issued bearer token can present expired tokens to any jwt.verify() = call and retain authenticated access indefinitely, bypassing force-expired = sessions such as user logout or administrative revocation. 2026-06-16 9.1 C= VE-2026-53776 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53776 ] Personi= fyinc--Chromacam Chromacam 4.0.3.0 contains an unquoted service path vulner= ability in the PsyFrameGrabberService that allows local attackers to execut=
e arbitrary code by placing malicious executables in unquoted path director= ies. Attackers with write access to C:\ or subdirectories like C:\Program F= iles (x86)\Personify\ can place a malicious Program.exe or PsyFrameGrabberS= ervice.exe file that executes with LocalSystem privileges when the service = starts automatically at boot. 2026-06-19 7.8 CVE-2023-54353 [
https://www.c= ve.org/CVERecord?id=3DCVE-2023-54353 ] pgadmin.org--pgAdmin 4 Read-only tra= nsaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can in= fluence database content that the assistant reads to execute arbitrary SQL = with the privileges of the pgAdmin user's database role. The AI Assistant's=
execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION R= EAD ONLY wrapper to prevent data modification. The LLM-supplied query was f= orwarded to the database driver without restriction to a single statement o=
r to read-only verbs, so a multi-statement payload beginning with COMMIT, E= ND, ROLLBACK, or ABORT terminated the read-only transaction and ran subsequ= ent statements in autocommit mode. The trailing ROLLBACK then had no effect=
. Delivery is via prompt injection: an attacker who can write content into = any object the AI Assistant may inspect (a row, a column value, a comment) = can cause the LLM to emit the multi-statement payload as a tool call. With = ordinary write privileges on the pgAdmin user's role the attacker can perfo=
rm unauthorised data modification. When the pgAdmin user's role is a Postgr= eSQL superuser or holds pg_execute_server_program, the chain extends to rem= ote code execution on the database server host via COPY ... TO PROGRAM. Fix=
validates the LLM-supplied query up front: it must parse to exactly one no= n-empty / non-comment statement whose leading real token (after stripping w= hitespace, comments, and punctuation) is one of SELECT, WITH, EXPLAIN, SHOW=
, VALUES, or TABLE. Transaction-control verbs, DML, DDL, CALL, COPY, DO, SE= T/RESET, and everything else are rejected before any database work happens.=
PostgreSQL's READ ONLY mode continues to backstop data-modifying CTEs, EXP= LAIN ANALYZE on writes, and volatile side effects. This issue affects pgAdm=
in 4: from 9.13 before 9.16. 2026-06-18 9 CVE-2026-12045 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-12045 ] pgadmin.org--pgAdmin 4 Two state-mutati=
ng endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close= /<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgi= d>/<sid>/<did> -- were the only routes in the module missing the @pga_login= _required decorator. Both reach a pickle.loads sink on session['gridData'][= <trans_id>]['command_obj']: the close endpoint via close_sqleditor_session(=
), and update_sqleditor_connection via check_transaction_status(). In serve=
r mode these endpoints were reachable without any authenticated pgAdmin ses= sion. The defect is a missing-authentication-on-critical-function (CWE-306)=
wrapper around a deserialization-of-untrusted-data sink (CWE-502). Exploit= ing it for remote code execution requires the attacker to also forge a serv= er-side session file whose gridData entry contains a malicious pickle paylo= ad, which in turn requires both (a) knowledge of pgAdmin's Flask SECRET_KEY=
(no chain to leak it is described here -- the attacker must already posses=
s it) and (b) write access to pgAdmin's sessions/ directory on the host. Ne= ither precondition is granted by this defect on its own. When those precond= itions are met from another channel (misconfigured deployment, prior compro= mise, leaked configuration), the missing auth gate is the final hop that tu= rns an existing partial compromise into unauthenticated code execution in t=
he pgAdmin process -- and, by extension, on the host under whatever account=
runs pgAdmin. Fix is a one-line @pga_login_required decorator on each of t=
he two endpoints, matching the convention used by every other route in the = module. The is_authenticated / MFA chain now runs before the trans_id is de= referenced, so an unauthenticated request is rejected before reaching the d= eserialization path. The defect is server-mode only. In DESKTOP mode pgAdmi= n's before_request hook re-authenticates DESKTOP_USER on every request, so =
no endpoint can be exercised in an unauthenticated state and no auth decora= tor (or its absence) is meaningful. The accompanying regression test mirror=
s the attacker's path -- harvests an X-pgA-CSRFToken from GET /login and re= plays it against both endpoints -- and self-skips outside server mode for t= hat reason; it is wired into the existing server-mode CI workflow alongside=
the data-isolation tests. This issue affects pgAdmin 4: from 6.9 before 9.= 16. 2026-06-18 9 CVE-2026-12046 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-12046 ] pgadmin.org--pgAdmin 4 Stored cross-site scripting in pgAdmin 4'=
s error-rendering and plan-node-rendering paths. Text returned by a Postgre= SQL server (ErrorResponse messages, including object names quoted back insi=
de relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact H= eap Blocks fields) was passed verbatim through html-react-parser at every u= ser-facing sink - the notifier toasts, FormFooterMessage / FormInput help a=
nd error areas, FormNote, ModalProvider AlertContent and confirmDelete, Too= lErrorView, the Explain visualiser's NodeText panel, the SQL editor confirm=
dialogs, ConfirmSaveContent, PreferencesHelper modal alerts, and SelectThe= mes helper text. A PostgreSQL server an attacker controls - or any server r= eturning attacker-influenced text such as a table or column name a low-priv= ilege database user can create - could inject arbitrary HTML (including <if= rame>) into the pgAdmin DOM the moment the victim's pgAdmin connected to th=
at server or viewed an Explain plan that referenced the crafted object. The=
injected iframe's srcdoc could fetch attacker-served JavaScript and, by wr= iting to parent.location, redirect the victim's top-level pgAdmin browser t=
ab to an attacker-controlled URL. Because the injection originates from ins= ide pgAdmin's own interface, standard anti-clickjacking controls (X-Frame-O= ptions, Content-Security-Policy: frame-ancestors) do not mitigate it. A phi= shing page rendered inside the legitimate pgAdmin window is indistinguishab=
le from a genuine pgAdmin dialog. Fix combines three complementary layers. = (1) DOMPurify sanitisation is wrapped around every html-react-parser call s= ite reachable from notifier, alert, form-error, Explain, and SQL-editor flo= ws. (2) A new plain-text rendering contract - SafeMessage / SafeHtmlMessage=
components plus Notifier.errorText / alertText / warningText / infoText / = successText helpers - is introduced; around fifty callers across browser, t= ools, dashboard, debugger, misc, llm, preferences, schema diff, and the SQL=
editor that previously interpolated backend-derived strings are migrated t=
o the plain-text variants. (3) Backend HTML-escape is applied at the post-c= onnection-SQL handler (execute_post_connection_sql) via a new sanitize_exte= rnal_text helper, so third-party JSON consumers (audit logs, API clients) n= ever receive raw markup either; the Explain plan-info renderer is also patc= hed to _.escape Recheck Cond and Exact Heap Blocks at construction (matchin=
g every sibling field), giving defence in depth even before DOMPurify runs.=
This issue affects pgAdmin 4: from 6.0 before 9.16. 2026-06-18 9.3 CVE-202= 6-12048 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12048 ] pgadmin.org--= pgAdmin 4 SQL injection in pgAdmin 4 across every dialog template that rend= ers ``COMMENT ON ... IS '<description>'`` for a user-supplied description f= ield. The Jinja templates for Domains (and their constraints), Foreign Tabl= es, Languages, and Event Triggers, plus the Views OID-lookup query, interpo= lated the description directly inside a single-quoted SQL literal -- ``'{{ = data.description }}'`` -- instead of passing it through the ``qtLiteral`` e= scape filter. An authenticated pgAdmin user with permission to create or al= ter the affected object types could submit a description containing an apos= trophe, break out of the literal and chain arbitrary SQL. The injected SQL = runs under the PostgreSQL role the user is already authenticated as; for a = connected role with ``COPY ... TO/FROM PROGRAM`` (typically PostgreSQL supe= ruser), this chains to OS command execution on the PostgreSQL host. The def= ect does not cross a privilege boundary -- the user already has direct SQL = access to that role through pgAdmin's Query Tool -- so the attacker gains n=
o capability beyond what their database role already grants. The marginal i= mpact captures bypass of any application-layer Query Tool gating an operato=
r may have configured. The defect was originally reported against the Domai=
n Dialog ``description`` field; a code-wide audit identified sixteen sites =
of the same pattern across the templates listed above. The same review also=
surfaced ten related sinks in the pgstattuple/pgstatindex stats templates =
-- ``pgstattuple('{{schema}}.{{table}}')`` and the matching pgstatindex sha=
pe -- where ``qtIdent`` escapes embedded double quotes inside the identifie=
r but not apostrophes, so a user with CREATE privilege on a schema could pl= ant a table or index named ``foo'bar`` and a later stats viewer would rende=
r an unbalanced literal. Fix is layered: 1. Sites: replace every ``'{{ x.de= scription }}'`` with ``{{ x.description|qtLiteral(conn) }}`` (no surroundin=
g quotes -- the filter wraps the value in escaped quotes itself). Plumb ``c= onn=3Dself.conn`` through every ``render_template`` call that loads one of = these templates. Also corrects a ``{ % elif`` Jinja typo in the foreign-tab=
le schema diff (dead branch). Rewrite the ten pgstattuple/pgstatindex stats=
sites to address the relation via OID + ``::oid::regclass`` cast (e.g. ``p= gstattuple({{ tid }}::oid::regclass)``), eliminating the embedded literal-c= all form entirely so that bug-class can no longer recur there. 2. Driver ha= rdening: ``qtLiteral`` (in ``utils/driver/psycopg3/__init__.py``) used to s= ilently return the raw unescaped value when its ``conn`` argument was falsy=
. It now raises ``ValueError`` -- surfacing the entire bug class going forw= ard. The change immediately uncovered eight latent plumbing bugs (in ``sche= mas/__init__.py``, ``schemas/functions/__init__.py``, ``schemas/tables/util= s.py``, ``foreign_servers/__init__.py``, and seven sites in ``roles/__init_= _.py``) -- all fixed as part of this patch. The inner ``except`` block that=
swallowed adapter-level failures and returned the raw value is also remove=
d, so unadaptable inputs raise instead of leaking unescaped values. 3. Regr= ession tests: a per-template behavioural test renders each previously-vulne= rable template with an apostrophe-injection payload and asserts the escaped=
fragment is present and the vulnerable fragment absent; a lint test walks = every ``*.sql`` template flagging any ``'{{ ... }}'`` single-quote-wrapped = interpolation against an explicit allowlist; unit tests cover the new qtLit= eral fail-fast and inner-except raise paths. This issue affects pgAdmin 4: = from 1.0 before 9.16. 2026-06-18 8.8 CVE-2026-12044 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-12044 ] php-standard-library--php-standard-library P=
HP Standard Library (PSL) is set of APIs covering async, collections, netwo= rking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 and 6.= 2.0, the Psl\H2\ServerConnection does not validate that the total bytes rec= eived in DATA frames match the content-length header declared in the HEADER=
S frame, allowing request smuggling. This is in violation of RFC 9113 =C3= =82=C2=A78.1.1. A malicious client is able to send more DATA bytes than dec= lared, smuggling additional content past application-level size limits and = send fewer DATA bytes than declared and close the stream early, causing app= lications that trust the declared length to behave incorrectly. The vulnera= bility is only reachable for consumers using Psl\H2\ServerConnection direct=
ly to accept untrusted client traffic. Consumers of documented high-level P=
SL APIs are not affected. This issue has been fixed in versions 6.1.2 and 6= .2.1. 2026-06-17 7.5 CVE-2026-48979 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-48979 ] phpMyFAQ--phpMyFAQ phpMyFAQ before 4.1.4 contains missing au= thorization vulnerabilities in editUser() and updateUserRights() endpoints = that allow authenticated administrators to escalate privileges. Non-SuperAd= min users with edit_user permission can set is_superadmin flag or grant arb= itrary rights to escalate to SuperAdmin access. 2026-06-21 8.8 CVE-2026-563=
96 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56396 ] PickleScan--Pickle= Scan PickleScan before 0.0.33 fails to include the pty.spawn function in it=
s unsafe globals list, allowing attackers to bypass security checks. Malici= ous actors can craft pickle payloads using pty.spawn to achieve arbitrary c= ode execution when files are processed by PickleScan. 2026-06-17 8.8 CVE-20= 25-71322 [
https://www.cve.org/CVERecord?id=3DCVE-2025-71322 ] picklescan--= picklescan picklescan before 1.0.4 fails to block pkgutil.resolve_name, all= owing attackers to bypass the entire blocklist by resolving any dangerous f= unction through indirect REDUCE calls. Remote attackers can invoke any bloc= ked function such as os.system, builtins.exec, or subprocess.call to achiev=
e remote code execution. 2026-06-17 10 CVE-2026-3490 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-3490 ] picklescan--picklescan picklescan before 0.0= .33 contains an incomplete deny-list that fails to block pydoc.locate and o= perator.methodcaller functions, allowing attackers to bypass security check=
s. Remote attackers can craft malicious pickle files using these unblocked = functions to achieve arbitrary code execution when the pickle is deserializ= ed. 2026-06-17 9.8 CVE-2025-71320 [
https://www.cve.org/CVERecord?id=3DCVE-= 2025-71320 ] picklescan--picklescan picklescan before 0.0.33 contains an ar= bitrary file writing vulnerability that allows attackers to bypass the dang= erous blocklist by using distutils.file_util.write_file. Attackers can cons= truct malicious pickle objects to overwrite critical system files and achie=
ve denial of service or remote code execution. 2026-06-17 9.8 CVE-2025-7132=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2025-71321 ] picklescan--pickles= can picklescan before 0.0.33 fails to block the ctypes module, allowing att= ackers to achieve remote code execution by invoking direct syscalls and acc= essing raw memory. Attackers can craft malicious pickle files using ctypes.= WinDLL to load kernel32.dll and execute arbitrary commands, bypassing sandb=
ox protections and gadget chain detection. 2026-06-17 9.8 CVE-2025-71323 [ =
https://www.cve.org/CVERecord?id=3DCVE-2025-71323 ] picklescan--picklescan = picklescan before 0.0.27 contains a parsing logic error in the _list_global=
s function when handling STACK_GLOBAL opcodes, failing to track arguments i=
n the correct range and allowing malicious pickle files to bypass detection=
. Attackers can craft pickle files with arguments at position zero to trigg=
er unexpected exceptions and evade security scanning. 2026-06-17 9.8 CVE-20= 25-71325 [
https://www.cve.org/CVERecord?id=3DCVE-2025-71325 ] picklescan--= picklescan picklescan before 1.0.4 contains an incomplete blocklist for the=
profile module that fails to block the module-level profile.run() function=
, allowing attackers to achieve arbitrary code execution via exec(). Attack= ers can craft malicious pickle files calling profile.run(statement) to exec= ute arbitrary Python code while picklescan reports zero security issues. 20= 26-06-17 9.8 CVE-2026-53873 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 3873 ] picklescan--picklescan picklescan before 1.0.1 contains an unsafe de= serialization vulnerability allowing unauthenticated users to execute arbit= rary code by hiding eval calls nested under callable objects via getattr. A= ttackers can embed malicious code in pickle files that evades detection but=
executes when the pickle is loaded from untrusted sources. 2026-06-17 9.8 = CVE-2026-53874 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53874 ] pickle= scan--picklescan picklescan before 0.0.28 fails to detect malicious pickle = files that invoke torch.utils._config_module.load_config function within re= duce methods. Attackers can craft pickle files embedding arbitrary code tha=
t evades detection but executes during pickle.load, enabling remote code ex= ecution in supply chain attacks. 2026-06-21 8.1 CVE-2025-71348 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2025-71348 ] picklescan--picklescan picklescan=
before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell= .ModifiedInterpreter.runcommand in reduce methods. Attackers can embed unde= tected code in pickle files that executes remote commands when loaded by vi= ctims. 2026-06-21 8.1 CVE-2025-71357 [
https://www.cve.org/CVERecord?id=3DC= VE-2025-71357 ] picklescan--picklescan picklescan before 0.0.30 fails to de= tect cProfile.runctx function calls in pickle file reduce methods, allowing=
attackers to execute arbitrary code. Malicious pickle files bypass pickles= can detection and execute remote code when loaded via pickle.load(). 2026-0= 6-21 8.1 CVE-2025-71378 [
https://www.cve.org/CVERecord?id=3DCVE-2025-71378=
] picklescan--picklescan picklescan before 0.0.35 contains an unsafe pickl=
e deserialization vulnerability allowing unauthenticated attackers to read = arbitrary server files by chaining io.FileIO and urllib.request.urlopen. At= tackers can bypass RCE-focused blocklists to exfiltrate sensitive data like=
/etc/passwd to external servers. 2026-06-17 7.5 CVE-2026-53872 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-53872 ] Pimcore GmbH--Pimcore CMS/DXP Pi= mcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that a= llows authenticated administrative attackers to execute arbitrary methods o=
n PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAll= owed() implementations in the custom Twig SecurityPolicy. Attackers can sup= ply malicious Twig templates through the DataObject ClassDefinition Layout\= Text component to perform arbitrary file reads, execute arbitrary database = queries, and potentially achieve remote code execution via PHP object gadge=
t chains, with the pimcore_* function wildcard further broadening the bypas=
s to all Pimcore Twig functions. 2026-06-17 7.2 CVE-2026-11407 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-11407 ] Pods Framework--Pods Unauthentica= ted Cross Site Scripting (XSS) in Pods <=3D 3.3.8 versions. 2026-06-16 7.1 = CVE-2026-54191 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54191 ] ponted= ilana--php-weasyprint PhpWeasyPrint is a PHP library allowing PDF generatio=
n from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weas= yprint` builds the shell command for WeasyPrint by passing the binary path = through `escapeshellarg()` first and then checking the *quoted* result with=
`is_executable()`. On POSIX `escapeshellarg('/usr/local/bin/weasyprint')` = returns `'/usr/local/bin/weasyprint'` with the single-quote characters as p= art of the string, so `is_executable()` looks for a file whose actual name = includes those quotes. That file never exists, the "safe" branch is dead co= de, and the raw `$binary` string (set via the constructor or `setBinary()`)=
flows directly into `Symfony\Component\Process\Process::fromShellCommandli= ne()`. Any deployment whose binary path is sourced from configuration, an e= nvironment variable, or a per-tenant setting reaches a shell-command-inject= ion sink. The library is documented as a one-to-one substitute for KnpLabs/= snappy and inherited the exact pre-fix codepath KnpLabs patched in GHSA-vpr= 4-p6fq-85jc. PhpWeasyPrint version 2.5.1 contains a patch for the issue. 20= 26-06-19 8.2 CVE-2026-49260 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 9260 ] pontedilana--php-weasyprint PhpWeasyPrint is a PHP library allowing = PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedi= lana/php-weasyprint` guarded the output filename against the `phar://` stre=
am wrapper with a case-sensitive blacklist. PHP stream wrappers are case-in= sensitive, so `PHAR://`, `Phar://`, etc. bypass the check and reach `fileEx= ists()` (`file_exists()`) in `prepareOutput()`. On PHP 7 (which the library=
still supports - PHP 7.4+), this triggers deserialization of a crafted PHA=
R archive's metadata, leading to remote code execution. This is the patch-b= ypass of CVE-2023-28115. The same issue and fix were handled upstream in Kn= pLabs/snappy (GHSA-92rv-4j2h-8mjj). PhpWeasyPrint version 2.6.0 contains a = patch for the issue. 2026-06-19 8.1 CVE-2026-49286 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-49286 ] Powerpackelements--PowerPack Pro for Elemento=
r Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2= .13.0 versions. 2026-06-17 8.8 CVE-2026-42629 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-42629 ] PraisonAI--PraisonAI PraisonAI before 4.5.128 cont= ains an arbitrary shell command execution vulnerability where the UI module=
s hardcode approval_mode to auto, overriding administrator configuration fr=
om PRAISON_APPROVAL_MODE environment variable. Authenticated attackers can = instruct the LLM agent to execute arbitrary shell commands via subprocess.r=
un with shell=3DTrue, bypassing the manual approval gate and insufficient c= ommand sanitization blocklists. 2026-06-18 8.8 CVE-2026-56075 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-56075 ] PraisonAI--PraisonAI PraisonAI bef= ore 1.5.128 contains a cross-origin agent execution vulnerability in the AG=
UI endpoint that allows remote attackers to trigger arbitrary agent executi= on. The POST /agui endpoint lacks authentication and hardcodes Access-Contr= ol-Allow-Origin: * headers, combined with Starlette's Content-Type-agnostic=
JSON parsing, enabling attackers to bypass CORS preflight checks via simpl=
e requests and exfiltrate sensitive agent responses including tool executio=
n results and environment data. 2026-06-18 8.1 CVE-2026-56076 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-56076 ] PraisonAI--PraisonAI PraisonAI bef= ore 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor th=
at fails to sanitize agent IDs when building file paths. Attackers can incl= ude traversal sequences like ../ in agent IDs to read, write, or overwrite = arbitrary files, enabling sensitive disclosure, denial of service, or code = execution. 2026-06-18 8.8 CVE-2026-56078 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56078 ] PremiumPress Limited.--WordPress Dating Theme Unauthent= icated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <=3D 11.= 2.0 versions. 2026-06-17 8.8 CVE-2026-22342 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-22342 ] PremiumPress Limited.--WordPress Dating Theme Unauth= enticated Broken Access Control in WordPress Dating Theme <=3D 11.2.0 versi= ons. 2026-06-17 8.6 CVE-2026-22343 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-22343 ] premmerce--Premmerce Dev Tools The Premmerce Dev Tools plugin=
for WordPress is vulnerable to Remote Code Execution via missing authoriza= tion in versions up to and including 2.0. This is due to the 'generatePlugi= nHandler' function lacking any authorization check before processing user-s= upplied POST data, combined with the 'createFromStub' function performing u= nsanitized string substitution of the 'premmerce_plugin_namespace' paramete=
r directly into PHP stub files written to the wp-content/plugins/ directory=
. An attacker can inject a semicolon followed by arbitrary PHP code into th=
e namespace parameter, causing the generated plugin file to contain and exe= cute that code when accessed via HTTP. This makes it possible for authentic= ated attackers with Subscriber-level access and above to create arbitrary P=
HP files on the server and achieve remote code execution. 2026-06-16 8.8 CV= E-2026-6933 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6933 ] PressLayou= ts--Alukas Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.=
2026-06-17 8.1 CVE-2026-39445 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-39445 ] PressLayouts--EmallShop Unauthenticated PHP Object Injection in E= mallShop <=3D 2.4.21 versions. 2026-06-16 8.1 CVE-2026-39443 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-39443 ] PressLayouts--Kapee Unauthenticated=
PHP Object Injection in Kapee < 1.7.0 versions. 2026-06-16 8.1 CVE-2026-39= 446 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39446 ] PressLayouts--Kap=
ee Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions. 20= 26-06-17 7.1 CVE-2026-41557 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 1557 ] PressLayouts--PressMart Unauthenticated PHP Object Injection in Pres= sMart <=3D 1.2.26 versions. 2026-06-17 8.1 CVE-2026-39442 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-39442 ] Prince--Integrate Google Drive Missing=
Authorization vulnerability in Prince Integrate Google Drive allows Exploi= ting Incorrectly Configured Access Control Security Levels. This issue affe= cts Integrate Google Drive: from n/a through 1.3.8. 2026-06-17 8.3 CVE-2024= -32949 [
https://www.cve.org/CVERecord?id=3DCVE-2024-32949 ] Projectopia--P= rojectopia Custom role Insecure Direct Object References (IDOR) in Projecto= pia <=3D 5.1.25.2 versions. 2026-06-15 7.5 CVE-2025-59133 [
https://www.cve= .org/CVERecord?id=3DCVE-2025-59133 ] Pulseextensions--Flip Wall Joomla! Com= ponent Flip Wall 8.0 contains an SQL injection vulnerability that allows un= authenticated attackers to execute arbitrary SQL queries by injecting malic= ious code through the wallid parameter. Attackers can send GET requests to = index.php with the option=3Dcom_flipwall&task=3Dclick&wallid parameter cont= aining SQL injection payloads to extract sensitive database information. 20= 26-06-19 7.1 CVE-2017-20265 [
https://www.cve.org/CVERecord?id=3DCVE-2017-2= 0265 ] Pulseextensions--Sponsor Wall Joomla! Component Sponsor Wall 8.0 con= tains an SQL injection vulnerability that allows unauthenticated attackers =
to execute arbitrary SQL queries by injecting malicious code through the wa= llid parameter. Attackers can send GET requests to index.php with the optio= n=3Dcom_sponsorwall&task=3Dclick&wallid parameter containing SQL injection = payloads to extract sensitive database information including credentials an=
d configuration data. 2026-06-19 7.1 CVE-2017-20264 [
https://www.cve.org/C= VERecord?id=3DCVE-2017-20264 ] Qihoo--360 Total Security A security flaw ha=
s been discovered in Qihoo 360 Total Security 6.0. This vulnerability affec=
ts the function RpcStringBindingComposeW of the component Nucleus Engine Mo= nitoring Logic. Performing a manipulation of the argument NetworkAddr resul=
ts in protection mechanism failure. The attack requires a local approach. T=
he exploit has been released to the public and may be used for attacks. The=
vendor was contacted early about this disclosure but did not respond in an=
y way. 2026-06-15 7.8 CVE-2026-12214 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-12214 ] QuantumCloud--ChatBot Subscriber Broken Access Control in C= hatBot <=3D 7.9.7 versions. 2026-06-15 7.1 CVE-2026-40788 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-40788 ] QuantumCloud--Conversational Forms for=
ChatBot Improper Limitation of a Pathname to a Restricted Directory ('Path=
Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot=
allows Path Traversal. This issue affects Conversational Forms for ChatBot=
: from n/a through 1.1.8. 2026-06-17 7.5 CVE-2024-32729 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2024-32729 ] QuantumCloud--WPBot Pro Wordpress Chatbo=
t Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <=3D 13= .6.5 versions. 2026-06-17 7.7 CVE-2025-60223 [
https://www.cve.org/CVERecor= d?id=3DCVE-2025-60223 ] quarkusio--quarkus Quarkus is a Java framework for = building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.= 2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based author= ization policies can be bypassed using encoded semicolons (%3B) to smuggle = matrix parameters past the security layer, and using encoded slashes (%2F) =
or backslashes (%5C) to access protected static resources. This is a distin=
ct issue from CVE-2026-39852, which addressed only literal semicolon stripp= ing. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.= 6.2 contain a patch. 2026-06-19 7.5 CVE-2026-50559 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-50559 ] Radiflow--iSAP Smart Collector The device has=
a webserver that exposes a REST API authenticated with a token on the mana= gement network. By exploiting an OS command injection vulnerability an auth= enticated attacker can send arbitrary commands to the device that are execu= ted with administrative permissions by the underlying operating system. 202= 6-06-16 9.1 CVE-2026-22313 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22= 313 ] Radiflow--iSAP Smart Collector The device has a webserver that expose=
s a REST API authenticated with a constant token. The unauthenticated API c=
an be used by an attacker to get access to system settings, modify the conf= iguration and execute some commands (e.g. system reboot). 2026-06-16 8.6 CV= E-2026-22312 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22312 ] rainafar= ai--Notification for Telegram Unauthenticated Cross Site Scripting (XSS) in=
Notification for Telegram <=3D 3.5 versions. 2026-06-15 7.1 CVE-2026-40732=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-40732 ] Raindropsinfotech--T= witch Tv Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerab= ility that allows unauthenticated attackers to execute arbitrary SQL querie=
s by injecting malicious code through the username and id parameters. Attac= kers can send GET requests to index.php with option=3Dcom_twitchtv and view=
parameters containing SQL injection payloads to extract sensitive database=
information including credentials and configuration data. 2026-06-19 8.2 C= VE-2017-20270 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20270 ] Real--R= ealTimes Desktop Service RealTimes Desktop Service 18.1.4 contains an unquo= ted service path vulnerability in the rpdsvc.exe binary that allows local a= ttackers to escalate privileges. Attackers can place malicious executables =
in unquoted path directories to execute arbitrary code with LocalSystem pri= vileges during service startup or system reboot. 2026-06-19 7.8 CVE-2020-37= 251 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37251 ] Really Simple Plu= gins--Really Simple SSL Unauthenticated Broken Authentication in Really Sim= ple SSL <=3D 9.5.10 versions. 2026-06-15 8.1 CVE-2026-48970 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-48970 ] RealMag777--InPost Gallery Unauthent= icated SQL Injection in InPost Gallery <=3D 2.1.4.6 versions. 2026-06-16 9.=
3 CVE-2026-39574 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39574 ] Real= tek--Realtek Audio Service Realtek Audio Service 1.0.0.55 contains an unquo= ted service path vulnerability in RtkAudioService64.exe that allows local a= ttackers to escalate privileges by injecting malicious code. Attackers can = place executable files in the unquoted service path directory to execute ar= bitrary code with LocalSystem privileges during service startup or system r= eboot. 2026-06-19 7.8 CVE-2020-37252 [
https://www.cve.org/CVERecord?id=3DC= VE-2020-37252 ] Realtek--Realtek High Definition Audio Driver Realtek High = Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulner= ability that allows local attackers to escalate privileges by placing a mal= icious executable in the service path. Attackers can insert an executable f= ile in the unquoted path and restart the service to execute code with Local= System privileges. 2026-06-19 7.8 CVE-2016-20085 [
https://www.cve.org/CVER= ecord?id=3DCVE-2016-20085 ] Realtyna--Realtyna Organic IDX plugin Unauthent= icated SQL Injection in Realtyna Organic IDX plugin <=3D 5.1.0 versions. 20= 26-06-15 9.3 CVE-2026-45439 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 5439 ] Red Hat--Red Hat Ansible Automation Platform 2 A command injection v= ulnerability was found in galaxy_ng. The do_git_checkout() function in the = legacy role import API (v1) interpolates unsanitized git ref names (branch/= tag names) into shell commands executed via subprocess.run() with shell=3DT= rue. An authenticated user who controls a git repository can create a branc=
h or tag with shell metacharacters in the name to achieve remote code execu= tion on the pulp worker. The vulnerable endpoint is only reachable when GAL= AXY_ENABLE_LEGACY_ROLES is set to True, which is not the default configurat= ion. 2026-06-16 7.5 CVE-2026-12398 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-12398 ] Red Hat--Red Hat Enterprise Linux 10 A flaw was found in Pace= maker. An unauthenticated remote attacker can exploit an integer overflow v= ulnerability in the remote message decompression process. By sending a spec= ially crafted compressed remote message before authentication, an attacker = can cause memory corruption, leading to a denial of service (DoS) in the CI=
B remote listener. This can result in the affected service crashing. 2026-0= 6-16 8.6 CVE-2026-10649 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10649=
] Red Hat--Red Hat Enterprise Linux 10 A heap buffer overflow vulnerabilit=
y was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds ch= eck incorrectly validates area rather than individual dimensions, allowing =
a malicious VNC server to send a rectangle that extends beyond the framebuf= fer. A remote attacker could set up a malicious VNC server and trick a user=
into connecting, resulting in an out-of-bounds heap write that could lead =
to code execution or a crash. 2026-06-15 8.8 CVE-2026-52720 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-52720 ] Red Hat--Red Hat Enterprise Linux 10=
A flaw was found in the cifs-utils package where the cifs.upcall helper fa= ils to securely drop its root privileges before looking up user information=
inside a user-controlled environment. A local, low privileged attacker can=
exploit this by using a crafted request_key payload to trick the root-owne=
d helper into entering a custom environment (namespace) containing a malici= ous NSS module. This forces the system to load the attacker's controlled NS=
S Module and configuration, allowing them to execute arbitrary commands as = the root user, elevating their privileges and fully compromising the system=
. 2026-06-18 7.8 CVE-2026-12505 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-12505 ] Red Hat--Red Hat Enterprise Linux 10 An out-of-bounds read vulne= rability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. T=
he JPEG parser reads a segment length value from the bitstream without vali= dating it against available data. A remote attacker could trick a user into=
opening a specially crafted JPEG file, causing downstream parsing to read = beyond the provided input buffer, leading to a crash or potential informati=
on disclosure. 2026-06-15 7.1 CVE-2026-52719 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-52719 ] Red Hat--Red Hat Enterprise Linux 10 A signed integ=
er overflow vulnerability was found in GStreamer's VMnc decoder. A crafted = VMnc stream with large cursor dimensions can overflow signed integer payloa= d-size arithmetic, bypassing a length check and leading to out-of-bounds re= ads. A remote attacker could trick a user into opening a specially crafted = VMnc file, potentially causing a crash or information disclosure. 2026-06-1=
5 7.1 CVE-2026-52722 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52722 ] = Red Hat--Red Hat Enterprise Linux 10 A vulnerability was found in the GStre= amer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm=
) file, the demuxer parses MDPR (media properties) chunks to configure audi=
o streams. For audio stream header versions 4 and 5, the parser reads field=
s such as codec type, packet size, sample rate, channel count, and extra co= dec data length from fixed offsets within the chunk without first checking = that the chunk contains enough data. If a malicious file provides an MDPR c= hunk that is too small to contain a complete audio stream header, the parse=
r reads beyond the end of the buffer. This can cause the application to cra= sh. In some cases, bytes read past the buffer boundary may be incorporated = into stream metadata, which could result in limited information disclosure.=
2026-06-15 7.1 CVE-2026-53703 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-53703 ] Red Hat--Red Hat Enterprise Linux 10 A flaw was found in GStreame= r's RealMedia demuxer in the gst-plugins-ugly package. When processing a Re= alMedia file containing a specially crafted FILEINFO metadata section, the = demuxer parses variable-name and variable-value pairs using re_skip_pascal_= string() without validating that offsets remain within the mapped buffer. A= dditionally, the element count controlling the parsing loop is read from at= tacker-controlled data without validation, which can cause an infinite loop=
. A crafted RealMedia file can cause the application to crash, hang, or pot= entially read limited adjacent memory contents. 2026-06-15 7.1 CVE-2026-537=
04 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53704 ] Red Hat--Red Hat E= nterprise Linux 10 A flaw was found in GStreamer's WavPack audio decoder in=
gst-plugins-good. When processing a specially crafted WavPack file, an int= eger overflow in the buffer size calculation (4 * block_samples * channels)=
in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The=
WavPack library then writes decoded audio samples far beyond the allocated=
buffer, resulting in heap memory corruption. This affects both 32-bit and = 64-bit systems since the arithmetic is performed in 32-bit integers before = promotion to the allocation size type. A remote attacker could use this fla=
w to crash an application or potentially execute arbitrary code by convinci=
ng a user to open a malicious WavPack audio file. 2026-06-15 7.6 CVE-2026-5= 3705 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53705 ] Red Hat--Red Hat=
Enterprise Linux 10 A heap buffer overflow vulnerability was found in liba= om, the reference AV1 codec implementation. A flaw in the AV1 encoder's Loo= k-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-= around guard to be bypassed when g_lag_in_frames is set to 1 or higher. Thi=
s results in a 232-byte out-of-bounds write on every encoded frame after th=
e second, corrupting adjacent heap objects. An attacker who can influence e= ncoder configuration in a transcoding service or WebRTC session could explo=
it this to cause a denial of service (process crash) or potentially achieve=
code execution. 2026-06-19 7.6 CVE-2026-56208 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-56208 ] Red Hat--Red Hat Enterprise Linux 10 An arbitrary=
address write vulnerability was found in libaom, the reference AV1 codec i= mplementation. A missing bounds check in the SVC (Scalable Video Coding) la= yer ID control function allows an attacker to inject an arbitrary pointer i= nto the cyclic refresh map field via crafted image pixel values. The encode=
r then writes approximately 1,200 bytes at the attacker-controlled address.=
This is fully deterministic and does not require a separate information le= ak. An attacker who can supply frames to a network-facing libaom encoder wi=
th SVC enabled could exploit this for denial of service or potential code e= xecution. 2026-06-19 7.1 CVE-2026-56209 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56209 ] Red Hat--Red Hat Enterprise Linux 10 A heap-buffer-over= flow read vulnerability was found in libaom, the reference AV1 codec implem= entation. A missing bounds check in the SVC (Scalable Video Coding) layer I=
D control function allows setting a spatial_layer_id exceeding the configur=
ed number of layers. This causes an out-of-bounds heap read of approximatel=
y 40,728 bytes when computing a layer context array index. An attacker who = can influence SVC encoder parameters in a network-facing service could expl= oit this for information disclosure (heap content leak) or denial of servic=
e (segmentation fault from hitting unmapped memory). 2026-06-19 7.1 CVE-202= 6-56210 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56210 ] Red Hat--Red = Hat Enterprise Linux 10 A remote code execution vulnerability was found in = libaom, the reference AV1 codec implementation. Insufficient bounds validat= ion in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allow=
s an attacker to supply crafted video frame pixels that overlap with intern=
al encoder layer context structures. In fork-based video processing service=
s, an attacker can use this to hijack the cyclic refresh map pointer, brute= -force the process base address via a crash oracle, and redirect control fl=
ow to achieve arbitrary command execution. Exploitation requires the target=
service to use libaom with SVC encoding enabled and accept attacker-suppli=
ed video frames. 2026-06-19 7.1 CVE-2026-56211 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-56211 ] Redhat--QEMU A flaw was found in QEMU. When readi=
ng input audio in the virtio-snd device input callback, the `virtio_snd_pcm= _in_cb` function did not check whether the iov could fit the data buffer, p= otentially leading to a heap out-of-bounds write. This issue exists due to =
an incomplete fix for CVE-2024-7730. 2026-06-19 7.4 CVE-2026-3195 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-3195 ] RelyWP--Coupon Affiliates Unaut= henticated Cross Site Scripting (XSS) in Coupon Affiliates <=3D 7.5.3 versi= ons. 2026-06-15 7.1 CVE-2026-40770 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-40770 ] RelyWP--Coupon Affiliates Subscriber Sensitive Data Exposure =
in Coupon Affiliates <=3D 7.8.1 versions. 2026-06-15 7.5 CVE-2026-49068 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-49068 ] ReviewX--ReviewX Unauthe= nticated Broken Authentication in ReviewX <=3D 2.3.6 versions. 2026-06-15 7=
.5 CVE-2026-40781 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40781 ] Rit= labs--TinyWeb Server A security vulnerability has been detected in Ritlabs = TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the=
library libeay32.dll.html of the component Header Handler. The manipulatio=
n of the argument Authorization leads to stack-based buffer overflow. The a= ttack can be initiated remotely. The exploit has been disclosed publicly an=
d may be used. The vendor was contacted early about this disclosure but did=
not respond in any way. 2026-06-15 7.3 CVE-2026-12200 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12200 ] Royal Elementor Addons--Royal Elementor A= ddons Pro Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Add= ons Pro < 1.7.1041 versions. 2026-06-17 7.1 CVE-2026-40720 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-40720 ] Royal Plugins--Royal MCP Unauthentica= ted Broken Access Control in Royal MCP <=3D 1.4.2 versions. 2026-06-15 7.3 = CVE-2026-40775 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40775 ] Ruben = Garcia--AutomatorWP Subscriber Broken Authentication in AutomatorWP <=3D 5.= 6.7 versions. 2026-06-15 7.1 CVE-2026-40785 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-40785 ] Ruben Garcia--AutomatorWP Unauthenticated Cross Site=
Scripting (XSS) in AutomatorWP <=3D 5.6.7 versions. 2026-06-15 7.2 CVE-202= 6-42650 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42650 ] Ruben Garcia-= -AutomatorWP Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <=3D=
5.7.2 versions. 2026-06-15 7.1 CVE-2026-42775 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-42775 ] Ruben Garcia--GamiPress Subscriber SQL Injection =
in GamiPress <=3D 7.8.7 versions. 2026-06-15 8.5 CVE-2026-48874 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-48874 ] rxi--microtar A stack-based buff=
er overflow exists in the raw_to_header() function in src/microtar.c in rxi=
microtar 0.1.0. The function copies the 100-byte name and linkname fields =
of a TAR header with strcpy() without guaranteeing null termination of the = source. The POSIX ustar format permits these fixed-width fields to be fully=
populated with non-null bytes, so a crafted archive whose linkname field (= followed by the trailing padding of the 512-byte raw header) contains no nu=
ll terminator causes strcpy() to read past the end of the 512-byte raw head=
er stack buffer and to write past the destination header buffer. A remote a= ttacker who supplies a crafted TAR archive that the victim opens or parses = (via mtar_open(), mtar_read_header(), or mtar_find()) can cause an out-of-b= ounds read and a stack buffer overflow, resulting in denial of service (cra= sh) and potentially arbitrary code execution. Confirmed with AddressSanitiz= er: stack-buffer-overflow READ of size 356 in raw_to_header at src/microtar= .c:112. 2026-06-17 8.8 CVE-2026-55738 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-55738 ] rxi--microtar An integer overflow in the mtar_next() funct= ion in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cau=
se a denial of service (uncontrolled CPU consumption / infinite loop) via a=
crafted tar archive. mtar_next() computes the offset to the next record as=
round_up(h.size, 512) + sizeof(mtar_raw_header_t) using 32-bit arithmetic.=
When the header size field is a multiple of 512 in the range 0xFFFFFC01-0x= FFFFFE00 (e.g. 0xFFFFFE00), the addition wraps to 0, so mtar_next() seeks t=
o the current record position instead of advancing. As a result, mtar_find(=
) and any loop that iterates entries with mtar_next() repeat indefinitely o= ver the same record, hanging the process at 100% CPU with no recovery. 2026= -06-17 7.5 CVE-2026-54417 [
https://www.cve.org/CVERecord?id=3DCVE-2026-544=
17 ] SaasProject--Booking Package Unauthenticated Broken Access Control in = Booking Package <=3D 1.7.06 versions. 2026-06-15 7.5 CVE-2026-40774 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-40774 ] Satinder Singh--Contact Form=
Extender for Divi Save Entries, File Upload & Country Code Field Unauthent= icated Arbitrary File Deletion in Contact Form Extender for Divi – Sa=
ve Entries, File Upload & Country Code Field <=3D 1.0.6 versions. 2026-= 06-15 8.6 CVE-2026-40769 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4076=
9 ] sbouey--Falang multilanguage Subscriber Privilege Escalation in Falang = multilanguage <=3D 1.4.2 versions. 2026-06-17 8.8 CVE-2026-54805 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-54805 ] Schiocco--Support Board Unauthe= nticated Privilege Escalation in Support Board < 3.8.9 versions. 2026-06-16=
9.8 CVE-2026-27395 [
https://www.cve.org/CVERecord?id=3DCVE-2026-27395 ] S= elect-Themes--Getaway Unauthenticated Local File Inclusion in Getaway < 1.8=
versions. 2026-06-16 8.1 CVE-2026-39547 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-39547 ] Select-Themes--Hiroshi Unauthenticated PHP Object Injec= tion in Hiroshi <=3D 1.5.1 versions. 2026-06-17 8.1 CVE-2026-39560 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-39560 ] Select-Themes--Manufaktur Sol= utions Unauthenticated PHP Object Injection in Manufaktur Solutions <=3D 1.= 1.1 versions. 2026-06-17 8.1 CVE-2026-40752 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-40752 ] Select-Themes--Micdrop Unauthenticated PHP Object In= jection in Micdrop <=3D 1.3.1 versions. 2026-06-16 8.1 CVE-2026-39580 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-39580 ] Select-Themes--Mildhill Un= authenticated PHP Object Injection in Mildhill <=3D 1.5 versions. 2026-06-1=
7 8.1 CVE-2026-39573 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39573 ] = Select-Themes--Sant Unauthenticated PHP Object Injection in Sant=C3=83=C2=
=A9 <=3D 1.5.1 versions. 2026-06-16 8.1 CVE-2026-39567 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-39567 ] Select-Themes--Zermatt Unauthenticated PH=
P Object Injection in Zermatt <=3D 1.6.1 versions. 2026-06-17 8.1 CVE-2026-= 39545 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39545 ] sentriz--gonic = gonic is a music streaming server / free-software subsonic server API imple= mentation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePl= aylist` allows any authenticated Subsonic user (including non-admin) to wri=
te playlist M3U content to an attacker-controlled absolute filesystem path =
on the gonic host, and to create intermediate directories with `0o777` perm= issions. The bug is independent of CVE-2026-49338 and CVE-2026-49339. It is=
an unreachable guard clause combined with no path containment in `Store.Wr= ite`. Version 0.21.0 patches the issue. 2026-06-19 8.1 CVE-2026-49340 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-49340 ] sentriz--gonic gonic is a = music streaming server / free-software subsonic server API implementation. = Prior to version 0.21.0, the Subsonic API endpoints `/rest/deletePlaylist.v= iew` and `/rest/getPlaylist.view` perform no per-resource authorization. On=
ce authenticated as any user (admin or not), an attacker can delete any pla= ylist owned by any other user (including admin) by passing its `id` and rea=
d the full contents (name, comment, song list) of any other user's **privat= e** (non-public) playlist by passing its `id`. The Subsonic playlist `id` i=
s `base64url("<userID>/<filename>.m3u")`. Because filenames are user-suppli=
ed or time-derived and the `userID` is a small integer, IDs are guessable a=
nd frequently exposed (e.g. a previously-public playlist that was later mad=
e private still has the same ID). This breaks the multi-user trust boundary=
of gonic: a low-privileged user can wipe an administrator's curated playli= sts, and a user can exfiltrate any private playlist they obtain an ID for. = The issue was fixed in commit `6dd71e6a3c966867ef8c900d359a7df75789f410`, w= hich is part of version 0.21.0. 2026-06-19 7.1 CVE-2026-49338 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-49338 ] sentriz--gonic gonic is a music st= reaming server / free-software subsonic server API implementation. The main= tainer's fix in commit `6dd71e6a3c966867ef8c900d359a7df75789f410` added an = ownership check based on `playlist.UserID`. However, `playlist.UserID` is d= erived from the first path segment of the attacker-controlled playlist ID, = with no path containment on the resolved file path. Any authenticated Subso= nic user can therefore bypass the ownership check and read any other user's=
playlist, delete any other user's playlist, and probe arbitrary file paths=
on the host for existence/readability. This is a bypass of the boundary th=
e `6dd71e6` fix is trying to enforce; it is closely related to the original=
GONIC-1 IDOR but uses a different primitive (path traversal in the `id` pa= rameter rather than direct cross-user access). Commit 0824bed88f6bbc490ba28= bf09d28e5dfeb07b445 in version 0.21.0 fixes the issue. 2026-06-19 7.1 CVE-2= 026-49339 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49339 ] SEO Squirrl= y--SEO Plugin by Squirrly SEO Unauthenticated Broken Access Control in SEO = Plugin by Squirrly SEO <=3D 12.4.16 versions. 2026-06-16 7.5 CVE-2026-52714=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-52714 ] ServerCo--getssl In = ServerCo getssl version 2.49 and prior, the ACME challenge token returned t=
o the client was not strictly validated against RFC 8555 before being used =
in challenge-file handling, allowing a maliciously crafted token to influen=
ce local path/filename usage during validation. An attacker who can supply = ACME challenge responses to getssl (for example, a malicious or compromised=
CA endpoint, or an on-path adversary able to tamper with that response pat=
h) could exploit this to achieve unauthorized file write/path traversal eff= ects, usually with elevated privileges, ultimately allowing for remote comm= and injection. This issue appears related in spirit to CVE-2023-38198, and =
is an instance of CWE-73, "External control of file name or path." Other AC=
ME shell script handlers may be affected by similar issues. 2026-06-16 7.4 = CVE-2026-10303 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10303 ] Sevent= hQueen--SweetDate Core Unauthenticated Cross Site Scripting (XSS) in SweetD= ate Core < 1.1.5 versions. 2026-06-17 7.1 CVE-2025-69140 [
https://www.cve.= org/CVERecord?id=3DCVE-2025-69140 ] Shipster--Baggage Freight Shipping Aust= ralia WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an=
unrestricted file upload vulnerability that allows unauthenticated attacke=
rs to upload arbitrary files by exploiting the upload-package.php endpoint.=
Attackers can submit POST requests with malicious file extensions to the u= pload handler, which moves files without validation to the plugin upload di= rectory, enabling remote code execution. 2026-06-15 9.8 CVE-2018-25436 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2018-25436 ] ShopXO--ShopXO A vulnerab= ility was determined in ShopXO up to 6.7.1. This vulnerability affects the = function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the = file app/api/controller/Crontab.php of the component Scheduled Task Endpoin=
t. Executing a manipulation can lead to authorization bypass. The attack ca=
n be executed remotely. The exploit has been publicly disclosed and may be = utilized. The vendor was contacted early about this disclosure but did not = respond in any way. 2026-06-15 7.3 CVE-2026-12204 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-12204 ] ShortPixel--ShortPixel Image Optimizer Author = PHP Object Injection in ShortPixel Image Optimizer <=3D 6.4.3 versions. 202= 6-06-15 7.2 CVE-2026-39471 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39= 471 ] Significant-Gravitas--AutoGPT AutoGPT is a workflow automation platfo=
rm for creating, deploying, and managing continuous artificial intelligence=
agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XS=
S) vulnerability in AutoGPT's signup page. The application improperly trust=
s a URL parameter (`next`), which is passed to `router.push`. An attacker c=
an craft a malicious link that, when opened by an authenticated user, perfo= rms a client-side redirect and executes arbitrary JavaScript in the context=
of their browser. This could lead to credential theft, internal network pi= voting, and unauthorized actions performed on behalf of the victim. Version=
0.6.62 patches the issue. 2026-06-18 8.8 CVE-2026-55237 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-55237 ] Simbunch--SIMGenealogy Joomla! Componen=
t SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows un= authenticated attackers to manipulate database queries by injecting SQL cod=
e through the type parameter. Attackers can send GET requests to index.php = with the option=3Dcom_simgenealogy, view=3Dlatest parameters and inject mal= icious SQL in the type parameter to extract sensitive database information.=
2026-06-19 8.2 CVE-2017-20276 [
https://www.cve.org/CVERecord?id=3DCVE-201= 7-20276 ] SiYuan--SiYuan SiYuan before v3.6.1 fails to sanitize package met= adata and README content in the Bazaar marketplace, allowing malicious pack= age authors to inject arbitrary HTML and JavaScript. Attackers can achieve = remote code execution on any user browsing the Bazaar by embedding XSS payl= oads in package displayName, description, or README fields, exploiting Elec= tron's nodeIntegration setting to execute OS commands. 2026-06-21 9.6 CVE-2= 026-56395 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56395 ] SiYuan--SiY= uan SiYuan before v3.6.1 fails to sanitize package metadata and README cont= ent in the Bazaar marketplace, allowing malicious package authors to inject=
arbitrary HTML and JavaScript. Attackers can achieve remote code execution=
on any user browsing the Bazaar by embedding XSS payloads in package displ= ayName, description, or README fields, exploiting Electron's nodeIntegratio=
n setting to execute OS commands. 2026-06-21 9.6 CVE-2026-56397 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-56397 ] SlicedInvoices--Sliced Invoices = WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vul= nerability that allows authenticated attackers to manipulate database queri=
es by injecting SQL code through the 'post' parameter. Attackers can send r= equests to the admin.php endpoint with action=3Dduplicate_quote_invoice and=
malicious 'post' values to extract sensitive database information or modif=
y data. 2026-06-15 7.1 CVE-2019-25746 [
https://www.cve.org/CVERecord?id=3D= CVE-2019-25746 ] Sneeit--MagOne Unauthenticated Cross Site Scripting (XSS) =
in MagOne <=3D 9.0 versions. 2026-06-16 7.1 CVE-2026-39548 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-39548 ] Soft-Php--jCart for OpenCart Joomla! = Component jCart for OpenCart 2.0 contains an SQL injection vulnerability th=
at allows unauthenticated attackers to manipulate database queries by injec= ting SQL code through the product_id parameter. Attackers can send GET requ= ests to index.php with the option=3Dcom_jcart&route=3Dproduct/product param= eters and malicious product_id values to extract sensitive database informa= tion. 2026-06-19 8.2 CVE-2017-20282 [
https://www.cve.org/CVERecord?id=3DCV= E-2017-20282 ] SONAAR MUSIC--Sonaar Subscriber Privilege Escalation in Sona=
ar <=3D 4.27.4 versions. 2026-06-17 8.8 CVE-2025-59563 [
https://www.cve.or= g/CVERecord?id=3DCVE-2025-59563 ] SONAAR MUSIC--Sonaar Unauthenticated Cros=
s Site Scripting (XSS) in Sonaar <=3D 4.27.4 versions. 2026-06-17 7.1 CVE-2= 025-59560 [
https://www.cve.org/CVERecord?id=3DCVE-2025-59560 ] SourceCodes= ter--CET Automated Grading System with AI Predictive Analytics A security v= ulnerability has been detected in SourceCodester CET Automated Grading Syst=
em with AI Predictive Analytics 1.0. Affected is an unknown function of the=
file /index.php of the component Student Self-Registration Endpoint. The m= anipulation leads to improper access controls. Remote exploitation of the a= ttack is possible. 2026-06-17 7.3 CVE-2026-12529 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-12529 ] SpeakOut!--SpeakOut! Email Petitions Unauthenti= cated SQL Injection in SpeakOut! Email Petitions <=3D 4.6.5 versions. 2026-= 06-15 9.3 CVE-2026-39530 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3953=
0 ] Splunk--Splunk AI Toolkit In Splunk AI Toolkit versions below 5.7.4, a = user who holds the "admin" Splunk role could execute arbitrary OS commands =
on the host running the Splunk Enterprise instance. The vulnerability is po= ssible because of an unsafe shell execution pattern in the btool configurat= ion helper, which constructs OS command strings from dynamic parameters wit= hout disabling shell interpretation. 2026-06-17 9.1 CVE-2026-20266 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-20266 ] Spring--Spring AI In Spring A=
I Vector Stores, special characters could be used to force the execution of=
arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affe= cted components: spring-ai-elasticsearch-store, spring-ai-opensearch-store,=
spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x = (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8). 2026-06-15 8.6 CVE-= 2026-47835 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47835 ] Spring--Sp= ring Cloud Gateway Spring Cloud Gateway Server forwards the X-Forwarded-For=
and Forwarded headers from untrusted proxies in certain configuration scen= arios. This affects both the WebMVC and WebFlux Gateway Servers. Affected v= ersions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.=
x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gatewa=
y 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2). 2026-06-15 8.6=
CVE-2026-47825 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47825 ] Sprin= g--Spring Cloud Sleuth In Spring Cloud Sleuth, it is possible for a user to=
provide specially crafted calls that may cause a denial-of-service (DoS) c= ondition. The application is vulnerable when it uses a vulnerable version o=
f org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring =
TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth = 3.1.0 through 3.1.13. 2026-06-15 7.5 CVE-2026-41708 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-41708 ] startreedata--mcp-pinot mcp-pinot is a Pytho= n-based Model Context Protocol (MCP) server for interacting with Apache Pin= ot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP = server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools,=
including SQL query execution, schema creation, and table-config mutation,=
are reachable by any network-adjacent caller. The server proxies these cal=
ls using server-side Pinot credentials, producing a confused-deputy conditi=
on that yields full read/write access to the configured Pinot cluster. This=
issue has been fixed in version 3.1.0 2026-06-18 10 CVE-2026-49257 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-49257 ] statamic--cms Statamic is a = Laravel and Git powered content management system (CMS). Prior to 5.73.23 a=
nd 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issu=
e in the query builder, but the same protection was not applied to in-memor=
y collection sorting. Manipulating sort parameters could result in the loss=
of content and assets. This requires a front-end template that passes requ= est input into a tag's sort parameter. It is not exploitable by default - a=
template would need to be explicitly set up to sort by a visitor-controlle=
d value. This has been fixed in 5.73.23 and 6.20.0. 2026-06-19 7.4 CVE-2026= -49287 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49287 ] SteeltoeOSS--S= teeltoe.Discovery.Eureka Steeltoe is an open source project that provides a=
collection of libraries that helps users build cloud-native applications. =
In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and 3.4.0, `DataCenter= Info.FromJson` throws `ArgumentException` for any `name` value other than `= "MyOwn"` or `"Amazon"`, despite the Java Eureka specification defining a th= ird valid value: `"Netflix"`. The exception propagates through the entire r= egistry deserialization chain and is swallowed by the periodic cache refres=
h task, leaving the local service registry permanently empty or stale. Vers= ions 4.2.0 and 3.4.0 patch the issue. If an immediate upgrade is not possib= le, remove any registrations using unsupported `DataCenterInfo.name` values=
from the registry. In mixed Java/Spring and Steeltoe environments, audit f=
or the `Netflix` data center type before deploying Steeltoe Eureka clients.=
2026-06-17 7.5 CVE-2026-50196 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-50196 ] SteeltoeOSS--Steeltoe.Management.Endpoint Steeltoe is an open sou= rce project that provides a collection of libraries that helps users build = cloud-native applications. When Steeltoe management endpoints versions 3.2.=
2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`M= anagement:Endpoints:Port` is configured), the middleware responsible for re= stricting access to the endpoints uses the `Host` HTTP header rather than t=
he actual network socket port. Versions 3.4.0 and 4.2.0 patch the issue. If=
an immediate upgrade to a patched version is not possible, add explicit AS= P.NET Core authorization (`RequireAuthorization`) to all sensitive actuator=
endpoints as a defense-in-depth measure independent of port isolation and/=
or configure the reverse proxy or load balancer to enforce the `Host` heade=
r value and prevent clients from setting an arbitrary port. 2026-06-17 8.2 = CVE-2026-50194 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50194 ] Steelt= oeOSS--Steeltoe.Management.Endpoint Steeltoe is an open source project that=
provides a collection of libraries that helps users build cloud-native app= lications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steel= toe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` compone=
nt in the Environment actuator redacts configuration values by matching the=
configuration key name against a suffix list. The default list (`password`=
, `secret`, `key`, `token`, `.*credentials.*`, `vcap_services`) does not co= ver the standard .NET pattern `ConnectionStrings:<name>` or Steeltoe Connec= tors' `Steeltoe:Client:<type>:Default:ConnectionString`. There is no value-= based scrubbing, so full connection string values including embedded `Passw= ord=3D` and `user:pass@host` segments are returned verbatim in `/actuator/e= nv` responses. Steeltoe.Management.Endpoint 4.2.0 and Steeltoe.Management.E= ndpointCore 3.4.0 patch the issue. If an immediate upgrade is not possible:=
On the standard path, remove `env` from the actuator exposure list; add `.= *connectionstring.*` to `KeysToSanitize` as a defense-in-depth measure for = both paths; and/or require authorization on actuator endpoints. 2026-06-17 = 7.5 CVE-2026-50200 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50200 ] St= iofan--Events Calendar for GeoDirectory Contributor PHP Object Injection in=
Events Calendar for GeoDirectory <=3D 2.3.25 versions. 2026-06-15 8.8 CVE-= 2026-39532 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39532 ] Stiofan--G= etPaid Insertion of Sensitive Information Into Sent Data vulnerability in S= tiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects = GetPaid: from n/a through 2.8.49. 2026-06-15 7.5 CVE-2026-49064 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-49064 ] strukturag--libde265 libde265 is=
an open source implementation of the h.265 video codec. Prior to version 1= .0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in = `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:137= 6`). The root cause is a missing aggregate bound check on predicted short-t= erm reference picture set entries. Individual list sizes are validated, but=
the combined count after predicted RPS construction can exceed the 16-entr=
y `PocStFoll` array, writing at index 16. Version 1.0.20 patches the issue.=
2026-06-19 7.1 CVE-2026-49295 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-49295 ] strukturag--libde265 libde265 is an open source implementation of=
the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream w= ith large SPS dimensions and 16-bit bit depth causes a signed integer overf= low in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow w= raps the plane allocation size to a small value (~1 KB), but the subsequent=
`fill_image()` call computes the real size using `size_t`, writing ~4 GB i= nto the undersized heap buffer. Version 1.1.0 patches the issue. 2026-06-19=
7.1 CVE-2026-49346 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49346 ] S= tudio Keren Aga LTD.--Unlimited Elements for Elementor (Premium) Contributo=
r Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <=3D = 2.0.6 versions. 2026-06-17 9.9 CVE-2026-27041 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-27041 ] StylemixThemes--MasterStudy LMS Subscriber SQL Inj= ection in MasterStudy LMS <=3D 3.7.25 versions. 2026-06-15 8.5 CVE-2026-407=
66 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40766 ] StylemixThemes--Mo= tors Improper Neutralization of Special Elements used in an SQL Command ('S=
QL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Inje= ction. This issue affects Motors: from n/a through 1.4.109. 2026-06-17 9.3 = CVE-2026-54812 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54812 ] Stylem= ixThemes--Motors Improper Control of Filename for Include/Require Statement=
in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThem=
es Motors allows PHP Local File Inclusion. This issue affects Motors: from = n/a through 1.4.109. 2026-06-17 8.1 CVE-2026-54814 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-54814 ] sunnyadn--js-toml js-toml is a TOML parser fo=
r JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and = including 1.1.0 parse hexadecimal / octal / binary integer literals via a h= and-written `parseBigInt` loop that multiplies a `BigInt` accumulator by th=
e radix once per input digit. Each iteration performs a `BigInt * BigInt` o= peration on an accumulator that grows linearly with the number of digits al= ready consumed, so the whole loop is O(n=C3=82=C2=B2) in the literal length=
. The lexer regex places no upper bound on the literal length, so a single = TOML document containing one ~500 kB hex literal pins one CPU core for ~40 = seconds on a modern laptop (Apple M-series, Node v22). Memory amplification=
is bounded but CPU amplification is severe and grows quadratically: doubli=
ng the literal length quadruples the work. A caller that invokes `load()` o=
n attacker-controlled TOML (configuration upload endpoints, CI/CD systems i= ngesting third-party `*.toml`, IDE plugins, build tools) is exposed to a si= ngle-request CPU exhaustion DoS. Version 1.1.1 fixes the issue. 2026-06-19 = 7.5 CVE-2026-49293 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49293 ] SU= SE--Harvester An attacker with network-level access between the SUSE Virtua= lization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere=
with the TLS handshake and abuse it to bypass TLS as a security control. 2= 026-06-16 8.6 CVE-2025-71261 [
https://www.cve.org/CVERecord?id=3DCVE-2025-= 71261 ] SUSE--wicked Passing of unsanitized strings from DHCP replies into = the wicked dhcp client before wicked 0.6.79 could be used by attackers oper= ating a malicious DHCP server to execute code on the local machine. 2026-06= -16 8.8 CVE-2026-44932 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44932 =
] Syed Balkhi--PushEngage Web Push Notifications, eCommerce Automation & Ch=
at Widget Subscriber Sensitive Data Exposure in PushEngage - Web Push Notif= ications, eCommerce Automation & Chat Widget <=3D 4.2.3 versions. 2026-= 06-17 7.4 CVE-2026-52698 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5269=
8 ] Sync-in--server Sync-in Server is a secure, open-source platform for fi=
le storage, sharing, collaboration, and syncing. Prior to version 2.3.0, th=
e private IP blocklist regex used in the URL download feature does not matc=
h IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protect= ion to be bypassed on dual-stack systems. Version 2.3.0 fixes the issue. 20= 26-06-16 7.7 CVE-2026-47684 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 7684 ] sysown--proxysql ProxySQL is a proxy for MySQL and its forks, as wel=
l as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL fronte=
nd accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as=
a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 specifi= cation says that when the protocol token is `UNKNOWN`, the receiver MUST ig= nore any address fields that follow it, because the proxy has declared it c= annot determine the client identity. ProxySQL parses those address fields a= nyway via `sscanf` and writes the spoofed source address into the session's=
`addr.addr` field. From there it flows directly into the query-rule matche=
r, where the `client_addr` predicate decides routing and ACL. When `mysql-p= roxy_protocol_networks =3D '*'` (the default), any TCP peer can send a PP1 = frame and choose any source IP claim. With that, any `mysql_query_rules` ro=
w pinned to a `client_addr` value is forgeable: the attacker writes the add= ress they want to match into the PP1 line, and ProxySQL routes their query =
as if it came from that address. In practice this is a routing and ACL bypa= ss. Real deployments use `client_addr` for read-write splitting (internal a= pps go to the primary, public traffic to read replicas), per-app schema pin= ning, and query-filter rules (DDL allowed only from admin CIDR, public quer= ies blocked from dangerous patterns). An attacker that can reach the fronte=
nd port can forge their way into any of those routes. Version 3.0.9 patches=
this issue. 2026-06-19 10 CVE-2026-48772 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-48772 ] sysown--proxysql ProxySQL is a proxy for MySQL and its=
forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-aut= hentication heap memory corruption vulnerability in the MySQL and PostgreSQ=
L protocol first-read paths. A remote unauthenticated client can declare an=
oversized first packet length, and ProxySQL passes that attacker-controlle=
d length directly to `recv()` while writing into a fixed 32 KB input queue.=
Version 3.0.9 patches the issue. 2026-06-19 9.8 CVE-2026-48773 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-48773 ] sysown--proxysql ProxySQL is a p= roxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 thro= ugh 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool violates its docume= nted read-only contract for MySQL targets. The tool validates only the full=
input string with a substring blacklist and first-keyword allowlist, but t= hen executes the entire SQL string on a backend connection created with `CL= IENT_MULTI_STATEMENTS`. As a result, a caller can submit a read-only first = statement followed by a side-effecting second statement, such as `SELECT 1;=
RENAME TABLE ...`. The validator accepts the payload because it starts wit=
h `SELECT` and because side-effecting MySQL statements such as `RENAME TABL= E`, `SET`, `RESET`, `LOCK TABLES`, and `KILL` are not rejected by the black= list. In a live MCP runtime test, the `/mcp/query` endpoint accepted a `run= _sql_readonly` request. The MCP response reported success for the first `SE= LECT`, and direct backend verification showed that the table had actually b= een renamed. This violates the endpoint's read-only security contract and l= ets an MCP caller perform backend writes or administrative SQL, limited by = the configured MCP target account's database privileges. Version 3.0.9 cont= ains a fix. Other operator mitigations include: keeping MCP disabled unless=
required; setting a non-empty `mcp-query_endpoint_auth` token before expos= ing `/mcp/query`; restricting MCP listener network exposure; configuring MC=
P backend target credentials as database-level read-only users; and adding = temporary MCP query rules to block obvious multi-statement patterns. 2026-0= 6-19 7.5 CVE-2026-48774 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48774=
] szTheory--relyra Relyra is a strict-by-default SAML 2.0 Service Provider=
library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAM=
L signatures because SignatureValue was not cryptographically verified befo=
re the library returned a successful authentication result. The XMLDSig tru=
st boundary was incomplete as :public_key.verify over the exclusive-C14N ca= nonicalized SignedInfo was not performed against the configured IdP certifi= cate's public key, DigestValue was not recomputed over the canonicalized re= ferenced element, and canonicalize/2 remained an unused passthrough in the = signature-verification path. The result was a structure-only acceptance pat=
h where document shape and trust-source rejection could succeed without pro= ving the signature bytes. A forged SignatureValue carrying an attacker-cont= rolled NameID could be accepted as {:ok}. This issue has been fixed in vers= ion 1.2.0. 2026-06-18 9.1 CVE-2026-49454 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49454 ] Takashi Kitajima--MW WP Form Unauthenticated Cross Site=
Scripting (XSS) in MW WP Form <=3D 5.1.3 versions. 2026-06-15 7.1 CVE-2026= -48871 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48871 ] Tammersoft--Sh= ared Files Unauthenticated Path Traversal in Shared Files <=3D 1.7.64 versi= ons. 2026-06-15 7.5 CVE-2026-49112 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-49112 ] Taskbuilder--Taskbuilder Subscriber SQL Injection in Taskbuil= der <=3D 5.0.7 versions. 2026-06-15 8.5 CVE-2026-52697 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-52697 ] Techspawn--MultiLoca Subscriber Privilege=
Escalation in MultiLoca <=3D 4.2.15 versions. 2026-06-17 7.6 CVE-2026-3954=
6 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39546 ] Terrywcarter--KissG= allery Joomla! Component KissGallery 1.0.0 contains an SQL injection vulner= ability that allows unauthenticated attackers to inject SQL commands throug=
h the component URL path. Attackers can supply malicious SQL code in the ki= ssgallery endpoint to execute arbitrary database queries and extract sensit= ive information. 2026-06-19 8.2 CVE-2017-20269 [
https://www.cve.org/CVERec= ord?id=3DCVE-2017-20269 ] The Browser Company of New York`--Arc Search Addr= ess bar spoofing in Arc Search for Android allows a remote attacker to disp= lay a trusted domain in the address bar while rendering attacker-controlled=
content, enabling phishing. 2026-06-16 7.4 CVE-2026-12348 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-12348 ] themagnifico52--Charity Zone Subscrib=
er Arbitrary File Upload in Charity Zone <=3D 1.1.1 versions. 2026-06-17 9.=
9 CVE-2026-40749 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40749 ] them= agnifico52--Ecommerce Zone Subscriber Arbitrary File Upload in Ecommerce Zo=
ne <=3D 0.9.7 versions. 2026-06-17 9.9 CVE-2026-40747 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-40747 ] themagnifico52--Kids Gift Shop Subscriber = Arbitrary File Upload in Kids Gift Shop <=3D 0.5.4 versions. 2026-06-17 9.9=
CVE-2026-40748 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40748 ] thema= gnifico52--Kids Online Store Unrestricted Upload of File with Dangerous Typ=
e vulnerability in themagnifico52 Kids Online Store allows Upload a Web She=
ll to a Web Server. This issue affects Kids Online Store: from n/a through = 0.8.9. 2026-06-16 9.9 CVE-2026-40750 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-40750 ] themagnifico52--Restaurant Zone Subscriber Arbitrary File U= pload in Restaurant Zone <=3D 0.7.8 versions. 2026-06-17 9.9 CVE-2026-40746=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-40746 ] Theme passion--Suppo=
rt Ticket Management System Unauthenticated Privilege Escalation in Support=
Ticket Management System <=3D 1.9 versions. 2026-06-17 9.8 CVE-2025-69179 =
[
https://www.cve.org/CVERecord?id=3DCVE-2025-69179 ] THEMECO--Cornerstone = Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. 2026-0= 6-16 8.5 CVE-2026-49113 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49113=
] THEMECO--Cornerstone Subscriber SQL Injection in Cornerstone < 7.8.8 ver= sions. 2026-06-17 8.5 CVE-2026-54185 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-54185 ] ThemeFusion--Avada Contributor PHP Object Injection in Avad=
a <=3D 3.15.3 versions. 2026-06-16 8.8 CVE-2026-12256 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-12256 ] themefusion--Avada (Fusion) Builder The Av= ada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file d= eletion due to insufficient file path validation in the maybe_delete_files = function in all versions up to, and including, 3.15.3. This makes it possib=
le for unauthenticated attackers to delete arbitrary files on the server, w= hich can easily lead to remote code execution when the right file is delete=
d (such as wp-config.php). The attack requires a published Avada form confi= gured to save entries to the database; an unauthenticated attacker submits =
a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax han= dler while also controlling the fusion_privacy_expiration_interval and priv= acy_expiration_action fields to force an immediate 'delete' cleanup, causin=
g the planted entry to be automatically processed by the Fusion_Form_DB_Pri= vacy shutdown-hook routine without any administrator interaction. 2026-06-1=
9 9.1 CVE-2026-8713 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8713 ] Th= emeFusion--Fusion Builder Contributor PHP Object Injection in Fusion Builde=
r <=3D 3.15.4 versions. 2026-06-16 9.8 CVE-2026-54194 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-54194 ] ThemeFusion--Fusion Builder Contributor Ar= bitrary File Deletion in Fusion Builder <=3D 3.15.4 versions. 2026-06-17 7.=
7 CVE-2026-54193 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54193 ] Them= eGoods--Avante Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5=
versions. 2026-06-17 7.1 CVE-2025-68524 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-68524 ] ThemeGoods--Grand Car Rental Unauthenticated Cross Site=
Scripting (XSS) in Grand Car Rental <=3D 3.7 versions. 2026-06-16 7.1 CVE-= 2025-69151 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69151 ] ThemeGrill= --Masteriyo - LMS Incorrect Privilege Assignment vulnerability in ThemeGril=
l Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo=
- LMS: from n/a through 2.2.0. 2026-06-15 8.8 CVE-2026-49111 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-49111 ] ThemeGrill--Masteriyo - LMS Unauth= enticated Broken Access Control in Masteriyo - LMS <=3D 2.1.5 versions. 202= 6-06-15 7.5 CVE-2026-39524 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39= 524 ] ThemeGrill--Registration Form for WooCommerce Unauthenticated Privile=
ge Escalation in Registration Form for WooCommerce <=3D 1.0.9 versions. 202= 6-06-17 9.8 CVE-2026-54807 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54= 807 ] ThemeGrill--User Registration Unauthenticated Broken Access Control i=
n User Registration <=3D 5.1.2 versions. 2026-06-15 7.5 CVE-2026-25425 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-25425 ] ThemeGrill--User Registra= tion Stripe Unauthenticated Broken Access Control in User Registration Stri=
pe <=3D 1.3.14 versions. 2026-06-17 8.2 CVE-2026-40726 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-40726 ] ThemeGrill--User Registration Stripe Unau= thenticated Broken Access Control in User Registration Stripe <=3D 1.3.12 v= ersions. 2026-06-17 8.2 CVE-2026-49081 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49081 ] Themeisle--Redirection for Contact Form 7 Unauthenticat=
ed Cross Site Scripting (XSS) in Redirection for Contact Form 7 <=3D 3.2.8 = versions. 2026-06-15 7.1 CVE-2026-23970 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-23970 ] Themeisle--Social Slider Feed Unauthenticated Cross Sit=
e Scripting (XSS) in Social Slider Feed <=3D 2.3.2 versions. 2026-06-15 7.1=
CVE-2026-39507 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39507 ] THEME= LOGI--Roneous Unauthenticated Local File Inclusion in Roneous <=3D 2.1.5 ve= rsions. 2026-06-16 8.1 CVE-2025-69177 [
https://www.cve.org/CVERecord?id=3D= CVE-2025-69177 ] THEMELOGI--Wanium Unauthenticated Local File Inclusion in = Wanium <=3D 1.9.8 versions. 2026-06-16 8.1 CVE-2025-69136 [
https://www.cve= .org/CVERecord?id=3DCVE-2025-69136 ] ThemeMove--Atomlab Unauthenticated Loc=
al File Inclusion in Atomlab <=3D 2.4.5 versions. 2026-06-17 8.1 CVE-2026-3= 9590 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39590 ] ThemeREX Group--= Elementra Unauthenticated PHP Object Injection in Elementra <=3D 1.0.9 vers= ions. 2026-06-16 9.8 CVE-2026-39529 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-39529 ] ThemeREX Group--Geya Unauthenticated Local File Inclusion in=
Geya <=3D 1.15 versions. 2026-06-16 8.1 CVE-2025-58924 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2025-58924 ] ThemeREX Group--Learnify Unauthenticated=
Local File Inclusion in Learnify <=3D 1.15.0 versions. 2026-06-16 8.1 CVE-= 2025-60085 [
https://www.cve.org/CVERecord?id=3DCVE-2025-60085 ] ThemeREX--= Abelle Unauthenticated Local File Inclusion in Abelle <=3D 1.22 versions. 2= 026-06-16 8.1 CVE-2025-69142 [
https://www.cve.org/CVERecord?id=3DCVE-2025-= 69142 ] ThemeREX--AirSupply Unauthenticated Local File Inclusion in AirSupp=
ly <=3D 2.0.0 versions. 2026-06-17 8.1 CVE-2025-69110 [
https://www.cve.org= /CVERecord?id=3DCVE-2025-69110 ] ThemeREX--AutoParts Unauthenticated Local = File Inclusion in AutoParts <=3D 1.5.8 versions. 2026-06-17 8.1 CVE-2026-22= 331 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22331 ] ThemeREX--Choreo = Unauthenticated Local File Inclusion in Choreo <=3D 1.6 versions. 2026-06-1=
6 8.1 CVE-2025-69165 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69165 ] = ThemeREX--CopyPress Unauthenticated Local File Inclusion in CopyPress <=3D = 1.4.5 versions. 2026-06-16 8.1 CVE-2025-69118 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2025-69118 ] ThemeREX--Corbesier Unauthenticated Local File Inc= lusion in Corbesier <=3D 1.15.0 versions. 2026-06-16 8.1 CVE-2025-69119 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2025-69119 ] ThemeREX--Dazzle Unauthe= nticated Local File Inclusion in Dazzle <=3D 1.0.0 versions. 2026-06-17 8.1=
CVE-2025-69120 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69120 ] Theme= REX--Deliciosa Unauthenticated Local File Inclusion in Deliciosa <=3D 1.10.=
0 versions. 2026-06-16 8.1 CVE-2025-69121 [
https://www.cve.org/CVERecord?i= d=3DCVE-2025-69121 ] ThemeREX--Dom Unauthenticated Local File Inclusion in = Dom <=3D 1.24 versions. 2026-06-16 8.1 CVE-2025-69146 [
https://www.cve.org= /CVERecord?id=3DCVE-2025-69146 ] ThemeREX--EcoBlue Unauthenticated Local Fi=
le Inclusion in EcoBlue <=3D 1.15 versions. 2026-06-17 8.1 CVE-2026-22338 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-22338 ] ThemeREX--Eros Unauthe= nticated Local File Inclusion in Eros <=3D 1.3 versions. 2026-06-16 8.1 CVE= -2025-69167 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69167 ] ThemeREX-= -Especio Unauthenticated Local File Inclusion in Especio <=3D 1.0 versions.=
2026-06-16 8.1 CVE-2025-69124 [
https://www.cve.org/CVERecord?id=3DCVE-202= 5-69124 ] ThemeREX--Etude Unauthenticated Local File Inclusion in Etude <=
=3D 1.6 versions. 2026-06-17 8.1 CVE-2025-69174 [
https://www.cve.org/CVERe= cord?id=3DCVE-2025-69174 ] ThemeREX--Eventicity Unauthenticated Local File = Inclusion in Eventicity <=3D 1.5 versions. 2026-06-17 8.1 CVE-2025-69170 [ =
https://www.cve.org/CVERecord?id=3DCVE-2025-69170 ] ThemeREX--Food Drop Una= uthenticated Local File Inclusion in Food Drop <=3D 1.3 versions. 2026-06-1=
6 8.1 CVE-2025-69125 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69125 ] = ThemeREX--Fortius Unauthenticated Local File Inclusion in Fortius <=3D 2.3.=
0 versions. 2026-06-17 8.1 CVE-2025-69126 [
https://www.cve.org/CVERecord?i= d=3DCVE-2025-69126 ] ThemeREX--Gamic Unauthenticated Local File Inclusion i=
n Gamic <=3D 1.15 versions. 2026-06-17 8.1 CVE-2025-69157 [
https://www.cve= .org/CVERecord?id=3DCVE-2025-69157 ] ThemeREX--Gat Unauthenticated Local Fi=
le Inclusion in Gat <=3D 1.16 versions. 2026-06-17 8.1 CVE-2025-69145 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2025-69145 ] ThemeREX--Gita Unauthentic= ated Local File Inclusion in Gita <=3D 1.11 versions. 2026-06-16 8.1 CVE-20= 25-69160 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69160 ] ThemeREX--Gr= anola Unauthenticated Local File Inclusion in Granola <=3D 1.13 versions. 2= 026-06-17 8.1 CVE-2025-69158 [
https://www.cve.org/CVERecord?id=3DCVE-2025-= 69158 ] ThemeREX--Grecko Unauthenticated Local File Inclusion in Grecko <=
=3D 5.17 versions. 2026-06-16 8.1 CVE-2025-69162 [
https://www.cve.org/CVER= ecord?id=3DCVE-2025-69162 ] ThemeREX--Gunslinger Unauthenticated Local File=
Inclusion in Gunslinger <=3D 1.7 versions. 2026-06-17 8.1 CVE-2025-69166 [=
https://www.cve.org/CVERecord?id=3DCVE-2025-69166 ] ThemeREX--HomeRoofer U= nauthenticated Local File Inclusion in HomeRoofer <=3D 2.11.0 versions. 202= 6-06-17 8.1 CVE-2025-58954 [
https://www.cve.org/CVERecord?id=3DCVE-2025-58= 954 ] ThemeREX--Hot Coffee Unauthenticated PHP Object Injection in Hot Coff=
ee <=3D 1.7 versions. 2026-06-16 9.8 CVE-2025-69108 [
https://www.cve.org/C= VERecord?id=3DCVE-2025-69108 ] ThemeREX--Imba Unauthenticated Local File In= clusion in Imba <=3D 1.5.0 versions. 2026-06-17 8.1 CVE-2025-69106 [ https:= //www.cve.org/CVERecord?id=3DCVE-2025-69106 ] ThemeREX--Ingenioso Unauthent= icated Local File Inclusion in Ingenioso <=3D 1.14.0 versions. 2026-06-17 8=
.1 CVE-2025-69117 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69117 ] The= meREX--Iona Unauthenticated Local File Inclusion in Iona <=3D 1.0.8 version=
s. 2026-06-16 8.1 CVE-2025-69116 [
https://www.cve.org/CVERecord?id=3DCVE-2= 025-69116 ] ThemeREX--ITactics Unauthenticated Local File Inclusion in ITac= tics <=3D 1.0 versions. 2026-06-16 8.1 CVE-2025-69176 [
https://www.cve.org= /CVERecord?id=3DCVE-2025-69176 ] ThemeREX--Joly Unauthenticated Local File = Inclusion in Joly <=3D 1.22.0 versions. 2026-06-17 8.1 CVE-2025-58953 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2025-58953 ] ThemeREX--Kelly Young Unau= thenticated Local File Inclusion in Kelly Young <=3D 1.1.0 versions. 2026-0= 6-16 8.1 CVE-2025-69141 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69141=
] ThemeREX--Line Agency Unauthenticated Local File Inclusion in Line Agenc=
y <=3D 1.3.1 versions. 2026-06-17 8.1 CVE-2025-69175 [
https://www.cve.org/= CVERecord?id=3DCVE-2025-69175 ] ThemeREX--LuxMed | Medicine & Healthcare Do= ctor WordPress Theme Unauthenticated Local File Inclusion in LuxMed | Medic= ine & Healthcare Doctor WordPress Theme <=3D 1.2.2 versions. 2026-06-17 8.1=
CVE-2025-69115 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69115 ] Theme= REX--MaxiNet Unauthenticated Local File Inclusion in MaxiNet <=3D 1.2.10 ve= rsions. 2026-06-16 8.1 CVE-2025-69114 [
https://www.cve.org/CVERecord?id=3D= CVE-2025-69114 ] ThemeREX--Medeus Unauthenticated Local File Inclusion in M= edeus <=3D 1.14 versions. 2026-06-16 8.1 CVE-2025-69150 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2025-69150 ] ThemeREX--Mission Unauthenticated Local = File Inclusion in Mission <=3D 1.22 versions. 2026-06-16 8.1 CVE-2025-69143=
[
https://www.cve.org/CVERecord?id=3DCVE-2025-69143 ] ThemeREX--Modernee U= nauthenticated Local File Inclusion in Modernee <=3D 1.6.0 versions. 2026-0= 6-16 8.1 CVE-2025-69105 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69105=
] ThemeREX--Neuronet Unauthenticated Local File Inclusion in Neuronet < 1.= 14.0 versions. 2026-06-17 8.1 CVE-2025-58952 [
https://www.cve.org/CVERecor= d?id=3DCVE-2025-58952 ] ThemeREX--Nexio Unauthenticated Local File Inclusio=
n in Nexio <=3D 1.10.0 versions. 2026-06-16 8.1 CVE-2025-69113 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2025-69113 ] ThemeREX--Orpheus Unauthenticated=
Local File Inclusion in Orpheus <=3D 1.3 versions. 2026-06-17 8.1 CVE-2025= -69171 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69171 ] ThemeREX--Plan=
ty Unauthenticated Local File Inclusion in Planty <=3D 1.14.0 versions. 202= 6-06-16 8.1 CVE-2025-69112 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69= 112 ] ThemeREX--Plumbing Unauthenticated PHP Object Injection in Plumbing <= =3D 1.6 versions. 2026-06-17 9.8 CVE-2025-69127 [
https://www.cve.org/CVERe= cord?id=3DCVE-2025-69127 ] ThemeREX--Preservation Unauthenticated Local Fil=
e Inclusion in Preservation <=3D 1.10 versions. 2026-06-17 8.1 CVE-2025-691=
44 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69144 ] ThemeREX--Printo U= nauthenticated Local File Inclusion in Printo <=3D 1.11 versions. 2026-06-1=
6 8.1 CVE-2025-69159 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69159 ] = ThemeREX--Putter Unauthenticated Local File Inclusion in Putter <=3D 1.17 v= ersions. 2026-06-16 8.1 CVE-2025-69147 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-69147 ] ThemeREX--Quirky Unauthenticated Local File Inclusion i=
n Quirky <=3D 1.23 versions. 2026-06-17 8.1 CVE-2025-69148 [
https://www.cv= e.org/CVERecord?id=3DCVE-2025-69148 ] ThemeREX--Raider Spirit Unauthenticat=
ed Local File Inclusion in Raider Spirit <=3D 1.1.2 versions. 2026-06-16 8.=
1 CVE-2025-69109 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69109 ] Them= eREX--Reisen Unauthenticated PHP Object Injection in Reisen <=3D 1.4.1 vers= ions. 2026-06-17 9.8 CVE-2025-69111 [
https://www.cve.org/CVERecord?id=3DCV= E-2025-69111 ] ThemeREX--Resurs Unauthenticated Local File Inclusion in Res= urs <=3D 1.3 versions. 2026-06-17 8.1 CVE-2025-69172 [
https://www.cve.org/= CVERecord?id=3DCVE-2025-69172 ] ThemeREX--Rosaleen Unauthenticated Local Fi=
le Inclusion in Rosaleen <=3D 2.8 versions. 2026-06-16 8.1 CVE-2025-69107 [=
https://www.cve.org/CVERecord?id=3DCVE-2025-69107 ] ThemeREX--SeaFood Comp= any Unauthenticated PHP Object Injection in SeaFood Company <=3D 1.4 versio= ns. 2026-06-16 9.8 CVE-2025-69122 [
https://www.cve.org/CVERecord?id=3DCVE-= 2025-69122 ] ThemeREX--Skyward Unauthenticated Local File Inclusion in Skyw= ard <=3D 1.10 versions. 2026-06-17 8.1 CVE-2025-69164 [
https://www.cve.org= /CVERecord?id=3DCVE-2025-69164 ] ThemeREX--Snow Club Unauthenticated Local = File Inclusion in Snow Club <=3D 1.1 versions. 2026-06-17 8.1 CVE-2025-6912=
3 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69123 ] ThemeREX--Snowy Una= uthenticated Local File Inclusion in Snowy <=3D 1.13 versions. 2026-06-17 8=
.1 CVE-2025-69161 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69161 ] The= meREX--Spike Unauthenticated Local File Inclusion in Spike <=3D 1.2 version=
s. 2026-06-16 8.1 CVE-2025-69168 [
https://www.cve.org/CVERecord?id=3DCVE-2= 025-69168 ] ThemeREX--ThemeREX Addons Unauthenticated PHP Object Injection =
in ThemeREX Addons <=3D 2.36.1.1 versions. 2026-06-17 9.8 CVE-2025-60205 [ =
https://www.cve.org/CVERecord?id=3DCVE-2025-60205 ] ThemeREX--Tipsy Unauthe= nticated Local File Inclusion in Tipsy <=3D 1.1 versions. 2026-06-17 8.1 CV= E-2025-69173 [
https://www.cve.org/CVERecord?id=3DCVE-2025-69173 ] ThemeREX= --Top Dog Unauthenticated Local File Inclusion in Top Dog <=3D 1.0.5 versio= ns. 2026-06-16 8.1 CVE-2025-69149 [
https://www.cve.org/CVERecord?id=3DCVE-= 2025-69149 ] ThemeREX--WineShop Unauthenticated Local File Inclusion in Win= eShop <=3D 3.17 versions. 2026-06-16 8.1 CVE-2025-69163 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2025-69163 ] themetechmount--TrueBooker Unauthenticat=
ed Broken Access Control in TrueBooker <=3D 1.1.9 versions. 2026-06-15 9.1 = CVE-2026-48881 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48881 ] Themet= on--Lagom Deserialization of Untrusted Data vulnerability in Themeton Lagom=
allows Object Injection. This issue affects Lagom: from n/a through 2.0. 2= 026-06-17 9.8 CVE-2025-60229 [
https://www.cve.org/CVERecord?id=3DCVE-2025-= 60229 ] Themeton--The Barber Shop Deserialization of Untrusted Data vulnera= bility in Themeton The Barber Shop allows Object Injection. This issue affe= cts The Barber Shop: from n/a through 1.9. 2026-06-17 9.8 CVE-2025-60230 [ =
https://www.cve.org/CVERecord?id=3DCVE-2025-60230 ] Themeum--Right Way Unau= thenticated Local File Inclusion in Right Way <=3D 4.0 versions. 2026-06-17=
8.1 CVE-2026-22330 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22330 ] T= hemeum--Skillate Unauthenticated Cross Site Scripting (XSS) in Skillate <=
=3D 1.2.10 versions. 2026-06-17 7.1 CVE-2026-22329 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-22329 ] Themeum--Tutor LMS Pro Unauthenticated SQL In= jection in Tutor LMS Pro <=3D 3.9.6 versions. 2026-06-17 9.3 CVE-2026-22332=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-22332 ] Themify--Themify Fol=
o Improper Neutralization of Input During Web Page Generation ('Cross-site = Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue = affects Themify Folo: from n/a through 1.9.6. 2026-06-17 7.1 CVE-2025-31013=
[
https://www.cve.org/CVERecord?id=3DCVE-2025-31013 ] Themovation--Entrepr= eneur - Booking for Small Businesses WordPress Theme Subscriber PHP Object = Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <=
=3D 3.1.3 versions. 2026-06-17 8.8 CVE-2025-69130 [
https://www.cve.org/CVE= Record?id=3DCVE-2025-69130 ] Thrive Themes--Thrive Apprentice Unauthenticat=
ed PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. 2026-06-=
17 9.8 CVE-2026-49107 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49107 ]=
tinyhumansai--OpenHuman The shell tool command allowlist in the SecurityPo= licy of OpenHuman desktop agent through 0.54.0 (default Supervised security=
policy) can be bypassed to execute arbitrary OS commands with the privileg=
es of the desktop user. Two flaws in src/openhuman/security/policy.rs combi= ne: (1) is_args_safe() blocks the find flags -exec and -ok but not the func= tionally identical -execdir and -okdir, which also execute an arbitrary com= mand for each matched file; and (2) skip_env_assignments() strips leading i= nline KEY=3Dvalue environment-variable assignments before allowlist validat= ion, so a command such as GIT_EXTERNAL_DIFF=3D<cmd> git diff is validated a=
s the allowed git diff but, when executed via the shell, runs <cmd> through=
git's environment-driven hooks (for example GIT_EXTERNAL_DIFF or GIT_SSH_C= OMMAND). Because the sandbox is the primary trust boundary between untruste=
d LLM-processed content and the host operating system, an attacker can achi= eve remote code execution via indirect prompt injection: a malicious docume= nt, email, calendar event, or web page ingested by the agent instructs it t=
o run a benign-looking allowlisted command, resulting in arbitrary command = execution, data exfiltration, arbitrary file read/write, and lateral moveme=
nt on the user's machine. The issue was fixed in commit 60050aa09a870f53ed7= e4cd40ed41fd2860329e7 (first released in 0.54.22-staging; first stable rele= ase 0.56.0), which blocks -execdir/-okdir for find. 2026-06-17 9.6 CVE-2026= -55743 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55743 ] tinyproxy--tin= yproxy Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcil=
e conflicting Content-Length and Transfer-Encoding: chunked headers, forwar= ding both verbatim to the backend while using Content-Length to determine h=
ow many request body bytes to consume. Remote attackers can desynchronize t=
he proxy and backend parser state, allowing injection of arbitrary HTTP req= uests to the backend to enable cache poisoning, access control bypass, and = request hijacking. 2026-06-17 9.1 CVE-2026-54387 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-54387 ] tinyproxy--tinyproxy Tinyproxy through 1.11.3, = fixed in commit 364cdb6, fails to reject requests containing multiple Conte= nt-Length headers with differing values, forwarding all duplicate headers t=
o the backend while using the first value to determine how many request bod=
y bytes to consume. Remote attackers can desynchronize the proxy and backen=
d parser state, allowing injection of arbitrary HTTP requests to the backen=
d to enable cache poisoning, access control bypass, and request hijacking. = 2026-06-17 9.1 CVE-2026-54388 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -54388 ] tinyproxy--tinyproxy Tinyproxy through 1.11.3, fixed in commit 093= 12a1, fails to properly validate the Host header during stathost detection,=
allowing unauthenticated attackers to access the stats page by injecting a=
matching Host header or bypass detection via port manipulation. Remote att= ackers can trigger unauthorized access to internal proxy statistics or misr= oute requests as transparent proxy connections to circumvent access control=
s. 2026-06-17 8.2 CVE-2026-55202 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-55202 ] Tips and Tricks HQ--WP eMember Unauthenticated SQL Injection in=
WP eMember < v10.9.4 versions. 2026-06-17 9.3 CVE-2026-54811 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-54811 ] TMS--Amelia Subscriber Privilege E= scalation in Amelia <=3D 2.3 versions. 2026-06-15 8.8 CVE-2026-48889 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-48889 ] TMS--Amelia Unauthenticated=
Sensitive Data Exposure in Amelia <=3D 2.2 versions. 2026-06-15 7.5 CVE-20= 26-40789 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40789 ] TMS--wpDataT= ables Unauthenticated SQL Injection in wpDataTables <=3D 7.3.6 versions. 20= 26-06-16 9.3 CVE-2026-49080 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 9080 ] tnomi--Attendance Manager Subscriber SQL Injection in Attendance Man= ager <=3D 0.6.2 versions. 2026-06-16 7.6 CVE-2026-52712 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-52712 ] Tomdever--wpForo Forum Unauthenticated S=
QL Injection in wpForo Forum <=3D 3.0.4 versions. 2026-06-15 9.3 CVE-2026-4= 0798 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40798 ] Tomdever--wpForo=
Forum Unauthenticated Broken Authentication in wpForo Forum <=3D 3.1.0 ver= sions. 2026-06-17 9.8 CVE-2026-49767 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-49767 ] Tomdever--wpForo Forum Unauthenticated PHP Object Injection=
in wpForo Forum <=3D 3.1.0 versions. 2026-06-15 9.8 CVE-2026-49769 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-49769 ] Tomdever--wpForo Forum Unaut= henticated Broken Access Control in wpForo Forum < 3.0.2 versions. 2026-06-=
15 7.5 CVE-2026-40767 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40767 ]=
traccar--traccar-client Traccar Client is a GPS tracking mobile app for se= nding location updates to private servers using the open-source Traccar pla= tform. In versions 9.7.19 and below, a single crafted deep link can silentl=
y hijack all GPS tracking parameters and redirect telemetry to an attacker-= controlled server. The app registers a custom org.traccar.client://config d= eep-link scheme that silently writes attacker-supplied parameters (server U= RL, device ID, accuracy, distance, and interval) into the app's persistent = configuration with no confirmation, notification, or visual indication. A s= ingle crafted link delivered via SMS, email, a webpage, or any installed ap=
p can therefore reconfigure the app the moment the victim taps it, with no = special permissions required. As a result, an attacker can covertly redirec=
t all of the victim's GPS telemetry to their own server at maximum precisio=
n and frequency, and the change persists across restarts. This gives the at= tacker continuous, real-time tracking of the victim's location. This issue = has been fixed in version 9.7.20. 2026-06-16 9.3 CVE-2026-48745 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-48745 ] truelockmc--streambert Streamber=
t is a cross-platform Electron Desktop App to stream and download any video=
media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability=
was identified in Streambert's subtitle extraction logic. The application = does not sanitize archive entry filenames during extraction, allowing a mal= icious archive to perform path traversal and write arbitrary files to the h= ost filesystem. The subtitle extraction process downloads a ZIP archive and=
extracts its entries. The destination file path is constructed by concaten= ating the raw archive entry name (extracted.name) directly to the temporary=
directory path. If a malicious ZIP archive containing directory traversal = sequences is processed, it escapes the temporary directory boundaries. The = application then writes the extracted payload anywhere on the host filesyst=
em subject to the application's current write permissions. This issue has b= een fixed in version 2.5.0. 2026-06-16 10 CVE-2026-48055 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-48055 ] TURCK--TBEN-LL-SE-M2 Due to the imprope=
r neutralization of special elements used in a name parameter a low privile= ged remote attacker can exploit a command injection vulnerability in the Ma= naged Ethernet Switch, resulting in full system compromise. 2026-06-16 8.8 = CVE-2026-5416 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5416 ] tychesof= twares--Order Delivery Date for WooCommerce Unauthenticated SQL Injection i=
n Order Delivery Date for WooCommerce <=3D 4.5.1 versions. 2026-06-15 9.3 C= VE-2026-42386 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42386 ] Ultimat= ebeaver--Ultimate Addons for Beaver Builder WordPress Ultimate Addons for B= eaver Builder 1.2.4.1 contains an authentication bypass vulnerability that = allows attackers to gain unauthorized access by exploiting the social media=
login form functionality. Attackers can submit a POST request to the admin= -ajax.php endpoint with the uabb-lf-google-submit action, a valid administr= ator email address, and a valid nonce to obtain session cookies and authent= icate as that user. 2026-06-20 9.8 CVE-2019-25763 [
https://www.cve.org/CVE= Record?id=3DCVE-2019-25763 ] undici--undici Impact: The undici WebSocket cl= ient enforces maxPayloadSize on the cumulative byte count of fragments in a=
message but does not enforce a limit on the number of fragments. A malicio=
us WebSocket server can stream many small or empty continuation frames that=
each pass per-frame and cumulative-size validation, collectively causing u= nbounded memory growth in the client process. The result is memory exhausti=
on and a denial of service. Affected applications are those using the undic=
i WebSocket client (new WebSocket(...)) or the WebSocketStream API that can=
be induced to connect to an attacker-controlled or compromised WebSocket e= ndpoint. All releases starting at undici 6.17.0 are affected. Patches:=C2= =A0Upgrade to undici >=3D 6.26.0, >=3D 7.28.0, or >=3D 8.5.0.=C2=A0Workarou= nds: No workaround is available. The fix must be applied through an upgrade=
. 2026-06-17 7.5 CVE-2026-12151 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-12151 ] undici--undici Impact: When using Socks5ProxyAgent, undici reuse=
s a single connection pool across different origins without verifying that = the pool's origin matches the requested origin. All requests are dispatched=
through the pool connected to the first origin, regardless of the intended=
destination. This causes cross-origin request routing: credentials and req= uest data intended for origin B are sent to origin A, responses from the wr= ong origin are trusted, and HTTPS requests may be silently downgraded to HT= TP. Impacted users are applications that use Socks5ProxyAgent (directly or = via setGlobalDispatcher) and make requests to more than one origin. This wa=
s introduced in undici 7.23.0 via PR #4385 and affects all versions through=
8.1.0. Patches: Upgrade to undici v7.26.0 or v8.2.0. Workarounds: Use a se= parate Socks5ProxyAgent instance per origin, or avoid using Socks5ProxyAgen=
t with multiple origins. 2026-06-17 7.5 CVE-2026-6734 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-6734 ] undici--undici Impact: The undici WebSocket=
client enforces maxPayloadSize per-frame but does not enforce the cumulati=
ve size of fragmented uncompressed messages. A malicious WebSocket server c=
an stream many small fragments that each pass per-frame validation but coll= ectively exceed the configured limit, causing unbounded memory growth in th=
e client process. The result is memory exhaustion and a denial of service. = Affected applications are those using the undici WebSocket client (new WebS= ocket(...)) that can be induced to connect to an attacker-controlled or com= promised WebSocket endpoint. This is a regression specific to undici 8.1.0.=
The 6.25.0 line shipped the equivalent cumulative check from the start and=
is unaffected. The 7.x line never had the maxPayloadSize feature and is al=
so unaffected. Patches: Upgrade to undici >=3D 8.5.0. Workarounds: No worka= round is available. The fix must be applied through an upgrade. 2026-06-17 = 7.5 CVE-2026-9675 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9675 ] undi= ci--undici Impact: undici's ProxyAgent silently drops the requestTls option=
when configured with a SOCKS5 proxy URI (socks5:// or socks://). The targe=
t HTTPS connection through the SOCKS5 tunnel falls back to Node's default t= rust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and=
servername settings. Applications that pin to an internal or corporate CA = via requestTls.ca will, when their proxy URI is SOCKS5, get the default Moz= illa CA bundle as the trust anchor instead. Any cert signed by any publicly= -trusted CA for the target hostname is accepted, breaking the intended pin = and enabling MITM read and tamper of the HTTPS exchange. Affected applicati= ons are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) w= ith SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was in= troduced in undici 7.23.0 when SOCKS5 support was added. Patches: Upgrade t=
o undici v7.28.0 or v8.5.0. Workarounds: No workaround is available within = the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required a=
nd an upgrade is not yet possible, route the traffic through an HTTP-proxy = ProxyAgent instead, where requestTls is honored correctly. 2026-06-17 7.4 C= VE-2026-9697 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9697 ] Utillz--B= rikk Subscriber Arbitrary Content Deletion in Brikk <=3D 3.0.0 versions. 20= 26-06-16 7.5 CVE-2025-69103 [
https://www.cve.org/CVERecord?id=3DCVE-2025-6= 9103 ] VamTam--Auto Repair Unauthenticated Cross Site Scripting (XSS) in Au=
to Repair <=3D 22.6 versions. 2026-06-17 7.1 CVE-2026-22328 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-22328 ] vanyukov--Offload, AI & Optimize wit=
h Cloudflare Images The Offload, AI & Optimize with Cloudflare Images plugi=
n for WordPress is vulnerable to Remote Code Execution in all versions up t=
o, and including, 1.10.2 via the 'account-id' parameter parameter. This is = due to insufficient privilege enforcement on the cf_images_do_setup AJAX ha= ndler, which requires only the upload_files capability (Author+) rather tha=
n manage_options before writing to wp-config.php, combined with the absence=
of single-quote escaping - sanitize_text_field() does not strip single quo= tes, and filter_input(INPUT_POST) bypasses wp_magic_quotes() slashing - all= owing a single quote in the account-id or api-key parameter to break out of=
the single-quoted PHP string literal in the write_config() define() statem= ent. This makes it possible for authenticated attackers, with author-level = access and above, to execute code on the server. This is possible because t=
he 'cf-images-nonce' nonce required by the AJAX handler is exposed to all A= uthor-level and above users on wp-admin/upload.php via the CFImages JavaScr= ipt object, meaning any upload-capable user can satisfy the nonce check and=
reach the vulnerable wp-config.php write path. 2026-06-18 8.8 CVE-2026-986=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9860 ] Vembu--Vembu StoreGr=
id Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in t=
he RemoteBackup and RemoteBackup_webServer services that allows local attac= kers to escalate privileges. Attackers can place a malicious executable in = the unquoted path and restart the service to execute code with LocalSystem = privileges. 2026-06-19 7.8 CVE-2016-20086 [
https://www.cve.org/CVERecord?i= d=3DCVE-2016-20086 ] VeronaLabs--Slimstat Analytics Improper Neutralization=
of Special Elements used in an SQL Command ('SQL Injection') vulnerability=
in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue af= fects Slimstat Analytics: from n/a through 5.4.11. 2026-06-17 8.5 CVE-2026-= 54818 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54818 ] VideoWhisper.co= m--Broadcast Live Video Unauthenticated PHP Object Injection in Broadcast L= ive Video < 7.1.3 versions. 2026-06-15 9.8 CVE-2026-27053 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-27053 ] VideoWhisper.com--Paid Videochat Turnk=
ey Site Unauthenticated Deserialization of untrusted data in Paid Videochat=
Turnkey Site <=3D 7.3.23 versions. 2026-06-15 8.1 CVE-2026-27333 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-27333 ] VillaTheme--GIFT4U Improper Ne= utralization of Special Elements used in an SQL Command ('SQL Injection') v= ulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue af= fects GIFT4U: from n/a through 1.0.10. 2026-06-17 9.3 CVE-2026-54809 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-54809 ] vLLM--vLLM vLLM versions >=
=3D 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal = embeddings processing. Because PyTorch disables sparse tensor invariant che= cks by default, an attacker can submit crafted embedding requests with malf= ormed (negative or out-of-bounds) tensor indices, when the prompt-embeds fe= ature is enabled, to trigger crashes or resource exhaustion (denial of serv= ice), with potential for out-of-bounds/write-what-where memory corruption. = This continues CVE-2025-62164, whose prior fix only disabled the feature by=
default rather than addressing the root cause. 2026-06-20 8.8 CVE-2026-563=
40 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56340 ] Wasiliy Strecker--= Contest Gallery Unauthenticated SQL Injection in Contest Gallery <=3D 28.1.=
6 versions. 2026-06-15 9.3 CVE-2026-40771 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-40771 ] WC Lovers.--WooCommerce Frontend Manager Ultimate Subs= criber SQL Injection in WooCommerce Frontend Manager - Ultimate < 6.7.7 ver= sions. 2026-06-17 8.5 CVE-2026-22335 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-22335 ] WC Product Table--WooCommerce Product Table Lite Unauthenti= cated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <=3D 4.6=
.3 versions. 2026-06-15 7.1 CVE-2026-34902 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-34902 ] WcMultishipping Mondial Relay & Chronopost for Wooomm= erce--WCMultiShipping Subscriber SQL Injection in WCMultiShipping <=3D 3.0.=
2 versions. 2026-06-15 8.5 CVE-2026-52700 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-52700 ] Wdmtech--vAccount Joomla! Component vAccount 2.0.2 con= tains an SQL injection vulnerability that allows unauthenticated attackers =
to execute arbitrary SQL queries by injecting malicious code through the vi=
d parameter. Attackers can send GET requests to the vaccount-dashboard/expe= nse endpoint with crafted SQL payloads in the vid parameter to extract sens= itive database information including version and database names. 2026-06-19=
8.2 CVE-2019-25756 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25756 ] W= dmtech--vBizz Joomla! Component vBizz 1.0.7 contains an unrestricted file u= pload vulnerability that allows authenticated attackers to upload arbitrary=
PHP files by submitting malicious files through the profile_pic parameter.=
Attackers can upload PHP files via POST requests to the employee view endp= oint and execute them from the uploads directory to achieve remote code exe= cution. 2026-06-19 8.8 CVE-2019-25758 [
https://www.cve.org/CVERecord?id=3D= CVE-2019-25758 ] Wdmtech--vBizz Joomla! Component vBizz 1.0.7 contains an S=
QL injection vulnerability that allows authenticated attackers to execute a= rbitrary SQL queries by injecting malicious code through the payid paramete=
r. Attackers can submit POST requests to the employee management interface = with crafted payid array values containing SQL commands to extract sensitiv=
e database information including version and database names. 2026-06-19 7.1=
CVE-2019-25759 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25759 ] Wdmte= ch--VMap Joomla! Component VMap 1.9.6 contains an SQL injection vulnerabili=
ty that allows unauthenticated attackers to execute arbitrary SQL queries b=
y injecting malicious code into the latlngbound parameter. Attackers can se=
nd GET requests to index.php with the option=3Dcom_vmap&task=3Dloadmarker p= arameters containing SQL injection payloads to manipulate database queries = and extract sensitive information. 2026-06-19 8.2 CVE-2019-25753 [
https://= www.cve.org/CVERecord?id=3DCVE-2019-25753 ] Wdmtech--vRestaurant Joomla Com= ponent vRestaurant 1.9.4 contains an SQL injection vulnerability that allow=
s unauthenticated attackers to execute arbitrary SQL queries by injecting m= alicious code through the keysearch parameter. Attackers can send POST requ= ests to the menu-listing-layout endpoint with crafted SQL payloads in the k= eysearch parameter to extract database table names and sensitive informatio=
n from the database. 2026-06-19 8.2 CVE-2019-25754 [
https://www.cve.org/CV= ERecord?id=3DCVE-2019-25754 ] Wdmtech--vReview Joomla Component vReview 1.9= .11 contains an SQL injection vulnerability that allows unauthenticated att= ackers to execute arbitrary SQL queries by injecting malicious code through=
the cmId parameter. Attackers can send POST requests to the editReview tas=
k endpoint with URL-encoded SQL UNION statements in the cmId parameter to e= xtract database information including usernames, passwords, and database ve= rsions. 2026-06-19 8.2 CVE-2019-25755 [
https://www.cve.org/CVERecord?id=3D= CVE-2019-25755 ] Wdmtech--vWishlist Joomla vWishlist 1.0.1 contains an SQL = injection vulnerability that allows authenticated attackers to execute arbi= trary SQL queries by injecting malicious code through the vproductid and us= erid parameters. Attackers can send POST requests to the component with cra= fted SQL payloads in these parameters to extract sensitive database informa= tion including version and database names. 2026-06-19 7.1 CVE-2019-25757 [ =
https://www.cve.org/CVERecord?id=3DCVE-2019-25757 ] Web Guy--Stop Spammers = Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <=3D 2026.3 ver= sions. 2026-06-15 7.1 CVE-2026-48876 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-48876 ] WebAppick--CTX Feed Shop manager PHP Object Injection in CT=
X Feed <=3D 6.6.26 versions. 2026-06-15 7.2 CVE-2026-39434 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-39434 ] WebGeniusLab--Integrio Core Unauthent= icated Local File Inclusion in Integrio Core < 1.2.8 versions. 2026-06-16 8=
.1 CVE-2026-34894 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34894 ] Web= GeniusLab--Softlab Core Unauthenticated Local File Inclusion in Softlab Cor=
e < 1.2.11 versions. 2026-06-16 8.1 CVE-2026-34895 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-34895 ] WebGeniusLab--Thegov Core Unauthenticated Loc=
al File Inclusion in Thegov Core < 2.0.23 versions. 2026-06-16 8.1 CVE-2026= -34893 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34893 ] Webilia Inc.--= Listdom Improper Neutralization of Special Elements used in an SQL Command = ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL In= jection. This issue affects Listdom: from n/a through 5.4.0. 2026-06-17 9.3=
CVE-2026-54819 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54819 ] Webil=
ia Inc.--Listdom Unauthenticated Privilege Escalation in Listdom <=3D 5.5.0=
versions. 2026-06-15 7.3 CVE-2026-49063 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49063 ] Webkul--Ajax Quiz Joomla! Component Ajax Quiz 1.8 conta= ins an SQL injection vulnerability that allows unauthenticated attackers to=
execute arbitrary SQL queries by injecting malicious code through the cid = parameter. Attackers can send GET requests to index.php with the option=3Dc= om_ajaxquiz and view=3Dajaxquiz parameters to extract sensitive database in= formation including table names and column structures. 2026-06-19 8.2 CVE-2= 017-20262 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20262 ] Webmin--Web= min The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers t=
o impersonate any user with a configured SSL client certificate by sending =
a forged HTTP header. A remote attacker can spoof certificate DNs and authe= nticate as any user. Fixed in 2.641. 2026-06-18 8.1 CVE-2026-56020 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-56020 ] Weborange--Bargain Product VM=
3 Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulne= rability that allows unauthenticated attackers to execute arbitrary SQL que= ries by injecting malicious code through the product_id parameter. Attacker=
s can supply crafted SQL statements in GET requests to the brainy and alice=
views to extract sensitive database information. 2026-06-19 8.2 CVE-2017-2= 0261 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20261 ] Weborange--Price=
Alert Joomla! Component Price Alert 3.0.2 contains an SQL injection vulner= ability that allows unauthenticated attackers to execute arbitrary SQL quer= ies by injecting malicious code through the product_id parameter. Attackers=
can send requests to the subscribeajax view with crafted SQL payloads in t=
he product_id parameter to extract sensitive database information including=
credentials and configuration data. 2026-06-19 8.2 CVE-2017-20260 [ https:= //www.cve.org/CVERecord?id=3DCVE-2017-20260 ] websockets--ws ws is an open = source WebSocket client and server for Node.js. All versions from 1.1.0 up =
to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.= 11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vul= nerability. A peer can send a high volume of exceptionally small fragments = and data chunks, with modest network traffic, to force the remote peer into=
allocating and holding structural wrappers that consume far more memory th=
an the default documented message-size limit, leading to process terminatio=
n due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, a=
nd 8.21.0. 2026-06-16 7.5 CVE-2026-48779 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-48779 ] WebToffee--WooCommerce PDF Invoices, Packing Slips, Del= ivery Notes and Shipping Labels Unauthenticated Sensitive Data Exposure in = WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels=
<=3D 4.9.4 versions. 2026-06-15 7.5 CVE-2026-49056 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-49056 ] Weird-Solutions--TFTP Broadband TFTP Broadba=
nd 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.= exe service binary that allows local attackers to execute arbitrary code wi=
th system privileges. Attackers can place a malicious executable in the Pro= gram Files directory path that will be executed during service startup or s= ystem reboot with LocalSystem privileges. 2026-06-19 7.8 CVE-2020-37250 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2020-37250 ] Winstep--Winstep Winstep=
18.06.0096 contains an unquoted service path vulnerability in the Winstep = Xtreme Service that allows local attackers to escalate privileges. Attacker=
s can place malicious executables in the Program Files directory to be exec= uted with LocalSystem privileges when the service starts. 2026-06-19 7.8 CV= E-2020-37253 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37253 ] Wise--Wi= secleaner Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted se= rvice path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service=
respectively, allowing local users to execute arbitrary code with SYSTEM p= rivileges. Attackers can insert malicious executables in the system root pa=
th that execute during service startup or system reboot with elevated privi= leges. 2026-06-19 7.8 CVE-2016-20093 [
https://www.cve.org/CVERecord?id=3DC= VE-2016-20093 ] WishList Products, LLC.--WishList Member X Subscriber Arbit= rary File Upload in WishList Member X <=3D 3.29.0 versions. 2026-06-17 9.9 = CVE-2026-25446 [
https://www.cve.org/CVERecord?id=3DCVE-2026-25446 ] Wombat=
Plugins--Advanced Product Fields (Product Addons) for WooCommerce Shop man= ager PHP Object Injection in Advanced Product Fields (Product Addons) for W= ooCommerce <=3D 1.6.19 versions. 2026-06-15 7.2 CVE-2026-39499 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-39499 ] Wondershare--PDFelement Wondersha=
re PDFelement 5.2.9 contains a privilege escalation vulnerability due to an=
unquoted service path in the WsAppService Windows service. Local attackers=
can place a malicious executable in the service path and execute code with=
LocalSystem privileges upon service restart or system reboot. 2026-06-19 7=
.8 CVE-2020-37254 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37254 ] Woo= Commerce--WooCommerce WooCommerce 7.1.0 contains a remote code execution vu= lnerability that allows attackers to execute arbitrary PHP code by injectin=
g shell commands through the product-type parameter. Attackers can send req= uests to the class-wc-meta-box-product-images.php endpoint with unsanitized=
product-type values to write malicious PHP files to the web root. 2026-06-=
20 9.8 CVE-2022-50972 [
https://www.cve.org/CVERecord?id=3DCVE-2022-50972 ]=
WP Chill--Modula Image Gallery Author PHP Object Injection in Modula Image=
Gallery <=3D 2.14.18 versions. 2026-06-15 7.2 CVE-2026-39481 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-39481 ] Wp Directory Kit--WP Directory Kit=
Unauthenticated Broken Access Control in WP Directory Kit <=3D 1.5.0 versi= ons. 2026-06-15 7.5 CVE-2026-39534 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-39534 ] WP E-Signature--Signature Add-On for WooCommerce Unauthentica= ted Sensitive Data Exposure in Signature Add-On for WooCommerce <=3D 2.0 ve= rsions. 2026-06-15 7.5 CVE-2026-52694 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-52694 ] WP Engine--Faust.js Authentication Bypass Using an Alterna=
te Path or Channel vulnerability in WP Engine Faust.Js allows Password Reco= very Exploitation. This issue affects Faust.Js: from n/a through 1.8.7. 202= 6-06-15 8.8 CVE-2026-49062 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49= 062 ] WP Overnight--WooCommerce PDF Invoices & Packing Slips Shop manager P=
HP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 ver= sions. 2026-06-15 7.2 CVE-2026-39472 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-39472 ] WP Swings--Event Tickets Manager for WooCommerce Unauthenti= cated Broken Access Control in Event Tickets Manager for WooCommerce <=3D 1= .5.3 versions. 2026-06-15 7.5 CVE-2026-34898 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-34898 ] WP Swings--Upsell Order Bump Offer for WooCommerce = Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCom= merce <=3D 3.1.4 versions. 2026-06-15 7.5 CVE-2026-49110 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-49110 ] WP Travel Engine--WP Travel Engine Unau= thenticated PHP Object Injection in WP Travel Engine <=3D 6.7.12 versions. = 2026-06-15 9.8 CVE-2026-49770 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -49770 ] WP Travel Engine--WP Travel Engine Unauthenticated Other Vulnerabi= lity Type in WP Travel Engine <=3D 6.7.10 versions. 2026-06-15 7.5 CVE-2026= -49078 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49078 ] WP Travel--WP = Travel Gutenberg Blocks Improper Neutralization of Special Elements used in=
an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gute= nberg Blocks allows Blind SQL Injection. This issue affects WP Travel Guten= berg Blocks: from n/a through 3.9.4. 2026-06-17 9.3 CVE-2026-54808 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-54808 ] WP User Manager--WP User Mana= ger Subscriber Arbitrary File Deletion in WP User Manager <=3D 2.9.16 versi= ons. 2026-06-15 9.9 CVE-2026-49766 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-49766 ] wp-buy--SEO Redirection Unauthenticated Cross Site Scripting = (XSS) in SEO Redirection <=3D 9.17 versions. 2026-06-15 7.1 CVE-2026-52702 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-52702 ] wp.insider--Affiliate=
s Manager Unauthenticated Sensitive Data Exposure in Affiliates Manager <=
=3D 2.9.50 versions. 2026-06-15 7.5 CVE-2026-52692 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-52692 ] wp.insider--Simple Membership Unauthenticated=
Broken Access Control in Simple Membership <=3D 4.7.1 versions. 2026-06-15=
7.5 CVE-2026-34886 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34886 ] W= PClever--WPC Product Bundles for WooCommerce Unauthenticated Broken Access = Control in WPC Product Bundles for WooCommerce <=3D 8.5.3 versions. 2026-06= -15 7.5 CVE-2026-48883 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48883 =
] WPClever--WPC Product Options for WooCommerce Unauthenticated Arbitrary F= ile Download in WPC Product Options for WooCommerce <=3D 3.2.1 versions. 20= 26-06-15 7.5 CVE-2026-49061 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 9061 ] WPDeveloper--EmbedPress Unauthenticated Sensitive Data Exposure in E= mbedPress <=3D 4.5.2 versions. 2026-06-15 7.5 CVE-2026-48872 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-48872 ] WPExperts--Post SMTP Unauthenticate=
d Cross Site Scripting (XSS) in Post SMTP <=3D 3.6.2 versions. 2026-06-15 7=
.1 CVE-2026-48838 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48838 ] WPF= actory--Min Max Step Quantity Limits Manager for WooCommerce Unauthenticate=
d Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for Wo= oCommerce <=3D 5.2.2 versions. 2026-06-16 7.1 CVE-2026-39437 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-39437 ] WPFunnels--WPFunnels Pro Unauthenti= cated Cross Site Scripting (XSS) in WPFunnels Pro <=3D 2.9.4 versions. 2026= -06-17 7.1 CVE-2026-49778 [
https://www.cve.org/CVERecord?id=3DCVE-2026-497=
78 ] WPGraphQL--WPGraphQL Unauthenticated SQL Injection in WPGraphQL < 2.11=
.1 versions. 2026-06-15 7.5 CVE-2026-40762 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-40762 ] WPLocker--PT Luxa Addons Subscriber Arbitrary File Up= load in PT Luxa Addons <=3D 1.2.2 versions. 2026-06-17 9.9 CVE-2025-60218 [=
https://www.cve.org/CVERecord?id=3DCVE-2025-60218 ] WPManageNinja--Best Pa= yments Plugin for WP Unauthenticated Bypass Vulnerability in Best Payments = Plugin for WP <=3D 4.6.19 versions. 2026-06-15 7.5 CVE-2026-42655 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-42655 ] WPMet--MetForm Pro Unauthentic= ated Broken Access Control in MetForm Pro <=3D 3.9.1 versions. 2026-06-17 9=
.1 CVE-2026-24611 [
https://www.cve.org/CVERecord?id=3DCVE-2026-24611 ] wpm= udev--Branda White Label & Branding, Free Login Page Customizer The Branda = plugin for WordPress is vulnerable to privilege escalation via account take= over in all versions up to, and including, 3.4.29. This is due to the plugi=
n not properly validating a user's identity prior to updating their passwor=
d. This makes it possible for unauthenticated attackers to change arbitrary=
user's passwords, including administrators, and leverage that to gain acce=
ss to their account. 2026-06-19 9.8 CVE-2026-11551 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-11551 ] WPos--Woocommerce Book Price Subscriber Arbit= rary File Download in Woocommerce Book Price <=3D 1.3 versions. 2026-06-17 = 7.5 CVE-2026-22334 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22334 ] WP= Tasty--AWP Classifieds Unauthenticated Broken Access Control in AWP Classif= ieds <=3D 4.4.4 versions. 2026-06-15 7.5 CVE-2026-39533 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-39533 ] Wptimecapsule--Time Capsule Plugin WordP= ress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerab= ility that allows unauthenticated attackers to gain administrative access b=
y sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers=
can exploit this flaw to obtain valid administrator session cookies and ac= cess the WordPress dashboard without providing credentials. 2026-06-20 7.5 = CVE-2020-37255 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37255 ] wpWax-= -Directorist Booking Improper Neutralization of Special Elements used in an=
SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking a= llows Blind SQL Injection. This issue affects Directorist Booking: from n/a=
through 3.0.3. 2026-06-16 8.5 CVE-2026-49073 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-49073 ] WPZOOM--WPZOOM Addons for Elementor Unauthenticate=
d Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <=3D 1.3.4 vers= ions. 2026-06-17 7.1 CVE-2026-39597 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-39597 ] XServer--CloudSecure WP Security Unauthenticated Broken Auth= entication in CloudSecure WP Security <=3D 1.4.7 versions. 2026-06-15 8.1 C= VE-2026-42411 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42411 ] xtemos-= -Hitek Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions. 2026= -06-17 8.1 CVE-2026-39582 [
https://www.cve.org/CVERecord?id=3DCVE-2026-395=
82 ] Yandex--Punto Switcher Punto Switcher through 4.5.0.583 contains an un= quoted search path element vulnerability that allows local attackers to exe= cute arbitrary code by exploiting the application's call to WinExec without=
a fully qualified path for RunDll32.exe when invoking shell32.dll Control_= RunDLL input.dll. Attackers can place a malicious executable earlier in the=
search order to achieve arbitrary code execution in the context of the aff= ected user. 2026-06-18 7.8 CVE-2026-25865 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-25865 ] Yannick Lefebvre--Link Library Contributor Arbitrary F= ile Deletion in Link Library <=3D 7.8.8 versions. 2026-06-15 7.7 CVE-2026-4= 0779 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40779 ] Yealink--SIP-T46=
U A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affecte=
d element is the function StartReportInformation of the file /api/inner/bef= orewifitest of the component Web FastCGI Service. The manipulation of the a= rgument port results in stack-based buffer overflow. Access to the local ne= twork is required for this attack. The exploit is now public and may be use=
d. The vendor was contacted early about this disclosure but did not respond=
in any way. 2026-06-15 8 CVE-2026-12218 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12218 ] Yealink--SIP-T46U A vulnerability has been found in Yea= link SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePart= sUpload of the file /api/upgrade/accupgradebychunk of the component Firmwar=
e Chunk Upload handler. Such manipulation of the argument uid leads to stac= k-based buffer overflow. The attack can only be initiated within the local = network. The exploit has been disclosed to the public and may be used. The = vendor was contacted early about this disclosure but did not respond in any=
way. 2026-06-15 8 CVE-2026-12220 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-12220 ] Yealink--SIP-T46U A vulnerability was found in Yealink SIP-T46=
U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/= upgrade of the component Firmware Chunk Upload Handler. Performing a manipu= lation of the argument uid/start_offset results in stack-based buffer overf= low. The attack needs to be approached within the local network. The exploi=
t has been made public and could be used. The vendor was contacted early ab= out this disclosure but did not respond in any way. 2026-06-15 8 CVE-2026-1= 2221 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12221 ] Yealink--SIP-T46=
U A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected=
is the function mod_webd.BlueToothTest of the file /api/inner/bttest of th=
e component Web FastCGI Service. Executing a manipulation of the argument b= tMac/pin/reserved can lead to stack-based buffer overflow. The attack needs=
to be done within the local network. The exploit has been publicly disclos=
ed and may be utilized. The vendor was contacted early about this disclosur=
e but did not respond in any way. 2026-06-15 8 CVE-2026-12222 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-12222 ] Yeeaddons--YayMail Shop manager PH=
P Object Injection in YayMail <=3D 4.3.3 versions. 2026-06-15 7.2 CVE-2026-= 39498 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39498 ] yeoman--environ= ment Yeoman Environment provides an API to discover, create, and run genera= tors, and to configure where and how a generator is resolved. Versions 2.9.=
0 through 6.0.0 install missing local generator packages from caller-suppli=
ed package names without user confirmation. In downstream consumers that pa=
ss attacker-controlled project configuration into this path, this can resul=
t in arbitrary package installation and code execution during CLI bootstrap=
. The vulnerable method is installLocalGenerators(), which calls repository= .install() directly without prompting the user. This issue has been fixed i=
n version 6.0.0. 2026-06-16 8.6 CVE-2026-42089 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-42089 ] yydevelopment--Advanced 301 and 302 Redirect Unau= thenticated SQL Injection in Advanced 301 and 302 Redirect <=3D 1.6.9 versi= ons. 2026-06-15 9.3 CVE-2026-49067 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-49067 ] Zcontent--Zap Calendar Lite Joomla! Component Zap Calendar Li=
te 4.3.4 contains an SQL injection vulnerability that allows unauthenticate=
d attackers to execute arbitrary SQL queries by injecting malicious code th= rough the 'eid' parameter. Attackers can send GET requests to the RSVP plug=
in endpoint with crafted SQL payloads to extract sensitive database informa= tion including database names and table structures. 2026-06-19 8.2 CVE-2017= -20268 [
https://www.cve.org/CVERecord?id=3DCVE-2017-20268 ] zephyrproject-= -zephyr Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role=
parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds = write. During Service Level Connection setup the HF sends AT+CIND=3D? and p= arses the AG's +CIND: response in cind_handle(), which assigns a per-entry = counter index and calls cind_handle_values() for each list element. cind_ha= ndle_values() then wrote hf-ind_table[index] =3D i without verifying that i= ndex is within the 20-element int8_t ind_table[] array of struct bt_hfp_hf.=
Because the parser places no cap on the number of +CIND: list entries, a r= emote Attendant Gateway (a malicious, compromised, or spoofed peer the devi=
ce connects to over Bluetooth) can send a response with more than 20 recogn= ized indicator entries and drive index arbitrarily large, writing a small a= ttacker-positioned value past the array into adjacent struct fields (featur=
e masks, SDP/version state, the calls[] array, work/atomic bookkeeping) and=
potentially beyond the static connection pool slot. This yields memory cor= ruption and at least denial of service of the Bluetooth host, triggered by =
a single malformed AT response with no user interaction. The sibling consum=
er ag_indicator_handle_values() already performed the equivalent bounds che= ck; this commit adds the same index =3D ARRAY_SIZE(hf-ind_table) guard to c= lose the gap. Affects builds with CONFIG_BT_HFP_HF enabled; introduced with=
the original HFP HF CIND parser (~v1.7) and present through v4.4.0. 2026-0= 6-17 7.1 CVE-2026-10641 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10641=
] Zidithemes--Grip Subscriber Arbitrary File Upload in Grip <=3D 1.0.9 ver= sions. 2026-06-17 9.9 CVE-2024-52488 [
https://www.cve.org/CVERecord?id=3DC= VE-2024-52488 ] Zozothemes--Restaurt Subscriber Arbitrary File Upload in Re= staurt <=3D 1.0.4 versions. 2026-06-17 9.9 CVE-2026-22327 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-22327 ] Zyxel--GS1900-48HPv2 firmware A stack-= based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HP=
v2 firmware versions through=C2=A02.90(ABTQ.1)C0 could allow a LAN-based, u= nauthenticated attacker to exploit the flaw and potentially execute OS comm= ands via a crafted HTTP request. 2026-06-16 8.8 CVE-2026-7273 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-7273 ]=20
Back to top [ #top ]
Medium Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info 10web--Form = Maker by 10Web Mobile-Friendly Drag & Drop Contact Form Builder The Form Ma= ker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for = WordPress is vulnerable to generic SQL Injection via the 'groupids' paramet=
er in all versions up to, and including, 1.15.43 due to insufficient escapi=
ng on the user supplied parameter and lack of sufficient preparation on the=
existing SQL query. This makes it possible for authenticated attackers, wi=
th administrator-level access and above, to append additional SQL queries i= nto already existing queries that can be used to extract sensitive informat= ion from the database. 2026-06-18 4.9 CVE-2026-11776 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-11776 ] 10web--Form Maker by 10Web Mobile-Friendly = Drag & Drop Contact Form Builder The Form Maker by 10Web - Mobile-Friendly = Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to gene= ric SQL Injection via the 'name' parameter in all versions up to, and inclu= ding, 1.15.43 due to insufficient escaping on the user supplied parameter a=
nd lack of sufficient preparation on the existing SQL query. This makes it = possible for authenticated attackers, with administrator-level access, to a= ppend additional SQL queries into already existing queries that can be used=
to extract sensitive information from the database. 2026-06-18 4.9 CVE-202= 6-11777 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11777 ] 2download--2D= ownload Connector for 2DL Hosted Checkout The 2Download Connector for 2DL H= osted Checkout plugin for WordPress is vulnerable to unauthorized access in=
all versions up to, and including, 0.1.5. This is due to the plugin not pr= operly verifying that a user is authorized to perform an action. This makes=
it possible for unauthenticated attackers to view arbitrary customers' sub= scription data including subscription status, product names, order IDs, pur= chase dates, and expiry dates. 2026-06-19 5.3 CVE-2026-6798 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-6798 ] abtest--Abtest WordPress Plugin Abtes=
t contains a local file inclusion vulnerability that allows unauthenticated=
attackers to include arbitrary files by manipulating the action parameter.=
Attackers can send GET requests to abtest_admin.php with malicious action = values to include files from the admin directory and execute arbitrary code=
. 2026-06-15 6.2 CVE-2016-20082 [
https://www.cve.org/CVERecord?id=3DCVE-20= 16-20082 ] AcademySoftwareFoundation--openexr OpenEXR is the reference impl= ementation and specification for the EXR image format, widely used in the m= otion picture industry. In versions 3.4.0 through 3.4.11, an integer overfl=
ow in ht_undo_impl() in src/lib/OpenEXRCore/internal_ht.cpp leads to a heap= -buffer overflow when decoding a crafted HTJ2K-compressed EXR file. decode-= >channels[i].width (int32_t) is multiplied by bytes_per_element in 32-bit s= igned arithmetic. With large widths (e.g., >=3D 536870912 for FLOAT data), = this overflows, producing a corrupted offset that is later used for pointer=
arithmetic and can cause a heap out-of-bounds write. The same unchecked mu= ltiplication pattern appears in two other HTJ2K paths (bytes-per-line accum= ulation and pixel-line pointer advancement). As with related CVE-2026-34378=
through CVE-2026-34589 fixes in other codecs, validating only after the mu= ltiplication is too late because the value may already be overflowed. This = issue has been fixed in version 3.4.12. 2026-06-18 6.1 CVE-2026-44663 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-44663 ] activepieces--activepieces=
A vulnerability was detected in activepieces up to 0.83.0. This vulnerabil= ity affects the function handleUrlFile in the library packages/server/engin= e/src/lib/variables/processors/file.ts of the component File URL Handler. T=
he manipulation results in server-side request forgery. The attack can be e= xecuted remotely. The exploit is now public and may be used. The vendor was=
contacted early about this disclosure but did not respond in any way. 2026= -06-21 6.3 CVE-2026-12813 [
https://www.cve.org/CVERecord?id=3DCVE-2026-128=
13 ] adamsilverstein--User Admin Simplifier The User Admin Simplifier plugi=
n for WordPress is vulnerable to Cross-Site Request Forgery in all versions=
up to, and including, 3.0.0. This is due to missing or incorrect nonce val= idation on the useradminsimplifier_options_page function. This makes it pos= sible for unauthenticated attackers to reset and permanently delete any use= r's stored menu and admin-bar configuration via a forged request that trigg= ers uas_save_admin_options() and overwrites the useradminsimplifier_options=
database entry via a forged request granted they can trick a site administ= rator into performing an action such as clicking on a link. 2026-06-19 4.3 = CVE-2026-11775 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11775 ] addons= press--Advanced Import The Advanced Import plugin for WordPress is vulnerab=
le to Server-Side Request Forgery in all versions up to, and including, 1.4= .6. This is due to the plugin using wp_remote_get() to fetch a user-supplie=
d URL without validating that the URL does not point to internal or private=
network resources in the demo_download_and_unzip() function. The 'demo_fil=
e' parameter from $_POST is passed through sanitize_text_field() (which onl=
y handles XSS-related sanitization) and then directly into wp_remote_get() = when 'demo_file_type' is set to 'url'. Notably, the plugin uses wp_safe_rem= ote_get() in other locations (theme template libraries) which would provide=
SSRF protection, but fails to use it in this critical AJAX handler. This m= akes it possible for authenticated attackers, with Author-level access and = above (upload_files capability), to make web requests to arbitrary location=
s originating from the web application, which can be used to query and view=
data from internal services, including cloud instance metadata endpoints. = 2026-06-19 6.4 CVE-2026-4328 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 4328 ] Adobe--DNG SDK DNG SDK versions 1.7.1 2536 and earlier are affected =
by an out-of-bounds read vulnerability that could lead to disclosure of sen= sitive memory. An attacker could leverage this vulnerability to disclose se= nsitive information. Exploitation of this issue requires user interaction i=
n that a victim must open a malicious file. 2026-06-16 5.5 CVE-2026-47927 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-47927 ] Adobe--DNG SDK DNG SDK=
versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vuln= erability that could lead to disclosure of sensitive memory. An attacker co= uld leverage this vulnerability to disclose sensitive information. Exploita= tion of this issue requires user interaction in that a victim must open a m= alicious file. 2026-06-16 5.5 CVE-2026-47934 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-47934 ] Adobe--DNG SDK DNG SDK versions 1.7.1 2536 and earl= ier are affected by an out-of-bounds read vulnerability that could lead to = disclosure of sensitive memory. An attacker could leverage this vulnerabili=
ty to disclose sensitive information. Exploitation of this issue requires u= ser interaction in that a victim must open a malicious file. 2026-06-16 5.5=
CVE-2026-47963 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47963 ] Ahmad= --JS Help Desk Unauthenticated Broken Access Control in JS Help Desk <=3D 3= .0.9 versions. 2026-06-15 6.5 CVE-2026-48887 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-48887 ] Ahmad--WP Job Portal Subscriber Cross Site Scriptin=
g (XSS) in WP Job Portal <=3D 2.5.2 versions. 2026-06-15 6.5 CVE-2026-48880=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-48880 ] algolplus--Advanced = Order Export For WooCommerce The Advanced Order Export For WooCommerce plug=
in for WordPress is vulnerable to generic SQL Injection via the 'sort_direc= tion' parameter in all versions up to, and including, 4.0.10 due to insuffi= cient escaping on the user supplied parameter and lack of sufficient prepar= ation on the existing SQL query. This makes it possible for authenticated a= ttackers, with shop manager-level access and above, to append additional SQ=
L queries into already existing queries that can be used to extract sensiti=
ve information from the database. The endpoint requires a valid woe_nonce a=
nd Shop Manager-level capabilities (view_woocommerce_reports or export_wooc= ommerce_orders), and wp_magic_quotes protection is stripped via stripslashe= s_deep() before processing, allowing quote and backslash characters to surv= ive intact into the SQL context. 2026-06-18 4.9 CVE-2026-11360 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-11360 ] ali2woo--AliNext Missing Authoriz= ation vulnerability in ali2woo AliNext allows Exploiting Incorrectly Config= ured Access Control Security Levels. This issue affects AliNext: from n/a t= hrough 3.3.5. 2026-06-17 6.5 CVE-2024-37210 [
https://www.cve.org/CVERecord= ?id=3DCVE-2024-37210 ] Amit Mittal--Shipment Tracker for Woocommerce Subscr= iber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <=3D 1.= 5.3.2 versions. 2026-06-15 6.5 CVE-2026-39540 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-39540 ] Andy Moyle--Emergency Password Reset Cross-Site re= quest forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset a= llows Cross Site Request Forgery. This issue affects Emergency Password Res= et: from n/a through 8.0. 2026-06-17 4.3 CVE-2024-35648 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2024-35648 ] Apollo Pharmacy--Blood Glucose Monitorin=
g System (Model No. APG-01 BT) An attacker within BLE communication range c=
an passively intercept wireless traffic and obtain sensitive health-related=
information, including glucose measurement values. 2026-06-18 6.5 CVE-2026= -50034 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50034 ] Apollo Pharmac= y--Blood Glucose Monitoring System (Model No. APG-01 BT) An attacker within=
BLE communication range can monopolize the device's only available BLE con= nection slot, preventing legitimate users or applications from establishing=
a connection. 2026-06-18 6.5 CVE-2026-52866 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-52866 ] artbees--JupiterX Core Subscriber Cross Site Script= ing (XSS) in JupiterX Core <=3D 4.14.1 versions. 2026-06-15 6.5 CVE-2026-39= 491 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39491 ] authlib--joserfc = joserfc is a Python library that provides an implementation of several JSON=
Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through = 1.6.5, joserfc accepts oversized RFC7797 b64=3Dfalse JWS payloads without a= pplying JWSRegistry.max_payload_length, which can lead to resource exhausti= on. The normal JWS compact and flattened JSON paths reject payloads above t=
he configured payload-size limit with ExceededSizeError. The RFC7797 unenco= ded payload paths do not make the same check. A valid b64=3Dfalse compact o=
r flattened JSON JWS can therefore deserialize successfully with a payload = larger than JWSRegistry.max_payload_length. Applications that accept lower-= trust JWS values and rely on joserfc to reject oversized token content duri=
ng verification have a moderate availability risk. This issue has been fixe=
d in version 1.6.7. 2026-06-17 5.3 CVE-2026-48990 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-48990 ] Autodesk--Revit A maliciously crafted RFA file=
, when converted to FormIt via "Convert RFA to FormIt" in Autodesk Revit, c=
an force a NULL Pointer Dereference vulnerability. Successful exploitation = may cause the application to crash, leading to a denial-of-service conditio=
n. 2026-06-17 5.5 CVE-2026-1288 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-1288 ] AVideo--AVideo AVideo through version 27.0 contains a server-side=
request forgery vulnerability in plugin/Live/test.php that allows authenti= cated administrators to read arbitrary URLs via the statsURL parameter, whi=
ch lacks isSSRFSafeURL() validation and accepts requests to private IP rang=
es and cloud metadata endpoints. Attackers can exploit this by crafting req= uests to internal services, cloud metadata endpoints like 169.254.169.254, = and localhost to retrieve sensitive information including IAM credentials, = internal service responses, and network configuration details. 2026-06-20 6=
.8 CVE-2026-56342 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56342 ] AVi= deo--AVideo AVideo through version 25.0 contains an authentication bypass v= ulnerability in the decryptMessage.json.php endpoint that allows unauthenti= cated users to decrypt PGP messages. Remote attackers can submit private ke= ys, ciphertext, and passphrases to perform server-side decryption without c= redentials, exposing key material to logs and enabling resource exhaustion = attacks. 2026-06-20 6.5 CVE-2026-56346 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56346 ] Avirtum--iPages Flipbook Missing Authorization vulnerab= ility in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured A= ccess Control Security Levels. This issue affects iPages Flipbook: from n/a=
through 1.5.1. 2026-06-17 5.3 CVE-2024-33909 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2024-33909 ] Awesomemotive--Envira Photo Gallery Unauthenticate=
d Broken Access Control in Envira Photo Gallery <=3D 1.12.5 versions. 2026-= 06-16 6.5 CVE-2026-54190 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5419=
0 ] AWS--Kiro IDE Incorrect default permissions in Kiro IDE on macOS and Li= nux before version 0.11.133 could expose the authentication token cache fil=
e to other local users or processes via world-readable permissions (0644) i= nstead of owner-restricted permissions (0600). To remediate this issue, use=
rs should upgrade to Kiro IDE version 0.11.133 or later. After upgrading an=
d restarting the application, the cache file permissions are automatically = updated on the next token refresh. Users operating in a multi-user environm= ent can invalidate existing tokens by reauthenticating. 2026-06-15 5.5 CVE-= 2026-11931 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11931 ] BerriAI--l= itellm A security flaw has been discovered in BerriAI litellm up to 1.82.2.=
This impacts the function authenticate_user of the file litellm/proxy/auth= /login_utils.py of the component PROXY_ADMIN database API Key Generator. Pe= rforming a manipulation results in session expiration. The attack may be in= itiated remotely. The exploit has been released to the public and may be us=
ed for attacks. The vendor was contacted early about this disclosure. 2026-= 06-21 6.3 CVE-2026-12772 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1277=
2 ] BerriAI--litellm A security vulnerability has been detected in BerriAI = litellm up to 1.82.2. Affected by this vulnerability is the function _execu= te_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_= endpoints.py of the component MCP Server Connection Testing. The manipulati=
on leads to server-side request forgery. Remote exploitation of the attack =
is possible. The exploit has been disclosed publicly and may be used. The v= endor was contacted early about this disclosure. 2026-06-21 6.3 CVE-2026-12= 774 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12774 ] BerriAI--litellm =
A vulnerability was identified in BerriAI litellm up to 1.82.2. This impact=
s the function get_redirect_response_from_openid of the file litellm/proxy/= management_endpoints/ui_sso.py of the component SSO Authentication Flow. Th=
e manipulation leads to session expiration. The attack is possible to be ca= rried out remotely. The exploit is publicly available and might be used. Th=
e vendor was contacted early about this disclosure. 2026-06-21 6.3 CVE-2026= -12796 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12796 ] BerriAI--litel=
lm A security flaw has been discovered in BerriAI litellm up to 1.82.5. Aff= ected is the function async_pre_call_hook of the file enterprise/enterprise= _hooks/banned_keywords.py of the component Completions Interface. The manip= ulation of the argument prompt results in incorrect authorization. The atta=
ck may be performed from remote. The exploit has been released to the publi=
c and may be used for attacks. The vendor was contacted early about this di= sclosure. 2026-06-21 6.3 CVE-2026-12797 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12797 ] BerriAI--litellm A weakness has been identified in Berr= iAI litellm up to 1.82.2. Affected by this vulnerability is the function lo= ad_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/op= enapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This ma= nipulation of the argument spec_path causes server-side request forgery. It=
is possible to initiate the attack remotely. The exploit has been made ava= ilable to the public and could be used for attacks. The vendor was contacte=
d early about this disclosure. 2026-06-21 6.3 CVE-2026-12798 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-12798 ] BerriAI--litellm A vulnerability wa=
s determined in BerriAI litellm up to 1.63.1. The impacted element is an un= known function of the file litellm/proxy/management_endpoints/key_managemen= t_endpoints.py of the component Admin Key Handler. This manipulation causes=
improper authorization. The attack can be initiated remotely. The exploit = has been publicly disclosed and may be utilized. Patch name: 23781. It is r= ecommended to apply a patch to fix this issue. The vendor was contacted ear=
ly about this disclosure. 2026-06-21 5.4 CVE-2026-12770 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-12770 ] BerriAI--litellm A vulnerability was ide= ntified in BerriAI litellm up to 1.82.2. This affects an unknown function o=
f the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT=
Handler. Such manipulation leads to improper authorization. The attack can=
be launched remotely. A high complexity level is associated with this atta= ck. The exploitability is reported as difficult. The exploit is publicly av= ailable and might be used. The vendor was contacted early about this disclo= sure. 2026-06-21 5 CVE-2026-12771 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-12771 ] BerriAI--litellm A security vulnerability has been detected in=
BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_vi= ew_users of the file litellm/proxy/management_endpoints/internal_user_endpo= ints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation le= ads to improper authorization. It is possible to launch the attack remotely=
. The exploit has been disclosed publicly and may be used. The vendor was c= ontacted early about this disclosure. 2026-06-21 4.3 CVE-2026-12799 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-12799 ] Bitnami--bitnami/mariadb-gal= era Bitnami MariaDB Galera container images and Helm chart are affected by =
a hardcoded default credential vulnerability in the Galera replication heal= th-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWOR=
D environment variables defaulted to monitor and monitor respectively. This=
user is granted REPLICATION CLIENT privileges from any host ('%'). The Bit= nami Helm chart for MariaDB Galera did not expose parameters to configure t= his user's credentials, resulting in all chart deployments using this publi= cly known credential by default. Affected versions - Container image: 10.6.=
x prior to 10.6.27-photon-5-r0; 10.11.x prior to 10.11.17-photon-5-r1; 11.4=
.x prior to 11.4.12-photon-5-r0; 11.8.x prior to 11.8.7-photon-5-r1; 12.3.x=
prior to 12.3.2-photon-5-r0 / 12.3.2-debian-12-r0. Helm chart: prior to 18= .3.0. 2026-06-18 5.3 CVE-2026-47847 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-47847 ] bitpressadmin--Bit integrations Form Integration, Webhook, S= preadsheets, CRM, LMS & Email Automation The Bit integrations - Form Integr= ation, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPr= ess is vulnerable to Server-Side Request Forgery in all versions up to, and=
including, 2.8.7 via the upload_attachment. This makes it possible for una= uthenticated attackers to make web requests to arbitrary locations originat= ing from the web application and can be used to query and modify informatio=
n from internal services. Exploitation requires a form integration to be co= nfigured with a field mapped to a WooCommerce product image, product galler=
y, downloadable files, or Google Contacts attachment field, which is a defa= ult use case for these integrations. 2026-06-19 6.5 CVE-2026-11989 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-11989 ] Black Lantern Security--BBOT = The postman_download module uses the workspace name field from the Postman = API to construct the local directory path without sanitization. If a malici= ous workspace has a name containing path traversal characters, pathlib reso= lves the path outside the intended output directory, allowing an attacker t=
o write arbitrary files to the user's system. 2026-06-17 6.5 CVE-2026-12568=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12568 ] Black Lantern Securi= ty--BBOT The unarchive internal module's archive extraction commands perfor=
m no code-level validation on extracted file paths, relying entirely on the=
behavior of external tools (e.g. GNU tar) which varies by platform. While = CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive e= xtraction path traversal was never fixed. On systems with GNU tar < 1.34 (U= buntu 20.04, Debian Buster, CentOS 7, many Docker base images), a malicious=
archive can write files outside the intended extraction directory. 2026-06= -17 5.3 CVE-2026-12565 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12565 =
] blubrry--PowerPress Podcasting plugin by Blubrry The PowerPress Podcastin=
g plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site=
Scripting via 'embed' Episode Meta Field in all versions up to, and includ= ing, 11.16.8 due to insufficient input sanitization and output escaping. Th=
is makes it possible for authenticated attackers, with author-level access = and above, to inject arbitrary web scripts in pages that will execute whene= ver a user accesses an injected page. The embed value is stored via update_= post_meta() rather than through WordPress core's post content pipeline, mea= ning kses-on-save filtering is never applied - even for Author-role users w=
ho would otherwise lack unfiltered_html - making this path unprotected by W= ordPress's standard role-based XSS mitigations. 2026-06-18 6.4 CVE-2026-120=
98 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12098 ] BoldGrid--W3 Total=
Cache Author Broken Access Control in W3 Total Cache <=3D 2.9.1 versions. = 2026-06-17 4.7 CVE-2026-39595 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -39595 ] Booking Activities Team--Booking Activities Unauthenticated Broken=
Access Control in Booking Activities <=3D 1.16.48.1 versions. 2026-06-15 6=
.5 CVE-2026-39525 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39525 ] Boo= tstrapped Ventures--Visual Link Preview Subscriber Sensitive Data Exposure =
in Visual Link Preview <=3D 2.4.1 versions. 2026-06-15 6.5 CVE-2026-48878 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-48878 ] bplugins--Services Sec= tion Block Showcase Service Details in Grid or Columns The Services Section=
Block - Showcase Service Details in Grid or Columns plugin for WordPress i=
s vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in a=
ll versions up to, and including, 1.4.4 due to insufficient input sanitizat= ion and output escaping. This makes it possible for authenticated attackers=
, with contributor-level access and above, to inject arbitrary web scripts =
in pages that will execute whenever a user accesses an injected page. The p= ayload persists inside HTML comments in post_content, bypassing wp_kses_pos=
t sanitization at save time, and executes via both the primary service link=
anchor and a secondary title-wrapped anchor when the linkIn option is set =
to 'title'. 2026-06-18 6.4 CVE-2026-11402 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-11402 ] Brandfolder--Brandfolder WordPress Brandfolder plugin = version 3.0 and earlier contains a local file inclusion vulnerability in ca= llback.php that allows unauthenticated attackers to include arbitrary files=
by manipulating the wp_abspath parameter. Attackers can supply path traver= sal sequences or remote URLs through the wp_abspath parameter to read sensi= tive files like wp-config.php or execute remote code. 2026-06-15 6.2 CVE-20= 16-20080 [
https://www.cve.org/CVERecord?id=3DCVE-2016-20080 ] Bricks--Bric=
ks Builder Subscriber Broken Access Control in Bricks Builder <=3D 2.1.4 ve= rsions. 2026-06-17 4.3 CVE-2026-40723 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-40723 ] Bricksable--Bricksable for Bricks Builder Improper Neutral= ization of Input During Web Page Generation ('Cross-site Scripting') vulner= ability in Bricksable for Bricks Builder allows Stored XSS. This issue affe= cts Bricksable for Bricks Builder: from n/a through 1.6.83. 2026-06-18 5.9 = CVE-2026-56009 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56009 ] bunny.= net--bunny.net Subscriber Broken Access Control in bunny.net <=3D 2.3.6 ver= sions. 2026-06-15 6.3 CVE-2025-68049 [
https://www.cve.org/CVERecord?id=3DC= VE-2025-68049 ] Canon Inc.--EOS Network Setting Tool for Windows Improper v= alidation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 =
or earlier 2026-06-15 6.5 CVE-2026-9258 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-9258 ] Canon Inc.--EOS Network Setting Tool for Windows Imprope=
r validation of server certificates in Canon EOS Network Setting Tool Versi=
on 1.5.0 or earlier 2026-06-15 6.5 CVE-2026-9259 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-9259 ] Canon Inc.--EOS Network Setting Tool for Windows=
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Ver= sion 1.5.0 or earlier 2026-06-15 6.2 CVE-2026-9260 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-9260 ] Canon Inc.--EOS Network Setting Tool for Windo=
ws Use of weak SSH cryptographic algorithms in Canon EOS Network Setting To=
ol Version 1.5.0 or earlier 2026-06-15 6.8 CVE-2026-9261 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-9261 ] Canon Inc.--EOS Network Setting Tool for=
Windows Use of a non-secure protocol as the default FTP configuration in C= anon EOS Network Setting Tool Version 1.5.0 or earlier 2026-06-15 6.5 CVE-2= 026-9262 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9262 ] Cap-go--capgo=
Cap-go capgo before 12.128.2 contains an authorization bypass in several S= upabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_t= otal_metrics) that are granted to the anon role without enforcing org membe= rship or permission checks. An unauthenticated attacker using only the publ=
ic Supabase API key (sb_publishable_*) can query arbitrary org_id values to=
disclose cross-tenant usage telemetry (MAU, bandwidth, installs, gets), en= umerate app IDs for a target org, and determine org existence via an oracle=
(valid org returns metrics, invalid returns []). 2026-06-20 5.3 CVE-2026-5= 6235 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56235 ] Cap-go--capgo Ca= p-go before 12.128.2 contains an information disclosure vulnerability in th=
e OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attac= kers to enumerate valid builder job IDs through observable response discrep= ancies. Attackers can probe the endpoint without authentication to distingu= ish valid job IDs from invalid ones and generate sustained unauthenticated = traffic for resource consumption. 2026-06-21 5.3 CVE-2026-56316 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-56316 ] Cap-go--capgo Capgo before 12.12= 8.2 contains a flaw in the Enforce Password Policy feature: after a Super A= dmin enables the policy and successfully changes their password to a compli= ant one, the backend does not update the password-compliance state. As a re= sult, the backend continues to treat the account as non-compliant and repea= tedly forces password-reset prompts, permanently locking the Super Admin ou=
t of organization access (organization lockout / denial of service) despite=
valid authentication. 2026-06-19 4.9 CVE-2026-56080 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-56080 ] Cap-go--capgo Cap-go before 12.128.12 conta= ins a broken cursor pagination vulnerability in the /private/devices endpoi=
nt on the Cloudflare/workerd path that allows authenticated attackers to ca= use duplicate-page loops and make later rows unreachable. Attackers with ap= p.read_devices access can exploit non-advancing cursor filters to trigger i= nfinite pagination loops, prevent dataset traversal, and cause repeated pro= cessing in device-management workflows. 2026-06-20 4.3 CVE-2026-56307 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-56307 ] capacitor-native-biometric= --capacitor-native-biometric capacitor-native-biometric before 12.128.2 con= tains an authentication bypass vulnerability where the onAuthenticationSucc= eeded() method fails to validate CryptoObject parameters. Attackers can hoo=
k the onAuthenticationSucceeded() function using dynamic instrumentation to=
bypass biometric authentication without valid credentials. 2026-06-20 4.8 = CVE-2026-56294 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56294 ] Capgo-= -Capgo Capgo before 12.128.2 contains a cross-tenant authorization bypass v= ulnerability in PostgREST endpoints that allows org-scoped read API keys to=
access other tenants' webhook secrets and delivery logs. Attackers can que=
ry the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing=
secrets and delivery payloads, enabling forged webhook events against vict=
im organizations. 2026-06-19 6.5 CVE-2026-56079 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-56079 ] Capgo--Capgo Capgo before 12.128.2 contains an a= uthorization bypass vulnerability in the /build/status and /build/logs endp= oints that allows attackers to access build jobs belonging to different app= lications by supplying a mismatched app_id and job_id combination. Limited = API keys restricted to a single app can retrieve build status and logs from=
other apps by providing an authorized app_id while using a job_id from an = unauthorized app, exposing sensitive build information including logs, meta= data, and potentially credentials. 2026-06-21 6.5 CVE-2026-56229 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-56229 ] Capgo--Capgo Capgo before 12.12= 8.2 contains a broken row level security policy in the org_users table that=
allows authenticated users to elevate privileges from admin to super_admin=
. Attackers can exploit the insufficient RLS enforcement to gain unauthoriz=
ed super_admin access and compromise system security. 2026-06-21 6.5 CVE-20= 26-56251 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56251 ] Capgo--Capgo=
Capgo before 12.128.2 contains an authorization bypass vulnerability in we= bhook management endpoints that allows non-expiring API keys to bypass the = require_apikey_expiration organization policy. The checkWebhookPermission f= unction fails to call apikeyHasOrgRightWithPolicy, enabling attackers with = legacy non-expiring keys to list, create, and delete webhooks despite expli= cit organizational policy requiring key expiration. 2026-06-20 6.3 CVE-2026= -56295 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56295 ] Capgo--Capgo C= apgo before 12.128.2 contains an authorization bypass vulnerability in the = public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST = RPC, allowing unauthenticated attackers to insert arbitrary rows into versi= on_meta for any app_id. Attackers can exploit this by calling the RPC endpo= int with a public anon key to poison storage metrics, causing persistent fa= lse data in dashboards and triggering incorrect alerts across victim applic= ations. 2026-06-20 5.3 CVE-2026-56213 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-56213 ] Capgo--Capgo Capgo before 12.128.2 fails to strip EXIF met= adata including GPS geolocation data from uploaded images, allowing informa= tion disclosure. Attackers can download uploaded images and extract precise=
latitude and longitude coordinates revealing user physical location at cap= ture time. 2026-06-20 5.3 CVE-2026-56218 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56218 ] Capgo--Capgo Capgo before 12.128.2 contains a server-si=
de request forgery vulnerability in webhook URL validation that allows loop= back and internal addresses. Organization admins can configure webhooks poi= nting to localhost or 127.0.0.1, and when triggered, the backend performs o= utbound requests to these addresses with error responses disclosed to users=
. 2026-06-20 5.4 CVE-2026-56227 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-56227 ] Capgo--Capgo Capgo before 12.128.2 contains an information discl= osure vulnerability in the unauthenticated /replication endpoint that expos=
es internal PostgreSQL replication telemetry including slot names and WAL L=
SN positions. Attackers can access this endpoint without authentication to = retrieve sensitive infrastructure details such as replication slot names, c= onfirmed_flush_lsn, restart_lsn values, and database error messages for rec= onnaissance purposes. 2026-06-20 5.3 CVE-2026-56282 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-56282 ] Capgo--Capgo Capgo before 12.128.2 contains =
an authentication bypass vulnerability in the /build/upload/:jobId/* endpoi=
nt that allows unauthenticated attackers to trigger consistent 500 errors. = Remote attackers can send OPTIONS requests to bypass authentication middlew= are and invoke tusProxy logic with invalid credentials, enabling trivial re= quest flooding and denial of service. 2026-06-21 5.3 CVE-2026-56299 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-56299 ] Capgo--Capgo Capgo before 12= .128.2 fails to enforce a maximum value on the minimum password length fiel=
d in its password policy configuration. An authenticated organization admin= istrator can set an extremely large numeric value (e.g., billions of charac= ters) as the minimum password length, making compliance impossible for all = organization members. Once the policy is enabled, users (including administ= rators) are unable to change their passwords or access the organization, re= sulting in an organization-wide account lockout and application-level denia=
l of service. 2026-06-20 4.9 CVE-2026-56228 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-56228 ] Capgo--Capgo Capgo before 12.128.2 contains an infor= mation disclosure vulnerability in the GET /statistics/app/:app_id endpoint=
that allows app-limited API keys to distinguish existing sibling app IDs t= hrough differential error responses. Attackers can enumerate real app IDs o= utside their allowed scope by observing 500 PGRST116 errors for inaccessibl=
e apps versus 401 errors for nonexistent apps, breaking tenant isolation. 2= 026-06-20 4.3 CVE-2026-56319 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 56319 ] Capgo--Capgo Capgo before 12.128.2 contains an open redirect vulner= ability in the confirm-signup endpoint that allows attackers to redirect us= ers to arbitrary external websites. The confirmation_url parameter is not v= alidated, enabling attackers to craft malicious links for phishing and cred= ential harvesting attacks. 2026-06-20 4.7 CVE-2026-56332 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-56332 ] capgo--cli Capgo CLI before 12.128.2 co= ntains arbitrary file overwrite vulnerabilities in login and build credenti= als operations that follow symlinks without validation. Attackers can creat=
e malicious symlinks in repositories to overwrite arbitrary files or expose=
credentials with world-readable permissions when developers run the CLI. 2= 026-06-21 6.1 CVE-2026-56236 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 56236 ] carrierwaveuploader--carrierwave CarrierWave is a framework to uplo=
ad files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the = content_type_denylist check fails to escape regex metacharacters in string = entries, causing the denylist to silently not match the content types it is=
intended to block. In lib/carrierwave/uploader/content_type_denylist.rb:57=
, denylist entries are interpolated directly into a regex without Regexp.qu= ote or anchoring, so an entry such as image/svg+xml becomes the pattern /im= age\/svg+xml/, in which + is treated as a quantifier rather than a literal = character and therefore never matches the real MIME type image/svg+xml. Thi=
s is inconsistent with the allowlist implementation, which correctly applie=
s both Regexp.quote and a \A anchor. Other content types containing regex m= etacharacters, such as application/xhtml+xml, are affected as well. As a re= sult, any application that relies on content_type_denylist to block image/s= vg+xml, most commonly to prevent stored XSS, is silently unprotected. An at= tacker can upload an SVG file containing arbitrary JavaScript; if the appli= cation serves that SVG inline from its own origin, the script executes in t=
he victim's browser, resulting in stored XSS. This issue has been fixed in = versions 2.2.7 and 3.1.3. 2026-06-16 4.7 CVE-2026-44587 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-44587 ] Cisco--Cisco Catalyst SD-WAN Manager A v= ulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WA=
N vManage, could allow an authenticated, remote attacker to create a file o=
r overwrite any file on the filesystem of an affected system. This vulnerab= ility exists because the affected software does not properly validate user-= supplied input during a file upload process. An attacker could exploit this=
vulnerability by sending a crafted HTTP request to an affected API endpoin=
t of the affected system. A successful exploit could allow the attacker to = create or overwrite any file on the underlying operating system. This file = could later be used to elevate to root. To exploit this vulnerability, the = attacker must have valid credentials with at least a lower-privileged, sing= le-task user account. 2026-06-15 6.5 CVE-2026-20262 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-20262 ] Cisco--Cisco Crosswork Network Change Automa= tion A vulnerability in the web-based management interface of Cisco Crosswo=
rk Network Controller could allow an authenticated, remote attacker to=
execute arbitrary commands on an affected device. This vulnerability is du=
e to insufficient input validation in the configuration template engin=
e of the web-based management interface. An attacker could exploit this vul= nerability by sending a crafted request to the affected device. A successfu=
l exploit could allow the attacker to execute arbitrary commands on the und= erlying operating system in limited areas of the file system. This vulnerab= ility affects only areas of the operating system for which the template use=
r has write permissions. To exploit this vulnerability, the attacker = must have valid template user credentials with write permissions. Template = users with read permissions cannot exploit this vulnerability. 2026-0= 6-17 6.3 CVE-2026-20220 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20220=
] Cisco--Cisco Umbrella Insights Virtual Appliance A vulnerability in the = vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticate=
d, local attacker to elevate privileges on an affected device. This vulnera= bility is due to insufficient validation of user-supplied commands. An atta= cker with vmadmin privileges could exploit this vulnerability by using cert= ain commands at the CLI. A successful exploit could allow the attacker to e= levate privileges to root. 2026-06-17 6 CVE-2026-20246 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-20246 ] Cisco--Cisco Webex App A vulnerability in=
the browser-based version of Cisco Webex App could have allowed an unauthe= nticated, remote attacker to redirect users to a malicious webpage. Cisco h=
as addressed this vulnerability in the Cisco Webex App, and no customer act= ion is needed. This vulnerability existed due to improper input validation =
of URL parameters in an HTTP request. Prior to this vulnerability being add= ressed, an attacker could have exploited this vulnerability by persuading a=
user to click a crafted URL. A successful exploit could have allowed the a= ttacker to redirect a user to a malicious website. 2026-06-17 4.3 CVE-2026-= 20178 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20178 ] Client Portal L= td.--Client Portal (Pro) CP Client Arbitrary File Download in Client Portal=
(Pro) <=3D 5.6.2 versions. 2026-06-17 6.5 CVE-2026-40724 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-40724 ] Cloud Foundry Foundation--bpm-release = setupBpmLogs follows symlink for bpm.log open and chown - container-to-host=
privilege escalation via /etc/shadow. A compromised process inside a bpm c= ontainer can cause root to chown an arbitrary host file to vcap and append = bpm JSON log lines to it. The chown alone lets the attacker take ownership =
of /etc/shadow and read every password hash on the host via the read-only /= etc bind mount. This is a container-to-host confidentiality break affecting=
every bpm-managed job. Affected versions: bpm-release, all versions prior =
to v1.4.30. 2026-06-18 6.1 CVE-2026-47833 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-47833 ] Cloudflare--Quiche Cloudflare Quiche was affected by 2=
use-after-free vulnerabilities in the connection ID iterator FFI functions=
. The "quiche_connection_id_iter_next" and "quiche_conn_retired_scid_next" = functions would return a pointer to a "ConnectionId" to the applications vi=
a function arguments, but the owned "ConnectionId" would be dropped at the = end of those functions' scope. Only applications using those FFI functions = are affected. The FFI API is disabled by default by a build-time feature fl= ag. Impact If unpatched, an application calling the affected FFI functions = will dereference freed memory. The most likely outcome is undefined behavio=
r leading to a process crash (denial of service). Depending on allocator st= ate, the read may also return adjacent heap contents, resulting in limited = information disclosure or incorrect connection identifier handling. Mitigat= ion Users are requested to upgrade to quiche 0.29.2 which is the earliest v= ersion containing the fix for this issue. 2026-06-19 5.6 CVE-2026-11941 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-11941 ] codepeople--Appointment = Booking Calendar The Appointment Booking Calendar plugin for WordPress is v= ulnerable to Sensitive Information Exposure in versions up to, and includin=
g, 1.4.01. This is due to insufficient authorization and missing per-calend=
ar ownership checks in the cpabc_appointments_calendar_load2() function, wh= ich is reachable via the cpabc_calendar_load2=3D1 query parameter in wp-adm=
in and only checks is_admin() && current_user_can('edit_posts'), a capabili=
ty available to Contributor-level users and above. This makes it possible f=
or authenticated attackers with Contributor-level access and above to suppl=
y an arbitrary calendar ID via the id parameter and extract customer bookin=
g information, including email addresses, names, phone numbers, booking tim= es, and comments, from any calendar managed by the plugin. 2026-06-18 4.3 C= VE-2026-12111 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12111 ] Comfast= --CF-WR631AX V3 A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.=
8. This issue affects the function system of the file /cgi-bin/mbox-config?= section=3Dping_config of the component API Endpoint. This manipulation of t=
he argument destination causes os command injection. The attack is possible=
to be carried out remotely. The exploit has been published and may be used=
. The vendor was contacted early about this disclosure but did not respond =
in any way. 2026-06-21 6.3 CVE-2026-12814 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-12814 ] contrid--Slideshow Gallery LITE The Slideshow Gallery = LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via = the 'alwaysauto' shortcode attribute in all versions up to, and including, = 1.8.5. This is due to insufficient input sanitization and output escaping o=
n user-supplied attributes. This makes it possible for authenticated attack= ers, with Contributor-level access and above, to inject arbitrary web scrip=
ts in pages that will execute whenever a user accesses an injected page. 20= 26-06-18 6.4 CVE-2026-2021 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20=
21 ] coollabsio--coolify A vulnerability has been found in coollabsio cooli=
fy 4.0.0. Impacted is an unknown function of the component Image Name Handl= er. Such manipulation leads to os command injection. The attack may be perf= ormed from remote. The vendor was contacted early about this disclosure but=
did not respond in any way. The changelog for 4.1.2 mentions "[i]mproved i= mage, branch, proxy, and deployment input validation". 2026-06-21 6.3 CVE-2= 026-12815 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12815 ] Cotonti--Co= tonti Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross= -Site Request Forgery in the Personal File Storage (PFS) module. In modules= /pfs/inc/pfs.editfolder.php, the folder update action ('a=3Dupdate') update=
s folder metadata (title, description, public/gallery flags) without callin=
g cot_check_xg() to validate the anti-CSRF token. A remote attacker who lur=
es an authenticated user into visiting a malicious page can force the brows=
er to submit a forged request that modifies the victim's folder metadata, i= ncluding making a private folder public. 2026-06-18 5.4 CVE-2026-55745 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-55745 ] coturn--coturn Coturn is =
a free open source implementation of TURN and STUN Server. Versions prior t=
o 4.11.0 contain a stored cross-site scripting (XSS) vulnerability in the w= eb-admin HTTPS interface. An attacker who can create a TURN allocation with=
a crafted USERNAME value can inject HTML/JavaScript that executes when an = authenticated web-admin user views the TURN session list. In configurations=
using anonymous TURN access (--no-auth), this may be exploitable without T= URN credentials. In authenticated deployments, exploitation requires valid = TURN credentials or control over a provisioned username. This issue has bee=
n fixed in version 4.11.0. 2026-06-18 5.4 CVE-2026-43915 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-43915 ] craftcms--cms Craft CMS from 4.0.0-RC1 = contains an authenticated path traversal vulnerability in the assets/icon e= ndpoint where the extension parameter is not validated before file existenc=
e checks. Attackers can bypass extension validation by passing traversal se= quences that resolve to existing SVG files, allowing local file read access=
. 2026-06-21 6.5 CVE-2026-56394 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-56394 ] craftcms--cms Craft CMS from version 5.0.0-RC1 contains a stored=
cross-site scripting vulnerability in the User Permissions page where user=
group names are rendered without proper HTML escaping. Attackers with admi=
n access can inject arbitrary JavaScript via the user group name field that=
executes when other users view or edit permissions. 2026-06-21 4.8 CVE-202= 6-56381 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56381 ] craftcms--cms=
Craft CMS contains a stored cross-site scripting (XSS) vulnerability in th=
e editableTable.twig component when using the 'Row Heading' column type. Th=
e application fails to sanitize input within row heading default values, al= lowing an attacker with an administrator account (with allowAdminChanges en= abled) to inject arbitrary JavaScript that executes when another user views=
a page containing the affected table field. Affected versions are >=3D 4.5= .0-beta.1 through 4.16.18 and >=3D 5.0.0-RC1 through 5.8.22; fixed in 4.16.=
19 and 5.8.23. 2026-06-21 4.8 CVE-2026-56383 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-56383 ] craftcms--cms Craft CMS contains a missing authoriz= ation vulnerability in the assets/preview-thumb endpoint. A Control Panel u= ser without permission to view a target private asset can call the endpoint=
with an attacker-controlled assetId and receive preview HTML containing a = signed fallback transform preview link for that private asset, because no a= sset-view permission check is performed before preview generation. This aff= ects versions >=3D 4.0.0-RC1, <=3D 4.17.7 and >=3D 5.0.0-RC1, <=3D 5.9.13, = and is fixed in 4.17.8 and 5.9.14. 2026-06-21 4.3 CVE-2026-56384 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-56384 ] craftcms--cms Craft CMS version=
s >=3D 5.0.0-RC1, <=3D 5.9.13 and >=3D 4.0.0-RC1, <=3D 4.17.7 contain an au= thorization bypass in the assets/preview-file endpoint. The action does not=
enforce per-asset view authorization before returning preview content, all= owing an authenticated low-privileged user to supply a controlled assetId f=
or an asset they are not permitted to view and still receive preview respon=
se data (previewHtml), including a private preview image route containing t=
he target private assetId. Fixed in 5.9.14 and 4.17.8. 2026-06-21 4.3 CVE-2= 026-56385 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56385 ] craftcms--c=
ms Craft CMS 4.x (>=3D 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>=3D 5.0.0-RC1,=
< 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabiliti=
es where settings names and field option labels are rendered without saniti= zation (e.g., via the checkbox.twig template, which used {{ label|raw }}). =
An authenticated administrator (with allowAdminChanges enabled) can inject = malicious payloads into section names, volume names, user group names, glob=
al set names, generated field names, checkbox/radio option labels, and cust=
om source labels, causing arbitrary JavaScript to execute in other users' c= ontrol-panel sessions. Fixed in 4.17.0-beta.1 and 5.9.0-beta.1. 2026-06-21 = 4.8 CVE-2026-56393 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56393 ] cr= eativethemeshq--Blocksy Companion The Blocksy Companion plugin for WordPres=
s is vulnerable to Stored Cross-Site Scripting via admin settings in all ve= rsions up to, and including, 2.1.45 due to insufficient input sanitization = and output escaping. This makes it possible for authenticated attackers, wi=
th editor-level permissions and above, to inject arbitrary web scripts in p= ages that will execute whenever a user accesses an injected page. This only=
affects multi-site installations and installations where unfiltered_html h=
as been disabled. 2026-06-19 4.4 CVE-2026-12430 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-12430 ] creavi--Creavi Appointment Booking Calendar The = Appointment Booking Calendar plugin for WordPress is vulnerable to Stored C= ross-Site Scripting via custom booking field labels in all versions up to, = and including, 1.4.4 due to insufficient input sanitization and output esca= ping. This makes it possible for authenticated attackers, with Author-level=
access and above, to inject arbitrary web scripts in pages that will execu=
te whenever a user accesses an injected page. 2026-06-19 6.4 CVE-2026-1856 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-1856 ] deepakkite--Secure Cli= ent Portal and Private File Sharing Plugin User Private Files The File Shar= ing & Download Manager - User Private Files plugin for WordPress is vulnera= ble to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all vers= ions up to, and including, 2.1.6 due to insufficient input sanitization and=
output escaping. This makes it possible for authenticated attackers, with = subscriber-level access and above, to inject arbitrary web scripts in pages=
that will execute whenever a user accesses an injected page. 2026-06-16 6.=
4 CVE-2026-10093 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10093 ] Dell= --Peripheral Manager Dell Peripheral Manager, versions prior to 1.7.3, cont= ain an uncontrolled search path element vulnerability. An attacker could po= tentially exploit this vulnerability through preloading malicious dll., lea= ding to arbitrary code execution. 2026-06-16 6.7 CVE-2024-22447 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2024-22447 ] Dell--Peripheral Manager Dell Pe= ripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled sea= rch path element vulnerability. An attacker could potentially exploit this = vulnerability through preloading malicious executable, leading to arbitrary=
code execution. 2026-06-16 6.7 CVE-2024-22451 [
https://www.cve.org/CVERec= ord?id=3DCVE-2024-22451 ] Dell--PowerFlex Dell PowerFlex Manager, version(s=
) [Versions], contain(s) an Improper Access Control vulnerability. A low pr= ivileged attacker with adjacent network access could potentially exploit th=
is vulnerability, leading to Elevation of privileges and Unauthorized acces=
s. 2026-06-17 5.7 CVE-2026-35067 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-35067 ] Dell--PowerFlex Dell PowerFlex Manager, version(s) [Versions], = contain(s) an Improper Neutralization of Special Elements used in an SQL Co= mmand ('SQL Injection') vulnerability. A low privileged attacker with adjac= ent network access could potentially exploit this vulnerability, leading to=
Script injection. 2026-06-17 5.7 CVE-2026-35069 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-35069 ] Dell--PowerFlex Dell PowerFlex Manager, version= (s) [Versions], contain(s) an Improper Access Control vulnerability. A low = privileged attacker with remote access could potentially exploit this vulne= rability, leading to denial of service. 2026-06-17 4.3 CVE-2026-35162 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-35162 ] Dell--PowerFlex Dell Power= Flex Manager, version(s) 4.6.0.1, contain(s) an Use of a Broken or Risky Cr= yptographic Algorithm vulnerability. An unauthenticated attacker with remot=
e access could potentially exploit this vulnerability, leading to Informati=
on disclosure and Information tampering. 2026-06-17 4.8 CVE-2026-40641 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-40641 ] Dell--PowerFlex Manager D= ell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certi= ficate validation vulnerability. A remote unauthenticated attacker could po= tentially exploit this vulnerability leading to man-in-the-middle attack in=
tandem with DNS cache poisoning. 2026-06-17 6.5 CVE-2024-47477 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2024-47477 ] Dell--PowerFlex rack Dell PowerF= lex rack, version(s) RCM 3.7/3.7, contain(s) a Host Header Injection vulner= ability. An unauthenticated attacker with remote access could potentially e= xploit this vulnerability to trigger redirections. 2026-06-17 4.3 CVE-2025-= 32748 [
https://www.cve.org/CVERecord?id=3DCVE-2025-32748 ] Dell--PowerStor=
e PowerStore contains a Stored Cross-Site Scripting Vulnerability in the Po= werStore Manager. A remote authenticated low-privileged malicious actor cou=
ld potentially exploit this vulnerability, it could lead to script executio=
n in the client browser. 2026-06-16 5.4 CVE-2024-30476 [
https://www.cve.or= g/CVERecord?id=3DCVE-2024-30476 ] dijitul--Fancy Testimonials The Fancy Tes= timonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting=
via the 'author' shortcode attribute in the 'testimonial' shortcode in all=
versions up to, and including, 1.0 due to insufficient input sanitization = and output escaping. This makes it possible for authenticated attackers, wi=
th Contributor-level access and above, to inject arbitrary web scripts in p= ages that will execute whenever a user accesses an injected page. 2026-06-1=
8 6.4 CVE-2026-8039 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8039 ] Di= scuz!--Discuz! X5.0 Discuz! X5.0 releases 20260320 through 20260610 contain=
s a CAPTCHA bypass vulnerability that allows unauthenticated remote attacke=
rs to defeat challenge controls by exploiting limited complexity and predic= table character sets in generated CAPTCHA images. Attackers can train a cus= tom optical character recognition model against collected CAPTCHA samples t=
o reliably predict challenge text, bypassing protections on login, registra= tion, and other functionality from automated abuse. 2026-06-15 6.5 CVE-2026= -49953 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49953 ] dokaninc--Doka=
n: AI Powered WooCommerce Multivendor Marketplace Solution Build Your Own A= mazon, eBay, Etsy The Dokan: AI Powered WooCommerce Multivendor Marketplace=
Solution - Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulne= rable to Insecure Direct Object Reference in all versions up to, and includ= ing, 5.0.3 via the change_order_status, add_order_note, delete_order_note, = add_shipping_tracking_info, grant_access_to_download, and revoke_access_to_= download AJAX handlers due to missing ownership validation on a user-contro= lled order ID key. This makes it possible for authenticated attackers, with=
custom vendor-level access and above, to modify the status of arbitrary or= ders, add attacker-controlled notes to any order (including customer-facing=
notes that trigger WooCommerce notification emails to buyers), delete any = order note or WordPress comment by ID regardless of ownership, inject fake = shipping tracking information on any order, and grant or revoke downloadabl= e-product permissions on any order in the marketplace. Critically, nonce va= lidity is not a barrier to exploitation: each of these AJAX handlers genera= tes and embeds its nonce on the authenticated vendor's own dashboard order = pages (e.g., /dashboard/orders/?order_id=3DOWN_ORDER_ID), which the attacke=
r legitimately controls. The attacker harvests a valid nonce from their own=
order detail page and replays it against a victim order ID - the nonce onl=
y proves the request originates from a logged-in session, not that the orde=
r belongs to that vendor. This directly rebuts the prior rejection reasonin=
g that 'users cannot generate valid nonces on command': vendor users can an=
d do generate valid nonces on demand simply by loading their own dashboard = pages. Source-code analysis confirmed the vulnerable code path is present a=
nd unpatched through version 5.0.1. 2026-06-18 4.3 CVE-2026-10023 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-10023 ] dwbooster--Booking Calendar Co= ntact Form WordPress Booking Calendar Contact Form 1.0.23 contains privileg=
e escalation and stored cross-site scripting vulnerabilities that allow aut= henticated users to modify plugin options and inject malicious scripts by f= ailing to verify user privileges and sanitize input parameters. Attackers w= ith subscriber-level accounts can inject XSS payloads through parameters li=
ke price, name, calendar_language, and email_confirmation_to_user via admin= -ajax.php and admin.php endpoints to execute arbitrary JavaScript in admini= strator browsers. 2026-06-15 6.4 CVE-2016-20070 [
https://www.cve.org/CVERe= cord?id=3DCVE-2016-20070 ] dwbooster--CP Polls WordPress CP Polls 1.0.8 con= tains a cross-site request forgery vulnerability that allows attackers to p= erform unauthorized actions on behalf of authenticated users. Attackers can=
craft malicious HTML pages that execute unwanted poll operations when admi= nistrators visit the page while logged in. 2026-06-15 4.3 CVE-2016-20067 [ =
https://www.cve.org/CVERecord?id=3DCVE-2016-20067 ] Edimax--BR-6478AC V2 A = vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the funct= ion setWAN of the file /goform/setWAN of the component POST Request Handler=
. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName re= sults in command injection. It is possible to launch the attack remotely. T=
he exploit has been made public and could be used. The vendor was contacted=
early about this disclosure but did not respond in any way. 2026-06-21 6.3=
CVE-2026-12807 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12807 ] Edima= x--BR-6478AC V2 A vulnerability was determined in Edimax BR-6478AC V2 1.23.=
This impacts the function stainfo of the file /goform/stainfo of the compo= nent POST Request Handler. This manipulation of the argument interface caus=
es command injection. The attack can be initiated remotely. The exploit has=
been publicly disclosed and may be utilized. The vendor was contacted earl=
y about this disclosure but did not respond in any way. 2026-06-21 6.3 CVE-= 2026-12808 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12808 ] Edimax--BR= -6478AC V2 A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affe= cted is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirec=
t of the component POST Request Handler. Such manipulation of the argument = newpass leads to command injection. The attack can be launched remotely. Th=
e exploit is publicly available and might be used. The vendor was contacted=
early about this disclosure but did not respond in any way. 2026-06-21 6.3=
CVE-2026-12809 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12809 ] Edima= x--BR-6478AC V2 A security flaw has been discovered in Edimax BR-6478AC V2 = 1.23. Affected by this vulnerability is the function mp of the file /goform= /mp of the component POST Request Handler. Performing a manipulation of the=
argument command results in command injection. The attack may be initiated=
remotely. The exploit has been released to the public and may be used for = attacks. The vendor was contacted early about this disclosure but did not r= espond in any way. 2026-06-21 6.3 CVE-2026-12810 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-12810 ] eemitch--Simple File List The Simple File List = plugin for WordPress is vulnerable to unauthorized file operations due to a=
missing authorization check on the 'frontmanage' shortcode attribute in al=
l versions up to, and including, 6.3.7. This makes it possible for authenti= cated attackers, with contributor-level access and above, to perform arbitr= ary file operations including deletion, move, folder creation, and download=
. An attacker can create a draft post containing the 'eeSFL' shortcode, ren= der it via the post preview endpoint to harvest the nonce needed to authori=
ze the operations, and then submit file operation requests that bypass the = intended authorization checks in includes/ee-list-ops-bar-process.php. 2026= -06-20 6.5 CVE-2026-12119 [
https://www.cve.org/CVERecord?id=3DCVE-2026-121=
19 ] eLightUp--Meta Box WordPress Custom Fields Framework Contributor Arbit= rary File Deletion in Meta Box - WordPress Custom Fields Framework <=3D 5.1= 1.1 versions. 2026-06-15 6.8 CVE-2026-39468 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-39468 ] equalizedigital--Equalize Digital Accessibility Chec= ker WCAG, ADA, EAA and Section 508 compliance The Equalize Digital Accessib= ility Checker - WCAG, ADA, EAA and Section 508 compliance plugin for WordPr= ess is vulnerable to authorization bypass in all versions up to, and includ= ing, 1.42.1. This is due to the plugin not properly verifying that a user i=
s authorized to perform an action. This makes it possible for authenticated=
attackers, with author-level access and above, to dismiss, ignore, or rest= ore accessibility audit issue records belonging to posts they are not permi= tted to edit by supplying an issue from their own post as an authorization = token to affect matching issues across the entire site. An Author-level use=
r can exploit this by passing largeBatch=3Dtrue on a dismiss-issue request = referencing one of their own post's issues, causing the handler to bulk-mod= ify all site-wide accessibility issues sharing the same 'object' value - in= cluding those belonging to administrator-owned posts. 2026-06-18 4.3 CVE-20= 26-9199 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9199 ] eventkoi--Even=
t Koi Lite Events Calendar, Event Management, RSVP, and Tickets The Event K=
oi Lite - Events Calendar, Event Management, RSVP, and Tickets plugin for W= ordPress is vulnerable to Sensitive Information Exposure in all versions up=
to, and including, 1.3.13.1 via the get_events. This makes it possible for=
unauthenticated attackers to extract sensitive data including virtual meet= ing URLs, physical location data, latitude/longitude coordinates, Google Ma=
ps links, and RSVP configuration belonging to draft, pending, and private e= vents that are otherwise inaccessible via public URLs. 2026-06-18 5.3 CVE-2= 026-10029 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10029 ] Extend Them= es--Skyline WP Cross-Site request forgery (CSRF) vulnerability in Extend Th= emes Skyline WP allows Cross Site Request Forgery. This issue affects Skyli=
ne WP: from n/a through 1.0.10. 2026-06-17 4.3 CVE-2024-34810 [
https://www= .cve.org/CVERecord?id=3DCVE-2024-34810 ] F5--NGINX Gateway Fabric When NGIN=
X Gateway Fabric is configured using GRPCRoutes, an authenticated, remote a= ttacker with permission to create or modify GRPCRoute resources can cause t=
he NGINX Gateway Fabric control plane to terminate by sending undisclosed G= RPCRoute configurations containing backendRef filters. Note: Software versi= ons which have reached End of Technical Support (EoTS) are not evaluated. 2= 026-06-17 6.5 CVE-2026-32682 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 32682 ] F5--NGINX Open Source NGINX Plus and NGINX Open Source have a vulne= rability in the ngx_http_charset_module=C2=A0module. When content is served=
or proxied through a location block with both source_charset=C2=A0utf-8; a=
nd a charset=C2=A0directive (for example, charset koi8-r;) configured, remo= te, unauthenticated attackers can send requests (in conjunction with condit= ions beyond their control) to cause a heap buffer over-read in the NGINX wo= rker process, leading to limited disclosure of memory or a restart. Note: S= oftware versions which have reached End of Technical Support (EoTS) are not=
evaluated. 2026-06-17 4.8 CVE-2026-48142 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-48142 ] fduflyer--DroneAware-Node-Releases DroneAware is a dro=
ne detection platform. The centralized DroneAware server backing droneaware= .io was vulnerable to an account pre-hijacking attack in which an attacker = could register an account using a victim's email address with an attacker-c= ontrolled password before the victim completed account activation. When the=
legitimate owner later activated the account, either by clicking the email=
verification link or by logging in via Google SSO, the attacker-set passwo=
rd became fully valid, enabling silent and persistent account takeover with= out any notification to the victim. The vulnerability was fixed server-side=
on 2025-05-20; no user action is required. Node binaries and self-hosted d= etection nodes are not affected. There are no workarounds; the fix was depl= oyed server-side and no client-side mitigation is applicable. 2026-06-17 6.=
8 CVE-2026-48117 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48117 ] fire= plugins--FireBox Popups Increase Sales and Grow Your Email List The FireBox=
Popups - Increase Sales and Grow Your Email List plugin for WordPress is v= ulnerable to Sensitive Information Exposure in all versions up to, and incl= uding, 3.1.7 via the 'form_id' parameter. This makes it possible for unauth= enticated attackers to extract download a full CSV export of all form submi= ssions - including any personally identifiable information submitted by use=
rs - for any arbitrary form_id. 2026-06-18 5.3 CVE-2026-12120 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-12120 ] Flowise--Flowise Flowise before 3.= 0.8 contains a cross-site scripting (XSS) vulnerability caused by insuffici= ent input filtering in chat messages and custom agent functions. An attacke=
r can inject malicious JavaScript by sending an iframe payload (e.g., <ifra=
me src=3D"javascript:alert(document.cookie)">) in a chat box, or by having =
a custom agent function return an XSS payload from an external website. The=
injected script executes in the victim's browser, enabling theft of cookie=
s and session data. 2026-06-20 6.1 CVE-2025-71331 [
https://www.cve.org/CVE= Record?id=3DCVE-2025-71331 ] FlowiseAI--Flowise A vulnerability was determi= ned in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown fu= nction of the file packages/components/nodes/documentloaders/S3/S3.ts of th=
e component S3 Document Loader. Executing a manipulation can lead to path t= raversal. It is possible to launch the attack remotely. The vendor was cont= acted early about this disclosure but did not respond in any way. 2026-06-2=
1 6.3 CVE-2026-12821 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12821 ] = FluxBuilder--MStore API Authentication Bypass Using an Alternate Path or Ch= annel vulnerability in FluxBuilder MStore API allows Password Recovery Expl= oitation. This issue affects MStore API: from n/a through 4.18.4. 2026-06-1=
7 6.5 CVE-2026-54817 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54817 ] = FolioVision--FV Flowplayer Video Player Subscriber Cross Site Scripting (XS=
S) in FV Flowplayer Video Player < 7.5.51.7212 versions. 2026-06-15 6.5 CVE= -2026-49773 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49773 ] geoserver= --org.geoserver.web:gs-web-app GeoServer is an open source server that allo=
ws users to share and edit geospatial data. Prior to versions 2.26.4 and 2.= 27.3, a GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` may allow attacke=
r to perform unauthenticated Server-Side Request Forgery (SSRF). This vulne= rability requires that GeoServer is set up to use a proxy base URL and the = `ENTITY_RESOLUTION_ALLOWLIST` (default since 2.25.0). Versions 2.26.4 and 2= .27.3 contain a fix. GeoServer installations are only affected by this vuln= erability if they use a proxy base URL that does not contain a URL path or = end with a slash. If the proxy base URL does not contain a path, adding a s= lash to the end of the URL will mitigate this vulnerability. 2026-06-18 6.5=
CVE-2025-58175 [
https://www.cve.org/CVERecord?id=3DCVE-2025-58175 ] gitro= omhq--postiz-app Postiz is an AI social media scheduling tool. Versions pri=
or to 2.21.8 contained an unauthenticated endpoint that accepted a signed t= oken and applied subscription-enforcement side effects to the organization = referenced in that token's claims, without verifying the token's intended p= urpose. The endpoint, /public/modify-subscription, could not change the per= sisted subscription tier, but it did execute enforcement-related side effec=
ts on the caller's own organization, including adjusting team-member enable= ment state, disabling integrations exceeding the asserted plan's limits, an=
d resetting the scheduled-post cron when the asserted plan was the free tie=
r. Impact is limited to the attacker's own organization and cannot be redir= ected at other tenants through this endpoint. This issue has been fixed in = version 2.21.8. 2026-06-16 4.8 CVE-2026-48783 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-48783 ] GNOME--Evolution Data Server A flaw was found in e= volution-data-server. Inconsistent comparison logic in the addressbook file=
backend allows a Flatpak application with D-Bus access to craft a maliciou=
s URI containing directory traversal sequences. This URI is stored without = proper validation during contact creation or modification. Later, during co= ntact deletion, the URI is processed with a less strict check, leading to t=
he deletion of arbitrary files on the host filesystem. This could potential=
ly include critical Flatpak override files. 2026-06-16 5.6 CVE-2026-2604 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-2604 ] Government Accountabilit=
y Office--Electronic Protest Docketing System (EPDS) The U.S. Government Ac= countability Office (GAO) Electronic Protest Docketing System (EPDS) and Ci= vilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) e= xpose sensitive account information through the 'update-profile/' API endpo= int. A remote, unauthenticated attacker can submit a request containing an = arbitrary 'user_id' parameter and receive a JSON response containing accoun= t-specific information, including the associated email address. 2026-06-18 = 5.3 CVE-2026-54105 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54105 ] Go= vernment Accountability Office--Electronic Protest Docketing System (EPDS) = The U.S. Government Accountability Office (GAO) Electronic Protest Docketin=
g System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Do= cketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing=
a remote attacker with compromised administrator credentials to bypass net= work access controls and log in. 2026-06-18 4.7 CVE-2026-54106 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-54106 ] Grafana--Enterprise Traces (GET) =
A TraceQL query in Grafana Tempo with a large exemplars hint value can caus=
e the Tempo instance to allocate an excessive amount of memory, resulting i=
n an out-of-memory crash. This could allow an authenticated user to trigger=
a denial of service against the Tempo service. 2026-06-19 6.5 CVE-2026-278=
78 [
https://www.cve.org/CVERecord?id=3DCVE-2026-27878 ] Greg Winiarski--WP= Adverts Unauthenticated Broken Access Control in WPAdverts <=3D 2.3.0 versi= ons. 2026-06-15 6.5 CVE-2026-40782 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-40782 ] Grit42--Grit A vulnerability was identified in Grit42 Grit up=
to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity o=
f the file modules/assays/backend/app/models/grit/assays/data_table_entity.= rb. The manipulation leads to sql injection. The attack is possible to be c= arried out remotely. The exploit is publicly available and might be used. T=
he vendor was contacted early about this disclosure but did not respond in = any way. 2026-06-15 6.3 CVE-2026-12206 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12206 ] Groundhogg--Groundhogg Subscriber Broken Access Control=
in Groundhogg < 4.4.1 versions. 2026-06-15 6.5 CVE-2026-40793 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-40793 ] Hackplayers--evil-winrm Evil-WinR=
M through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerabi= lity in the download_dir() function that allows a rogue or compromised remo=
te Windows server to write files outside the intended download directory by=
returning filenames with traversal sequences from Get-ChildItem command ou= tput that are passed unsanitized to File.join(). Attackers controlling the = remote server can exploit this to overwrite sensitive client-side files suc=
h as SSH authorized_keys or shell configuration files, achieving persistent=
access or privilege escalation on the client machine. 2026-06-17 6.8 CVE-2= 026-55201 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55201 ] harttle--li= quidjs LiquidJS is a Shopify/GitHub Pages compatible template engine writte=
n in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS thro= ugh a flaw in the strip_html filter logic. The strip_html filter is intende=
d to remove HTML tags from a string before rendering, and is widely used as=
an XSS sanitizer. The implementation uses a regex whose catch-all branch (= <.*?>) does not match line terminators, so any HTML tag containing a \n or =
\r character passes through unmodified. An attacker who can place a newline=
inside a tag (e.g. <img\nsrc=3Dx\nonerror=3Dalert(1)>) bypasses sanitizati=
on entirely, since browsers treat newlines as whitespace within a tag and e= xecute the resulting onerror/onload/etc. handler. Exploitation is possible = for applications that both render attacker-controlled strings via {{ x | st= rip_html }} to defend against HTML injection and do not separately HTML-esc= ape that output (default behavior - outputEscape is unset by default). This=
issue has been fixed in version 10.26.0. 2026-06-17 6.1 CVE-2026-44644 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-44644 ] harttle--liquidjs Liquid=
JS is a Shopify/GitHub Pages compatible template engine written in pure Jav= aScript. In versions 10.25.7 and below, the renderLimit option can be fully=
bypassed by a {% for %} (or {% tablerow %}) tag whose body is empty. The r= enderLimit option is documented in docs/source/tutorials/dos.md as the mech= anism that "mitigates this by limiting the time consumed by each render() c= all." The per-iteration time check is reached only when the body contains a=
t least one template node, so a template such as {%- for i in (1..N) -%}{%-=
endfor -%} iterates the full collection without ever consulting renderLimi=
t. With a configured renderLimit of 50 ms, a single parseAndRenderSync call=
has been observed to consume 2.26 seconds (~45=C3=83=E2=80=94 over the lim= it) and scales linearly with N up to memoryLimit, allowing a low-privileged=
template author to wedge an event-loop thread for an attacker-chosen durat= ion. Deployments that rely on a finite renderLimit for DoS protection (comm=
on in multi-tenant template-authoring environments) can still be forced by =
a single crafted template to monopolize a Node.js event-loop worker for att= acker-controlled time, potentially stalling in-flight requests, with availa= bility impact only. This issue has been fixed in version 10.26.0. 2026-06-1=
7 6.5 CVE-2026-44645 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44645 ] = harttle--liquidjs LiquidJS is a Shopify/GitHub Pages compatible template en= gine written in pure JavaScript. In versions 10.25.7 and below, Context.spa= wn() creates a child Context for the {% render %} tag but does not propagat=
e the parent context's resolved ownPropertyOnly value, resulting in a silen=
t bypass. The new context re-derives ownPropertyOnly from opts.ownPropertyO= nly (the instance-level option), silently discarding any RenderOptions.ownP= ropertyOnly override that was supplied to parseAndRender(). As a result, a = developer who runs a Liquid instance with the backwards-compatible ownPrope= rtyOnly:false and then locks down an untrusted render with parseAndRender(.= .., { ownPropertyOnly: true }) still leaks prototype-chain properties from = inside any {% render %} partial. This is a distinct exploit surface from th=
e previously identified array-filter variants (where, reject, group_by, fin=
d, find_index, has) - the underlying root cause in Context.spawn() is share=
d, but {% render %} is a separately reachable sink that needs no filter usa= ge. This issue has been fixed in version 10.26.0. 2026-06-17 5.3 CVE-2026-4= 4646 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44646 ] hashgraph--guard= ian Hashgraph Guardian through 3.5.0, fixed in commit ba8c566, contains a s= tored cross-site scripting vulnerability that allows authenticated users wi=
th the STANDARD_REGISTRY role to inject malicious scripts by submitting a c= rafted companyName value via the branding configuration API endpoint. Attac= kers can exploit the unsanitized innerHTML assignment in the branding servi=
ce to execute arbitrary JavaScript in the browser of every authenticated us=
er on every page load. 2026-06-18 4.8 CVE-2026-22674 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-22674 ] hcengineering--Huly Platform A vulnerabilit=
y has been found in hcengineering Huly Platform up to 0.7.0. Affected is th=
e function getMailboxSecret of the file server/account/src/operations.ts of=
the component RPC Interface. The manipulation leads to improper access con= trols. The attack may be initiated remotely. The exploit has been disclosed=
to the public and may be used. The vendor was contacted early about this d= isclosure but did not respond in any way. 2026-06-15 4.3 CVE-2026-12212 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-12212 ] hcengineering--Huly Plat= form A vulnerability was found in hcengineering Huly Platform up to 0.7.0. = Affected by this vulnerability is the function getAccountInfo of the file s= erver/account/src/operations.ts of the component User Information Handler. = The manipulation results in improper authorization. The attack may be launc= hed remotely. The exploit has been made public and could be used. The vendo=
r was contacted early about this disclosure but did not respond in any way.=
2026-06-15 4.3 CVE-2026-12213 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-12213 ] HCL Software--ZIE HCL ZIE for Web is affetced by an Unrestricted = File Upload vulnerability, If the server is configured to execute code, the=
n it may be possible to obtain command execution on the server by uploading=
a file known as a web shell, which allows you to execute arbitrary code or=
operating system commands. For this attack to be successful, the file need=
s to be uploaded inside the Webroot, and the server must be configured to e= xecute the code 2026-06-17 4.3 CVE-2025-59872 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2025-59872 ] HCLSoftware--Verse for Android The compose-rich-ed= itor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email = composition fails to properly validate all HTML input thereby allowing mali= cious content to be executed in certain situations. 2026-06-19 6.3 CVE-2026= -21768 [
https://www.cve.org/CVERecord?id=3DCVE-2026-21768 ] henrikmelin--M= ore Fields WordPress More Fields Plugin 2.1 contains a cross-site request f= orgery vulnerability that allows attackers to perform unauthorized actions =
by disabling CSRF token validation. Attackers can craft malicious web pages=
that trick logged-in administrators into adding or deleting custom fields = and boxes on the Write/Edit page via POST and GET requests to the options-g= eneral.php endpoint. 2026-06-15 5.3 CVE-2016-20083 [
https://www.cve.org/CV= ERecord?id=3DCVE-2016-20083 ] Henrique Dias--IMDb Profile Widget WordPress = IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability tha=
t allows unauthenticated attackers to read arbitrary files by manipulating = the url parameter. Attackers can supply directory traversal sequences in GE=
T requests to pic.php to access sensitive files like wp-config.php containi=
ng database credentials and configuration data. 2026-06-15 6.2 CVE-2016-200=
78 [
https://www.cve.org/CVERecord?id=3DCVE-2016-20078 ] HKUDS--AI-Trader A=
vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365= c8544678a16e215. This affects an unknown part of the file /api/research/age= nts.csv of the component Research Export. Performing a manipulation results=
in information disclosure. Remote exploitation of the attack is possible. = The exploit has been made public and could be used. This product follows a = rolling release approach for continuous delivery, so version details for af= fected or updated releases are not provided. The patch is named 91a31aac1b0= f4dbc6b8bef9f6eff0b7912e0bc65. Applying a patch is the recommended action t=
o fix this issue. The vendor confirms: "Research export endpoints now requi=
re an authenticated agent with the research_exports capability". 2026-06-15=
5.3 CVE-2026-12203 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12203 ] I= LIAS--Learning Management System A vulnerability was identified in ILIAS Le= arning Management System 11.0. This issue affects the function ilTrQuery::e= xecuteQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery= .php of the component Learning Progress Tracking. Such manipulation of the = argument troup_table_nav leads to sql injection. It is possible to launch t=
he attack remotely. The exploit is publicly available and might be used. Th=
e vendor was contacted early about this disclosure but did not respond in a=
ny way. 2026-06-21 4.7 CVE-2026-12789 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-12789 ] info@welcart--Welcart e-Commerce Unauthenticated Broken Ac= cess Control in Welcart e-Commerce <=3D 2.11.28 versions. 2026-06-15 6.5 CV= E-2026-49775 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49775 ] Inisev--= Social Media & Share Icons : Missing Authorization vulnerability in Inisev = Social Media & Share Icons allows Exploiting Incorrectly Configured Access = Control Security Levels. This issue affects Social Media & Share Icons: fro=
m n/a through 2.8.6. 2026-06-17 4.3 CVE-2024-31435 [
https://www.cve.org/CV= ERecord?id=3DCVE-2024-31435 ] IObit--Malware Fighter A flaw has been found =
in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an=
unknown functionality of the component DLL Handler. This manipulation caus=
es permission issues. The attack requires local access. The exploit has bee=
n published and may be used. The vendor was contacted early about this disc= losure but did not respond in any way. 2026-06-15 5.3 CVE-2026-12201 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-12201 ] Iqonic Design--KiviCare Sub= scriber Insecure Direct Object References (IDOR) in KiviCare <=3D 4.2.1 ver= sions. 2026-06-15 6.3 CVE-2026-40792 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-40792 ] j_3rk--Video Conferencing with Zoom The Video Conferencing = with Zoom plugin for WordPress is vulnerable to authorization bypass in all=
versions up to, and including, 4.6.7. This is due to the plugin not proper=
ly verifying that a user is authorized to perform an action. This makes it = possible for unauthenticated attackers to obtain the site's Zoom SDK API ke=
y and a freshly-signed JWT that can be used with the Zoom Web SDK to join a=
ny Zoom meeting associated with those credentials without a legitimate invi= tation. 2026-06-16 5.3 CVE-2026-6964 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-6964 ] jamie--Dharma Booking WordPress Dharma Booking 2.28.3 and ea= rlier contains a local file inclusion vulnerability that allows unauthentic= ated attackers to include arbitrary files by manipulating the gateway param= eter. Attackers can supply file paths with directory traversal sequences or=
null byte injection to the gateway parameter in proccess.php to read sensi= tive files like configuration and system files. 2026-06-15 6.2 CVE-2016-200=
79 [
https://www.cve.org/CVERecord?id=3DCVE-2016-20079 ] Jegstudio--Startup=
zy Missing Authorization vulnerability in Jegstudio Startupzy startupzy all= ows Exploiting Incorrectly Configured Access Control Security Levels. This = issue affects Startupzy: from n/a through 1.1.1. 2026-06-17 4.3 CVE-2024-33= 685 [
https://www.cve.org/CVERecord?id=3DCVE-2024-33685 ] Jetmonsters--JetF= ormBuilder Subscriber Privilege Escalation in JetFormBuilder <=3D 3.6.1 ver= sions. 2026-06-17 6.8 CVE-2026-54196 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-54196 ] jgwhite33--WP Google Review Slider Unauthenticated Cross Si=
te Scripting (XSS) in WP Google Review Slider <=3D 18.0 versions. 2026-06-1=
5 6.3 CVE-2026-39451 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39451 ] = Joomtech--Easy Shop Joomla! Component Easy Shop 1.2.3 contains a local file=
inclusion vulnerability that allows unauthenticated attackers to read arbi= trary files by supplying base64-encoded file paths. Attackers can send GET = requests to index.php with the option parameter set to com_easyshop, task s=
et to ajax.loadImage, and a base64-encoded file path in the file parameter =
to retrieve sensitive files like configuration.php and system files. 2026-0= 6-19 6.2 CVE-2019-25760 [
https://www.cve.org/CVERecord?id=3DCVE-2019-25760=
] jsonata-js--jsonata A weakness has been identified in jsonata-js jsonata=
up to 2.2.0. The affected element is the function createFrame of the file = src/jsonata.js of the component Function Binding Frame System. This manipul= ation causes improperly controlled modification of object prototype attribu= tes. It is possible to initiate the attack remotely. The exploit has been m= ade available to the public and could be used for attacks. The vendor was c= ontacted early about this disclosure but did not respond in any way. 2026-0= 6-15 5.3 CVE-2026-12208 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12208=
] Jthemes--Genemy Subscriber Broken Access Control in Genemy <=3D 1.6.6 ve= rsions. 2026-06-16 6.5 CVE-2025-69137 [
https://www.cve.org/CVERecord?id=3D= CVE-2025-69137 ] juice-shop--multi-juicer MultiJuicer is used to run separa=
te Juice Shop instances on a central kubernetes cluster without the need fo=
r local instances. In versions 8.0.0 through 10.0.0, the team join endpoint=
(POST /multi-juicer/api/teams/{team}/join) accepted requests with any Cont= ent-Type, including text/plain. Because that content type does not trigger =
a CORS preflight, an attacker could host a cross-site HTML form that auto-s= ubmits to the endpoint and forces a victim's browser to log in as the attac= ker's team. A successful, undetected attacker can cause victims to unwittin= gly solve Juice Shop challenges under the attacker's team identity. In a CT=
F context this lets the attacker inflate their team's score using other pla= yers' activity, and any sensitive data the victim enters into "their" Juice=
Shop ends up in the attacker's instance. The vulnerability is exploitable = without any prior authentication; the victim only needs to visit a page the=
attacker controls while having network access to the MultiJuicer deploymen=
t. SameSite=3DStrict on the session cookie does not mitigate this, because = the attack plants a new cookie rather than relying on an existing one. This=
issue was fixed in version 10.0.1. 2026-06-15 4.3 CVE-2026-48518 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-48518 ] KaymeePhotography--Photocart L= ink WordPress Plugin Photocart Link 1.6 contains a local file inclusion vul= nerability that allows unauthenticated attackers to read arbitrary files by=
exploiting insufficient input validation in decode.php. Attackers can supp=
ly base64-encoded file paths in the 'id' parameter to the decode.php endpoi=
nt to retrieve sensitive files like wp-config.php containing database crede= ntials and configuration data. 2026-06-15 6.2 CVE-2016-20077 [
https://www.= cve.org/CVERecord?id=3DCVE-2016-20077 ] kestra-io--kestra Kestra is an open= -source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2= .19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file name=
s directly under the task working directory. When a flow forwards untrusted=
execution or webhook data into an `inputFiles` file name, a caller can use=
`../` path segments to create or overwrite files outside that task working=
directory on the worker filesystem. Versions 1.3.19, 1.2.19, 1.1.19, and 1= .0.43 patch the issue. 2026-06-19 6.5 CVE-2026-48129 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-48129 ] King Addons--King Addons for Elementor Subs= criber Cross Site Scripting (XSS) in King Addons for Elementor <=3D 51.1.62=
versions. 2026-06-15 6.5 CVE-2026-48870 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-48870 ] Kludex--starlette Starlette is a lightweight ASGI frame= work/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTP= Endpoint selects the handler by lowercasing the HTTP method and looking it =
up as an attribute with getattr, without restricting the lookup to a known = set of HTTP verbs. When an HTTPEndpoint subclass is registered through Rout= e(...) without an explicit methods=3D argument, the route does not constrai=
n the method and every method reaches the endpoint. If a non-standard HTTP = method whose lowercased name matches an attribute on the endpoint subclass = reaches the endpoint, that attribute is invoked as if it were a request han= dler. An attacker can use this to reach methods that were never meant to be=
HTTP handlers, such as internal helpers, without the authorization checks = applied by the intended public handler. An application (including Starlette= -based frameworks like FastAPI) is affected if it registers an HTTPEndpoint=
subclass via Route(...) without explicitly setting methods=3D, and that su= bclass includes extra methods named like non-standard HTTP verbs that take = one request argument and return a response. This issue has been fixed in ve= rsion 1.1.0. 2026-06-17 5.3 CVE-2026-48817 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-48817 ] kortix-ai--suna A weakness has been identified in kor= tix-ai suna up to 0.8.38. Affected by this issue is the function router.rep= lace/router.push of the file apps/frontend/src/app/auth/page.tsx of the com= ponent Auth Endpoint. Executing a manipulation of the argument returnURL ca=
n lead to cross site scripting. The attack may be launched remotely. The ex= ploit has been made available to the public and could be used for attacks. = Upgrading to version 0.8.39 can resolve this issue. This patch is called f5= dec7aa0c1b8fa0125938f292c0f2430ca75f6c. It is advisable to upgrade the affe= cted component. The researcher explains: "The issue was fixed in v0.8.39 wi= thout notifying the wider user base via a security disclosure." 2026-06-21 = 4.3 CVE-2026-12811 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12811 ] la= ngchain-ai--langchain-ai LangGraph Python SDK is used to connect to running=
LangGraph API servers, manage assistants, threads and stream runs from Pyt= hon applications. Versions 0.3.14 and prior have unsafe URL path constructi=
on through unsanitized caller-supplied identifier values used in HTTP reque=
st paths for resource operations. Without sanitization of those values, ide= ntifiers that contain characters with special meaning in URL paths could ca= use the resulting request to address a different resource (and potentially =
a different resource type) than the SDK method's call site indicates. In de= ployments where the SDK receives identifier values that originate from untr= usted sources, this could result in unintended access, modification, or del= etion of resources beyond the calling user's authorization scope. This issu=
e is most consequential in deployments that forward end-user-supplied value=
s directly into SDK identifier parameters without first validating them aga= inst an expected format (such as a UUID), and rely on URL-prefix-based auth= orization at an upstream layer (reverse proxy, edge gateway, WAF), where th=
e authorization decision is made on the SDK call's intended path rather tha=
n on the final delivered request path. The issue has been fixed in version = 0.3.15. 2026-06-16 4.2 CVE-2026-48776 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-48776 ] langchain-ai--langgraph LangGraph SQLite Checkpoint is an = implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync = and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSeriali= zer can reconstruct Python objects from JSON checkpoint payloads. Under con= ditions where someone could modify checkpoint bytes at rest in the backing = store, the deserialization path could reconstruct objects beyond what the a= pplication expects, which could in turn result in code execution at checkpo= int load time. This is a defense-in-depth issue. The affected behavior is r= eachable only when checkpoint bytes at rest in the backing store can be mod= ified by an unauthorized party. In most deployments that prerequisite alrea=
dy implies a serious incident; the additional concern is turning "checkpoin= t-store write access" into code execution in the application runtime. This = issue has been fixed in version 4.1.1. 2026-06-16 6.8 CVE-2026-48775 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-48775 ] langflow-ai--langflow A vul= nerability was identified in langflow-ai langflow up to 1.9.3. This affects=
an unknown function of the component Bundle URL Loader. The manipulation l= eads to code injection. The attack needs to be performed locally. The vendo=
r was contacted early about this disclosure but did not respond in any way.=
2026-06-21 5.3 CVE-2026-12822 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-12822 ] leejet--stable-diffusion.cpp stable-diffusion.cpp is a pure C/C++=
library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Ima= ge, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are = vulnerable to an out-of-bounds reads error through PyTorch checkpoint pickl=
e opcode parsing. The pickle .ckpt parser in src/model.cpp did not consiste= ntly check that enough input remained before reading opcode arguments or ad= vancing the parser buffer with a crafted or truncated .ckpt file. Throughou=
t the pickle parser, opcode handlers advanced the parser position with expr= essions such as buffer +=3D N without first checking that buffer + N <=3D b= uffer_end. A truncated file could therefore cause reads past the end of the=
metadata buffer. LibFuzzer found crashes in under one second using malform=
ed checkpoint inputs. Any application using affected stable-diffusion.cpp r= eleases to load untrusted .ckpt model files could be vulnerable. The attack=
requires the victim or application to load a .ckpt file from an untrusted = source, such as a downloaded model from a model sharing site. This issue ha=
s been fixed in version master-584-0a7ae07. If developers are unable to imm= ediately update their applications, they can work around this issue by ensu= ring they do not load .ckpt checkpoint files from untrusted sources. They s= hould prefer trusted model sources and safer formats such as .safetensors w= here possible. 2026-06-16 5.5 CVE-2026-47748 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-47748 ] leethompson--Lazy Content Slider Plugin WordPress L= azy Content Slider Plugin 3.4 contains a cross-site request forgery vulnera= bility that allows attackers to perform unauthorized actions by crafting ma= licious HTML forms. Attackers can trick authenticated administrators into s= ubmitting POST requests to the plugin settings page via lzcs_admin.php to m= odify plugin configuration parameters like lzcs_color and lzcs_count. 2026-= 06-15 4.3 CVE-2016-20074 [
https://www.cve.org/CVERecord?id=3DCVE-2016-2007=
4 ] legalweb--WP DSGVO Tools (GDPR) The WP DSGVO Tools (GDPR) plugin for Wo= rdPress is vulnerable to authorization bypass in all versions up to, and in= cluding, 3.1.39. This is due to the plugin not properly verifying that a us=
er is authorized to perform an action. This makes it possible for unauthent= icated attackers to supply an arbitrary victim email address and trigger im= mediate SAR processing via the process_now and is_ajax parameters, receivin=
g tokenized download links (zip_link, pdf_link) in the HTTP response that e= xpose the victim's personal data - including WordPress account details, com= ment author names, email addresses, IP addresses, and comment content - wit= hout any proof of ownership. The nonce used for the CSRF check is publicly = rendered by the SAR shortcode form and is shared across all anonymous visit= ors, meaning any unauthenticated attacker can trivially obtain a valid nonc=
e and bypass this gate entirely. 2026-06-19 5.3 CVE-2026-10034 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-10034 ] lemonldap-ng--lemonldap-ng A vuln= erability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown=
function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm=
of the component SAML Common Domain Cookie Endpoint. Performing a manipula= tion of the argument url results in open redirect. The attack is possible t=
o be carried out remotely. The exploit is now public and may be used. The v= endor was contacted early about this disclosure but did not respond in any = way. 2026-06-21 4.3 CVE-2026-12804 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-12804 ] libexpat project--libexpat In libexpat before 2.8.2, there is=
a heap-based buffer overflow in doProlog in xmlparse.c because scaffold ba= cking array reallocation is mishandled when there is data-structure sharing=
across parsers. 2026-06-19 6.9 CVE-2026-56132 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-56132 ] libexpat project--libexpat libexpat before 2.8.2 = has an integer overflow in storeAtts. 2026-06-21 6.9 CVE-2026-56403 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-56403 ] libexpat project--libexpat l= ibexpat before 2.8.2 has an integer overflow in addBinding. 2026-06-21 6.9 = CVE-2026-56404 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56404 ] libexp=
at project--libexpat libexpat before 2.8.2 has an integer overflow in getAt= tributeId. 2026-06-21 6.9 CVE-2026-56405 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56405 ] libexpat project--libexpat libexpat before 2.8.2 has an=
integer overflow in XML_ParseBuffer because it lacked a check that was pre= sent in XML_Parse. 2026-06-21 6.9 CVE-2026-56406 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-56406 ] libexpat project--libexpat libexpat before 2.8.=
2 has an integer overflow in doProlog that is related to storeEntityValue a=
nd entity textLen. 2026-06-21 6.9 CVE-2026-56407 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-56407 ] libexpat project--libexpat libexpat before 2.8.=
2 has an integer overflow in copyString. 2026-06-21 6.9 CVE-2026-56408 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-56408 ] libexpat project--libexpa=
t xmlwf in libexpat before 2.8.2 has an integer overflow for the output fil= ename when -d outputDir is used. 2026-06-21 6.5 CVE-2026-56409 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-56409 ] libexpat project--libexpat xmlwf =
in libexpat before 2.8.2 has an integer overflow in resolveSystemId. 2026-0= 6-21 6.9 CVE-2026-56410 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56410=
] libexpat project--libexpat xmlwf in libexpat before 2.8.2 has an integer=
overflow in endDoctypeDecl via NOTATION declarations. 2026-06-21 6.9 CVE-2= 026-56411 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56411 ] libexpat pr= oject--libexpat libexpat before 2.8.2 lacks handler call depth tracking for=
calls to XML_ResumeParser from within handlers in cases of a policy violat= ion. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situat= ion). 2026-06-19 4.9 CVE-2026-56131 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-56131 ] libexpat project--libexpat libexpat before 2.8.2 does not co= nsider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call dep=
th tracking for various calls from within handlers in cases of a policy vio= lation. Thus, a use-after-free can occur. NOTE: this issue exists because o=
f an incomplete fix for CVE-2026-50219. 2026-06-21 4.9 CVE-2026-56412 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-56412 ] libssh2--libssh2 libssh2 t= hrough 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read=
vulnerability in the sftp_symlink() function in src/sftp.c that allows a m= alicious SSH server or man-in-the-middle attacker to disclose heap memory c= ontents or cause a crash by sending a crafted SSH_FXP_NAME response. Attack= ers can supply a link_len value larger than the actual packet data in SSH_F= XP_NAME responses for SFTP READLINK and REALPATH operations, triggering a h= eap buffer over-read of up to target_len minus one bytes due to the missing=
validation of available packet buffer size before the memcpy operation. 20= 26-06-18 6.5 CVE-2025-15661 [
https://www.cve.org/CVERecord?id=3DCVE-2025-1= 5661 ] libssh2--libssh2 libssh2 through 1.11.1, fixed in commit 1762685, co= ntains a pre-authentication denial of service vulnerability in the SSH_MSG_= EXT_INFO handler in src/packet.c that allows a malicious SSH server to caus=
e a client CPU exhaustion loop by sending a crafted extension count value. =
A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange,=
causing the client to spin in a tight CPU loop for over 60 seconds because=
return values from _libssh2_get_string() are unchecked and the session tim= eout does not apply to CPU-bound loops. 2026-06-17 5.9 CVE-2026-55199 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-55199 ] Liquid Web / StellarWP--Ev= ent Tickets Unauthenticated Bypass Vulnerability in Event Tickets <=3D 5.27=
.5 versions. 2026-06-15 6.5 CVE-2026-42662 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-42662 ] liseperu--Elizaibots Contributor Cross Site Scripting=
(XSS) in Elizaibots <=3D 1.0.2 versions. 2026-06-15 6.5 CVE-2025-15659 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2025-15659 ] lsegal--yard YARD is a d= ocumentation generation tool for the Ruby programming language. Prior to ve= rsion 0.9.44, YARD's static cache lookup reads a request path before the ro= uter's path cleanup runs. When a server is configured with a document root,=
a traversal path such as `/../yard-cache-secret.html` is joined against th=
at root and can return a readable sibling `.html` file outside the intended=
static tree. Version 0.9.44 patches the issue. 2026-06-19 5.3 CVE-2026-493=
42 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49342 ] Mamunur Rashid--Cl= assified Listing Unauthenticated Broken Access Control in Classified Listin=
g <=3D 5.3.8 versions. 2026-06-15 6.5 CVE-2026-42640 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-42640 ] Mamunur Rashid--Classified Listing Subscrib=
er Broken Access Control in Classified Listing <=3D 5.3.9 versions. 2026-06= -15 6.3 CVE-2026-42651 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42651 =
] marimo-team--marimo marimo before 0.23.9 contains a reflected cross-site = scripting vulnerability in the notebook page that allows unauthenticated at= tackers to inject arbitrary JavaScript by exploiting improper escaping of s= ingle quotes in the file query parameter reflected into an inline JavaScrip=
t string literal. Attackers can craft a malicious link with a payload begin= ning with __new__ to bypass the 404 check and inject JavaScript into the pa= ge, which executes without Content-Security-Policy restrictions in the orig=
in of a victim's marimo server. 2026-06-17 6.1 CVE-2026-54386 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-54386 ] markdown-it--markdown-it markdown-=
it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-serv= ice vulnerability when typographer: true is enabled, due to quadratic (O(n^= 2)) processing in the smartquotes rule. The issue stems from repeatedly mod= ifying strings with replaceAt(), which performs O(n) slicing and concatenat= ion per quote character. This can cause excessive CPU consumption when pars= ing quote-heavy, user-supplied markdown and may let attackers degrade or di= srupt service availability. Although typographer is disabled by default, ma=
ny production apps enable it for smart typography, making the issue relevan=
t. This issue has been fixed in version 14.2.0. 2026-06-17 5.3 CVE-2026-489=
88 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48988 ] MarketingFire--Wid= get Options Insertion of sensitive information into sent data vulnerability=
in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. T= his issue affects Widget Options: from n/a through 4.0.1. 2026-06-17 6.5 CV= E-2024-35690 [
https://www.cve.org/CVERecord?id=3DCVE-2024-35690 ] Mattermo= st--Mattermost Mattermost Desktop App versions <=3D6.1 5.5.13.0 fail to res= trict the allow list of domains to which NTLM credentials were forwarded to=
in the Mattermost Desktop App which allows any user on a server without th=
e image proxy enabled to intercept other users credentials via embedding an=
image that routes to an external web server. Mattermost Advisory ID: MMSA-= 2026-00651 2026-06-15 6.3 CVE-2026-6517 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-6517 ] Mattermost--Mattermost Mattermost Desktop App versions <= =3D6.1 5.5.13.0 fail to account for attempting to open extremely long URLs =
in the Mattermost Desktop App which allows a malicious server owner to cras=
h the application via including a script to call window.open on a very larg=
e URL. Mattermost Advisory ID: MMSA-2026-00652 2026-06-15 6.5 CVE-2026-8683=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-8683 ] mbis--Permalink Manag=
er Lite The Permalink Manager Lite plugin for WordPress is vulnerable to St= ored Cross-Site Scripting via post titles in the admin URI Editor interface=
in all versions up to, and including, 2.5.3.3 due to insufficient output e= scaping. This makes it possible for authenticated attackers, with Contribut= or-level access and above, to inject arbitrary web scripts in the admin Per= malink Manager page that will execute whenever an administrator accesses th=
e Permalink Manager page. 2026-06-17 6.4 CVE-2026-8494 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-8494 ] mcdope--pam_usb pam_usb provides hardware = authentication for Linux using removable media. In versions prior to 0.9.2,=
getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow enviro= nment variable injection into local-check logic. These environment variable=
s influence whether a current session is local or remote, and a PAM module = that runs in the context of setuid binaries (sudo, su), getenv() returns at= tacker-controlled values whenever the process environment has been manipula= ted by a local user. This issue has been fixed in version 0.9.2. 2026-06-18=
6.3 CVE-2026-48980 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48980 ] m= cdope--pam_usb pam_usb provides hardware authentication for Linux using ord= inary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFil= e() with flags=3D0 when loading the configuration file, allowing libxml2 to=
process external entity references (XXE), potentially making outbound netw= ork connections or local file reads at XML parse time from the context of t=
he authenticating process. The vulnerability requires the configuration fil=
e to contain crafted XML entity references. Since pam_usb.conf is root-owne=
d, direct exploitation requires prior write access to the config, but the d= efence-in-depth impact is significant given that pam_usb.so runs in setuid = contexts (sudo, su). This issue has been fixed in version 0.9.2. 2026-06-18=
6.7 CVE-2026-48981 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48981 ] m= cdope--pam_usb pam_usb provides hardware authentication for Linux using ord= inary removable media. In versions prior to 0.9.2, when updating a one-time=
pad file, a temporary file is created using open() without the O_EXCL flag=
. Without O_EXCL, the create operation is not atomic: two concurrent proces= ses racing to update the same pad may both succeed in opening the file, wit=
h the second write silently overwriting the first. The one-time pad is the = core replay-prevention mechanism of pam_usb. A successful race could result=
in the stored pad value diverging from what either process expected, poten= tially causing authentication failures or, in a precisely timed attack, cre= ating a window for pad reuse. This issue has been fixed in version 0.9.2. 2= 026-06-18 5.8 CVE-2026-48982 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 48982 ] mcdope--pam_usb pam_usb provides hardware authentication for Linux = using ordinary removable media. In versions prior to 0.9.2, a symlink race = condition exists in per-device and per-user pad directory creation. pam_usb=
uses a check-then-act pattern: it calls lstat() to test for existence and = then calls mkdir() separately to create the directory. A local attacker can=
win the race between these calls by replacing the target path with a symli=
nk to a directory they control. If successful, one-time pad files may be wr= itten to an attacker-controlled location, potentially exposing future pad v= alues before use or disrupting authentication. This issue has been fixed in=
version 0.9.2. 2026-06-18 5.8 CVE-2026-48983 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-48983 ] mcdope--pam_usb pam_usb provides hardware authenti= cation for Linux using ordinary removable media. In versions 0.9.1 and belo=
w, pusb_is_loginctl_local() can cause a NULL dereference crash when parsing=
loginctl output. The function calls popen() and reads the result; if the R= emote field is only a newline, fgets() succeeds but strtok_r(buf, "\n", &sa= veptr) returns NULL. A subsequent strcmp(is_remote, "no") then dereferences=
NULL, causing undefined behavior (typically SIGSEGV) and crashing the PAM = module. This can crash the authenticating process (e.g., sudo, login) and, = depending on PAM stack configuration, deny access for all users of the affe= cted service. This issue has been fixed in version 0.9.2. 2026-06-18 5.5 CV= E-2026-48985 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48985 ] mcdope--= pam_usb pam_usb provides hardware authentication for Linux using ordinary r= emovable media. In versions 0.9.1 and below, the xfree() memory release hel= per in calls free() without first zeroing the buffer contents, releasing he= ap-allocated buffers containing sensitive data - including one-time pad byt=
es read from disk - without clearing, leaving the sensitive content in free=
d heap memory until it happens to be overwritten by a subsequent allocation=
. On a system where a use-after-free condition exists, or where a heap insp= ection primitive becomes available, this could allow recovery of pad values=
or other authentication material from freed memory regions. This is a defe= nce-in-depth requirement consistent with prior hardening work in this codeb= ase (GHSA-vx6f-rrqr-j87c applied explicit_bzero to some pad paths; this iss=
ue generalises the pattern to the central deallocation helper). 2026-06-18 = 4.7 CVE-2026-48984 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48984 ] mc= dope--pam_usb pam_usb provides hardware authentication for Linux using remo= vable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can = cause an infinite loop DoS because it does not initialize *ppid on failure.=
In pusb_local_login(), the same variable is reused as input and output in =
a process-tree while loop; if /proc/<pid>/stat cannot be read (for example,=
when an ancestor process exits during authentication), the PID is not upda= ted and the loop does not terminate. This hangs the authenticating process = (such as sudo, sshd, or login) until it is forcibly terminated. This issue = has been fixed in version 0.9.2. 2026-06-18 4.7 CVE-2026-48986 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-48986 ] medkey-org--medkey A security fla=
w has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5= 380834216b09ed. Impacted is the function actionGetPatientById of the file a= pp\modules\medical\port\rest\controllers\PatientController.php of the compo= nent HTTP REST API. The manipulation of the argument ID results in improper=
control of resource identifiers. The attack may be performed from remote. = The exploit has been released to the public and may be used for attacks. Th=
is product utilizes a rolling release system for continuous delivery, and a=
s such, version information for affected or updated releases is not disclos= ed. The vendor was contacted early about this disclosure but did not respon=
d in any way. 2026-06-15 4.3 CVE-2026-12207 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-12207 ] Microsoft--GitHub Copilot Chat Initialization of a r= esource with an insecure default in GitHub Copilot and Visual Studio Code a= llows an unauthorized attacker to disclose information over a network. 2026= -06-19 6.5 CVE-2026-50519 [
https://www.cve.org/CVERecord?id=3DCVE-2026-505=
19 ] Microsoft--Microsoft 365 Copilot Improper neutralization of special el= ements used in a command ('command injection') in Microsoft Copilot allows =
an unauthorized attacker to perform tampering over a network. 2026-06-19 6.=
5 CVE-2026-42895 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42895 ] moha= mmadtanzilurrahman--Static Block The Static Block plugin for WordPress is v= ulnerable to Insecure Direct Object Reference in all versions up to, and in= cluding, 2.2. This is due to the static_block_content() shortcode handler r= etrieving a post via get_post() using an attacker-supplied 'id' attribute a=
nd outputting its post_content without verifying the post's status (private=
, draft, pending) or the requesting user's capability to view it. This make=
s it possible for authenticated attackers, with contributor-level access an=
d above, to read the contents of arbitrary posts, including private and dra=
ft static blocks (and any other post type) created by administrators, by em= bedding the [static_block_content id=3D"X"] shortcode in their own content = and previewing it. 2026-06-16 4.3 CVE-2026-10780 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-10780 ] Mojoomla--School Management Unauthenticated Ins= ecure Direct Object References (IDOR) in School Management <=3D 93.1.0 vers= ions. 2026-06-17 5.3 CVE-2025-15657 [
https://www.cve.org/CVERecord?id=3DCV= E-2025-15657 ] mojoomla--WPAMS Subscriber Arbitrary Content Deletion in WPA=
MS < 49.5.3 versions. 2026-06-16 6.5 CVE-2026-39433 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-39433 ] Montodel--House-Rental-Management A flaw has=
been found in Montodel House-Rental-Management up to 90010017b81265eb1ef38= 10268909f7719a33863. This affects an unknown part of the file /index.php?pa= ge=3Dhouses. This manipulation of the argument ID causes sql injection. The=
attack is possible to be carried out remotely. The exploit has been publis= hed and may be used. This product adopts a rolling release strategy to main= tain continuous delivery. Therefore, version details for affected or update=
d releases cannot be specified. The vendor was contacted early about this d= isclosure but did not respond in any way. 2026-06-21 6.3 CVE-2026-12776 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-12776 ] mra13 / Team Tips and Tr= icks HQ--Stripe Payments Unauthenticated Bypass Vulnerability in Stripe Pay= ments <=3D 2.0.98 versions. 2026-06-15 6.5 CVE-2026-42752 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-42752 ] multer--multer Impact: multer versions=
2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial o=
f Service when using diskStorage. Aborted or malformed multipart uploads le= ave orphaned partial files on disk because the Readable.pipe() call does no=
t propagate the stream destroy signal to the underlying fs.WriteStream. An = attacker can exhaust disk space by triggering many aborted uploads, with no=
application bug required. Patches: Users should upgrade to multer 2.2.0 (2=
.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight w= rite streams and clean them up on the abort path. Workarounds: None. 2026-0= 6-15 5.3 CVE-2026-5038 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5038 ]=
myCred--Bookify Subscriber Broken Access Control in Bookify <=3D 1.1.1 ver= sions. 2026-06-15 6.5 CVE-2025-69332 [
https://www.cve.org/CVERecord?id=3DC= VE-2025-69332 ] myCred--myCred Subscriber Broken Access Control in myCred <= =3D 3.0.3 versions. 2026-06-15 6.5 CVE-2026-40794 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-40794 ] Nasir Ahmed--Advanced Form Integration Subscri= ber Broken Access Control in Advanced Form Integration <=3D 1.126.12 versio= ns. 2026-06-15 6.5 CVE-2026-42659 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-42659 ] nesquena--hermes-webui Hermes WebUI before 0.51.443 contains a=
broken access control vulnerability in the /api/session endpoint that allo=
ws authenticated users to disclose cross-profile session transcripts. Attac= kers can bypass profile boundary checks by directly querying session IDs be= longing to other profiles via GET /api/session?session_id=3D<foreign_id>&me= ssages=3D1 to retrieve unauthorized conversation transcripts and metadata. = 2026-06-17 6.5 CVE-2026-55197 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -55197 ] nesquena--hermes-webui Hermes WebUI before 0.51.443 contains an au= thorization bypass vulnerability in the session export endpoint that allows=
authenticated users to access sessions from other profiles. The _handle_se= ssion_export handler in api/routes.py fails to verify active-profile owners= hip before serializing session data, enabling attackers to exfiltrate forei=
gn session transcripts by guessing or knowing session identifiers. 2026-06-=
17 6.5 CVE-2026-55198 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55198 ]=
nesquena--hermes-webui Hermes WebUI before 0.51.468 contains a resource ex= haustion vulnerability in the unauthenticated POST /api/onboarding/oauth/st= art endpoint that allows unbounded accumulation of in-memory flow state and=
daemon threads. Attackers can send repeated or concurrent requests to exha= ust server memory and thread resources, potentially triggering repeated out= bound device-code requests to upstream OAuth providers. 2026-06-18 5.3 CVE-= 2026-55205 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55205 ] NI--grpc-d= evice There is an unchecked enum cast vulnerability in NI grpc-device Begin= SidebandStream that may allow an attacker to trigger invalid enum states an=
d undefined behavior, potentially resulting in a denial of service. Success= ful exploitation requires an attacker to supply a specially crafted message=
containing an out-of-range value. This affects NI grpc-device 2.17.0 and p= rior versions. 2026-06-19 6.5 CVE-2026-48140 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-48140 ] NI--grpc-device There is a memory leak in NI grpc-d= evice BeginSidebandStream that may result in denial of service due to memor=
y exhaustion.=C2=A0 This affects NI grpc-device 2.17.0 and prior versions. = 2026-06-19 5.3 CVE-2026-48141 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -48141 ] nilfs-dev--nilfs-utils NILFS utilities through 2.3.0, fixed in com= mit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_siz=
e field in NILFS2 superblock before bit-shift operations. Attackers supplyi=
ng crafted NILFS2 images trigger undefined behavior through oversized shift=
s or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg. = 2026-06-18 5.5 CVE-2026-55392 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -55392 ] NousResearch--hermes-agent Hermes Agent before 0.16.0 creates resp= onse_store.db and webhook_subscriptions.json with world-readable permission=
s (mode 0o644), exposing conversation history and HMAC secrets to local use= rs. Attackers with local filesystem access can read these files directly to=
obtain sensitive data including conversation history, tool payloads, promp= ts, and per-route HMAC secrets. 2026-06-17 5.5 CVE-2026-53870 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-53870 ] OceanWP--Ocean Product Sharing Imp= roper Neutralization of Input During Web Page Generation ('Cross-site Scrip= ting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS. Th=
is issue affects Ocean Product Sharing: from n/a through 2.2.2. 2026-06-18 = 5.9 CVE-2026-56007 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56007 ] OF= FIS--DCMTK A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected e= lement is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml= .cc. Executing a manipulation can lead to heap-based buffer overflow. The a= ttack may be performed from remote. The exploit has been published and may =
be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It =
is best practice to apply a patch to resolve this issue. The vendor was con= tacted early, responded in a very professional manner and quickly released =
a fixed version of the affected product. 2026-06-21 6.3 CVE-2026-12805 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-12805 ] ollybach--WPPizza Subscri= ber Sensitive Data Exposure in WPPizza <=3D 3.19.9 versions. 2026-06-15 6.5=
CVE-2026-40796 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40796 ] OpenB= SD--OpenBSD sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2=
b1 allows authentication bypass via certain zero values for lengths. 2026-0= 6-17 5.8 CVE-2026-55706 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55706=
] openbsd--src OpenBSD before commit 6a23123 (2026-06-18) contains an out-= of-bounds read vulnerability in the mpls_do_error function within sys/netmp= ls/mpls_input.c that allows remote attackers to disclose kernel stack memor=
y by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit = set. 2026-06-18 5.3 CVE-2026-56099 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-56099 ] OpenClaw--OpenClaw OpenClaw before 2026.5.12 contains a cross= -site scripting vulnerability in exported session HTML that preserves unsaf=
e javascript: and data: links in generated content. Attackers can execute b= rowser-side scripts if a trusted operator opens the exported file and activ= ates a malicious link. 2026-06-16 6.1 CVE-2026-53841 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-53841 ] OpenClaw--OpenClaw OpenClaw before 2026.4.2=
9 contains a session visibility check bypass vulnerability in shared memory=
search that allows authenticated callers to access memory entries without = proper authorization. Attackers can skip session visibility guards on the s= earch path to retrieve memory entries that should not be visible to their s= ession. 2026-06-16 6.5 CVE-2026-53844 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-53844 ] OpenClaw--OpenClaw OpenClaw before 2026.4.25 contains a pr= ivilege escalation vulnerability in internal and webchat command authentica= tion that allows senders to inherit wildcard ownerAllowFrom state across ch= annel boundaries. Attackers can exploit this by sending commands on affecte=
d internal or webchat paths to execute owner-style command behavior outside=
intended channel scope, potentially bypassing access controls. 2026-06-16 = 6.5 CVE-2026-53854 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53854 ] Op= enClaw--OpenClaw OpenClaw before 2026.5.26 contains a hostname validation v= ulnerability allowing attackers to bypass blocklist comparisons using trail= ing-dot notation in model or workspace-derived URLs. Attackers can exploit = inconsistent hostname checks to reach destinations that operators intended =
to block through hostname policies. 2026-06-16 6.5 CVE-2026-53859 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-53859 ] OpenClaw--OpenClaw OpenClaw be= fore 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift=
exec feature that misses combined POSIX inline-command flags. Attackers ca=
n execute shell content outside the intended allowlist check by using combi= ned flag forms, potentially allowing unauthorized command execution dependi=
ng on operator configuration. 2026-06-16 6.6 CVE-2026-53861 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-53861 ] OpenClaw--OpenClaw OpenClaw before 2= 026.5.6 contains a privilege escalation vulnerability in the Active Memory = write scope that allows Gateway operators with operator.write access to mod= ify global configuration without requiring operator.admin privileges. Attac= kers with operator.write access can exploit insufficient scope validation t=
o apply unauthorized configuration changes beyond the intended write scope.=
2026-06-16 5.4 CVE-2026-53847 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-53847 ] OpenClaw--OpenClaw OpenClaw before 2026.4.25 contains a control s= cope enforcement bypass vulnerability in the focus command that allows auth= enticated callers to execute the command without proper authorization check=
s. Attackers can trigger the focus command to change focus state outside in= tended caller authority, potentially enabling unauthorized operations depen= ding on gateway configuration and input trust levels. 2026-06-16 5.5 CVE-20= 26-53850 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53850 ] OpenClaw--Op= enClaw OpenClaw before 2026.5.12 contains a notification bypass vulnerabili=
ty allowing Slack reaction events to enter the agent pipeline despite disab= led reaction notifications. Attackers can trigger unintended agent processi=
ng by sending reaction events when the feature is enabled, potentially lead= ing to unauthorized processing of lower-trust input. 2026-06-16 5.3 CVE-202= 6-53851 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53851 ] OpenClaw--Ope= nClaw OpenClaw before 2026.4.25 contains a scope containment bypass vulnera= bility in device re-pairing that allows authenticated operators to restore = broader scopes than intended by submitting empty-scope re-pairing requests.=
Attackers can exploit this by sending re-pairing requests with empty scope=
sets to skip containment guards and retain unauthorized device access. 202= 6-06-16 5.4 CVE-2026-53852 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53= 852 ] OpenClaw--OpenClaw OpenClaw 2026.4.23 before 2026.4.24 contains an in= secure file permissions vulnerability in config recovery that restores Open= Claw.json with overly broad permissions. Local attackers on shared hosts ca=
n read sensitive configuration data by exploiting the recovery path to acce=
ss the restored config file. 2026-06-16 5.5 CVE-2026-53856 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-53856 ] OpenClaw--OpenClaw OpenClaw before 20= 26.5.6 contains a hook bypass vulnerability where skill commands routed thr= ough the affected dispatch path skip before-tool-call hook coverage. Attack= ers can exploit this by sending skill commands through the vulnerable dispa= tch path to bypass hook-based auditing and policy enforcement mechanisms. 2= 026-06-16 4.3 CVE-2026-53845 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 53845 ] OpenClaw--OpenClaw OpenClaw before 2026.5.26 contains an exec allow= list bypass vulnerability allowing authenticated operators to execute wrapp= er-level side effects outside allowlisted command intent. Attackers can cra=
ft command requests that bypass allowlist validation by leveraging transpar= ent command wrappers to perform unintended operations. 2026-06-16 4.3 CVE-2= 026-53848 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53848 ] OpenClaw--O= penClaw OpenClaw before 2026.5.7 contains a sender policy bypass vulnerabil= ity in BlueBubbles that allows participants to match allowlist entries thro= ugh conversation metadata rather than stable sender identity. Attackers can=
influence conversation-level identifiers to receive agent responses intend=
ed for configured senders, potentially bypassing access controls. 2026-06-1=
6 4.2 CVE-2026-53860 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53860 ] = OpenClaw--OpenClaw OpenClaw before 2026.5.12 contains a bootstrap token rep= lay vulnerability allowing callers with pending token access to reuse token=
s with broader requested scopes. Attackers can replay bootstrap tokens befo=
re approval to escalate pairing authority beyond intended scope limits. 202= 6-06-16 4.2 CVE-2026-53862 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53= 862 ] OpenStack--Horizon OpenStack Horizon before 25.7.4 produces scripts f=
or OpenStack RC file downloading that may have a crafted project name with = shell metacharacters. NOTE: some parties consider this a security hardening=
opportunity to address certain types of user error, not a vulnerability. 2= 026-06-17 6 CVE-2026-55748 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55= 748 ] OpenStack--Nova In OpenStack Nova before 33.0.2, the server create AP=
I does not strip certain hint data. The resulting instance has no Placement=
allocation. 2026-06-16 5.4 CVE-2026-46448 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-46448 ] OPMC--WooCommerce Anti-Fraud Unauthenticated Broken A= ccess Control in WooCommerce Anti-Fraud <=3D 7.2.6 versions. 2026-06-17 6.5=
CVE-2026-49072 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49072 ] OPMC-= -WooCommerce Dropshipping Unauthenticated Broken Authentication in WooComme= rce Dropshipping <=3D 5.2.4 versions. 2026-06-17 6.5 CVE-2026-49071 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-49071 ] optimole--Optimole Optimize = Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization The Opt= imole - Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Opt= imization plugin for WordPress is vulnerable to Cross-Site Request Forgery =
in all versions up to, and including, 4.2.6. This is due to missing or inco= rrect nonce validation on the replace_file function. This makes it possible=
for unauthenticated attackers to overwrite existing media attachments with=
attacker-supplied file content by supplying a forged multipart POST reques=
t targeting any attachment the victim has edit_post capability over via a f= orged request granted they can trick a site administrator into performing a=
n action such as clicking on a link. The forged request requires a victim w= ith at least Author-level privileges, as the handler enforces a current_use= r_can('edit_post', $id) check; tricking an Author-level or higher user into=
clicking a crafted link is sufficient to trigger the overwrite against att= achments that user can edit. 2026-06-18 4.3 CVE-2026-11784 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-11784 ] Oracle Corporation--Identity Manager = Vulnerability in the Identity Manager product of Oracle Fusion Middleware (= component: End User Self Service). Supported versions that are affected are=
12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthe= nticated attacker with network access via IIOP to compromise Identity Manag= er. Successful attacks of this vulnerability can result in unauthorized upd= ate, insert or delete access to some of Identity Manager accessible data as=
well as unauthorized read access to a subset of Identity Manager accessibl=
e data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CV=
SS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). 2026-06-16 6.5 C= VE-2026-46810 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46810 ] Oracle = Corporation--MySQL Shell Vulnerability in the MySQL Shell product of Oracle=
MySQL (component: Shell: Dump and Load). Supported versions that are affec= ted are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allow=
s unauthenticated attacker with network access via multiple protocols to co= mpromise MySQL Shell. Successful attacks require human interaction from a p= erson other than the attacker. Successful attacks of this vulnerability can=
result in unauthorized access to critical data or complete access to all M= ySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impact= s). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). 2026-06-16=
6.5 CVE-2026-46869 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46869 ] O= racle Corporation--MySQL Shell Vulnerability in the MySQL Shell product of = Oracle MySQL (component: Shell for VS Code). The supported version that is = affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low pri= vileged attacker with network access via multiple protocols to compromise M= ySQL Shell. Successful attacks of this vulnerability can result in unauthor= ized access to critical data or complete access to all MySQL Shell accessib=
le data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). 2026-06-16 6.5 CVE-2026-46871=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-46871 ] Oracle Corporation--= Oracle Access Manager Vulnerability in the Oracle Access Manager product of=
Oracle Fusion Middleware (component: Authentication Engine). Supported ver= sions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable v= ulnerability allows unauthenticated attacker with network access via HTTP t=
o compromise Oracle Access Manager. Successful attacks of this vulnerabilit=
y can result in unauthorized update, insert or delete access to some of Ora= cle Access Manager accessible data as well as unauthorized read access to a=
subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.5 (= Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR= :N/UI:N/S:U/C:L/I:L/A:N). 2026-06-16 6.5 CVE-2026-35261 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-35261 ] Oracle Corporation--Oracle Access Manage=
r Vulnerability in the Oracle Access Manager product of Oracle Fusion Middl= eware (component: Authentication Engine). Supported versions that are affec= ted are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows = unauthenticated attacker with network access via HTTP to compromise Oracle = Access Manager. Successful attacks require human interaction from a person = other than the attacker and while the vulnerability is in Oracle Access Man= ager, attacks may significantly impact additional products (scope change). = Successful attacks of this vulnerability can result in unauthorized update,=
insert or delete access to some of Oracle Access Manager accessible data a=
s well as unauthorized read access to a subset of Oracle Access Manager acc= essible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impact= s). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). 2026-06-16=
6.1 CVE-2026-46812 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46812 ] O= racle Corporation--Oracle Application Development Framework (ADF) Vulnerabi= lity in the Oracle Application Development Framework (ADF) product of Oracl=
e Fusion Middleware (component: Security Framework). Supported versions tha=
t are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerabil= ity allows unauthenticated attacker with network access via HTTP to comprom= ise Oracle Application Development Framework (ADF). Successful attacks requ= ire human interaction from a person other than the attacker and while the v= ulnerability is in Oracle Application Development Framework (ADF), attacks = may significantly impact additional products (scope change). Successful att= acks of this vulnerability can result in unauthorized update, insert or del= ete access to some of Oracle Application Development Framework (ADF) access= ible data as well as unauthorized read access to a subset of Oracle Applica= tion Development Framework (ADF) accessible data. CVSS 3.1 Base Score 6.1 (= Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR= :N/UI:R/S:C/C:L/I:L/A:N). 2026-06-16 6.1 CVE-2026-46770 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-46770 ] Oracle Corporation--Oracle Application D= evelopment Framework (ADF) Vulnerability in the Oracle Application Developm= ent Framework (ADF) product of Oracle Fusion Middleware (component: Java Bu= siness Objects). Supported versions that are affected are 12.2.1.4.0 and 14= .1.2.0.0. Difficult to exploit vulnerability allows high privileged attacke=
r with logon to the infrastructure where Oracle Application Development Fra= mework (ADF) executes to compromise Oracle Application Development Framewor=
k (ADF). Successful attacks of this vulnerability can result in unauthorize=
d access to critical data or complete access to all Oracle Application Deve= lopment Framework (ADF) accessible data. CVSS 3.1 Base Score 4.1 (Confident= iality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N=
). 2026-06-16 4.1 CVE-2026-46771 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-46771 ] Oracle Corporation--Oracle Application Development Framework (A= DF) Vulnerability in the Oracle Application Development Framework (ADF) pro= duct of Oracle Fusion Middleware (component: ADF Faces). Supported versions=
that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vuln= erability allows high privileged attacker with logon to the infrastructure = where Oracle Application Development Framework (ADF) executes to compromise=
Oracle Application Development Framework (ADF). Successful attacks of this=
vulnerability can result in unauthorized access to critical data or comple=
te access to all Oracle Application Development Framework (ADF) accessible = data as well as unauthorized update, insert or delete access to some of Ora= cle Application Development Framework (ADF) accessible data. CVSS 3.1 Base = Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/A= V:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N). 2026-06-16 4.7 CVE-2026-46772 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-46772 ] Oracle Corporation--Oracle VM=
VirtualBox Vulnerability in the Oracle VM VirtualBox product of Oracle Vir= tualization (component: VMSVGA device). The supported version that is affec= ted is 7.2.8. Easily exploitable vulnerability allows high privileged attac= ker with logon to the infrastructure where Oracle VM VirtualBox executes to=
compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM V= irtualBox, attacks may significantly impact additional products (scope chan= ge). Successful attacks of this vulnerability can result in unauthorized ab= ility to cause a hang or frequently repeatable crash (complete DOS) of Orac=
le VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vect= or: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H). 2026-06-16 6 CVE-2026-4= 6768 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46768 ] Oracle Corporati= on--Oracle VM VirtualBox Vulnerability in the Oracle VM VirtualBox product =
of Oracle Virtualization (component: VMSVGA device). The supported version = that is affected is 7.2.8. Easily exploitable vulnerability allows high pri= vileged attacker with logon to the infrastructure where Oracle VM VirtualBo=
x executes to compromise Oracle VM VirtualBox. While the vulnerability is i=
n Oracle VM VirtualBox, attacks may significantly impact additional product=
s (scope change). Successful attacks of this vulnerability can result in un= authorized creation, deletion or modification access to critical data or al=
l Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Integrity = impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N). 2026= -06-16 6 CVE-2026-46825 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46825=
] Oracle Corporation--Oracle VM VirtualBox Vulnerability in the Oracle VM = VirtualBox product of Oracle Virtualization (component: VMSVGA device). The=
supported version that is affected is 7.2.8. Easily exploitable vulnerabil= ity allows high privileged attacker with logon to the infrastructure where = Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the=
vulnerability is in Oracle VM VirtualBox, attacks may significantly impact=
additional products (scope change). Successful attacks of this vulnerabili=
ty can result in unauthorized access to critical data or complete access to=
all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confide= ntiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A= :N). 2026-06-16 6 CVE-2026-46877 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-46877 ] Oracle Corporation--Oracle WebCenter Content Vulnerability in t=
he Oracle WebCenter Content product of Oracle Fusion Middleware (component:=
Content Server). The supported version that is affected is 14.1.2.0.0. Eas= ily exploitable vulnerability allows unauthenticated attacker with network = access via HTTP to compromise Oracle WebCenter Content. Successful attacks =
of this vulnerability can result in unauthorized read access to a subset of=
Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 5.3 (Confide= ntiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A= :N). 2026-06-16 5.3 CVE-2026-46790 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-46790 ] Oracle Corporation--PeopleSoft Enterprise CS Campus Community=
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of = Oracle PeopleSoft (component: Integration and Interfaces). The supported ve= rsion that is affected is 9.2.38. Easily exploitable vulnerability allows h= igh privileged attacker with network access via HTTPS to compromise PeopleS= oft Enterprise CS Campus Community. Successful attacks of this vulnerabilit=
y can result in unauthorized creation, deletion or modification access to c= ritical data or all PeopleSoft Enterprise CS Campus Community accessible da=
ta as well as unauthorized access to critical data or complete access to al=
l PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base = Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/A= V:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N). 2026-06-16 6.5 CVE-2026-46979 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-46979 ] Oracle Corporation--WebLogic = Server Vulnerability in the WebLogic Server product of Oracle Fusion Middle= ware (component: Console). Supported versions that are affected are 14.1.2.= 0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows high privileg=
ed attacker with network access via HTTP to compromise WebLogic Server. Suc= cessful attacks of this vulnerability can result in takeover of WebLogic Se= rver. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability = impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). 2026= -06-16 6.6 CVE-2026-35291 [
https://www.cve.org/CVERecord?id=3DCVE-2026-352=
91 ] pgadmin.org--pgAdmin 4 Open redirect in pgAdmin 4's multi-factor authe= ntication flow. The MFA validate and register endpoints honoured the user-s= upplied 'next' query/form parameter without confirming the target pointed b= ack inside pgAdmin, so an authenticated victim who clicked /mfa/validate?ne= xt=3D<external> -- a link typically delivered by phishing -- would be sent =
to an attacker-controlled host directly out of the trusted auth flow. The d= efect is a trusted-domain redirect, not a privilege bypass: the attacker ga= ins no read/write access to pgAdmin or the victim's database, but the redir= ect launders the attacker's destination through pgAdmin's URL, which raises=
the success rate of credential-phishing follow-on against the victim. Fix = introduces a same-origin _is_safe_redirect_url helper and gates every MFA r= edirect that consumes user-supplied 'next' values through it. The helper al= lows only relative paths and absolute URLs whose scheme is http(s) and whos=
e host matches the current request host; it rejects external hosts in absol= ute and protocol-relative form, non-http schemes (javascript:, data:, mailt= o:), userinfo tricks (
http://localhost@attacker/), and backslash variants t= hat some browsers normalize to forward slashes. Unsafe targets fall back to=
the internal browser index. A dedicated regression test exercises each acc= ept/reject category and the original reporter PoC. This issue affects pgAdm=
in 4: from 6.0 before 9.16. 2026-06-18 4.3 CVE-2026-12049 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12049 ] pgadmin.org--pgAdmin 4 SQL injection i=
n pgAdmin 4's named restore point endpoint (POST /browser/server/restore_po= int/{gid}/{sid}). The user-supplied 'value' field was interpolated directly=
into the SQL string with str.format() instead of being passed as a bound p= arameter, allowing an authenticated pgAdmin user with a connected PostgreSQ=
L session to inject additional statements through that endpoint. The inject=
ed SQL executes under the database role the user is already authenticated a=
s. The defect does not cross a privilege boundary -- the user already has d= irect SQL access to that role through the Query Tool -- so the attacker gai=
ns no capability beyond what their database role already grants them. The m= arginal impact accounts for the fact that the injection path is not the doc= umented SQL-execution interface, so a deployment that gates the Query Tool =
at the application layer could see SQL executed through a path it did not a= nticipate. Fix passes the restore point name as a bound parameter and schem= a-qualifies the function call as pg_catalog.pg_create_restore_point so a no= n-default search_path on the connection cannot redirect the call to a shado=
w definition. A regression test asserts the value arrives as a bound parame= ter and not spliced into the SQL string. This issue affects pgAdmin 4: from=
1.0 before 9.16. 2026-06-18 4.3 CVE-2026-12050 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-12050 ] phppoet--SysBasics Customize My Account for WooC= ommerce Dashboard, Endpoints, Avatar & Menu Manager The Customize My Accoun=
t For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site S= cripting via the 'sysbasics_user_avatar' shortcode in versions up to, and i= ncluding, 4.3.6. This is due to insufficient input sanitization and output = escaping on user supplied attributes (min_height, min_width, max_height, ma= x_width) in the wcmamtx_get_avatar_default() function, which are concatenat=
ed unescaped into the get_avatar() extra_attr style attribute. This makes i=
t possible for authenticated attackers, with Contributor-level access and a= bove, to inject arbitrary web scripts in pages that will execute whenever a=
user accesses an injected page. 2026-06-18 6.4 CVE-2026-12136 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-12136 ] phppoet--SysBasics Customize My A= ccount for WooCommerce Dashboard, Endpoints, Avatar & Menu Manager The SysB= asics Customize My Account for WooCommerce - Dashboard, Endpoints, Avatar &=
Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Sc= ripting via the 'tab' parameter in all versions up to, and including, 4.3.6=
due to insufficient input sanitization and output escaping. This makes it = possible for unauthenticated attackers to inject arbitrary web scripts in p= ages that execute if they can successfully trick a user into performing an = action such as clicking on a link. Because the vulnerable plugin_options_pa= ge() function is only rendered within the WordPress admin dashboard, succes= sful exploitation requires the targeted victim to be logged in with Shop Ma= nager-level access or higher. 2026-06-18 6.1 CVE-2026-12137 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-12137 ] picklescan--picklescan picklescan be= fore 1.0.1 contains an unsafe pickle deserialization vulnerability allowing=
unauthenticated attackers to create arbitrary zero-byte files via logging.= FileHandler class instantiation. Attackers can exploit this by crafting mal= icious pickle payloads to bypass RCE blocklists and create lock files or ot= her filesystem artifacts, potentially causing denial of service or applicat= ion disruption. 2026-06-20 6.5 CVE-2026-56304 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-56304 ] pontedilana--php-weasyprint PhpWeasyPrint is a PHP=
library allowing PDF generation from a URL or an HTML page. Prior to versi=
on 2.6.0, `pontedilana/php-weasyprint` fetches the content of option values=
server-side via `file_get_contents()` when the value looks like a URL, wit= hout restricting the URL scheme. The `attachment` option of `Pdf` is the re= achable sink: any value that passes `isOptionUrl()` (`filter_var(..., FILTE= R_VALIDATE_URL)`) is downloaded by the PHP process and embedded into the ge= nerated PDF. Because `FILTER_VALIDATE_URL` accepts `http`, `https`, `ftp`, = `file` and PHP stream wrappers such as `php://`, an attacker who can influe= nce the `attachment` value reaches both a **Server-Side Request Forgery** p= rimitive (e.g. internal HTTP endpoints, cloud metadata) and a local file di= sclosure primitive (`file://`, `php://filter/...`), with the fetched bytes = exfiltrated as a PDF attachment. This is the same class of issue KnpLabs/sn= appy patched for its `xsl-style-sheet` option in GHSA-c5fp-p67m-gq56. The l= ibrary is documented as a one-to-one substitute for KnpLabs/snappy and shar=
es the same code shape. PhpWeasyPrint version 2.6.0 contains a patch for th=
e issue. 2026-06-19 6.5 CVE-2026-49359 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49359 ] PraisonAI--PraisonAI PraisonAI before 1.5.115 contains =
an information disclosure vulnerability in the MultiAgentLedger component t= hat allows attackers to access sensitive data by registering agents with du= plicate IDs. Attackers can exploit the lack of agent ID uniqueness enforcem= ent to share ledger instances and expose system prompts and conversation hi= story between agents. 2026-06-18 6.5 CVE-2026-56077 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-56077 ] PraisonAI--PraisonAI PraisonAI before 1.5.12=
8 caches tool approval decisions by tool name only, not by invocation argum= ents, allowing subsequent execute_command calls to bypass approval prompts.=
Attackers can exploit this by obtaining initial approval for a benign comm= and, then silently exfiltrate API keys and credentials via subsequent shell=
commands without user consent. 2026-06-18 5.5 CVE-2026-56074 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-56074 ] pressprimer--PressPrimer Quiz AI Q= uiz Maker, Exam Builder & LMS Assessment Plugin The PressPrimer Quiz - AI Q= uiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vul= nerable to Insecure Direct Object Reference in all versions up to, and incl= uding, 2.3.0 via the 'rule_id' parameter due to missing validation on a use=
r controlled key. This makes it possible for authenticated attackers, with = custom-level access and above, to modify or delete quiz rules belonging to = other teachers, resulting in unauthorized tampering of another user's quiz = structure. 2026-06-18 4.3 CVE-2026-10623 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-10623 ] properfraction--ProfilePress Subscriber Cross Site Scri= pting (XSS) in ProfilePress <=3D 4.16.13 versions. 2026-06-15 6.5 CVE-2026-= 41556 [
https://www.cve.org/CVERecord?id=3DCVE-2026-41556 ] purethemes--Wor= kScout-Core Unauthenticated Arbitrary File Deletion in WorkScout-Core <=3D = 1.7.11 versions. 2026-06-17 6.5 CVE-2026-52716 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-52716 ] pydantic--pydantic-ai Pydantic AI is a Python age=
nt framework for building applications and workflows with Generative AI. In=
versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata = blocklist could be bypassed by encoding the metadata IP in an IPv6 transiti=
on form that the previous fix, CVE-2026-46678, did not decode, exposing clo=
ud IAM short-term credentials. The previous remediation decoded only IPv4-m= apped IPv6, 6to4, and the NAT64 well-known prefix, so the metadata guarante=
e did not hold for the remaining transition forms: IPv4-compatible IPv6 (::= a.b.c.d), the NAT64 RFC 8215 local-use prefix (64:ff9b:1::/48), operator-ch= osen NAT64 prefixes, and ISATAP. The IPv6 wrapper is then delivered to the = underlying IPv4 metadata endpoint. This occurs when an application using Py= dantic AI opts a URL into force_download=3D'allow-local' (which disables th=
e default block on private/internal IPs) and runs on a network that actuall=
y routes the affected IPv6 transition forms: NAT64-configured networks (IPv= 6-only or dual-stack-with-NAT64 deployments, including some Kubernetes setu= ps) for the NAT64 variants, or networks with an ISATAP tunnel for ISATAP. A=
standard dual-stack cloud VM or container does not route these forms and i=
s not affected in practice. The IPv4-compatible and Teredo variants are dep= recated and addressed as defense-in-depth. This is an incomplete fix of GHS= A-cqp8-fcvh-x7r3 / CVE-2026-46678 (itself a follow-up to CVE-2026-25580). T= his issue has been fixed in version 2.0.0b3. 2026-06-16 6.8 CVE-2026-48782 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-48782 ] Rain-Task Ltd.--WPBak= ery Page Builder Subscriber Broken Access Control in WPBakery Page Builder = <=3D 8.7.2 versions. 2026-06-17 6.5 CVE-2026-45436 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-45436 ] Rank Math SEO--Rank Math SEO Subscriber Broke=
n Access Control in Rank Math SEO <=3D 1.0.271 versions. 2026-06-15 6.5 CVE= -2026-34892 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34892 ] Rara Them= es--Metro Magazine Missing Authorization vulnerability in Rara Themes Metro=
Magazine allows Exploiting Incorrectly Configured Access Control Security = Levels. This issue affects Metro Magazine: from n/a through 1.4.1. 2026-06-=
16 6.5 CVE-2026-40809 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40809 ]=
Rara Themes--Metro Magazine Missing Authorization vulnerability in Rara Th= emes Metro Magazine allows Exploiting Incorrectly Configured Access Control=
Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7=
. 2026-06-17 4.3 CVE-2024-37496 [
https://www.cve.org/CVERecord?id=3DCVE-20= 24-37496 ] Really Simple Plugins B.V.--Really Simple SSL Subscriber Broken = Access Control in Really Simple SSL <=3D 9.5.9 versions. 2026-06-15 6.5 CVE= -2026-48969 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48969 ] Red Hat--= Red Hat AI Inference Server A flaw was found in vLLM, an open-source librar=
y for large language model inference. This vulnerability arises from improp=
er handling of image metadata, specifically EXIF orientation and PNG transp= arency (tRNS) data, during image processing. When images are converted to R= GB, transparency information may be implicitly discarded or remapped, leadi=
ng to unexpected rendering of transparent pixels and distortion of input co= ntent. This can result in the model misinterpreting image content, potentia= lly affecting the integrity of processed data. 2026-06-17 4.8 CVE-2026-1249=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12491 ] Red Hat--Red Hat An= sible Automation Platform 2 A flaw was found in the AWX GitHub webhook inte= gration. When processing GitHub pull_request webhooks, the controller store=
s the pull_request.statuses_url value from the webhook payload without vali= dating that it points to a trusted GitHub API endpoint. If a job template i=
s configured with a GitHub Personal Access Token as its webhook credential,=
the controller later POSTs that token to the stored callback URL when post= ing job status updates. An attacker who can submit a correctly signed forge=
d webhook using the job template's webhook_key can redirect the callback to=
an attacker-controlled URL and exfiltrate the configured GitHub PAT. 2026-= 06-19 6.3 CVE-2026-12726 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1272=
6 ] Red Hat--Red Hat Ansible Automation Platform 2.7 A flaw was found in An= sible Lightspeed. This vulnerability, related to insufficient session expir= ation, allows a remote attacker to maintain persistent access to the Ansibl=
e Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Autho= rization) access token before a user logs out, they can continue to authent= icate and access sensitive data. This is because the application fails to i= nvalidate the token on the backend, leaving it valid until its natural expi= ration. This can lead to unauthorized read access to Ansible resources such=
as inventories, playbooks, and configuration data. 2026-06-15 5.3 CVE-2026= -44188 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44188 ] Red Hat--Red H=
at Directory Server 11 A flaw was found in 389 Directory Server. During sch= ema reload, the attr_syntax_swap_ht() function unconditionally frees attrib= ute syntax information nodes, bypassing the refcount-based deferred deletio=
n used elsewhere in the attribute syntax subsystem. If an administrator tri= ggers schema reload while concurrent LDAP query traffic is active, worker t= hreads may access freed memory, resulting in use-after-free or double-free = and a denial of service (server crash). 2026-06-18 5 CVE-2026-11791 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-11791 ] Red Hat--Red Hat Directory S= erver 11 A flaw was found in 389 Directory Server in the __aclp__normalize_= acltxt() function of aclparse.c. A malformed ACI (Access Control Instructio=
n) string can trigger heap-buffer-overflow writes and reads during ACI pars= ing. The function fails to validate that the ACI keyword has sufficient len= gth after whitespace stripping, leading to a 1-byte out-of-bounds write and=
subsequent out-of-bounds reads. An authenticated user with write access to=
the aci attribute could send a crafted ACI value to silently corrupt heap = memory in the directory server process. 2026-06-17 5.4 CVE-2026-12528 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-12528 ] Red Hat--Red Hat Enterpris=
e Linux 10 A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` fu= nction, used for changing the Security Officer PIN, can lead to a use-after= -free vulnerability. This occurs when an attacker attempts to change the PI=
N with a NULL old PIN for a token that lacks a protected authentication pat=
h. 2026-06-16 6.6 CVE-2026-42014 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-42014 ] Red Hat--Red Hat Enterprise Linux 10 A denial of service vulner= ability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The g= st_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-r= eader API that expects a bit count, causing parser desynchronization. A rem= ote attacker could trick a user into opening a specially crafted AV1 media = file, triggering an assertion abort and causing the application to crash. 2= 026-06-15 6.5 CVE-2026-52718 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 52718 ] Red Hat--Red Hat Enterprise Linux 10 A flaw was found in GNOME loca= lsearch (previously known as tracker-miners) MP3 Extractor. When processing=
specially crafted MP3 files containing ID3v2.4 tags, a missing bounds chec=
k in the `extract_performers_tags` function can lead to a heap buffer overf= low. This vulnerability allows a remote attacker to cause a Denial of Servi=
ce (DoS) by triggering a read of unmapped memory. In some cases, it could a= lso lead to information disclosure by reading visible heap data. 2026-06-16=
5.6 CVE-2026-1764 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1764 ] Red=
Hat--Red Hat Enterprise Linux 10 A flaw was found in the `tracker-extract-= mp3` component of GNOME localsearch (previously known as tracker-miners). T= his vulnerability, a heap buffer overflow, occurs when processing specially=
crafted MP3 files. A remote attacker could exploit this by providing a mal= icious MP3 file, leading to a Denial of Service (DoS) where the application=
crashes. It may also potentially expose sensitive information from the sys= tem's memory. 2026-06-16 5.6 CVE-2026-1765 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-1765 ] Red Hat--Red Hat Enterprise Linux 10 A flaw was found =
in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, sp= ecifically within the tracker-extract-mp3 component. This heap buffer overf= low vulnerability occurs when processing specially crafted MP3 files contai= ning malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this =
by providing a malicious MP3 file, leading to a denial of service (DoS), wh= ich causes an application crash, and potentially disclosing sensitive infor= mation from the heap memory. 2026-06-16 5.6 CVE-2026-1766 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-1766 ] Red Hat--Red Hat Enterprise Linux 10 A = flaw was found in the GNOME localsearch (previously known as tracker-miners=
) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could ex= ploit this heap buffer overflow vulnerability by providing a specially craf= ted MP3 file containing malformed ID3 tags. This incorrect length calculati=
on during the parsing of performer tags can lead to a read beyond the alloc= ated buffer, potentially causing a Denial of Service (DoS) due to a crash o=
r enabling information disclosure. 2026-06-16 5.6 CVE-2026-1767 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-1767 ] Red Hat--Red Hat Enterprise Linux=
10 A flaw was found in libXpm. A local user with low privileges could expl= oit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by = processing a specially crafted or very small XPM (X PixMap) image file. Thi=
s improper validation of file boundaries can cause an internal pointer to r= ead beyond the file's end, leading to application crashes and Denial of Ser= vice conditions. 2026-06-16 5.5 CVE-2026-4367 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-4367 ] Red Hat--Red Hat Enterprise Linux 10 Multiple out-o= f-bounds read vulnerabilities were found in GStreamer's pcapparse element. = Malformed PCAP records can trigger reads beyond buffer boundaries during IP= v4/TCP header parsing. This element is primarily used in debugging pipeline=
s, limiting real-world exposure. A local attacker could trick a user into p= rocessing a specially crafted PCAP file, potentially leading to a crash or = information disclosure. 2026-06-15 5.3 CVE-2026-52721 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-52721 ] Red Hat--Red Hat Enterprise Linux AI (RHEL=
AI) 3 A use-after-free vulnerability was found in FFmpeg's RASC video deco= der. The decode_move() function initializes a read pointer into a decompres= sed buffer, but a subsequent reallocation of that same buffer during move-t= able processing leaves the pointer dangling. An attacker could exploit this=
by providing a specially crafted AVI file containing a malicious RASC vide=
o stream. When a user opens or plays the file, the decoder reads from freed=
heap memory, which could lead to a denial of service (crash). 2026-06-19 6=
.5 CVE-2026-12706 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12706 ] Red=
Hat--Red Hat Hardened Images A flaw was found in Katello's of Red Hat Sate= llite. A content upload functionality where insufficient authorization chec=
ks in the ContentUploadsController allowed users with the edit_products per= mission to query content information for repositories outside the products = they were authorized to manage. An authenticated attacker could exploit thi=
s issue to determine whether specific content exists within repositories th=
at should otherwise be inaccessible. This issue does not allow unauthorized=
modification, import, or publication of content. 2026-06-17 4.3 CVE-2026-1= 2515 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12515 ] RelyWP--Simple C= loudflare Turnstile Unauthenticated Broken Authentication in Simple Cloudfl= are Turnstile <=3D 1.38.0 versions. 2026-06-15 5.8 CVE-2026-40799 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-40799 ] rewish--WP Emmet Administrator=
Cross Site Scripting (XSS) in WP Emmet <=3D 0.3.4 versions. 2026-06-15 5.9=
CVE-2025-15658 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15658 ] rockl= obsterinc--Bogo The Bogo plugin for WordPress is vulnerable to Sensitive In= formation Exposure in all versions up to, and including, 3.9.1 via the bogo= _rest_create_post_translation. This makes it possible for authenticated att= ackers, with subscriber-level access and above, to extract the raw title, c= ontent, excerpt, and password of any private, draft, or password-protected = post by triggering its duplication via the translation endpoint and reading=
the returned title.raw, content.raw, and excerpt.raw fields of the duplica= ted post. This vulnerability is exploitable against posts written in a non-= default locale, as authenticated subscribers can request a translation into=
the site's default locale to pass the locale-only permission gate. While s= ubscribers can trigger the endpoint, this is only impactful at the Contribu= tor-level as they can actually read the duplicated content. 2026-06-19 4.3 = CVE-2026-9013 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9013 ] romethem= e--RTMKit The RTMKit plugin for WordPress is vulnerable to Incorrect Author= ization in all versions up to, and including, 2.0.7 This is due to the get_= submission_content AJAX endpoint lacking a capability check to verify that =
a user has permission to access the requested form submission data. This ma= kes it possible for authenticated attackers, with Contributor-level access = and above, to view arbitrary form submissions from other users by iterating=
the entries_id parameter. 2026-06-16 6.5 CVE-2026-5149 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-5149 ] rtCamp Inc.--rtMedia for WordPress, Buddy= Press and bbPress Subscriber Broken Access Control in rtMedia for WordPress=
, BuddyPress and bbPress <=3D 4.7.9 versions. 2026-06-15 6.5 CVE-2026-40773=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-40773 ] RubyLouvre--avalon A=
security vulnerability has been detected in RubyLouvre avalon up to 2.2.10=
. The impacted element is an unknown function of the file src/filters/index= .js of the component Template Filter Handler. Such manipulation leads to im= properly controlled modification of object prototype attributes. It is poss= ible to launch the attack remotely. The exploit has been disclosed publicly=
and may be used. The vendor was contacted early about this disclosure but = did not respond in any way. 2026-06-15 5.3 CVE-2026-12209 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12209 ] runtipi--runtipi Runtipi is a personal=
homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves m= arketplace app logos from files inside cloned app-store repositories throug=
h an unauthenticated endpoint, which leads to arbitrary file read through a= pp-store logo symlinks. The path guard checks only the lexical path before = Node reads the file, so a Git app store that contains metadata/logo.jpg as =
a symbolic link can cause Runtipi to read and return the symlink target. Be= cause the endpoint is public and the symlink target may point outside the c= loned repository, this can expose local files from the Runtipi container su=
ch as /data/.env, /data/state/seed, logs, or application files. This can di= sclose JWT secrets, service credentials, local configuration, and operation=
al logs depending on the instance. The issue has been fixed in version 4.10= .0. 2026-06-16 6.5 CVE-2026-47277 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-47277 ] Saad Iqbal--WP EasyPay Cross-Site Request Forgery (CSRF) vulne= rability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This i= ssue affects WP EasyPay: from n/a through 4.4.0. 2026-06-18 6.5 CVE-2026-56= 024 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56024 ] saadiqbal--Points=
Management System For Gamification, Ranks, Badges, and Loyalty Rewards Pro= gram myCred The Points Management System For Gamification, Ranks, Badges, a=
nd Loyalty Rewards Program - myCred plugin for WordPress is vulnerable to S= tored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions u=
p to, and including, 3.1 due to insufficient input sanitization and output = escaping. This makes it possible for authenticated attackers, with contribu= tor-level access and above, to inject arbitrary web scripts in pages that w= ill execute whenever a user accesses an injected page. 2026-06-17 6.4 CVE-2= 026-8607 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8607 ] sc Internet V= ivoo--WpStream Subscriber Arbitrary File Upload in WpStream < 4.11.2 versio= ns. 2026-06-15 5.4 CVE-2026-39527 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-39527 ] shaarli--Shaarli Shaarli is a personal bookmarking service. Ve= rsions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vuln= erability in the Thumbnail Synchronizer feature. When an administrator runs=
the thumbnail update process, malicious bookmark titles are returned via a=
n AJAX response and inserted into the DOM using innerHTML without proper sa= nitization. The issue originates from the interaction between the backend t= humbnail update endpoint and the frontend JavaScript responsible for render= ing update progress. On the backend, the ThumbnailsController::ajaxUpdate m= ethod returns bookmark data formatted using the 'raw' formatter. This inclu= des the unescaped bookmark title in the JSON response. On the client side, = the script thumbnails-update.js processes this AJAX response and dynamicall=
y updates the progress interface. Administrators using the thumbnail synchr= onization feature are affected and exploitation could lead to session hijac= king, privilege escalation, backdoor injection and full compromise. This is= sue has been fixed in version 0.16.2. 2026-06-17 5.8 CVE-2026-48821 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-48821 ] shaarli--Shaarli Shaarli is =
a personal bookmarking service. Versions 0.16.1 and prior contain a stored = Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion=
process used in the Bookmark Description field. An authenticated user can = inject a malicious javascript: URI inside a Markdown link. The vulnerabilit=
y originates in the filterProtocols method within BookmarkMarkdownFormatter= .php.This method attempts to sanitize Markdown links by filtering dangerous=
protocols (such as javascript:) before rendering. It uses the following re= gular expression: (#]\((.*?)\)#is). This regex is designed to detect inline=
Markdown links, but it fails to detect Markdown reference-style links beca= use reference-style links are resolved by the Markdown parser after preproc= essing. The filterProtocols method never inspects the actual URL used in th= ese references and as a result, an attacker can supply a javascript: URI in= side a reference definition. This issue has been fixed in version 0.16.2. 2= 026-06-17 5.8 CVE-2026-48822 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 48822 ] shaarli--Shaarli Shaarli is a personal bookmarking service. Version=
s 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerabilit=
y in the tag filtering functionality of Shaarli. An authenticated user can = inject arbitrary JavaScript into the tags field when creating a bookmark (S= haare). The malicious payload is stored and later executed when users inter= act with the "Filter by tag" search feature on the homepage. User-supplied = input in the tags field is not properly sanitized or output-escaped before = being rendered in the tag filtering interface. When a bookmark is created w= ith a malicious payload inside the tag field, the payload is stored in the = database. Later, when a user searches using the "Filter by tag" functionali=
ty on the homepage, the application renders matching tags dynamically. If t=
he tag value contains HTML with JavaScript event handlers, it is injected i= nto the DOM. This impacts anyone interacting with the "Filter by tag" searc=
h functionality, administrators and privileged users. This issue has been f= ixed in version 0.16.2. 2026-06-17 4.8 CVE-2026-48823 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-48823 ] Shareaholic--Shareaholic Missing Authoriza= tion vulnerability in Shareaholic allows Exploiting Incorrectly Configured = Access Control Security Levels. This issue affects Shareaholic: from n/a th= rough 9.7.11. 2026-06-17 4.3 CVE-2024-24709 [
https://www.cve.org/CVERecord= ?id=3DCVE-2024-24709 ] slimphp--Slim Slim is a PHP micro framework that ena= bles users to write simple web applications and APIs. In versions 4.4.0 thr= ough 4.15, if an application uses HttpException::setTitle() and/or setDescr= iption() to include untrusted/request-derived data in the error title or de= scription (e.g. "No products found matching '{$query}'."), an attacker coul=
d inject arbitrary HTML/JavaScript that executes in the victim's browser wh=
en they encounter an HTML error page generated by Slim. The vulnerability i=
s present even with displayErrorDetails =3D false as the unescaped title an=
d description are rendered on this error path. Built-in exceptions (HttpNot= FoundException, HttpBadRequestException, etc.) ship plain-text defaults, so=
a vanilla Slim app with no user code is not exploitable. Only applications=
that feed untrusted data into setTitle() and/or setDescription() are affec= ted. The issue has been fixed in 4.15.2. If developers are unable to immedi= ately update their applications, they can work around this issue by avoidin=
g passing untrusted/request-derived data into HttpException::setTitle() and=
setDescription() and using static, plain-text error copy instead. They sho= uld also register a custom error renderer (an ErrorRendererInterface implem= entation, or a subclass of HtmlErrorRenderer that escapes the title and des= cription) for the HTML media type. 2026-06-15 6.1 CVE-2026-48157 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-48157 ] Splunk--Splunk AI Toolkit In Sp= lunk AI Toolkit versions below 5.7.4, a low-privileged user that does not h= old the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit t=
o make outbound requests over HTTP to a server that an attacker controls, w= hich could allow for data exfiltration. The vulnerability exists because of=
an insecure default domain allowlist in the Splunk AI Toolkit, which does = not restrict outbound AI agent requests to approved external domains. 2026-= 06-17 4.3 CVE-2026-20265 [
https://www.cve.org/CVERecord?id=3DCVE-2026-2026=
5 ] statamic--cms Statamic is a Laravel and Git powered content management = system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel u= ser could view metadata and content for resources they don't have permissio=
n to view, including entries, assets, users, roles, groups, and other confi= gured resources. Depending on the resource, this could expose titles, custo=
m field values, entry content, asset metadata, and the existence of users, = roles, and groups. No data could be modified. This has been fixed in 5.73.2=
3 and 6.20.0. 2026-06-19 4.3 CVE-2026-49288 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-49288 ] SteeltoeOSS--Steeltoe.Configuration.Abstractions Ste= eltoe is an open source project that provides a collection of libraries tha=
t helps users build cloud-native applications. In Steeltoe.Configuration.Ab= stractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings f= rom `VCAP_SERVICES` include TLS client credentials, the Connectors library = writes those credentials to temporary files in `Path.GetTempPath()` using `= File.CreateText`. On Linux, `File.CreateText` creates files with mode `0644=
` (world-readable) under the process umask, and the files are never deleted=
. The same key material is protected at mode `0400` in `/proc/<pid>/environ=
`. Steeltoe.Configuration.Abstractions version 4.2.0 patches the issue. If =
an immediate upgrade is not possible, prevent other processes from running =
in the container under a different UID with access to `/tmp`. 2026-06-17 4.=
7 CVE-2026-50267 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50267 ] Stee= ltoeOSS--Steeltoe.Management.Endpoint Steeltoe is an open source project th=
at provides a collection of libraries that helps users build cloud-native a= pplications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Ste= eltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator=
endpoints default to `EndpointPermissions.Restricted`, which is mappeds to=
Cloud Foundry's `read_basic_data` permission (granted to Space Auditors an=
d similar low-trust roles). Sensitive actuators including heap dump, enviro= nment, and thread dump do not raise this to `EndpointPermissions.Full`, so = CF's `read_sensitive_data` permission flag is not enforced for those endpoi= nts. Spring Boot's equivalent Cloud Foundry integration gates these endpoin=
ts with `read_sensitive_data` by default. Steeltoe.Management.Endpoint 4.2.=
0 and Steeltoe.Management.EndpointCore 3.4.0 patch the issue. If an immedia=
te upgrade is not possible, explicitly set `RequiredPermissions =3D Endpoin= tPermissions.Full` in the options for `HeapDumpEndpointOptions`, `Environme= ntEndpointOptions`, and `ThreadDumpEndpointOptions`; and/or if heap dump, t= hread dump, or environment are not needed in production, register only the = required actuators individually instead of using `AddAllActuators()`. 2026-= 06-17 6.5 CVE-2026-50201 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5020=
1 ] SteeltoeOSS--Steeltoe.Security.Authentication.CloudFoundryBase Steeltoe=
is an open source project that provides a collection of libraries that hel=
ps users build cloud-native applications. In Steeltoe.Security.Authenticati= on.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authenticatio= n.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.Op= enIdConnect prior to version 4.2.0, the JWT signing key cache in `TokenKeyR= esolver` uses `kid` as the sole cache key without namespacing by authority.=
In applications with multiple `JwtBearer` schemes pointing to different id= entity providers, a key fetched for one scheme can satisfy token validation=
for another. Additionally, cached keys have no expiration, so rotated or r= evoked keys remain trusted until the application process restarts. Steeltoe= .Security.Authentication.CloudFoundryBase version 3.4.0, Steeltoe.Security.= Authentication.JwtBearer version 4.2.0, and Steeltoe.Security.Authenticatio= n.OpenIdConnect version 4.2.0 patch the issue. If an immediate upgrade is n=
ot possible: In multi-scheme deployments, configure only one `JwtBearer` sc= heme per application when different identity providers are required; and/or=
restart the application process after an identity provider signing key rot= ation to clear stale cached keys. 2026-06-17 5.9 CVE-2026-50202 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-50202 ] stellarwp--Kadence Blocks Page B= uilder Toolkit for Gutenberg Editor The Kadence Blocks - Page Builder Toolk=
it for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Inf= ormation Exposure in all versions up to, and including, 3.7.5 via the edito= r_assets_variables. This makes it possible for authenticated attackers, wit=
h contributor-level access and above, to extract the site's connected Kaden=
ce account license key, license owner email, api_key, api_email, and licens=
e domain from the browser console by inspecting window.kadence_blocks_param= s.proData. Exploitation requires only that an administrator has previously = connected a valid Kadence license; the full credential bundle is then reada= ble by any Contributor-level user from the block editor client context with= out any server-side request manipulation. 2026-06-18 4.3 CVE-2026-11357 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-11357 ] strablengineering--STRAB=
L A checkout solution The STRABL - A checkout solution plugin for WordPress=
is vulnerable to Missing Authentication in all versions up to and includin=
g 4.5. The plugin registers a REST API webhook endpoint at /wp-json/strabl/= webhook/order with a permission_callback of __return_true, which allows all=
incoming requests without any authentication or authorization checks. No s= hared secret, signature validation, HMAC verification, or token-based authe= ntication is implemented. This makes it possible for unauthenticated attack= ers to create fraudulent WooCommerce orders and mark them as completed by s= upplying paymentStatus=3Dpaid, manipulate existing order statuses by provid= ing an externalOrderId, create new WordPress user accounts with the custome=
r role, issue refunds on existing orders, cancel existing orders, and apply=
chargeback fees - all without making a legitimate payment or having any va= lid credentials. 2026-06-19 5.3 CVE-2026-3640 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-3640 ] strukturag--libde265 libde265 is an open source imp= lementation of the h.265 video codec. Prior to version 1.0.20, a crafted se= quence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libd= e265/decctx.cc:481`) to attach slice headers to a finished picture object t= hat has no active image unit, resulting in attacker-controlled unbounded he=
ap growth. The retained headers are never freed until the picture is releas= ed, which may not happen during continuous streaming. Version 1.0.20 patche=
s the issue. 2026-06-19 4.3 CVE-2026-49337 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-49337 ] strukturag--libheif libheif is a HEIF and AVIF file f= ormat decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF d= ecoder validates explicit icef compressed-unit offsets using unit_offset + = unit_size. Because the addition can wrap, a crafted HEIF file can pass the = range check and then construct a vector from iterators outside the compress=
ed item buffer, producing an out-of-bounds heap read and crash. Version 1.2= 2.1 patches the issue. 2026-06-19 6.5 CVE-2026-49271 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-49271 ] StylemixThemes--MasterStudy LMS Pro Missing=
Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows A= ccessing Functionality Not Properly Constrained by ACLs. This issue affects=
MasterStudy LMS Pro: from n/a before 4.7.16. 2026-06-15 6.5 CVE-2025-64215=
[
https://www.cve.org/CVERecord?id=3DCVE-2025-64215 ] StylemixThemes--Moto=
rs Subscriber Broken Access Control in Motors < 1.4.107 versions. 2026-06-1=
5 6.5 CVE-2026-39515 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39515 ] = SUSE--libzypp A path traversal in handling the "path" component of .repo fi= les processed by libzypp before 17.38.13 in the 17.x series, or before 16.2= 2.19 could be used by attackers to fill directories on the system outside o=
f the zypp cache with content. 2026-06-18 6.5 CVE-2026-44942 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-44942 ] svaarala--duktape A weakness has be=
en identified in svaarala duktape up to 2.99.99. This issue affects some un= known processing of the file duk_api_bytecode.c. Executing a manipulation o=
f the argument count_instr can lead to memory corruption. The attack requir=
es local access. The exploit has been made available to the public and coul=
d be used for attacks. The vendor was contacted early about this disclosure=
but did not respond in any way. 2026-06-15 5.3 CVE-2026-12216 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-12216 ] teamwsa--Woosa Marktplaats for Wo= oCommerce The Woosa - Marktplaats for WooCommerce plugin for WordPress is v= ulnerable to Arbitrary File Read via Path Traversal in versions up to and i= ncluding 2.0.4. This is due to insufficient path sanitization in the render= _logs_ui() function, which accepts a base64-encoded file name from the 'log= _file' GET parameter and concatenates it directly with the plugin's log dir= ectory path without validating that the resolved path remains within the in= tended directory. This makes it possible for authenticated attackers, with = Administrator-level access, to read the contents of arbitrary files on the = server, including wp-config. 2026-06-19 4.9 CVE-2026-7547 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-7547 ] techlabpro1--Classified Listing AI-Powe= red Classified ads & Business Directory The Classified Listing - Classified=
ads & Business Directory plugin for WordPress is vulnerable to Missing Aut= horization in all versions up to, and including, 5.4.2. This is due to a mi= ssing capability/ownership check on the gallery_image_update_as_feature AJA=
X handler (action: rtcl_fb_gallery_image_update_as_feature), which accepts =
a user-supplied listing ID and attachment ID and sets the featured image of=
a listing while only validating a nonce that is exposed to any logged-in u= ser on the frontend listing-submission form. This makes it possible for aut= henticated attackers, with Subscriber-level access and above, to change the=
featured image of arbitrary listings they do not own. 2026-06-19 4.3 CVE-2= 026-10779 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10779 ] Themefic--U= ltra Addons for WPForms Subscriber Broken Access Control in Ultra Addons fo=
r WPForms <=3D 1.0.11 versions. 2026-06-15 6.4 CVE-2026-39594 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-39594 ] ThemeGrill--Masteriyo - LMS Unauth= enticated Broken Authentication in Masteriyo - LMS <=3D 2.1.8 versions. 202= 6-06-15 6.5 CVE-2026-42743 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42= 743 ] themeisle--Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie=
Notice, Custom Fonts & More The Orbit Fox: Duplicate Page, Menu Icons, SVG=
Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulner= able to Stored Cross-Site Scripting via admin settings in all versions up t=
o, and including, 3.0.6 due to insufficient input sanitization and output e= scaping. This makes it possible for authenticated attackers, with administr= ator-level permissions and above, to inject arbitrary web scripts in pages = that will execute whenever a user accesses an injected page. This only affe= cts multi-site installations and installations where unfiltered_html has be=
en disabled. 2026-06-18 4.4 CVE-2026-11358 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-11358 ] Themeisle--WP Full Stripe Free Subscriber Broken Auth= entication in WP Full Stripe Free <=3D 8.4.1 versions. 2026-06-15 6.5 CVE-2= 026-42378 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42378 ] Themeum--Tu= tor LMS Unauthenticated Broken Access Control in Tutor LMS <=3D 3.9.7 versi= ons. 2026-06-15 6.5 CVE-2026-40743 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-40743 ] themeum--Tutor LMS eLearning and online course solution The T= utor LMS - eLearning and online course solution plugin for WordPress is vul= nerable to generic SQL Injection via the 'data' parameter in all versions u=
p to, and including, 3.9.11 due to insufficient escaping on the user suppli=
ed parameter and lack of sufficient preparation on the existing SQL query. = This makes it possible for authenticated attackers, with administrator-leve=
l access and above, to append additional SQL queries into already existing = queries that can be used to extract sensitive information from the database=
. 2026-06-18 4.9 CVE-2026-10736 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-10736 ] thorsten--phpMyFAQ phpMyFAQ is an open source FAQ web applicatio=
n. Versions prior to 4.1.4 have Missing Authorization in the API CategoryCo= ntroller. CVE-2026-24421 addressed this in the BackupController by adding: = $this->userHasPermission(PermissionType::BACKUP). The same fix was not appl= ied to 4 other write endpoints in the public API. All 4 only call $this->ha= sValidToken() - which checks a shared API key header, rather than the indiv= idual user's role permissions. The following APIs are affected: POST /api/v= 4.0/category (CategoryController::create), POST /api/v4.0/faq (FaqControlle= r::create), PUT /api/v4.0/faq (FaqController::update), and POST /api/v4.0/q= uestion (QuestionController::create). This issue has been fixed in version = 4.1.4. 2026-06-18 6.5 CVE-2026-49205 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-49205 ] TMS--Amelia Subscriber Broken Access Control in Amelia <=3D=
2.2 versions. 2026-06-15 6.5 CVE-2026-40795 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-40795 ] ts-deepmerge--ts-deepmerge Versions of the package = ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the i= mproper handling of built-in Object.prototype methods (such as toString, va= lueOf). When user-controlled input contains these keys with non-function va= lues, the resulting merged object becomes broken - any string context opera= tion throws a TypeError, crashing the application. 2026-06-19 5.3 CVE-2026-= 12644 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12644 ] typemill--typem= ill Typemill before 2.24.0 contains a path traversal vulnerability that all= ows authenticated attackers with Author-level privileges to read arbitrary = files outside the content directory by supplying traversal sequences in the=
path query parameter passed to Storage::getFile() with an empty folder arg= ument. Attackers can bypass traversal-prevention controls in Storage::getFo= lderPath() to access sensitive files. 2026-06-17 6.5 CVE-2026-49133 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-49133 ] undici--undici Impact: Undic= i's cache interceptor incorrectly classifies some responses as cacheable wh=
en the upstream Cache-Control header uses whitespace-padded qualified priva=
te or no-cache field names such as private=3D" authorization" or no-cache= =3D"\tauthorization". The parser preserves the surrounding whitespace, so l= ater comparisons against the literal authorization field name fail and the = response is stored. In shared-cache mode, this allows a response containing=
one user's authenticated data to be served from cache to a subsequent call= er, including an unauthenticated caller, when both requests resolve to the = same cache key. Affected applications are those that explicitly enable the = cache interceptor (interceptors.cache()) in shared mode, forward Authorizat= ion headers upstream, and receive cacheable responses with non-canonical qu= alified private or no-cache directives. Patches: Upgrade to undici v7.28.0 =
or v8.5.0. Workarounds: If upgrade is not immediately possible, disable sha= red-cache mode for traffic that includes Authorization headers, avoid cachi=
ng responses to authenticated requests, or add Vary: Authorization upstream=
. 2026-06-17 5.9 CVE-2026-9678 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-9678 ] undici--undici Impact: undici's cookie parser in parseSetCookie pe= rcent-decodes cookie values via qsUnescape, turning encoded sequences like = %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 =C3= =82=C2=A75.4 does not specify any decoding and browsers do not decode eithe=
r. Applications that parse a Set-Cookie header and then forward the parsed = value into a response header (proxies, middleware, SSR frameworks) become v= ulnerable to HTTP response header injection: an attacker-controlled upstrea=
m can inject arbitrary Set-Cookie, Location, or Cache-Control headers into = the application's downstream response, enabling session fixation, open redi= rect, or cache poisoning. Affected applications are those that use undici's=
cookie parsing (parseSetCookie, parseCookie, getSetCookies) and forward th=
e parsed cookie value into a response header. This was introduced in undici=
7.0.0 via PR #3789. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0.=
Workarounds: If upgrade is not immediately possible, do not forward values=
returned by parseSetCookie/parseCookie/getSetCookies directly into respons=
e headers; sanitize the value first to strip or reject CR, LF, NUL, ;, and = =3D bytes. 2026-06-17 5.9 CVE-2026-9679 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-9679 ] universal-tool-calling-protocol--python-utcp A vulnerabi= lity was detected in universal-tool-calling-protocol python-utcp 1.1.0. Thi=
s affects an unknown function of the component utcp-gql/utcp-websocket. Per= forming a manipulation results in server-side request forgery. The attack c=
an be initiated remotely. The exploit is now public and may be used. The ve= ndor was contacted early about this disclosure but did not respond in any w= ay. 2026-06-15 6.3 CVE-2026-12210 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-12210 ] valhalla--valhalla Valhalla is an open source routing engine a=
nd accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 a=
nd prior are vulnerable to reflected cross-site scripting (XSS) due to impr= oper neutralization of input in the JSONP callback parameter. When a reques=
t specifies a JSONP callback, the value is reflected directly into the HTTP=
response body with Content-Type: application/javascript, without any valid= ation, output encoding, or allowlist filtering. An attacker can craft a URL=
containing arbitrary JavaScript in the callback parameter; if a victim is = induced to load that URL via a <script src=3D"..."> tag, the injected scrip=
t executes in the context of the serving origin, potentially leading to ses= sion token theft, credential disclosure, or actions performed on behalf of = the victim. This issue was not fixed at time of publication. 2026-06-15 6.1=
CVE-2026-49294 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49294 ] Veron= aLabs--Slimstat Analytics Unauthenticated Deserialization of untrusted data=
in Slimstat Analytics < 5.4.0 versions. 2026-06-17 6.5 CVE-2026-27410 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-27410 ] VeronaLabs--WP SMS Subscr= iber Sensitive Data Exposure in WP SMS <=3D 7.2.1 versions. 2026-06-15 6.5 = CVE-2026-40790 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40790 ] virtio= -snd device--virtio-snd device An integer overflow vulnerability was found =
in the virtio-snd device via PCM_INFO requests from the guest. A malicious = guest can provide out-of-bounds stream counts, potentially leading to unbou= nded memory allocation on the host and a denial of service condition. 2026-= 06-19 5.5 CVE-2026-3196 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3196 =
] vllm--vllm vLLM versions >=3D 0.6.3 and < 0.9.0 contain multiple regular = expression denial of service (ReDoS) vulnerabilities. Several regex pattern=
s - in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compati= ble serving chat endpoint - are susceptible to catastrophic backtracking. A=
n attacker submitting crafted input with nested or repeated structures can = trigger severe CPU consumption and performance degradation, resulting in de= nial of service. 2026-06-20 4.3 CVE-2025-71379 [
https://www.cve.org/CVERec= ord?id=3DCVE-2025-71379 ] vynnus--PopAd Administrator Server Side Request F= orgery (SSRF) in PopAd <=3D 1.0.4 versions. 2026-06-15 4.4 CVE-2025-60175 [=
https://www.cve.org/CVERecord?id=3DCVE-2025-60175 ] Wasiliy Strecker--Cont= est Gallery Subscriber Cross Site Scripting (XSS) in Contest Gallery <=3D 2= 8.1.6 versions. 2026-06-15 6.5 CVE-2026-42656 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-42656 ] Wasiliy Strecker--Contest Gallery Unauthenticated = Other Vulnerability Type in Contest Gallery <=3D 28.1.7 versions. 2026-06-1=
5 6.5 CVE-2026-42657 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42657 ] = Wasiliy Strecker--Contest Gallery Subscriber Sensitive Data Exposure in Con= test Gallery <=3D 28.1.7 versions. 2026-06-15 6.5 CVE-2026-42660 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-42660 ] watchful--XCloner Subscriber Se= nsitive Data Exposure in XCloner <=3D 4.8.6 versions. 2026-06-15 6.5 CVE-20= 26-48965 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48965 ] Webful Creat= ions--RepairBuddy Subscriber Broken Access Control in RepairBuddy <=3D 4.11=
32 versions. 2026-06-15 6.5 CVE-2026-39584 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-39584 ] Webmin--Webmin Webmin allows unauthenticated attacker=
s to read the contents of any file ending in .conf within module directorie=
s, due to a bypassable regex pattern. 2026-06-18 5.3 CVE-2026-56021 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-56021 ] Webmin--Webmin Webmin accept=
s basic authentication without session cookies when an attacker provides th=
e 'User-Agent: webmin' header, allowing bypass of additional MFA requiremen= ts. Fixed in 2.641. 2026-06-18 5.3 CVE-2026-56022 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-56022 ] webpack-dev-server--webpack-dev-server Impact:=
When a user-configured proxy on webpack-dev-server has a broad context (e.=
g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket a=
nd forwards it to the proxy target. This leaks the browser's cookies and Or= igin header to the backend, bypasses the dev server's Host/Origin validatio=
n, and corrupts the HMR socket (both HMR and the proxy end up writing to th=
e same socket). Patches: Fixed in webpack-dev-server@5.2.5. Workarounds: Sc= ope user-defined proxy context to specific paths instead of /, or omit ws: = true from the proxy entry when WebSocket forwarding is not required. 2026-0= 6-15 5.3 CVE-2026-9595 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9595 ]=
WishList Member--WishList Member X Subscriber Broken Access Control in Wis= hList Member X <=3D 3.29.0 versions. 2026-06-17 4.3 CVE-2026-24575 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-24575 ] woocommerce--WooCommerce Stri=
pe Payment Gateway The WooCommerce Stripe Payment Gateway plugin for WordPr= ess is vulnerable to unauthorized modification of data due to a missing cap= ability check on the `ajax_pay_for_order()` function in all versions up to,=
and including, 10.7.0 This is due to a missing order ownership or order_ke=
y verification when processing payment for an order via the `wc_stripe_pay_= for_order` WC-AJAX endpoint. The function only validates a nonce (which is = publicly available on any WooCommerce page where Express Checkout is enable= d), but does not verify that the requesting user owns the target order and =
is allowed to modify it. This makes it possible for unauthenticated attacke=
rs to force any pending order into a failed status by providing a fake paym= ent method, causing a payment exception that updates the order status to "f= ailed" via sequential order ID enumeration. 2026-06-16 6.5 CVE-2026-2381 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-2381 ] WP Chill--Download Monit=
or Author Arbitrary File Download in Download Monitor <=3D 5.1.9 versions. = 2026-06-15 4.4 CVE-2026-39489 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -39489 ] WP Chill--Modula Image Gallery Subscriber Cross Site Scripting (XS=
S) in Modula Image Gallery <=3D 2.14.23 versions. 2026-06-15 6.5 CVE-2026-4= 2688 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42688 ] WP Engine--WP Mi= grate Lite Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate = Lite <=3D 2.7.8 versions. 2026-06-15 4.7 CVE-2026-49043 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-49043 ] wp.insider--Simple Membership Unauthenti= cated Cross Site Scripting (XSS) in Simple Membership <=3D 4.7.2 versions. = 2026-06-15 6.5 CVE-2026-42663 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -42663 ] wpcalc--Counter Box Add Countdowns, Timers & Dynamic Counters to W= ordPress The Counter Box - Add Countdowns, Timers & Dynamic Counters to Wor= dPress plugin for WordPress is vulnerable to PHP Object Injection in all ve= rsions up to, and including, 2.0.13 via deserialization of untrusted input =
. This makes it possible for authenticated attackers, with administrator-le= vel access and above, to inject a PHP Object. No known POP chain is present=
in the vulnerable software, which means this vulnerability has no impact u= nless another plugin or theme containing a POP chain is installed on the si= te. If a POP chain is present via an additional plugin or theme installed o=
n the target system, it may allow the attacker to perform actions like dele=
te arbitrary files, retrieve sensitive data, or execute code depending on t=
he POP chain present. Deserialization is triggered automatically upon the p= ost-import redirect that renders the list table, and again when any item is=
opened for editing, requiring no additional navigation beyond the import a= ction itself. 2026-06-17 6.6 CVE-2026-12115 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-12115 ] WPDeveloper--Essential Addons for Elementor Unauthen= ticated Broken Access Control in Essential Addons for Elementor < 6.6.0 ver= sions. 2026-06-15 5.3 CVE-2026-25440 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-25440 ] wpdevteam--BetterDocs AI Documentation, Knowledge Base, Doc=
s, Wikis, FAQ with Chatbot The BetterDocs - Knowledge Base Docs & FAQ Solut= ion for Elementor & Block Editor plugin for WordPress is vulnerable to Stor=
ed Cross-Site Scripting via the blockId attribute of the betterdocs/categor= y-slate-layout Gutenberg block in versions up to, and including, 4.5.3. Thi=
s is due to insufficient input sanitization and output escaping in the Cate= gorySlateLayout::render() method, which echoes the blockId block attribute = directly into an HTML class attribute without esc_attr(). This makes it pos= sible for authenticated attackers, with contributor-level access and above,=
to inject arbitrary web scripts in pages that will execute whenever a user=
accesses an injected page. 2026-06-19 6.4 CVE-2026-12157 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12157 ] wpgmaps--WP Go Maps Google Map, OpenSt= reetMap, Leaflet Map The WP Go Maps - Most Popular Map Plugin plugin for Wo= rdPress is vulnerable to authorization bypass in all versions up to, and in= cluding, 10.1.01. This is due to the plugin not properly verifying that a u= ser is authorized to perform an action. This makes it possible for unauthen= ticated attackers to create arbitrary records in plugin database tables (ma= ps, markers, circles, polygons, polylines, rectangles, and point labels) by=
supplying a WPGMZA-namespaced CRUD-backed class name via the phpClass para= meter. The namespace validation check (requiring the 'WPGMZA' prefix) does = not prevent exploitation because classes such as WPGMZA\Map and WPGMZA\Mark=
er satisfy it while still triggering an INSERT into the corresponding plugi=
n table before the route rejects the request. 2026-06-19 5.3 CVE-2026-12238=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12238 ] wpinsider-1--Simple = Membership The Simple Membership plugin for WordPress is vulnerable to auth= orization bypass in all versions up to, and including, 4.7.5. This is due t=
o the plugin not properly verifying that a user is authorized to perform an=
action. This makes it possible for unauthenticated attackers to deactivate=
arbitrary member accounts by forging a charge.refunded webhook event conta= ining a victim's subscription ID, setting the target member's account_state=
to 'inactive' and triggering cancellation hooks, transaction-record status=
changes, and cancellation notification emails. This vulnerability is explo= itable only on installations where no Stripe webhook signing secret has bee=
n configured, which is the default out-of-the-box state; sites that have co= nfigured the stripe-webhook-signing-secret option are routed to the properl=
y verified HMAC path and are not affected. 2026-06-18 5.3 CVE-2026-12093 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-12093 ] Wpmet--GetGenie Unauthe= nticated Sensitive Data Exposure in GetGenie <=3D 4.4.1 versions. 2026-06-1=
6 6.5 CVE-2026-54197 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54197 ] = WPMet--MetForm Pro Subscriber Broken Access Control in MetForm Pro <=3D 3.9=
.1 versions. 2026-06-17 4.3 CVE-2026-24610 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-24610 ] wproyal--Royal Addons for Elementor Addons and Templa= tes Kit for Elementor The Royal Addons for Elementor - Addons and Templates=
Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Rea=
d in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_han= dle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2= 026-6229) falling back to is_readable() and fopen($source, 'r') on the atta= cker-controlled settings.table_upload_csv.url value when it does not parse =
as an HTTP URL, with no allow-list, traversal block, or extension check. Th=
is makes it possible for authenticated attackers, with Contributor-level ac= cess and above, to save a crafted wpr-data-table widget through Elementor's=
save_builder endpoint and have the rendered preview return the line-by-lin=
e contents of any file readable by the PHP process, including wp-config.php=
. 2026-06-19 6.5 CVE-2026-8118 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-8118 ] WWBN--AVideo AVideo TopMenu plugin through version 26.0 contains a=
stored cross-site scripting vulnerability in menu item rendering due to mi= ssing output encoding of icon classes, URLs, and text labels. Attackers can=
inject malicious JavaScript through unescaped menu item fields that execut=
e for all site visitors, potentially stealing session cookies or performing=
unauthorized actions. 2026-06-20 6.1 CVE-2026-56347 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-56347 ] XianYuLauncher--XianYuLauncher XianYuLaunch=
er is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensit= ive authentication artifacts could be exposed during a user-initiated login=
under certain local attack conditions. Affected versions relied on a fixed=
localhost redirect URI without PKCE or state validation. Exploitation is m= ost likely to occur when an attacker is able to observe, intercept, or othe= rwise interfere with the local authentication flow on the same device. This=
issue has been fixed in version 1.5.5. 2026-06-17 5.5 CVE-2026-48991 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-48991 ] Yealink--SIP-T46U A flaw h=
as been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the=
function mod_diagnose.CommandShellByType of the file /api/diagnosis/start =
of the component Web FastCGI Service. This manipulation of the argument Tim=
e causes command injection. The attack can be initiated remotely. The explo=
it has been published and may be used. The vendor was contacted early about=
this disclosure but did not respond in any way. 2026-06-15 6.3 CVE-2026-12= 219 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12219 ] Yealink--SIP-T46U=
A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected =
by this vulnerability is the function mod_webd.TFTPUploadIperf of the file = /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipu= lation of the argument ip/port leads to command injection. The attack needs=
to be initiated within the local network. The exploit is publicly availabl=
e and might be used. The vendor was contacted early about this disclosure b=
ut did not respond in any way. 2026-06-15 5.5 CVE-2026-12223 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-12223 ] Yoast BV--Yoast SEO Premium Missing=
Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploitin=
g Incorrectly Configured Access Control Security Levels. This issue affects=
Yoast SEO Premium: from n/a through 26.6. 2026-06-17 5.5 CVE-2026-40722 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-40722 ] zealopensource--Abandon=
ed Contact Form 7 The Abandoned Contact Form 7 plugin for WordPress is vuln= erable to unauthorized arbitrary post deletion in versions up to, and inclu= ding, 2.2. This is due to a missing capability check and missing nonce vali= dation in the action__remove_abandoned() function, which is registered to b= oth the wp_ajax_remove_abandoned and wp_ajax_nopriv_remove_abandoned hooks.=
The handler takes a user-supplied recover_id parameter from $_POST and pas= ses it directly to wp_delete_post() with the force-delete flag set to true,=
without verifying that the ID belongs to the plugin's own cf7af_data post = type. This makes it possible for unauthenticated attackers to permanently d= elete arbitrary posts, pages, or other content on the affected site by send= ing a single admin-ajax. 2026-06-16 5.3 CVE-2026-9187 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-9187 ] zephyrproject--zephyr On Xtensa targets wit=
h CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/= core/ptables.c) maintains a global list, xtensa_domain_list, of active memo=
ry domains using a list node embedded inside the caller-owned struct k_mem_= domain. When a domain is destroyed via k_mem_domain_deinit() - arch_mem_dom= ain_deinit(), the page tables are torn down and domain-arch.ptables is set =
to NULL, but the domain's node was not removed from xtensa_domain_list. The=
freed/deinitialized domain therefore remained linked into the global list =
as a dangling pointer into caller-owned storage that may then be freed or r= eused. Any subsequent arch_mem_map()/arch_mem_unmap() operation (widely inv= oked by kernel memory-mapping and demand-paging code) traverses the stale n= ode and dereferences domain-ptables: at minimum a NULL pointer dereference = causing a fatal MMU exception (denial of service), and if the k_mem_domain = storage has been freed or reused, a use-after-free in which a stale/control= led ptables value is dereferenced and written through during the page-table=
walk (l2_page_table_map writes l1_table[...] and l2_table[...], and xtensa= _mmu_compute_domain_regs writes into the domain struct and the L1 table), y= ielding page-table memory corruption that can undermine userspace isolation=
. The vulnerable path is reachable only from privileged kernel/supervisor c= ode (k_mem_domain_deinit is not a syscall), not directly from unprivileged = user threads or remotely. Affected: Zephyr v4.4.0 (the Xtensa memory-domain=
de-initialization feature was introduced in commit 3032b58f52d and first s= hipped in v4.4.0); fixed on main by adding sys_slist_find_and_remove() in a= rch_mem_domain_deinit(). The Xtensa MPU path is unaffected. 2026-06-16 6.3 = CVE-2026-10635 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10635 ] zephyr= project--zephyr subsys/net/ip/ipv6_mld.c:mld_send() read the packet interfa=
ce via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. P=
er the network stack's ownership contract (include/zephyr/net/net_core.h, a=
nd the explicit warning in subsys/net/ip/net_core.c:453-460 'do not use pkt=
after that call'), a successful send transfers ownership of the net_pkt an=
d the L2 driver frees it (e.g. ethernet_send() unrefs the packet on success=
, subsys/net/l2/ethernet/ethernet.c:790), returning it to its k_mem_slab. T=
he subsequent net_pkt_iface(pkt) is therefore a read of a freed object; the=
recovered interface pointer is then dereferenced and incremented by the pe= r-interface statistics path (net_stats.h UPDATE_STAT/SET_STAT) when CONFIG_= NET_STATISTICS_PER_INTERFACE is enabled. If the freed slot is concurrently = reallocated, pkt-iface may read back as NULL (NULL-pointer dereference / cr= ash) or as a stale/garbage pointer (stray increment write / memory corrupti= on). The path is reachable remotely on the local link without authenticatio=
n: handle_mld_query() (registered for NET_ICMPV6_MLD_QUERY) responds to a v= alid MLDv2 General Query (unspecified multicast address, hop limit 1) by ca= lling send_mld_report() - mld_send(). The result is a remotely triggerable = denial of service of the networking stack, with a narrow possibility of mem= ory corruption. The fix caches the interface in a local before sending and =
no longer touches the packet after net_send_data(). The IPv4/IGMP sibling (= igmp_send) already used the corrected pattern. 2026-06-16 5.9 CVE-2026-1063=
7 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10637 ] zephyrproject--zeph=
yr subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after = that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_r= equest() and net_icmpv6_send_error(), the post-send statistics update calls=
net_pkt_iface(reply)/net_pkt_iface(pkt) on the just-sent packet. The send = path (net_try_send_data - net_if_tx) unreferences and may free the packet b= ack to its memory slab before returning - synchronously in the RX thread wh=
en no TX queue is configured (CONFIG_NET_TC_TX_COUNT =3D=3D 0), and asynchr= onously the driver/L2 may already have freed it otherwise. net_pkt_iface() = therefore dereferences a freed (and possibly reused) net_pkt; with CONFIG_N= ET_STATISTICS_PER_INTERFACE the stale iface pointer is further dereferenced=
and written through (iface-stats.icmp.sent++), turning the use-after-free = read into a write through an attacker-influenceable pointer. The core stack=
already documents this hazard in net_core.c ("do not use pkt after that ca= ll") and caches iface before sending; the ICMPv6 callers did not. An unauth= enticated remote attacker triggers the flaw simply by sending an ICMPv6 Ech=
o Request (ping) or an IPv6 packet that elicits an ICMPv6 error (unknown ne=
xt header, fragment reassembly timeout, destination unreachable), leading t=
o denial of service via crash and potential memory corruption. Affected: Ze= phyr networking with CONFIG_NET_NATIVE_IPV6, roughly v4.2.0 through v4.4.0.=
The fix caches the interface pointer before sending and uses it for all st= atistics updates; the sibling commit 86e21665d46 fixes the identical bug in=
ICMPv4. 2026-06-16 5.9 CVE-2026-10638 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-10638 ] zephyrproject--zephyr Zephyr's native TCP stack iterate=
s the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) usi=
ng the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to t=
he next list node. Prior to this fix the function released tcp_lock while i= nvoking the per-connection callback and re-acquired it afterwards. During t= hat window a concurrent tcp_conn_release(), running on the dedicated TCP wo= rk-queue thread when a connection's reference count drops to zero (e.g. a r= emote peer closing or resetting the connection), can remove and k_mem_slab_= free() the cached next connection. When the iterator advances it dereferenc=
es the freed (and possibly reallocated) slab memory - a use-after-free that=
can crash the system (denial of service) and, if the slot has been reused,=
cause the callback to operate on an attacker-influenced object (potential = information disclosure or further fault). net_tcp_foreach() is reached in p= roduction via the 'net conn' network shell command and via net_tcp_close_al= l_for_iface() on interface-down; the freeing side is driven by ordinary TCP=
traffic. The fix moves the connection/context teardown in tcp_conn_release=
() inside the tcp_lock critical section and keeps tcp_lock held across the = callback in net_tcp_foreach(). The defect was introduced with the modern (T= CP2) stack in 2020 and affects releases up to and including v4.4.0. 2026-06= -15 4.8 CVE-2026-10634 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10634 =
] zephyrproject--zephyr In Zephyr's native IPv4 stack, icmpv4_handle_echo_r= equest() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), han=
ds it to net_try_send_data(), and then, on success, calls net_stats_update_= icmp_sent(net_pkt_iface(reply)). net_try_send_data() transfers ownership of=
reply to the TX path (net_if_try_queue_tx - net_if_tx - L2/driver send, or=
the asynchronous net_if_tx_thread), which can unref it to refcount 0 and r= eturn the struct net_pkt to its slab (net_pkt_unref - k_mem_slab_free) befo=
re the stats line runs. net_core.c documents this exact contract ('the pkt = might contain garbage already ... do not use pkt after that call'). The pos= t-send net_pkt_iface(reply) therefore reads reply-iface out of a freed (and=
possibly already reallocated) net_pkt, a use-after-free read; with CONFIG_= NET_STATISTICS_PER_INTERFACE the stats macro additionally increments a coun= ter through that value, i.e. a dereference/write through a stale or recycle= d-slot pointer. The path is reached unauthenticated by any remote host that=
pings the device (net_icmpv4_input - net_icmp_call_ipv4_handlers - icmpv4_= handle_echo_request) and is gated on CONFIG_NET_STATISTICS_ICMP. Impact is =
a probabilistic read of recycled packet memory plus a possible wild-pointer=
write under a timing race, leading most likely to corrupted interface stat= istics or a remotely triggerable crash (DoS). The defect was introduced in = 2019 (v1.14) and is present through v4.4.0. The companion change in net_icm= pv4_send_error() is not a use-after-free because it reads net_pkt_iface(ori= g), the caller-owned received packet, which stays alive across the send. Th=
e fix caches the interface pointer from the live received packet before sen= ding and uses it for the post-send stats updates. 2026-06-16 4.8 CVE-2026-1= 0639 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10639 ] zephyrproject--z= ephyr Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ip= v6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-i= nterface ICMP-sent statistics by calling net_pkt_iface(pkt) after net_send_= data(pkt) had already returned successfully. On the success path the networ=
k stack owns and releases the packet's reference (the L2/driver send unrefs=
it, e.g. ethernet_send - net_pkt_unref), so for a freshly allocated packet=
with refcount 1 the net_pkt slab block can be freed before the statistics = line runs (synchronously when no TX queue thread is configured, or via a co= ncurrent TX thread otherwise). The subsequent net_pkt_iface(pkt) reads pkt-= iface from the freed slab block, and with CONFIG_NET_STATISTICS_PER_INTERFA=
CE enabled that loaded pointer is dereferenced to increment iface-stats.icm= p.sent, a use-after-free (CWE-416). If the slab block was reallocated in th=
e meantime the read/increment targets unrelated or attacker-influenced memo= ry, yielding corrupted statistics, a fault/crash (denial of service), or po= tential limited memory corruption. The vulnerable Neighbor Advertisement pa=
th is reachable by any unauthenticated on-link node simply by sending ICMPv=
6 Neighbor Solicitations to a Zephyr node with native IPv6 enabled (handle_= ns_input - net_ipv6_send_na). Affected from v3.3.0 through v4.4.0; the fix = uses the already-available iface argument instead of touching the sent pack= et. Configurations without per-interface statistics dereference only a glob=
al counter and are not affected by the memory-safety aspect. 2026-06-16 4.2=
CVE-2026-10640 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10640 ] zhili=
nk ()--ADP Application Developer Platform A vulnerability was found in zhil= ink =C3=A6=E2=84=A2=C2=BA=C3=A4=C2=BA=E2=80=99=C3=A8=C2=81=E2=80=9D(=C3=A6= =C2=B7=C2=B1=C3=A5=C5=93=C2=B3)=C3=A7=C2=A7=E2=80=98=C3=A6=C5=A0=E2=82=AC= =C3=A6=C5=93=E2=80=B0=C3=A9=E2=84=A2=C2=90=C3=A5=E2=80=A6=C2=AC=C3=A5=C2=8F= =C2=B8 ADP Application Developer Platform =C3=A5=C2=BA=E2=80=9D=C3=A7=E2=80= =9D=C2=A8=C3=A5=C2=BC=E2=82=AC=C3=A5=C2=8F=E2=80=98=C3=A8=E2=82=AC=E2=80=A6= =C3=A5=C2=B9=C2=B3=C3=A5=C2=8F=C2=B0 1.0.0. This affects an unknown part of=
the component testConnection Endpoint. The manipulation of the argument jd= bcUrl results in deserialization. The attack may be performed from remote. = The exploit has been made public and could be used. The vendor was contacte=
d early about this disclosure but did not respond in any way. 2026-06-21 6.=
3 CVE-2026-12787 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12787 ] zhil= ink ()--ADP Application Developer Platform A vulnerability was determined i=
n zhilink =C3=A6=E2=84=A2=C2=BA=C3=A4=C2=BA=E2=80=99=C3=A8=C2=81=E2=80=9D(= =C3=A6=C2=B7=C2=B1=C3=A5=C5=93=C2=B3)=C3=A7=C2=A7=E2=80=98=C3=A6=C5=A0=E2= =82=AC=C3=A6=C5=93=E2=80=B0=C3=A9=E2=84=A2=C2=90=C3=A5=E2=80=A6=C2=AC=C3=A5= =C2=8F=C2=B8 ADP Application Developer Platform =C3=A5=C2=BA=E2=80=9D=C3=A7= =E2=80=9D=C2=A8=C3=A5=C2=BC=E2=82=AC=C3=A5=C2=8F=E2=80=98=C3=A8=E2=82=AC=E2= =80=A6=C3=A5=C2=B9=C2=B3=C3=A5=C2=8F=C2=B0 1.0.0. This vulnerability affect=
s unknown code of the file /adpweb/a/base/barcodeDetail/import of the compo= nent XML Parser. This manipulation causes xml external entity reference. It=
is possible to initiate the attack remotely. The exploit has been publicly=
disclosed and may be utilized. The vendor was contacted early about this d= isclosure but did not respond in any way. 2026-06-21 6.3 CVE-2026-12788 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-12788 ]=20
Back to top [ #top ]
Low Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info Black Lanter=
n Security--BBOT The docker_pull module uses the realm parameter from a Doc= ker registry's WWW-Authenticate response header as the authentication endpo= int without validation. An attacker in a man-in-the-middle position between=
bbot and a Docker registry could modify this header to redirect the authen= tication request to an arbitrary endpoint, potentially leaking authenticati=
on tokens. 2026-06-17 3.1 CVE-2026-12566 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12566 ] Black Lantern Security--BBOT The github_workflows modul=
e constructs local directory paths from user-controlled repository names wi= thout validating for symlinks. A local attacker sharing the scan directory = can plant a symlink at the predictable output path, causing workflow data t=
o be written to an attacker-chosen location. 2026-06-17 2.2 CVE-2026-12567 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12567 ] Browerbase--Browserba=
se A security flaw has been discovered in Browserbase up to 20260526. This = impacts an unknown function of the component Autobrowse Trace Artifact Hand= ler. The manipulation results in incorrect default permissions. The attack = requires a local approach. The exploit has been released to the public and = may be used for attacks. The vendor was contacted early about this disclosu=
re but did not respond in any way. 2026-06-21 3.3 CVE-2026-12823 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-12823 ] Capgo--Capgo Capgo before 12.12= 8.2 contains an authentication logic flaw: a user with permission to manage=
team or organization security settings can enable mandatory two-factor aut= hentication for all team members without first enabling 2FA on their own ac= count. The application fails to verify the initiator's 2FA status before al= lowing the policy change, resulting in inconsistent security enforcement, p= otential administrative misuse, and lockout risk for team members. 2026-06-=
20 3.8 CVE-2026-56212 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56212 ]=
Capgo--Capgo Capgo before 12.128.2 uses ILIKE pattern matching instead of = exact matching for app_id lookup in the preview subdomain resolver, allowin=
g underscore characters in app_id to act as SQL wildcards. Attackers can cr= eate apps with app_ids differing by one character at underscore positions t=
o cause unintended pattern matches, breaking preview functionality for legi= timate apps or causing app-id confusion. 2026-06-20 3.1 CVE-2026-56325 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-56325 ] Capgo--Capgo Capgo before=
12.128.2 contains an open redirect vulnerability in stripe_portal and stri= pe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and = cancelUrl parameters. Authenticated attackers can craft malicious billing U= RLs to redirect users to attacker-controlled domains for phishing and crede= ntial harvesting. 2026-06-20 3.5 CVE-2026-56330 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-56330 ] Dell--PowerFlex Dell PowerFlex Manager, version(=
s) [Versions], contain(s) an Improper Neutralization of Special Elements us=
ed in an SQL Command ('SQL Injection') vulnerability. A low privileged atta= cker with adjacent network access could potentially exploit this vulnerabil= ity, leading to information disclosure. 2026-06-17 3.5 CVE-2026-35068 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-35068 ] GNU--Savane GNU Savannah A= dministration Savane through 3.17 uses untrusted data as part of authorizat= ion. 2026-06-20 3.7 CVE-2026-56355 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-56355 ] HCL Software--iControl HCL iControl was affected by Inadequat=
e Session Timeout vulnerability. The vulnerability involves a security risk=
where a web application fails to automatically terminate user sessions aft=
er a period of inactivity 2026-06-17 3.1 CVE-2025-62340 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2025-62340 ] ImageMagick--ImageMagick ImageMagick bef= ore 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the=
PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that ca= uses a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB f= ile can lead to information disclosure or a crash. 2026-06-21 3.7 CVE-2026-= 56367 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56367 ] ImageMagick--Im= ageMagick ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a=
heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD=
file can trigger a one-byte heap out-of-bounds read during image decoding,=
resulting in denial of service and potential disclosure of an adjacent hea=
p byte. 2026-06-21 3.7 CVE-2026-56378 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-56378 ] Intelbras--iNVU 7016 FT A flaw has been found in Intelbras=
iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown f= unction of the file /RPC2_Loadfile/syslog/ of the component Web Interface. = Executing a manipulation can lead to path traversal. The attack can be laun= ched remotely. The exploit has been published and may be used. It is recomm= ended to upgrade the affected component. The vendor was contacted early, re= sponded in a very professional manner and quickly released a fixed version =
of the affected product. 2026-06-15 2.7 CVE-2026-12211 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12211 ] Intelliants--Subrion CMS A vulnerability = has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this iss=
ue is some unknown functionality of the component Blocks Endpoint. Such man= ipulation of the argument CSS class name leads to cross site scripting. The=
attack may be launched remotely. The exploit has been disclosed to the pub= lic and may be used. The vendor was contacted early about this disclosure b=
ut did not respond in any way. 2026-06-15 2.4 CVE-2026-12202 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-12202 ] NI--grpc-device There is an incorre=
ct conversion between numeric types vulnerability in NI grpc-device due to = missing range checks in=C2=A0CodeGen.=C2=A0 This may silently discard high = bits if a size value exceeded the target type's range. This affects NI grpc= -device 2.17.0 and prior versions. 2026-06-19 3.7 CVE-2026-9143 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-9143 ] OliveTin--OliveTin OliveTin gives=
access to predefined shell commands from a web interface. In versions 3000= .0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/a= pi/api.go does not perform any authentication or authorization checks. Unli=
ke all other data-returning API endpoints, it does not call auth.UserFromAp= iCall or checkDashboardAccess. When AuthRequireGuestsToLogin is enabled (th=
e security-conscious configuration), this endpoint remains accessible to un= authenticated users and can be used as an oracle to enumerate valid action = binding IDs and their argument configurations. This issue has been fixed in=
version 3000.13.0. 2026-06-15 3.7 CVE-2026-48709 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-48709 ] Oracle Corporation--Oracle VM VirtualBox Vulne= rability in the Oracle VM VirtualBox product of Oracle Virtualization (comp= onent: VMSVGA device). The supported version that is affected is 7.2.8. Eas= ily exploitable vulnerability allows high privileged attacker with logon to=
the infrastructure where Oracle VM VirtualBox executes to compromise Oracl=
e VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attack=
s may significantly impact additional products (scope change). Successful a= ttacks of this vulnerability can result in unauthorized read access to a su= bset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Conf= identiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:= N/A:N). 2026-06-16 3.2 CVE-2026-46815 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-46815 ] Oracle Corporation--Oracle VM VirtualBox Vulnerability in = the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVG=
A device). The supported version that is affected is 7.2.8. Easily exploita= ble vulnerability allows high privileged attacker with logon to the infrast= ructure where Oracle VM VirtualBox executes to compromise Oracle VM Virtual= Box. While the vulnerability is in Oracle VM VirtualBox, attacks may signif= icantly impact additional products (scope change). Successful attacks of th=
is vulnerability can result in unauthorized read access to a subset of Orac=
le VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality = impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N). 2026= -06-16 3.2 CVE-2026-46816 [
https://www.cve.org/CVERecord?id=3DCVE-2026-468=
16 ] Oracle Corporation--Oracle VM VirtualBox Vulnerability in the Oracle V=
M VirtualBox product of Oracle Virtualization (component: Core). The suppor= ted version that is affected is 7.2.8. Easily exploitable vulnerability all= ows high privileged attacker with logon to the infrastructure where Oracle =
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulner= ability is in Oracle VM VirtualBox, attacks may significantly impact additi= onal products (scope change). Successful attacks of this vulnerability can = result in unauthorized read access to a subset of Oracle VM VirtualBox acce= ssible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector=
: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N). 2026-06-16 3.2 CVE-2026-4= 6874 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46874 ] Oracle Corporati= on--Oracle VM VirtualBox Vulnerability in the Oracle VM VirtualBox product =
of Oracle Virtualization (component: VMSVGA device). The supported version = that is affected is 7.2.8. Easily exploitable vulnerability allows high pri= vileged attacker with logon to the infrastructure where Oracle VM VirtualBo=
x executes to compromise Oracle VM VirtualBox. While the vulnerability is i=
n Oracle VM VirtualBox, attacks may significantly impact additional product=
s (scope change). Successful attacks of this vulnerability can result in un= authorized read access to a subset of Oracle VM VirtualBox accessible data.=
CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/= AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N). 2026-06-16 3.2 CVE-2026-46977 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-46977 ] pgadmin.org--pgAdmin 4 HTML = injection in pgAdmin 4's cloud deployment module. The verify_credentials, d= eploy, regions, and update-server endpoints under /rds/, /azure/, /google/,=
and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK ex= ception text - and the related file-resolution and database-commit exceptio=
n text - into the JSON response body (the info and errormsg fields) without=
HTML-encoding. The Cloud Wizard frontend rendered these strings through ht= ml-react-parser, so an attacker-influenced exception message embedded struc= tural HTML directly into the wizard's DOM. The reported entry point is /rds= /verify_credentials/. An authenticated pgAdmin user submits a crafted acces= s_key whose value contains an <iframe/src=3D...> payload; AWS STS rejects t=
he credential with an IncompleteSignature exception whose text quotes the a= ccess_key verbatim; the pgAdmin backend forwards that text into the JSON in=
fo field; the Cloud Wizard's FormFooterMessage parses it as HTML. The brows=
er fetches the iframe's src from an attacker-controlled host, and JavaScrip=
t executing inside the cross-origin iframe writes to parent.location, redir= ecting the victim's pgAdmin tab. Because the injection renders inside pgAdm= in's own interface, X-Frame-Options and Content-Security-Policy frame-ances= tors do not mitigate it. Baseline impact is self-targeted (the same user wh=
o supplied the payload sees the injection); escalation against other authen= ticated users requires an additional cross-site request-forgery primitive c= apable of submitting the malformed credential request with a valid X-pgA-CS= RFToken in the victim's browser context. The same unsanitised-error-into-JS=
ON pattern was present across multiple sibling endpoints - Azure's check_cl= uster_name_availability, every Google endpoint that surfaces SDK errors (ve= rification_ack, projects, regions, instance_types, database_versions, the v= erify_credentials path-resolution branches), the central /deploy endpoint t= hat bubbles str(e) from deploy_on_rds / deploy_on_azure / deploy_on_google,=
and update_cloud_server which surfaces the str(e) from a failing db.sessio= n.commit - all of which are now covered. Fix HTML-escapes every external/SD=
K exception string at the endpoint sink via a new shared sanitize_external_= text helper (HTML escape with control-character strip), promoted out of the=
psycopg3 driver into web/pgadmin/utils/text_sanitize.py. The Cloud Wizard = frontend additionally renders its FormFooterMessage in plain-text mode for = backend-derived strings, so the value is never parsed as HTML even if a fut= ure sink forgets the escape. This issue affects pgAdmin 4: from 6.6 before = 9.16. 2026-06-18 3.5 CVE-2026-12047 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-12047 ] pontedilana--php-weasyprint PhpWeasyPrint is a PHP library a= llowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, = `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporar= yFiles()` - invoked from `__destruct()` and from a registered shutdown func= tion - calls `unlink()` on every entry without verifying that the path is c= ontained within the temporary folder. Any code holding a reference to a gen= erator instance can push an arbitrary path into the array and have it delet=
ed on script shutdown. This mirrors the KnpLabs/snappy issue GHSA-87qc-37cw= -84h4. PhpWeasyPrint version 2.6.0 contains a patch for the issue. 2026-06-=
19 3 CVE-2026-49358 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49358 ] R= adware--Cyber Controller A security vulnerability has been detected in Radw= are Cyber Controller up to 10.11.0. This affects an unknown part of the com= ponent HTML Report Generation. The manipulation leads to HTML injection. Re= mote exploitation of the attack is possible. The exploit has been disclosed=
publicly and may be used. The vendor was contacted early about this disclo= sure but did not respond in any way. 2026-06-21 3.5 CVE-2026-12812 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-12812 ] Snes9X team--Snes9X snes9x 1.=
63 allows an out-of-bounds write and denial of service via a crafted .ups f= ile. 2026-06-17 2.9 CVE-2026-39199 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-39199 ] SteeltoeOSS--Steeltoe.Configuration.Encryption Steeltoe is an=
open source project that provides a collection of libraries that helps use=
rs build cloud-native applications. In Steeltoe.Configuration.Encryption 4.= 0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=3DOAEP` does not enab=
le OAEP encryption. Due to an incorrect BouncyCastle transformation string,=
the `OAEP` setting selects PKCS#1 v1.5, which is the same algorithm as the=
`DEFAULT` setting. Steeltoe.Configuration.Encryption version 4.2.0 patches=
the issue. 2026-06-17 1.9 CVE-2026-50268 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-50268 ] stiofansisland--UsersWP Front-end login form, User Reg= istration, User Profile & Members Directory plugin for WP The UsersWP - Fro= nt-end login form, User Registration, User Profile & Members Directory plug=
in for WP plugin for WordPress is vulnerable to Insecure Direct Object Refe= rence in all versions up to, and including, 1.2.63 via the 'user_id' parame= ter due to missing validation on a user controlled key. This makes it possi= ble for authenticated attackers, with editor-level access and above, to res=
et and permanently delete the avatar or banner image of any arbitrary user,=
including administrators, by clearing their avatar_thumb or banner_thumb m= etadata in the uwp_usermeta table. 2026-06-18 2.7 CVE-2026-12102 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-12102 ] undici--undici Impact: When und= ici parses a Set-Cookie header, it accepts any SameSite attribute value tha=
t contains Strict, Lax, or None as a substring, rather than the case-insens= itive exact match specified by RFC 6265. Non-spec values are silently mappe=
d to one of the three standard tokens. For example, SameSite=3DNoneOfYourBu= siness is parsed as None (the most permissive setting), and SameSite=3DStri= ctLax is parsed as Lax (a downgrade from Strict). Affected applications are=
those that consume Set-Cookie headers from server responses (for example v=
ia undici's fetch or proxy code paths) and then forward or rely on the pars=
ed sameSite attribute. A malicious or non-compliant server can coerce the c= onsumer's view of a cookie's SameSite policy to a weaker value, silently de= grading the SameSite enforcement the cookie is supposed to provide. This wa=
s introduced in undici 5.15.0 when the cookies feature was added. Patches: = Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a = Set-Cookie header, validate that the resulting sameSite attribute is one of=
'Strict', 'Lax', or 'None' (exact, case-insensitive) before forwarding or = relying on it. 2026-06-17 3.7 CVE-2026-11525 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-11525 ] undici--undici Impact: Undici's HTTP/1.1 client is = vulnerable to response queue poisoning on reused keep-alive sockets. An att= acker-controlled upstream server can inject an unsolicited HTTP/1.1 respons=
e onto an idle socket after a request completes. When the client dispatches=
the next request on that socket, it associates the injected response with = the new request, causing responses to be delivered to the wrong requests. T= his requires an attacker-controlled or compromised upstream HTTP/1.1 server=
and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28=
.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting k= eepAliveTimeout: 0 on the Client or Pool. 2026-06-17 3.7 CVE-2026-6733 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-6733 ] zephyrproject--zephyr In Z= ephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read = the network interface back out of the packet via net_pkt_iface(pkt) after t=
he packet had been handed to net_send_data(). On the successful-send path t=
he packet's last reference may already have been released by the L2 driver =
or by the network stack's TX handling (synchronously in the default NET_TC_= TX_COUNT=3D0 immediate-transmit configuration), returning the net_pkt slab = block to its free list. The subsequent net_pkt_iface(pkt) dereferences the = freed packet, a use-after-free read; with CONFIG_NET_STATISTICS_PER_INTERFA=
CE the resulting dangling interface pointer is further dereferenced for a s= tatistics-counter write. The IGMP send path is reachable without authentica= tion from inbound IPv4 IGMP membership queries addressed to 224.0.0.1 (net_= ipv4_igmp_input - send_igmp_report/send_igmp_v3_report - igmp_send), as wel=
l as from local multicast join/leave/rejoin operations. Realistic impact is=
undefined behavior and potential denial of service (sporadic crash or stat=
s corruption); a controllable write requires the asynchronous TX path plus =
a concurrent slab reuse. The flaw was introduced with IGMPv2 support and af= fects releases from v2.6.0 through v4.4.0. The fix caches the interface poi= nter before sending. Note the analogous IPv6 MLD path (mld_send in subsys/n= et/ip/ipv6_mld.c) retains the same unfixed pattern. 2026-06-16 3.7 CVE-2026= -10636 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10636 ]=20
Back to top [ #top ]
Severity Not Yet Assigned
Primary
Vendor -- Product Description Published CVSS Score Source Info AcademySoftw= areFoundation--openexr OpenEXR is the reference implementation and specific= ation for the EXR image format, widely used in the motion picture industry.=
In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) de= coder, ht_undo_impl() in OpenEXRCore is vulnerable to a heap-buffer-overflo=
w READ. The ht_undo_imp function copies decoded pixels out of a per-line Op= enJPH buffer using the EXR channel's declared width as the iteration count.=
The codestream embedded in the EXR chunk can declare different (smaller) t= ile/line dimensions than the EXR header advertises, but ht_undo_impl() does=
not validate this - it pulls width 32-bit samples from cur_line->i32[] wit= hout checking the OpenJPH line buffer's actual length. A crafted EXR file p= roduces a 4-byte heap-buffer-overflow READ immediately after a buffer alloc= ated by ojph::local::codestream::finalize_alloc(). The bug is reachable thr= ough the standard scanline-decode entry point used by every consumer of exr= _decoding_run/Imf::checkOpenEXRFile, including thumbnailers, asset pipeline=
s, and the exrcheck utility - i.e. any application that opens untrusted EXR=
files. The result is a deterministic crash (DoS) and potential adjacent-he=
ap leak. This issue has been fixed in version 3.4.12. 2026-06-18 not yet ca= lculated CVE-2026-45696 [
https://www.cve.org/CVERecord?id=3DCVE-2026-45696=
] ail-project--ail-framework AIL framework contains a path traversal vulne= rability in the /objects/item/diff endpoint. The endpoint accepts item iden= tifiers through the s1 and s2 query parameters and, prior to the fix, attem= pted to retrieve and compare item contents without first verifying that bot=
h referenced items existed as valid AIL objects. An authenticated AIL user = could craft malicious item identifiers containing path traversal sequences =
to cause the application to read gzip-compressed files accessible to the AI=
L process. This could result in unauthorized disclosure of local file conte= nts, limited to files readable by the application and compatible with the e= xpected gzip-compressed item format. The issue was fixed by validating that=
both requested items exist before their contents are accessed. 2026-06-19 = not yet calculated CVE-2026-56138 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-56138 ] Andrei Marcu--Andrei Marcu linx-server v2.3.8 An issue in the = uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attac= kers to cause a Denial of Service (DoS) via a crafted POST request. 2026-06= -15 not yet calculated CVE-2026-50879 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-50879 ] Android--Android In Contacts Provider, there is a possible=
way to access the contacts database due to SQL injection. This could lead =
to local information disclosure with no additional execution privileges nee= ded. User interaction is not needed for exploitation. 2026-06-17 not yet ca= lculated CVE-2026-28576 [
https://www.cve.org/CVERecord?id=3DCVE-2026-28576=
] anna-is-cute--paste v0.1.1 An issue in the /api/v0/pastes endpoint of an= na-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)=
via a crafted POST request. 2026-06-15 not yet calculated CVE-2026-50882 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-50882 ] ANSSI--DFIR-ORC Local = privilege escalation by loading DLLs from a shared temporary directory in A= NSSI's DFIR-ORC, versions 10.2.7 and prior. An attacker with prior access t=
o the system, can place a malicious DLL in C:\Windows\Temp and wait for the=
application to be executed. Because DFIR-ORC is extracted and executed fro=
m that location with administrative privileges, the malicious library can b=
e loaded automatically, allowing the attacker to gain administrator privile= ges on the affected machine. 2026-06-18 not yet calculated CVE-2026-11958 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-11958 ] Apache Software Founda= tion--Apache Airflow SFTP provider A path traversal in the SFTP provider (`= SFTPHook.retrieve_directory` / `SFTPOperator(operation=3Dget)`) let a malic= ious or compromised remote SFTP server write files outside the configured l= ocal destination directory via crafted directory-entry names. No Airflow ac= count is required - the attack surface is any deployment downloading direct= ories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp=
` to 5.8.1 or later. 2026-06-17 not yet calculated CVE-2026-50203 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-50203 ] Apache Software Foundation--Ap= ache APISIX Improper Input Validation vulnerability in Apache APISIX. The a= ttacker can take advantage of certain configuration in forward-auth plugin =
to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 th= rough 3.16.0. Users are recommended to upgrade to version 3.17.0, which fix=
es the issue. 2026-06-19 not yet calculated CVE-2026-39998 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-39998 ] Apache Software Foundation--Apache AP= ISIX Authentication Bypass by Spoofing vulnerability in Apache APISIX. The = attacker can completely bypass authentication capitalising on certain confi= gurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 t= hrough v3.16.0. Users are recommended to upgrade to version v3.17.0, which = fixes the issue. 2026-06-19 not yet calculated CVE-2026-39999 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-39999 ] Apache Software Foundation--Apache=
APISIX Use of Less Trusted Source vulnerability in Apache APISIX. Attacker=
can take advantage of wolf-rbac plugin under default configuration to pote= ntially pollute logs with spoofed identity information and exploit IP based=
access control rules. This issue affects Apache APISIX: from 1.2.0 through=
3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes th=
e issue. 2026-06-19 not yet calculated CVE-2026-44046 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-44046 ] Apache Software Foundation--Apache APISIX = Insufficient Verification of Data Authenticity vulnerability in Apache APIS= IX. The openid-connect plugin under default configuration has an attack sur= face that allows the attacker to spoof identity headers allowing the attack=
er to get unauthorized access the protected resources. This issue affects A= pache APISIX: from 2.3 through 3.16.0. Users are recommended to upgrade to = version 3.17.0, which fixes the issue. 2026-06-19 not yet calculated CVE-20= 26-44087 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44087 ] Apache Softw= are Foundation--Apache APISIX URL Redirection to Untrusted Site ('Open Redi= rect') vulnerability in Apache APISIX. The default configuration of cas-aut=
h in Apache APISIX is vulnerable to phishing and credential theft. This iss=
ue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended =
to upgrade to version 3.17.0, which fixes the issue. 2026-06-19 not yet cal= culated CVE-2026-44915 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44915 =
] Apache Software Foundation--Apache APISIX Incorrect Authorization vulnera= bility in Apache APISIX. An attacker can capitalise on authz-casdoor plugin=
under default configuration to authenticate themselves with credentials fr=
om a different source. This issue affects Apache APISIX: from 2.14.1 throug=
h 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes t=
he issue. 2026-06-19 not yet calculated CVE-2026-47339 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-47339 ] Apache Software Foundation--Apache APISIX=
Authentication Bypass by Capture-replay vulnerability in Apache APISIX. At= tacker can benefit from certain configurations in hmac-auth to re-use a tok=
en forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0=
through 3.16.0. Users are recommended to upgrade to version 3.17.0, which = fixes the issue. 2026-06-19 not yet calculated CVE-2026-47341 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-47341 ] Apache Software Foundation--Apache=
APISIX URL Redirection to Untrusted Site ('Open Redirect') vulnerability i=
n Apache APISIX. The attacker could manipulate some client headers to perfo=
rm an open-redirect, to potentially expose the session token. This issue af= fects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to up= grade to version 3.17.0, which fixes the issue. 2026-06-19 not yet calculat=
ed CVE-2026-48895 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48895 ] Apa= che Software Foundation--Apache APISIX Improper Validation of Integrity Che=
ck Value vulnerability in Apache APISIX. The jwe-decrypt plugin under defau=
lt configuration is vulnerable to authentication bypass.=C2=A0 This issue a= ffects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to u= pgrade to version 3.17.0, which fixes the issue. 2026-06-19 not yet calcula= ted CVE-2026-49230 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49230 ] Ap= ache Software Foundation--Apache APISIX Authentication Bypass by Spoofing v= ulnerability in opa plugin. An attacker could relay spoofed identity header=
s to upstream capitalising on non-default configuration in opa plugin. This=
could allow the attacker to assume higher privileges on the upstream servi= ce. This issue affects Apache APISIX: from 3.5.0 through 3.16.0. Users are = recommended to upgrade to version 3.17.0, which fixes the issue. 2026-06-19=
not yet calculated CVE-2026-49231 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-49231 ] Apache Software Foundation--Apache APISIX Cross-Site Request = Forgery (CSRF) vulnerability in the cas-auth plugin under default configura= tions. This defect allows a=C2=A0remote attacker that manages to send a vic= tim to a webpage controlled by them can cause the victim's browser to becom=
e authenticated as a different identity. Actions the victim takes upstream = are then attributed to attackers identity. This issue affects Apache APISIX=
: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.= 17.0, which fixes the issue. 2026-06-19 not yet calculated CVE-2026-49871 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-49871 ] Apache Software Founda= tion--Apache APISIX Improper Authentication vulnerability in Apache APISIX.=
When the cas-auth plugin is used in a route, an attacker can possibly auth= enticate itself with credentials from a different source. This issue affect=
s Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrad=
e to version 3.17.0, which fixes the issue. 2026-06-19 not yet calculated C= VE-2026-49872 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49872 ] Apache = Software Foundation--Apache DolphinScheduler DataSource API Missing Authori= zation Check Leads to Arbitrary Data Source Metadata Disclosure in Apache D= olphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. = Users are recommended to upgrade to version 3.4.2, which fixes the issue. 2= 026-06-17 not yet calculated CVE-2026-32966 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-32966 ] Apache Software Foundation--Apache DolphinScheduler = Incorrect Authorization vulnerability of `/v2` experimental interface in Ap= ache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3= .4.2. Users are recommended to upgrade to version 3.4.2, which fixes the is= sue. 2026-06-17 not yet calculated CVE-2026-32967 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-32967 ] Apache Software Foundation--Apache DolphinSche= duler Incorrect Authorization vulnerability allows users with system login = privileges to delete task definitions in unauthorized projects This issue a= ffects Apache DolphinScheduler versions prior to 3.4.2. Users are recommend=
ed to upgrade to version 3.4.2, which fixes this issue. 2026-06-17 not yet = calculated CVE-2026-41280 [
https://www.cve.org/CVERecord?id=3DCVE-2026-412=
80 ] Apache Software Foundation--Apache DolphinScheduler Incorrect Authoriz= ation vulnerability allows users to access workflow instance information be= longing to projects they do not have permission to access. This issue affec=
ts Apache DolphinScheduler versions prior to 3.4.2. Users are recommended t=
o upgrade to version 3.4.2, which fixes this issue. 2026-06-17 not yet calc= ulated CVE-2026-42357 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42357 ]=
Apache Software Foundation--Apache DolphinScheduler Allow authenticated us= ers to access alert instances associated with alert groups they do not have=
permission to access. in Apache DolphinScheduler. This issue affects Apach=
e DolphinScheduler: before 3.4.2. Users are recommended to upgrade to versi=
on 3.4.2, which fixes the issue. 2026-06-17 not yet calculated CVE-2026-473=
40 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47340 ] Apache Software Fo= undation--Apache Shiro A remote attacker can inject LDAP special characters=
into the Distinguished Name (DN) construction in DefaultLdapRealm class. U= ser-supplied username input is directly concatenated into the LDAP DN templ= ate without any escaping of RFC 2253 special characters. This allows an att= acker to manipulate the DN structure used for LDAP bind authentication, pot= entially bypassing authentication or impersonating other users. This issue = affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when usi= ng=C2=A0DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or = later, which fixes the issue. 2026-06-17 not yet calculated CVE-2026-49268 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-49268 ] authelia--authelia Au= thelia is an open-source authentication and authorization server providing = two-factor authentication and single sign-on (SSO) for applications via a w=
eb portal. In versions 4.38.0 through 4.39.19, when a user authenticates vi=
a Basic Auth (i.e via the `Authorization` header with the `Basic` scheme) o=
n the authz verification endpoint, Authelia takes the username directly fro=
m the `Authorization` header and passes it as is to the regulation system f=
or ban checking and attempt recording. LDAP treats usernames case insensiti= vely : `john`, `John`, and `JOHN` all bind as the same user. But the regula= tion SQL queries treat the lookup of these values in certain scenarios as c= ase sensitive. This allows each variation of a usernames case to have its o=
wn ban bucket. Upgrade to 4.39.20 to receive a patch. As a workaround, expl= icitly disable the basic auth mechanism. 2026-06-19 not yet calculated CVE-= 2026-47203 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47203 ] authelia--= authelia Authelia is an open-source authentication and authorization server=
providing two-factor authentication and single sign-on (SSO) for applicati= ons via a web portal. In versions 4.36.0 through 4.39.19, due to lack of ca= nonicalization of domains in very specific edge cases, an access control ru=
le may be skipped when it should match a request. The specific conditions t= hat could lead to a security issue for vulnerability are: 1. The specific t= arget resource of the attack must be using the forwarded authorization inte= gration; 2. The requested domain must have two additional segments compared=
to a session domain i.e. `a.b.example.com` is requested, but the session d= omain is `example.com`; 3. There access control rules must specify two sepa= rate rules which both contain inexact domain matches such as `*.b.example.c= om` and `*.example.com` i.e. wildcards, username matches, group matches; 4.=
The rules must be in order of most specific domain to least specific domai=
n; 5. The second rule must be more permissive than the first rule; 6. The a= ttacker must specifically request a URL for the more specific domain, with = the second part containing one or more capitalized letters i.e. `
https://a.= B.example.com` and no other segment with capitalized letters; 7. The integr= ation used must not be the Envoy ExtAuthz integration; and 8. The proxy mus=
t not canonicalize the requested host name in the relevant header before se= nding it to the relevant authorization endpoint. The kind of configuration = used to produce this issue and result in a `bypass` rule being matched has = long been highly discouraged. Essentially hosts which should be bypassed en= tirely should not be secured by having the proxy check them with the author= ization handlers. Upgrade to 4.39.20 to receive a patch. 2026-06-19 not yet=
calculated CVE-2026-48794 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48= 794 ] AzeoTech--DAQFactory In AzeoTech DAQFactory versions 21.1 and prior, =
a Type Confusion vulnerability can be exploited by an attacker using specia= lly crafted .ctl files which can result in code execution. 2026-06-18 not y=
et calculated CVE-2026-12390 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 12390 ] Ben Busby--whoogle-search v1.2.3 An information disclosure vulnerab= ility in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allo=
ws attackers to obtain sensitive information via a crafted GET request. 202= 6-06-15 not yet calculated CVE-2026-50870 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-50870 ] Benjamin Jonard Koillection--Benjamin Jonard Koillecti=
on v1.8.0 An authenticated Server-Side Request Forgery (SSRF) in the custom=
scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows a= ttackers to scan internal resources via supplying a crafted URL. 2026-06-15=
not yet calculated CVE-2026-50888 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-50888 ] Bernd Bestel--grocy v4.6.0 Bernd Bestel grocy v4.6.0 was disc= overed to contain a SQL injection vulnerability in the product-group parame= ter at /stockreports/spendings. This vulnerability allows attackers to acce=
ss sensitive database information via a crafted SQL statement. 2026-06-15 n=
ot yet calculated CVE-2026-50890 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-50890 ] BIAFRA--Dancer2::Plugin::Auth::OAuth Dancer2::Plugin::Auth::OAu=
th versions before 0.22 for Perl default to a predictable nonce. The defaul=
t nonce was generated using an MD5 hash of the epoch time, which is predict= able. 2026-06-15 not yet calculated CVE-2026-11832 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-11832 ] Bludit--Bludit CMS Bludit CMS before version = 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api= /files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authori= zation checks and lacks file extension validation. An attacker with a valid=
API token can upload a malicious PHP script and execute arbitrary code on = the server. 2026-06-15 not yet calculated CVE-2026-38329 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-38329 ] Bludit--Bludit v3.19.0 An issue in the = api/plugin.php component of Bludit v3.19.0 allows attackers to execute a di= rectory traversal via supplying a crafted request. 2026-06-15 not yet calcu= lated CVE-2026-50869 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50869 ] = Bonsai--Bonsai v6.0 Incorrect access control in the impworks Bonsai v6.0 al= lows authenticated attackers with Editor privileges to escalate privileges =
to Administrator and execute unauthorized account, password, and configurat= ion changes. 2026-06-15 not yet calculated CVE-2026-50881 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-50881 ] Boyleep--Boyleep K11 An issue in Boyle=
ep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker =
to execute arbitrary code via the factory test feature. 2026-06-15 not yet = calculated CVE-2026-36933 [
https://www.cve.org/CVERecord?id=3DCVE-2026-369=
33 ] byrongamatos--slopsmith Slopsmith is a self-contained web application = for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pri=
or to 0.2.9-alpha.5, a path-traversal vulnerability in Slopsmith's archive = extractors allows an attacker to write arbitrary files outside the extracti=
on directory by supplying a crafted PSARC or sloppak archive. With the defa= ult Docker configuration (running as root) and the ability to drop a file i= nto the plugin directory, this escalates to arbitrary remote code execution=
on the host. Three archive extractors concatenated archive-entry filenames=
directly onto the extraction root without validation: `lib/psarc.py::unpac= k_psarc` - PSARC TOC filenames; `lib/patcher.py::unpack_psarc` - duplicate =
of the above in the patcher flow; `lib/sloppak.py::_unpack_zip` - bare `Zip= File.extractall()` with no member filter. Each accepts entry names containi=
ng `..` segments, absolute paths, or backslash separators. The Python `zipf= ile` module's default `extractall()` is documented as not preventing traver= sal when callers don't supply a member-filter callback. Version 0.2.9-alpha=
.5 patches the issue. Until updated, do not open PSARC or sloppak archives = from untrusted sources, and do not expose the Slopsmith instance to the pub= lic internet. Docker users should also pull the latest image after the next=
slopsmith Docker image is published. 2026-06-19 not yet calculated CVE-202= 6-49290 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49290 ] cakephp--cake= php CakePHP is a rapid development framework for PHP. In versions 4.5.11 an=
d earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, = and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that th=
e resolved element path is within the application/plugin view template path=
s. When element names are created with specifically crafted user-supplied d= ata this weakness can be leveraged to include other PHP files on the server=
. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11=
. 2026-06-17 not yet calculated CVE-2026-48820 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-48820 ] Canonical--Microceph Canonical MicroCeph versions=
from the squid and tentacle track are vulnerable to a path traversal issue=
in the remote-import API. Holders of a trusted cluster mTLS certificate (s= uch as enrolled cluster members) or join token can manipulate files in an i= mported remote cluster within the /var/snap/microceph confinement. This wou=
ld allow daemon disruption and pollution of the cluster state. 2026-06-19 n=
ot yet calculated CVE-2026-10720 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-10720 ] Citrix--Citrix Cloud In Citrix Cloud through 2025-11-10, an acc= ount with read-only access can trigger the beginning of a workflow for writ=
e operations, e.g., the system will send a one-time password to an attacker= -controlled email address when the attacker attempts to reset the password =
of a user account. 2026-06-17 not yet calculated CVE-2025-66391 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2025-66391 ] cursor--cursor Cursor is a code = editor built for programming with AI. In versions prior to 3.0.0, the Curso=
r Desktop could execute workspace-defined Claude hook commands from .claude= /settings.local.json without dedicated user approval. A malicious workspace=
or agent-created file could configure hooks that run local commands in the=
user's context when an agent turn ends. This could allow sandbox escape, p= ersistence across turns, local data access, or follow-on compromise. This i= ssue has been fixed in version 3.0.0. 2026-06-15 not yet calculated CVE-202= 6-48124 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48124 ] CursorTouch--= Windows-MCP Windows-MCP is an open-source project that integrates AI agents=
with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the M=
CP control plane without authentication while enabling wildcard CORS (allow= _origins=3D*, allow_methods=3D*, allow_headers=3D*). Because the same serve=
r also exposed a PowerShell tool that executes caller-controlled commands a=
s the Windows user running Windows-MCP, attackers could reach the control p= lane from arbitrary origins or non-browser clients and achieve arbitrary Po= werShell execution. This issue was fixed in version 0.7.5. 2026-06-17 not y=
et calculated CVE-2026-48989 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 48989 ] Datadog, Inc--Vector v.0.54.0 Datadog, Inc Vector v0.54.0 was disco= vered to contain a SQL injection vulnerability in the set_uri_query paramet=
er in the KeyPartitioner::partition function. This vulnerability allows att= ackers to access sensitive database information via crafted SQL statements.=
2026-06-15 not yet calculated CVE-2026-39196 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-39196 ] Datadog, Inc--Vector v.0.54.0 An issue in the /uti= l/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers =
to cause a Denial of Service (DoS) via a crafted request or payload. 2026-0= 6-15 not yet calculated CVE-2026-39197 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-39197 ] Deck9--Deck9 Input v2.0.1 Incorrect access control in t=
he /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authent= icated attackers to arbitrarily modify or delete another tenant's webhook v=
ia a crafted request. 2026-06-15 not yet calculated CVE-2026-50875 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-50875 ] Deck9--Deck9 Intput v2.0.1 A = cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attac= kers to execute arbitrary web scripts or HTML via a crafted payload. 2026-0= 6-15 not yet calculated CVE-2026-50876 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-50876 ] Devolutions--Devolutions Server Improper access control=
in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21=
allows an authenticated user to retrieve account discovery scan results. 2= 026-06-16 not yet calculated CVE-2026-11890 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-11890 ] Devolutions--Devolutions Server Improper access cont= rol in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user =
to access attachments via folder duplication with inherited permissions. 20= 26-06-16 not yet calculated CVE-2026-12105 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-12105 ] Devolutions--Devolutions Server Improper access contr=
ol in the social login connection endpoint in Devolutions Server 2026.2.5 a= llows an authenticated vault member to enumerate social login entry metadat=
a to which they are not authorized via a crafted API request. 2026-06-16 no=
t yet calculated CVE-2026-12117 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-12117 ] Devolutions--Remote Desktop Manager Improper input validation in=
the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2=
.7 allows an authenticated user with permission to create or modify a share=
d SSH entry to execute arbitrary commands on a remote SSH host using stored=
elevation credentials via a crafted alternate username and user interactio=
n with the Elevate Shell action. 2026-06-15 not yet calculated CVE-2026-121=
61 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12161 ] Devolutions--Remot=
e Desktop Manager Improper host validation in the social login autofill fea= ture in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to d= isclose stored social login credentials via a crafted web entry pointing to=
a provider lookalike domain. 2026-06-15 not yet calculated CVE-2026-12162 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12162 ] Devolutions--UniGetUI=
Use of an incorrectly resolved name or reference in the pinget backend in = Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog=
contributor to cause an installed application to be correlated to an unrel= ated, attacker-controlled catalog package and to execute an attacker-contro= lled installer via a crafted catalog package whose normalized name is conta= ined as a substring within the installed application name when a user appli=
es the proposed update. 2026-06-17 not yet calculated CVE-2026-10696 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-10696 ] Docker--Docker Sandboxes Do= cker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not = apply it to DNS resolution: the per-network embedded DNS server forwards an=
y queried name to the host resolver whenever the network is internet-connec= ted, without consulting the policy. A workload inside a sandbox, which the = threat model treats as untrusted, can therefore encode data into DNS labels=
for an attacker-controlled domain and exfiltrate it through a DNS covert c= hannel, bypassing the configured allowlist. 2026-06-18 not yet calculated C= VE-2026-12039 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12039 ] Docker-= -Docker Sandboxes Docker Sandboxes (sbx) blocks ICMP egress with an authori= zer applied only at network-creation time, and does not re-apply it to netw= orks rebuilt from disk when the Docker daemon restarts, so a restart-surviv= ing sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, = which the threat model treats as untrusted, can therefore defeat the docume= nted ICMP egress block to perform network reconnaissance and exfiltrate dat=
a over an ICMP covert channel, regardless of the configured allowlist. 2026= -06-18 not yet calculated CVE-2026-12539 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12539 ] dtwang--line-desktop-mcp Line Desktop MCP is a project = that, while unaffiliated with the official line-bot-mcp-server, allows user=
s to directly operate the LINE Desktop application on Windows or Mac via MC=
P. `line-desktop-mcp` supports a `--http-mode` Streamable HTTP transport fo=
r use with clients such as n8n. In this mode the server binds to `0.0.0.0` = and exposes the MCP `/mcp` endpoint without an MCP-layer authentication che= ck. Prior to version 1.1.2, any network client that can reach the port can = initialize a session, list tools, and call tools that read LINE Desktop cha=
t history or send LINE messages through the already logged-in desktop appli= cation. Version 1.1.2 fixes the issue. 2026-06-19 not yet calculated CVE-20= 26-49357 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49357 ] Eclipse Foun= dation--Eclipse 4diac In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a spe= cially crafted DELETE connection command to the management interface can le=
ad to a dangling pointer. This allows subsequent commands to access freed m= emory (use-after-free). 2026-06-18 not yet calculated CVE-2026-9158 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-9158 ] Eclipse Foundation--Eclipse T= heia In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdo=
wn image tags from AI responses, triggering HTTP requests to arbitrary exte= rnal URLs without restriction. Combined with prompt injection in a maliciou=
s workspace, an attacker could induce the AI agent to construct image URLs = encoding sensitive information from the workspace or conversation context, = exfiltrating it to attacker-controlled servers. The workspace trust enforce= ment introduced in v1.71.0 mitigates the documented attack chain by disabli=
ng AI features in untrusted workspaces. 2026-06-18 not yet calculated CVE-2= 026-22551 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22551 ] Eclipse Fou= ndation--Eclipse Theia In Eclipse Theia versions prior to 1.71.0, the AI ch=
at agent processed workspace file and directory names as part of its prompt=
context without distinguishing them from system instructions. An attacker = could craft a malicious repository with adversarial directory or file names=
that, when analyzed by the AI agent, would cause the agent to follow attac= ker-controlled instructions (indirect prompt injection). Combined with othe=
r AI chat features available in untrusted workspaces, this enabled attack c= hains leading to data exfiltration via Markdown image rendering or arbitrar=
y command execution via task definitions. 2026-06-18 not yet calculated CVE= -2026-44688 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44688 ] Eclipse F= oundation--Eclipse Theia In Eclipse Theia versions prior to 1.69.0, custom = task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.= json) could be executed without requiring workspace trust. An attacker coul=
d craft a malicious repository that, when cloned and opened in Theia, leads=
to execution of arbitrary commands with the user's privileges. In combinat= ion with AI chat features and a workspace .theia/settings.json that disable=
d tool confirmation, this could be triggered automatically by sending a mes= sage in the AI chat. 2026-06-18 not yet calculated CVE-2026-44691 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-44691 ] Eclipse Foundation--Eclipse Th= eia In Eclipse Theia versions prior to 1.71.0, files matching the pattern .= prompts/*.prompttemplate in a workspace were automatically loaded and could=
override or extend the AI agent's system prompts. An attacker could craft =
a malicious repository containing prompt template files that, when the work= space was opened in Theia, replaced the AI's system instructions with attac= ker-controlled content (indirect prompt injection). Combined with other AI = chat features available in untrusted workspaces, this enabled attack chains=
leading to data exfiltration via Markdown image rendering or arbitrary com= mand execution via task definitions. 2026-06-18 not yet calculated CVE-2026= -46580 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46580 ] elixir-grpc--g= rpc Authorization Bypass Through User-Controlled Key vulnerability in elixi= r-grpc grpc allows authenticated attackers to access or modify resources be= longing to other users by smuggling a conflicting value for any path-bound = field via the query string or request body. In 'Elixir.GRPC.Server.Transcod= e':map_request/5 (lib/grpc/server/transcode.ex), all three clauses use Map.= merge/2 with path bindings as the first argument, giving them the lowest me= rge precedence. A request such as GET /users/me/profile?user_id=3Dvictim (o=
r a POST with {"user_id": "victim"} when body: "*") yields a decoded protob=
uf struct where the path-bound field carries the attacker-supplied value ra= ther than the router-extracted value. Any handler that uses the path-bound = field for authorization, multi-tenancy scoping, or ownership checks is sile= ntly bypassed. This issue affects grpc from 0.8.0 before 1.0.0. 2026-06-15 = not yet calculated CVE-2026-48599 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-48599 ] elixir-grpc--grpc Deserialization of Untrusted Data and Alloca= tion of Resources Without Limits or Throttling vulnerabilities in elixir-gr=
pc grpc allow unauthenticated attackers to crash the BEAM node via atom tab=
le exhaustion and, when a decoded term flows into a call site that invokes = it, achieve remote code execution on the server. 'Elixir.GRPC.Codec.Erlpack= ':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on th=
e raw gRPC message body without the :safe option, no size bound, and no typ=
e guard. Any unauthenticated peer that sends a request with Content-Type: a= pplication/grpc+erlpack can send a crafted payload that mints arbitrary new=
atoms (which are never garbage-collected, exhausting the bounded atom tabl=
e and crashing the VM) or that encodes a fun term which, if applied anywher=
e downstream, executes attacker-controlled code inside the server process. = This issue affects grpc from 0.4.0 before 1.0.0. 2026-06-15 not yet calcula= ted CVE-2026-48853 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48853 ] el= ixir-grpc--grpc Allocation of Resources Without Limits or Throttling vulner= ability in elixir-grpc grpc allows unauthenticated attackers to exhaust the=
BEAM's memory and crash the server by streaming a large or slow-trickle un= ary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_bo= dy/3 (lib/grpc/server/adapters/cowboy/handler.ex) accumulates every receive=
d chunk into a single growing binary with no size cap. Additionally, when t=
he client omits the grpc-timeout header, the per-chunk read timeout resolve=
s to :infinity, allowing a slow-trickle client to keep the connection alive=
indefinitely while memory grows. A single connection is sufficient to exha= ust server memory and crash the node. This issue affects grpc from 0.3.1 be= fore 1.0.0. 2026-06-15 not yet calculated CVE-2026-48854 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-48854 ] elixir-grpc--grpc Improper Handling of = Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc gr=
pc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service = via a gzip decompression bomb. This vulnerability is associated with progra=
m files lib/grpc/compressor/gzip.ex, lib/grpc/message.ex and program routin=
es 'Elixir.GRPC.Compressor.Gzip':decompress/1, 'Elixir.GRPC.Message':from_d= ata/2. 'Elixir.GRPC.Compressor.Gzip':decompress/1 calls :zlib.gunzip/1 dire= ctly on attacker-controlled bytes with no decompressed-size limit, ratio ch= eck, or incremental decoding. Because this module is the registered gzip GR= PC.Compressor implementation, it is invoked automatically whenever an incom= ing gRPC frame carries the grpc-encoding: gzip header. :zlib.gunzip/1 alloc= ates the entire decompressed result as a single binary, so a small highly c= ompressible payload (for example a few kilobytes of zeros, which gzip compr= esses at roughly 1000:1) expands to multiple gigabytes inside a single call=
. The max_receive_message_length limit is enforced only against the already= -decompressed message, so it provides no protection. An unauthenticated rem= ote peer can send a single crafted frame to exhaust the BEAM node's heap an=
d trigger an out-of-memory kill. This issue affects grpc: from 0.4.0 before=
1.0.0. 2026-06-15 not yet calculated CVE-2026-53430 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-53430 ] Enhancesoft--osTicket A session fixation vu= lnerability has been identified in osTicket v1.18.2. This security flaw all= ows an attacker to hijack a victim's account by keeping the initial session=
identifier (OSTSESSID) active after a successful login. The issue lies in = the fact that the application does not invalidate the pre-authentication co= okie or generate a new identifier for the authenticated context. As a resul=
t, if an attacker manages to set a known session identifier in the victim's=
browser, they will be able to maintain unauthorised access to the account = once the victim has authenticated. 2026-06-16 not yet calculated CVE-2026-9= 507 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9507 ] Feuerhamster--Mail= Form v1.1.0 An issue in the attachment handling component of Feuerhamster M= ailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a cr= afted request. 2026-06-15 not yet calculated CVE-2026-50878 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-50878 ] Filestash--Filestash v0.4.0 Incorrec=
t access control in the /admin/api/config component of Filestash v0.4.0 all= ows attackers to escalate privileges via sending a crafted request. 2026-06= -15 not yet calculated CVE-2026-50891 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-50891 ] flatnotes--flatnotes v5.5.4 An arbitrary file upload vulne= rability in the attachment handling component of flatnotes v5.5.4 allows at= tackers to execute arbitrary code via uploading a crafted HTML or SVG file.=
2026-06-15 not yet calculated CVE-2026-50873 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-50873 ] Flexera--FlexNet Manager Suite A security vulnerab= ility has been identified in FlexNet Manager Suite 2025 R1 that could allow=
an authenticated user with read-only access to account settings to escalat=
e their privileges to Administrator level. 2026-06-19 not yet calculated CV= E-2026-4026 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4026 ] Flexera--F= lexNet Manager Suite A security vulnerability has been identified in FlexNe=
t Manager Suite 2025 R1 and R2 that could allow unauthorized access to atta= chment files due to insufficient access control. 2026-06-19 not yet calcula= ted CVE-2026-4027 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4027 ] flip= ped-aurora--gin-vue-admin gin-vue-admin is an AI-assisted basic development=
platform. In version 2.9.1, an authenticated attacker with access to the c= ode-generation feature and MCP management interface can exploit this vulner= ability by injecting attacker-controlled Go source code through POST /autoC= ode/addFunc, and then invoking POST /autoCode/mcpStart to trigger a rebuild=
and restart of the standalone MCP service. This allows arbitrary operating=
system commands to be executed on the server with the privileges of the ap= plication process. Successful exploitation may lead to remote code executio=
n (RCE), modification of backend source code or runtime logic, deployment o=
f persistent backdoors, access to or manipulation of application data and c= onfiguration, and further impact on local resources running under the same = service account or privilege context. The risk is highest in deployments th=
at retain the source tree, allow writes to source files, and support local = build or startup of standalone MCP components. In environments using binary= -only releases, read-only filesystems, or with local build capabilities rem= oved, the exploitability of the full attack chain is significantly reduced.=
However, once the online code-generation capability and MCP-hosted startup=
workflow are enabled, the overall security impact may reach high to critic=
al severity. As of time of publication, it is unknown if a patched version =
is available. As a workaround, enforce strict allowlist validation on path-=
and identifier-related fields such as `humpPackageName`, `packageName`, `F= uncName`, and `Router`, and only permit safe identifier formats. 2026-06-19=
not yet calculated CVE-2026-48787 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-48787 ] Flowise--Flowise Flowise before 3.0.13 contains an informatio=
n exposure vulnerability in the POST /api/v1/account/forgot-password endpoi=
nt that returns full user objects including PII to unauthenticated attacker=
s. An attacker can enumerate valid email addresses and harvest sensitive us=
er data including user IDs, names, account status, and timestamps by sendin=
g requests with known email addresses. 2026-06-20 not yet calculated CVE-20= 26-56267 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56267 ] Flowise--Flo= wise Flowise before 3.1.2 contains a mass assignment vulnerability in the P=
UT /api/v1/user endpoint that allows authenticated users to directly modify=
the credential field without validation. Attackers can bypass password cha= nge verification and session invalidation by supplying a crafted password h= ash, establishing persistent account access after temporary session comprom= ise. 2026-06-20 not yet calculated CVE-2026-56276 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-56276 ] fossar--selfoss v2.20 An issue in the loopback=
request handling component of fossar selfoss v2.20-SNAPSHOT allows attacke=
rs to execute arbitrary commands and obtain sensitive information via suppl= ying a crafted HTTP request. 2026-06-15 not yet calculated CVE-2026-50872 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-50872 ] FuseSource--jansi A he=
ap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper = due to a lack of size verification for the argument array before the system=
call. This can lead to heap corruption and application crashes (DoS). All = versions are believed to be vulnerable.=C2=A0This project is unmaintained a=
t the time of CVE assignment. 2026-06-16 not yet calculated CVE-2026-8484 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-8484 ] Google--Android In mult= iple functions of btm_sec.cc, there is a possible way for an attacker to in= tercept SMS messages due to a logic error in the code. This could lead to r= emote information disclosure with no additional execution privileges needed=
. User interaction is needed for exploitation. 2026-06-17 not yet calculate=
d CVE-2025-48571 [
https://www.cve.org/CVERecord?id=3DCVE-2025-48571 ] Goog= le--Android In overrideConfig of CarrierConfigLoader.java, there is a possi= ble way to bypass UID check due to a permissions bypass. This could lead to=
local escalation of privilege with no additional execution privileges need= ed. User interaction is not needed for exploitation. 2026-06-17 not yet cal= culated CVE-2025-48617 [
https://www.cve.org/CVERecord?id=3DCVE-2025-48617 =
] Google--Android In multiple locations, there is a possible 3rd party pass= key entry pairing approval due to a missing permission check. This could le=
ad to remote (proximal/adjacent) escalation of privilege with no additional=
execution privileges needed. User interaction is not needed for exploitati= on. 2026-06-17 not yet calculated CVE-2025-48640 [
https://www.cve.org/CVER= ecord?id=3DCVE-2025-48640 ] Google--Android In multiple locations there is =
a possible provisioning bypass due to improper input validation. This could=
lead to local escalation of privilege with no additional execution privile= ges needed. User interaction is not needed for exploitation. 2026-06-17 not=
yet calculated CVE-2025-48643 [
https://www.cve.org/CVERecord?id=3DCVE-202= 5-48643 ] Google--Android In SettingsLib, there is a possible way to disabl=
e system components due to a logic error in the code. This could lead to lo= cal escalation of privilege with no additional execution privileges needed.=
User interaction is not needed for exploitation. 2026-06-17 not yet calcul= ated CVE-2026-0019 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0019 ] Goo= gle--Android In Contacts Provider, there is a possible way to access an inc= oming call's phone number and associated metadata due to a missing permissi=
on check. This could lead to local information disclosure with no additiona=
l execution privileges needed. User interaction is not needed for exploitat= ion. 2026-06-17 not yet calculated CVE-2026-0057 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-0057 ] Google--Android In setAllowedCarriers of PhoneIn= terfaceManager.java, there is a possible way to disable carrier restriction=
s due to a logic error in the code. This could lead to local escalation of = privilege with no additional execution privileges needed. User interaction =
is not needed for exploitation. 2026-06-17 not yet calculated CVE-2026-0063=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-0063 ] Google--Android In mu= ltiple places, there is a possible persistent denial of service due to reso= urce exhaustion. This could lead to local denial of service with no additio= nal execution privileges needed. User interaction is not needed for exploit= ation. 2026-06-17 not yet calculated CVE-2026-0064 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-0064 ] Google--Android In createSessionInternal of Pa= ckageInstallerService.java, there is a possible method to remove a DPC app = from a managed device without DO consent due to desync from persistence. Th=
is could lead to local escalation of privilege if a user can install a mali= cious app with no additional execution privileges needed. User interaction =
is needed for exploitation. 2026-06-17 not yet calculated CVE-2026-0068 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-0068 ] Google--Android In Settin= gsLib, there is a possible missing permission check due to a logic error in=
the code. This could lead to local escalation of privilege with no additio= nal execution privileges needed. User interaction is not needed for exploit= ation. 2026-06-17 not yet calculated CVE-2026-0071 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-0071 ] Google--Android In NFC, there is a possible wa=
y to spoof an NFC event due to a missing permission check. This could lead =
to local escalation of privilege with no additional execution privileges ne= eded. User interaction is not needed for exploitation. 2026-06-17 not yet c= alculated CVE-2026-0081 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0081 =
] Google--Android In tryStartActivity of NfcDispatcher.java, there is a pos= sible automatic special app access permission assignment due to an insecure=
default value. This could lead to local escalation of privilege with no ad= ditional execution privileges needed. User interaction is not needed for ex= ploitation. 2026-06-17 not yet calculated CVE-2026-0082 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-0082 ] Google--Android In Nfc::eventCallback() o=
f Nfc.h, there is a possible use after free due to a race condition. This c= ould lead to local escalation of privilege with no additional execution pri= vileges needed. User interaction is not needed for exploitation. 2026-06-17=
not yet calculated CVE-2026-0083 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-0083 ] Google--Android In Package Manager, there is a possible device = lock controller bypass due to a missing permission check. This could lead t=
o local escalation of privilege with no additional execution privileges nee= ded. User interaction is not needed for exploitation. 2026-06-17 not yet ca= lculated CVE-2026-0092 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0092 ]=
Google--Android In multiple functions of vpu_ioctl.c, there is a possible = use after free due to a race condition. This could lead to local escalation=
of privilege with no additional execution privileges needed. User interact= ion is not needed for exploitation. 2026-06-16 not yet calculated CVE-2026-= 0125 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0125 ] Google--Android I=
n WC-Radio, there is a possible out of bounds write due to a missing bounds=
check. This could lead to remote code execution with no additional executi=
on privileges needed. User interaction is not needed for exploitation. 2026= -06-16 not yet calculated CVE-2026-0126 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-0126 ] Google--Android In NrmmMsgCodec::DecodeUPUTransparentCon= text of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to m= emory corruption. This could lead to remote denial of service causing a com= munication processor crash with no additional execution privileges needed. = User interaction is not needed for exploitation. 2026-06-16 not yet calcula= ted CVE-2026-0127 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0127 ] Goog= le--Android In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of=
bounds read due to an integer overflow. This could lead to remote informat= ion disclosure with no additional execution privileges needed. User interac= tion is needed for exploitation. 2026-06-16 not yet calculated CVE-2026-012=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0128 ] Google--Android In R= tcpByePacket::decodeByePacket, there is a possible due to a missing bounds = check. This could lead to remote information disclosure with no additional = execution privileges needed. User interaction is needed for exploitation. 2= 026-06-16 not yet calculated CVE-2026-0129 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-0129 ] Google--Android In RtcpChunk::decodeRtcpChunk, there i=
s a possible out of bounds read due to a heap buffer overflow. This could l= ead to remote information disclosure with no additional execution privilege=
s needed. User interaction is needed for exploitation. 2026-06-16 not yet c= alculated CVE-2026-0130 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0130 =
] Google--Android In RtpPacket::decodePacket, there is a possible out of bo= unds access due to an integer overflow. This could lead to local escalation=
of privilege with no additional execution privileges needed. User interact= ion is needed for exploitation. 2026-06-16 not yet calculated CVE-2026-0131=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-0131 ] Google--Android In Mo= dem, there is a possible out of bounds write due to a heap buffer overflow.=
This could lead to remote code execution with no additional execution priv= ileges needed. User interaction is not needed for exploitation. 2026-06-16 = not yet calculated CVE-2026-0132 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-0132 ] Google--Android In smmu_attach_dev of arm-smmu-v3.c, there is a = possible way to sign malicious Android Runtime bootclass artifacts due to a=
missing permission check. This could lead to local escalation of privilege=
with no additional execution privileges needed. User interaction is not ne= eded for exploitation. 2026-06-16 not yet calculated CVE-2026-0133 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-0133 ] Google--Android In PostWipeDat=
a of recovery_ui.cpp, there is a possible data persistence issue after a fa= ctory reset due to a logic error in the code. This could lead to local info= rmation disclosure with no additional execution privileges needed. User int= eraction is not needed for exploitation. 2026-06-16 not yet calculated CVE-= 2026-0134 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0134 ] Google--Andr= oid In Modem, there is a possible out of bounds read due to a missing bound=
s check. This could lead to remote code execution with no additional execut= ion privileges needed. User interaction is not needed for exploitation. 202= 6-06-16 not yet calculated CVE-2026-0135 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-0135 ] Google--Android In Modem, there is a possible out of bou= nds read due to a missing bounds check. This could lead to remote denial of=
service with no additional execution privileges needed. User interaction i=
s not needed for exploitation. 2026-06-16 not yet calculated CVE-2026-0136 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-0136 ] Google--Android In edg= etpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible e= levation of privilege due to a use after free. This could lead to local esc= alation of privilege with System execution privileges needed. User interact= ion is not needed for exploitation. 2026-06-16 not yet calculated CVE-2026-= 0137 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0137 ] Google--Android I=
n lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of boun=
ds write due to memory corruption. This could lead to local escalation of p= rivilege with System execution privileges needed. User interaction is not n= eeded for exploitation. 2026-06-16 not yet calculated CVE-2026-0138 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-0138 ] Google--Android In Modem, the=
re is a possible out of bounds write due to a missing bounds check. This co= uld lead to remote code execution with no additional execution privileges n= eeded. User interaction is not needed for exploitation. 2026-06-16 not yet = calculated CVE-2026-0139 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0139=
] Google--Android In RtpPacket::decodePacket, there is a possible out-of-b= ounds read due to an integer overflow. This could lead to remote informatio=
n disclosure with no additional execution privileges needed. User interacti=
on is needed for exploitation. 2026-06-16 not yet calculated CVE-2026-0140 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-0140 ] Google--Android In dec= odeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a mi= ssing bounds check. This could lead to remote information disclosure with n=
o additional execution privileges needed. User interaction is not needed fo=
r exploitation. 2026-06-16 not yet calculated CVE-2026-0141 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-0141 ] Google--Android In iavb_parse_key_dat=
a of avb_rsa.c, there is a possible out of bounds read due to improper inpu=
t validation. This could lead to local information disclosure with no addit= ional execution privileges needed. User interaction is not needed for explo= itation. 2026-06-16 not yet calculated CVE-2026-0142 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-0142 ] Google--Android In lwis_device_external_even= t_emit of lwis_event.c, there is a possible memory corruption due to a use = after free. This could lead to local escalation of privilege with System ex= ecution privileges needed. User interaction is not needed for exploitation.=
2026-06-16 not yet calculated CVE-2026-0143 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-0143 ] Google--Android In writeAocCommand of AocAudioCodec.= cpp, there is a possible memory safety issue due to a missing bounds check.=
This could lead to remote denial of service with no additional execution p= rivileges needed. User interaction is not needed for exploitation. 2026-06-=
16 not yet calculated CVE-2026-0144 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-0144 ] Google--Android In keymint, there is a possible Permission By= pass due to a logic error in the code. This could lead to local information=
disclosure with no additional execution privileges needed. User interactio=
n is not needed for exploitation. 2026-06-16 not yet calculated CVE-2026-01=
45 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0145 ] Google--Android In = mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possibl=
e out of bounds write due to a missing bounds check. This could lead to rem= ote code execution with no additional execution privileges needed. User int= eraction is not needed for exploitation. 2026-06-16 not yet calculated CVE-= 2026-0146 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0146 ] Google--Andr= oid In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there=
is a possible out of bounds write due to a missing bounds check. This coul=
d lead to remote code execution with no additional execution privileges nee= ded. User interaction is not needed for exploitation. 2026-06-16 not yet ca= lculated CVE-2026-0147 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0147 ]=
Google--Android In multiple functions of VideoRtpPayloadDecoderNode.cpp, t= here is a possible out of bounds write due to an integer overflow. This cou=
ld lead to remote code execution with no additional execution privileges ne= eded. User interaction is not needed for exploitation. 2026-06-16 not yet c= alculated CVE-2026-0148 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0148 =
] Google--Android In RtpSession::rtpSendRtcpPacket, there is a possible OOB=
write due to a heap buffer overflow. This could lead to remote code execut= ion with no additional execution privileges needed. User interaction is not=
needed for exploitation. 2026-06-16 not yet calculated CVE-2026-0149 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-0149 ] Google--Android In ExecuteG= raph command handler of EdgeTPU firmware, there is a possible out of bounds=
write due to an integer overflow. This could lead to local escalation of p= rivilege with root privileges needed. User interaction is not needed for ex= ploitation. 2026-06-16 not yet calculated CVE-2026-0150 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-0150 ] Google--Android In IntfGraphCreate of int= fgraph.c, there is a possible out of bounds write due to an integer overflo=
w. This could lead to remote code execution with no additional execution pr= ivileges needed. User interaction is not needed for exploitation. 2026-06-1=
6 not yet calculated CVE-2026-0151 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-0151 ] Google--Android In OSMMapPMRGeneric of pmr_os.c, there is a po= ssible way to leverage a system call to system call to maliciously expand t=
he VMA out of bounds due to a logic error in the code. This could lead to l= ocal escalation of privilege with no additional execution privileges needed=
. User interaction is not needed for exploitation. 2026-06-16 not yet calcu= lated CVE-2026-0152 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0152 ] Go= ogle--Android In Write of msg_to_host_buffer.cc, there is a possible out of=
bounds write due to an incorrect bounds check. This could lead to local es= calation of privilege with no additional execution privileges needed. User = interaction is not needed for exploitation. 2026-06-16 not yet calculated C= VE-2026-0153 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0153 ] Google--A= ndroid In Modem, there is a possible way to trigger a modem crash during a = SIP REFER request due to memory corruption. This could lead to remote code = execution with no additional execution privileges needed. User interaction =
is not needed for exploitation. 2026-06-16 not yet calculated CVE-2026-0154=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-0154 ] Google--Android In Im= sMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a miss= ing bounds check. This could lead to remote information disclosure with no = additional execution privileges needed. User interaction is not needed for = exploitation. 2026-06-16 not yet calculated CVE-2026-0155 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-0155 ] Google--Android In checkSsrcCollisionOn= Rcv of RtpSession.cpp, there is a possible memory safety issue due to a mis= sing null check. This could lead to remote denial of service with no additi= onal execution privileges needed. User interaction is not needed for exploi= tation. 2026-06-16 not yet calculated CVE-2026-0156 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-0156 ] Google--Android In RtcpHeader::decodeRtcpHead= er, there is a possible OOB read due to a missing bounds check. This could = lead to remote information disclosure with no additional execution privileg=
es needed. User interaction is not needed for exploitation. 2026-06-16 not = yet calculated CVE-2026-0157 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 0157 ] Google--Android In Camera, there is a possible unauthorized way to a= ccess photos due to a missing permission check. This could lead to local in= formation disclosure with no additional execution privileges needed. User i= nteraction is not needed for exploitation. 2026-06-16 not yet calculated CV= E-2026-0158 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0158 ] Google--An= droid In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode= .cpp, there is a possible out of bounds write due to a missing bounds check=
. This could lead to remote code execution with no additional execution pri= vileges needed. User interaction is not needed for exploitation. 2026-06-16=
not yet calculated CVE-2026-0160 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-0160 ] Google--Android In numberOfReportBlocks of RtpSession.cpp, ther=
e is a possible out of bounds write due to an integer overflow. This could = lead to remote escalation of privilege with no additional execution privile= ges needed. User interaction is not needed for exploitation. 2026-06-16 not=
yet calculated CVE-2026-0161 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -0161 ] Google--Android In ParsePayloads of AudioSdpParser.cpp, there is a = possible memory corruption due to type confusion. This could lead to remote=
code execution with no additional execution privileges needed. User intera= ction is not needed for exploitation. 2026-06-16 not yet calculated CVE-202= 6-0162 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0162 ] Google--Android=
In Modem, there is a possible out of bounds write due to a missing bounds = check. This could lead to remote code execution with no additional executio=
n privileges needed. User interaction is not needed for exploitation. 2026-= 06-16 not yet calculated CVE-2026-0164 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-0164 ] Google--Android In several functions of the RTCP packet = decoder, there is a possible out-of-bounds read due to a missing bounds che= ck. This could lead to remote information disclosure with no additional exe= cution privileges needed. User interaction is needed for exploitation. 2026= -06-16 not yet calculated CVE-2026-0165 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-0165 ] Google--Android In AndroidManifest.xml, there is a possi= ble persistent denial of service due to a missing permission check. This co= uld lead to local denial of service with no additional execution privileges=
needed. User interaction is not needed for exploitation. 2026-06-18 not ye=
t calculated CVE-2026-28573 [
https://www.cve.org/CVERecord?id=3DCVE-2026-2= 8573 ] Google--Android In PackageInstaller.Session#transfer of frameworks/b= ase/services/core/java/com/android/server/pm/PackageInstallerSession.java, = there is a possible memory exhaustion attack due to a logic error in the co= de. This could lead to local denial of service with no additional execution=
privileges needed. User interaction is not needed for exploitation. 2026-0= 6-17 not yet calculated CVE-2026-28575 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-28575 ] Google--Android In MmsSmsProvider of MmsSmsProvider.jav=
a, there is a possible way to retrieve sensitive information due to a missi=
ng permission check. This could lead to local information disclosure with n=
o additional execution privileges needed. User interaction is not needed fo=
r exploitation. 2026-06-17 not yet calculated CVE-2026-28587 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-28587 ] Google--Android In Telecomm, there =
is a possible way to initiate an unauthorized phone call due to a permissio=
ns bypass. This could lead to local escalation of privilege with no additio= nal execution privileges needed. User interaction is not needed for exploit= ation. 2026-06-17 not yet calculated CVE-2026-28615 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-28615 ] Google--Chrome Use after free in WebShare in=
Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker=
who had compromised the renderer process to potentially perform a sandbox = escape via a crafted HTML page. (Chromium security severity: Critical) 2026= -06-17 not yet calculated CVE-2026-12437 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12437 ] Google--Chrome Inappropriate implementation in WebView =
in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attack=
er who had compromised the renderer process to potentially perform a sandbo=
x escape via a crafted HTML page. (Chromium security severity: Critical) 20= 26-06-17 not yet calculated CVE-2026-12438 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-12438 ] Google--Chrome Use after free in Digital Credentials =
in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to poten= tially exploit heap corruption via a crafted HTML page. (Chromium security = severity: Critical) 2026-06-17 not yet calculated CVE-2026-12439 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-12439 ] Google--Chrome Use after free i=
n DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 al= lowed a remote attacker to potentially perform a sandbox escape via a craft=
ed HTML page. (Chromium security severity: Critical) 2026-06-17 not yet cal= culated CVE-2026-12440 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12440 =
] Google--Chrome Use after free in File Input in Google Chrome on Linux pri=
or to 149.0.7827.155 allowed a remote attacker to potentially exploit heap = corruption via a crafted HTML page. (Chromium security severity: Critical) = 2026-06-17 not yet calculated CVE-2026-12441 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-12441 ] Google--Chrome Use after free in Passwords in Googl=
e Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to ex= ecute arbitrary code via a crafted HTML page. (Chromium security severity: = Critical) 2026-06-17 not yet calculated CVE-2026-12442 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12442 ] Google--Chrome Use after free in Web Auth= entication in Google Chrome prior to 149.0.7827.155 allowed a remote attack=
er to execute arbitrary code via a crafted HTML page. (Chromium security se= verity: Critical) 2026-06-17 not yet calculated CVE-2026-12443 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-12443 ] Google--Chrome Out of bounds read=
in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed =
a local attacker to obtain potentially sensitive information from process m= emory via a malicious file. (Chromium security severity: High) 2026-06-17 n=
ot yet calculated CVE-2026-12444 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-12444 ] Google--Chrome Use after free in Extensions in Google Chrome pr= ior to 149.0.7827.155 allowed an attacker who convinced a user to install a=
malicious extension to potentially exploit heap corruption via a crafted C= hrome Extension. (Chromium security severity: High) 2026-06-17 not yet calc= ulated CVE-2026-12445 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12445 ]=
Google--Chrome Inappropriate implementation in Passwords in Google Chrome = prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data=
via a crafted HTML page. (Chromium security severity: High) 2026-06-17 not=
yet calculated CVE-2026-12446 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-12446 ] Google--Chrome Heap buffer overflow in WebRTC in Google Chrome pr= ior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code i= nside a sandbox via a crafted HTML page. (Chromium security severity: High)=
2026-06-17 not yet calculated CVE-2026-12447 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-12447 ] Google--Chrome Inappropriate implementation in Web= View in Google Chrome on Android prior to 149.0.7827.155 allowed a remote a= ttacker to perform privilege escalation via a crafted HTML page. (Chromium = security severity: High) 2026-06-17 not yet calculated CVE-2026-12448 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-12448 ] Google--Chrome Use after f= ree in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allow=
ed a local attacker to perform OS-level privilege escalation via a maliciou=
s file. (Chromium security severity: High) 2026-06-17 not yet calculated CV= E-2026-12449 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12449 ] Google--= Chrome Inappropriate implementation in Media in Google Chrome prior to 149.= 0.7827.155 allowed a remote attacker to obtain potentially sensitive inform= ation from process memory via a crafted HTML page. (Chromium security sever= ity: High) 2026-06-17 not yet calculated CVE-2026-12450 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-12450 ] Google--Chrome Use after free in Digital= Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attac= ker who had compromised the renderer process to potentially perform a sandb=
ox escape via a crafted HTML page. (Chromium security severity: High) 2026-= 06-17 not yet calculated CVE-2026-12451 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12451 ] Google--Chrome Use after free in Downloads in Google Ch= rome on Android prior to 149.0.7827.155 allowed a remote attacker to potent= ially exploit heap corruption via a crafted HTML page. (Chromium security s= everity: High) 2026-06-17 not yet calculated CVE-2026-12452 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-12452 ] Google--Chrome Insufficient validati=
on of untrusted input in Input in Google Chrome prior to 149.0.7827.155 all= owed a remote attacker who had compromised the renderer process to bypass s= ame origin policy via a crafted HTML page. (Chromium security severity: Hig=
h) 2026-06-17 not yet calculated CVE-2026-12453 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-12453 ] Google--Chrome Race in Safe Browsing in Google C= hrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had comp= romised the renderer process to potentially perform a sandbox escape via a = crafted HTML page. (Chromium security severity: High) 2026-06-17 not yet ca= lculated CVE-2026-12454 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12454=
] Google--Chrome Use after free in Tab Strip in Google Chrome prior to 149= .0.7827.155 allowed a remote attacker who convinced a user to engage in spe= cific UI gestures to potentially exploit heap corruption via a crafted HTML=
page. (Chromium security severity: High) 2026-06-17 not yet calculated CVE= -2026-12455 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12455 ] Google--C= hrome Inappropriate implementation in Extensions in Google Chrome prior to = 149.0.7827.155 allowed an attacker who convinced a user to install a malici= ous extension to bypass same origin policy via a crafted Chrome Extension. = (Chromium security severity: High) 2026-06-17 not yet calculated CVE-2026-1= 2456 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12456 ] Google--Chrome I= nappropriate implementation in Extensions in Google Chrome prior to 149.0.7= 827.155 allowed a remote attacker who had compromised the renderer process =
to bypass site isolation via a crafted HTML page. (Chromium security severi= ty: High) 2026-06-17 not yet calculated CVE-2026-12457 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12457 ] Google--Chrome Inappropriate implementati=
on in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote a= ttacker who convinced a user to engage in specific UI gestures to leak cros= s-origin data via a crafted HTML page. (Chromium security severity: High) 2= 026-06-17 not yet calculated CVE-2026-12458 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-12458 ] Google--Chrome Inappropriate implementation in Seria=
l in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inj= ect arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium sec= urity severity: High) 2026-06-17 not yet calculated CVE-2026-12459 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-12459 ] Google--Chrome Insufficient p= olicy enforcement in File System Access in Google Chrome prior to 149.0.782= 7.155 allowed a remote attacker who had compromised the renderer process to=
bypass site isolation via a crafted PDF file. (Chromium security severity:=
High) 2026-06-17 not yet calculated CVE-2026-12460 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-12460 ] Google--Chrome Out of bounds read in WebRTC =
in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attack=
er to obtain potentially sensitive information from process memory via a cr= afted HTML page. (Chromium security severity: High) 2026-06-17 not yet calc= ulated CVE-2026-12461 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12461 ]=
Google--Chrome Use after free in Media in Google Chrome prior to 149.0.782= 7.155 allowed a remote attacker who had compromised the renderer process to=
execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium=
security severity: High) 2026-06-17 not yet calculated CVE-2026-12462 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-12462 ] Google--Chrome Inappropri= ate implementation in Views in Google Chrome on Linux prior to 149.0.7827.1=
55 allowed a remote attacker who had compromised the renderer process to in= ject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium se= curity severity: High) 2026-06-17 not yet calculated CVE-2026-12463 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-12463 ] Google--Chrome Use after fre=
e in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote atta= cker who had compromised the renderer process to potentially perform a sand= box escape via a crafted HTML page. (Chromium security severity: High) 2026= -06-17 not yet calculated CVE-2026-12464 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12464 ] Google--Chrome Object lifecycle issue in Metrics in Goo= gle Chrome prior to 149.0.7827.155 allowed a remote attacker who had compro= mised the renderer process to potentially perform a sandbox escape via a cr= afted HTML page. (Chromium security severity: High) 2026-06-17 not yet calc= ulated CVE-2026-12465 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12465 ]=
Google--Chrome Heap buffer overflow in WebRTC in Google Chrome on Windows = prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code=
via a crafted HTML page. (Chromium security severity: High) 2026-06-17 not=
yet calculated CVE-2026-12466 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-12466 ] Google--Chrome Use after free in Extensions in Google Chrome prio=
r to 149.0.7827.155 allowed a remote attacker who had compromised the rende= rer process to potentially perform a sandbox escape via a crafted HTML page=
. (Chromium security severity: High) 2026-06-17 not yet calculated CVE-2026= -12467 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12467 ] Google--Chrome=
Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a = remote attacker who had compromised the renderer process to potentially per= form a sandbox escape via a crafted HTML page. (Chromium security severity:=
High) 2026-06-17 not yet calculated CVE-2026-12468 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-12468 ] Google--Chrome Uninitialized Use in GPU in G= oogle Chrome on Android prior to 149.0.7827.155 allowed a remote attacker t=
o leak cross-origin data via a crafted HTML page. (Chromium security severi= ty: High) 2026-06-17 not yet calculated CVE-2026-12469 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12469 ] Google--MCP Toolbox for Databases (google= apis/mcp-toolbox) An authentication bypass vulnerability exists in the gene= ric opaque token validation path (validateOpaqueToken) of googleapis/mcp-to= olbox. When verifying an unparsed opaque token via an OAuth 2.0 introspecti=
on endpoint (RFC 7662), the toolbox decodes the response into an introspect= Resp struct where the Active field is declared as a pointer to a boolean (*= bool). The code only explicitly rejects a token if the response contains a = populated active field set to false (if introspectResp.Active !=3D nil && != *introspectResp.Active). If an introspection endpoint responds with a paylo=
ad that completely omits the mandatory active key, the internal variable re= mains nil, causing the conditional check to short-circuit. As a result, Too= lbox accepts authorization tokens missing the "active" field, granting acce=
ss to protected tools and underlying data sources. 2026-06-18 not yet calcu= lated CVE-2026-11717 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11717 ] = Google--MCP Toolbox for Databases (googleapis/mcp-toolbox) An authenticatio=
n bypass vulnerability exists in the generic opaque token validation path (= validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates =
an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it deco= des the response into an introspectResp struct. However, the subsequent cla= im-checking logic (validateClaims) evaluates the issuer condition as if a.i= ssuer !=3D "" && iss !=3D "". If the external OAuth provider's introspectio=
n response omits the optional iss (issuer) field completely, the variable i=
ss defaults to an empty string. This causes the conditional block to evalua=
te to false and be skipped silently. Consequently, the application accepts = tokens issued by unauthorized or unintended third-party identity providers.=
2026-06-18 not yet calculated CVE-2026-11718 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-11718 ] Google--MCP Toolbox for Databases (googleapis/mcp-= toolbox) An authenticated authorization bypass vulnerability exists in MCP = Toolbox for Databases due to missing scope enforcement across older protoco=
l handlers. While the 2025-11-25 protocol version handler correctly enforce=
s per-tool restrictions defined by scopesRequired, older supported protocol=
versions (2025-06-18, 2025-03-26, and 2024-11-05) omit this check. An auth= enticated client with low-privilege tokens (e.g., read) can bypass the inte= nded per-tool scope restrictions and execute high-privilege tools (e.g., ad= min) simply by specifying an older protocol version in the MCP-Protocol-Ver= sion header, or by omitting the header entirely (which causes the server to=
default to the vulnerable 2024-11-05 handler). 2026-06-18 not yet calculat=
ed CVE-2026-11719 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11719 ] GPA= C--MP4Box v.2.4 A NULL pointer dereference in the gf_isom_copy_sample_info = function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to ca= use a Denial of Service (DoS) via supplying a crafted MP4 file. 2026-06-15 = not yet calculated CVE-2025-55641 [
https://www.cve.org/CVERecord?id=3DCVE-= 2025-55641 ] GPAC--MP4Box v.2.4 GPAC MP4Box v2.4 was discovered to contain =
a floating point exception in the avidmx_process function (isomedia/isom_wr= ite.c). 2026-06-15 not yet calculated CVE-2025-55642 [
https://www.cve.org/= CVERecord?id=3DCVE-2025-55642 ] GPAC--MP4Box v.2.4 A NULL pointer dereferen=
ce in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Bo=
x v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a = crafted MP4 file. 2026-06-15 not yet calculated CVE-2025-55643 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2025-55643 ] GPAC--MP4Box v.2.4 A heap use-aft= er-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of G= PAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via sup= plying a crafted MP4 file. 2026-06-15 not yet calculated CVE-2025-55644 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2025-55644 ] GPAC--MP4Box v.2.4 A hea=
p buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) =
of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via=
supplying a crafted MP4 file. 2026-06-15 not yet calculated CVE-2025-55645=
[
https://www.cve.org/CVERecord?id=3DCVE-2025-55645 ] GPAC--MP4Box v.2.4 A=
n Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.=
c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) = via supplying a crafted MP4 file. 2026-06-15 not yet calculated CVE-2025-55= 647 [
https://www.cve.org/CVERecord?id=3DCVE-2025-55647 ] GPAC--MP4Box v.2.=
4 A heap buffer overflow in the gf_opus_parse_packet_header function (media= _tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial=
of Service (DoS) via supplying a crafted MP4 file. 2026-06-15 not yet calc= ulated CVE-2025-55648 [
https://www.cve.org/CVERecord?id=3DCVE-2025-55648 ]=
GPAC--MP4Box v.2.4 A NULL pointer dereference in the gf_media_map_esd func= tion (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cau=
se a Denial of Service (DoS) via supplying a crafted MP4 file. 2026-06-15 n=
ot yet calculated CVE-2025-55649 [
https://www.cve.org/CVERecord?id=3DCVE-2= 025-55649 ] GPAC--MP4Box v.2.4 A heap use-after-free in the gf_node_get_tag=
function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attacke=
rs to cause a Denial of Service (DoS) via supplying a crafted MP4 file. 202= 6-06-15 not yet calculated CVE-2025-55650 [
https://www.cve.org/CVERecord?i= d=3DCVE-2025-55650 ] GPAC--MP4Box v.2.4 A heap buffer overflow in the gf_is= om_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows a= ttackers to cause a Denial of Service (DoS) via supplying a crafted MP4 fil=
e. 2026-06-15 not yet calculated CVE-2025-55652 [
https://www.cve.org/CVERe= cord?id=3DCVE-2025-55652 ] GPAC--MP4Box v.2.4 A stack overflow in the gf_op= us_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo=
ws attackers to cause a Denial of Service (DoS) via supplying a crafted MP4=
file. 2026-06-15 not yet calculated CVE-2025-55660 [
https://www.cve.org/C= VERecord?id=3DCVE-2025-55660 ] GPAC--MP4Box v.2.4 A heap buffer overflow in=
the Opus audio stream parser component of GPAC MP4Box v2.4 allows attacker=
s to cause a Denial of Service (DoS) via supplying a crafted MP4 file. 2026= -06-15 not yet calculated CVE-2025-55661 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-55661 ] GPAC--MP4Box v.2.4 A segmentation violation in the Trac= k_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allow=
s attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 = file. 2026-06-15 not yet calculated CVE-2025-55663 [
https://www.cve.org/CV= ERecord?id=3DCVE-2025-55663 ] Grav--grav-plugin-api Grav 2.0.0-rc.9 with Ad= min2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability=
in the Admin2 Pages API save flow. 2026-06-18 not yet calculated CVE-2026-= 11982 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11982 ] gtsteffaniak--f= ilebrowser FileBrowser Quantum is a free, self-hosted, web-based file manag= er. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerabl=
e to Path Traversal through the publicPatchHandler in backend/http/public.g=
o which joins user-controlled fromPath and toPath body fields with the trus= ted d.share.Path BEFORE the downstream sanitizer runs. Because filepath.Joi=
n collapses .. segments during the join, the sanitizer in resourcePatchHand= ler never sees the traversal and the move/copy/rename operates on a path ou= tside the shared directory. The same root-cause pattern was patched for the=
bulk DELETE endpoint as CVE-2026-44542 (GHSA-fwj3-42wh-8673), but the PATC=
H handler with the identical pattern was not updated. A public share link w= ith AllowModify=3Dtrue is sufficient to exploit this. Anyone holding such a=
link can move, copy, or rename arbitrary files within the share owner's so= urce root. This issue has been fixed in versions 1.3.3-stable and 1.4.2-bet=
a. 2026-06-16 not yet calculated CVE-2026-48777 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-48777 ] HAYAJO--Mojolicious::Sessions::Storable Mojolici= ous::Sessions::Storable versions through 0.05 for Perl generate session ids=
insecurely. The default session id generator returns a SHA-1 hash seeded w= ith the built-in rand function, the epoch time, the heap address of an anon= ymous hash, and the PID. These are predictable or low-entropy sources that = are unsuitable for security purposes. 2026-06-18 not yet calculated CVE-202= 6-9692 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9692 ] HP Inc.--HP One=
Agent Software Potential security vulnerabilities have been identified in = the HP One Agent for certain HP PC products, which might allow for escalati=
on of privilege and/or denial of service. HP is releasing software updates =
to mitigate these potential vulnerabilities. 2026-06-15 not yet calculated = CVE-2026-5064 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5064 ] icagenda= .com--iCagenda extension for Joomla A vulnerability in the iCagenda extensi=
on for Joomla allows the upload of arbitrary files in the file attachment f= eature, ultimately resulting in PHP code upload and execution. 2026-06-20 n=
ot yet calculated CVE-2026-48939 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-48939 ] Imagination Technologies--Graphics DDK Software installed and r=
un as a non-privileged user may conduct improper GPU system calls to cause =
an error path leading to UAF of GPU page tables. The vulnerability allows p= hysical memory allocated for MMU page tables to be used after being freed. = This was caused by an error path that would not cleanup properly before fre= eing the physical allocation. 2026-06-19 not yet calculated CVE-2026-34192 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-34192 ] Imagination Technolog= ies--Graphics DDK Software installed and run as a non-privileged user may c= onduct improper GPU system calls to cause mismanagement of resources creati=
ng a write use after free scenario. A shared resource (memory page) managed=
by a CPU thread of control (driver) and accessed by a GPU thread of contro=
l (Firmware) can cause a write UAF when the CPU thread frees the resource b= efore the GPU FW has finished accessing it. 2026-06-19 not yet calculated C= VE-2026-41156 [
https://www.cve.org/CVERecord?id=3DCVE-2026-41156 ] InHand = Networks--IR912 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042=
(including earlier versions) were discovered to contain a command injectio=
n vulnerability in the Python configuration function. This vulnerability al= lows remote attackers to execute arbitrary commands as root via a crafted i= nput. 2026-06-18 not yet calculated CVE-2026-38714 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-38714 ] InHand Networks--IR912 InHand Networks IR912 = V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were dis= covered to contain a command injection vulnerability in the log viewing fun= ction. This vulnerability allows remote attackers to execute arbitrary comm= ands as root via a crafted input. 2026-06-18 not yet calculated CVE-2026-38= 715 [
https://www.cve.org/CVERecord?id=3DCVE-2026-38715 ] InHand Networks--= IR912 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (includin=
g earlier versions) were discovered to contain a command injection vulnerab= ility in the Python application export function. This vulnerability allows = remote attackers to execute arbitrary commands as root via a crafted input.=
2026-06-18 not yet calculated CVE-2026-38716 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-38716 ] InHand Networks--IR912 InHand Networks IR912 V1.0.= 0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discover=
ed to contain a command injection vulnerability in the file upload function=
. The vulnerability allows remote attackers to execute arbitrary commands a=
s root via a crafted input. 2026-06-18 not yet calculated CVE-2026-38717 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-38717 ] InHand Networks--IR912 = InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earl= ier versions) were discovered to contain a buffer overflow vulnerability in=
the device registration function. This vulnerability could allow an attack=
er to cause a denial of service attack on the remote target device. 2026-06= -18 not yet calculated CVE-2026-38718 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-38718 ] Iru, Inc--Kandi Agent An issue in Iru, Inc Kandji Agent be= fore v.4.7.5(5374) allows a local attacker to escalate privileges via a cli= ent validation gap to invoke restricted agent functionality. 2026-06-15 not=
yet calculated CVE-2026-39118 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-39118 ] JazzCore--python-pdfkit In JazzCore python-pdfkit 1.0.0, the from= _string method enables the execution of JavaScript code within the context =
of the server application and the exfiltration of local files. 2026-06-17 n=
ot yet calculated CVE-2025-26240 [
https://www.cve.org/CVERecord?id=3DCVE-2= 025-26240 ] JimuReport--JimuReport JimuReport versions 2.3.4 and below are = vulnerable to remote code execution due to improper handling of Aviator exp= ressions. The /jmreport/executeSelectApi endpoint passes user-supplied inpu=
t directly to the Aviator expression engine without adequate validation all= owing attackers to execute arbitrary code. 2026-06-17 not yet calculated CV= E-2026-36418 [
https://www.cve.org/CVERecord?id=3DCVE-2026-36418 ] JONASBN-= -Crypt::OpenSSL::PKCS12 Crypt::OpenSSL::PKCS12 versions before 1.96 for Per=
l permits a heap OOB read in print_attribute UTF8STRING path. print_attribu= te() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exa= ctly to its declared length via strncpy, leaving no NUL terminator. Downstr= eam callers run strlen() on the result and pass the inflated length to newS= Vpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar.=
2026-06-20 not yet calculated CVE-2026-9265 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-9265 ] joomshaper.net--SP LMS extension for Joomla SP LMS (= com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data w= ithout validation, enabling an unauthenticated remote attacker to execute a= rbitrary code on the server. 2026-06-20 not yet calculated CVE-2026-48909 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-48909 ] joomshaper.net--SP Pag=
e Builder extension for Joomla A vulnerability in SP Page Builder for Jooml=
a allows unauthenticated users to upload arbitrary files, ultimately result= ing in the upload and execution of PHP code. 2026-06-20 not yet calculated = CVE-2026-48908 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48908 ] kan-is= hka--linux Reminiscene v0.3.0 An OS command injection vulnerability in the = media archiving and export pipeline component of kanishka-linux Reminiscenc=
e v0.3.0 allows attackers to execute arbitrary commands via supplying a cra= fted input. 2026-06-15 not yet calculated CVE-2026-50871 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-50871 ] kanishka--linux Reminiscence v0.3.0 An =
OS command injection vulnerability in the /manage/features/media component =
of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary=
commands via supplying a crafted input. 2026-06-15 not yet calculated CVE-= 2026-50874 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50874 ] l3montree-= dev--devguard DevGuard provides vulnerability management for the full softw= are supply chain. Prior to 1.4.2, on a DevGuard API instance with one or mo=
re public assets, any authenticated user - including users from a different=
organization with no membership or role in the affected org/project - can = create, update, reapply, and delete VEX rules on those public assets. The s= ame flaw affects the other vulnerability-triage write endpoints exposed und=
er a public asset, including VEX rule create / update / reapply / delete; d= ependency-vuln event creation (accept / reject / mitigate decisions), batch=
event creation, vuln sync, and mitigation; license risk creation; external=
reference writes; and/or artifact creation and license refresh. The attack=
er needs a valid account on the instance, but no membership in the victim o= rganization, project, or asset is required. Version `v1.4.2`contains a patc=
h. As a workaround, make affected assets non-public. In the asset settings,=
switch visibility from public to private. This removes the public-read exe= mption in the access-control middleware and restores correct authorization =
on all write endpoints for that asset. Downstream consumers that previously=
relied on the public `vex.json` / `sbom.json` endpoints will need to be gr= anted explicit access or must receive an exported file version until the pa= tched release is deployed. 2026-06-19 not yet calculated CVE-2026-48089 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-48089 ] Linux--Linux In the Linu=
x kernel, the following vulnerability has been resolved: net/sched: fix ped=
it partial COW leading to page cache corruption tcf_pedit_act() computes th=
e COW range for skb_ensure_writable() once before the key loop using tcfp_o= ff_max_hint, but the hint does not account for the runtime header offset ad= ded by typed keys. This can leave part of the write region un-COW'd. Fix by=
moving skb_ensure_writable() inside the per-key loop where the actual writ=
e offset is known, and add overflow checking on the offset arithmetic. For = negative offsets (e.g. Ethernet header edits at ingress), use skb_cow() to = COW the headroom instead. Guard offset_valid() against INT_MIN, where negat= ion is undefined. 2026-06-16 not yet calculated CVE-2026-46331 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-46331 ] Linux--Linux In the Linux kernel,=
the following vulnerability has been resolved: RDMA: During rereg_mr ensur=
e that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to =
RW then the umem has to be re-evaluated to ensure it is properly pinned as = RW. Since the umem is hidden inside each driver's mr struct add a ib_umem_c= heck_rereg() function that each driver has to call before processing IB_MR_= REREG_ACCESS. mlx4 has to retain its duplicate ib_access_writable check bec= ause it implements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both = items in place sequentially while the MR is live, so it will continue to no=
t support this combination. 2026-06-19 not yet calculated CVE-2026-52908 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-52908 ] Linux--Linux In the Lin=
ux kernel, the following vulnerability has been resolved: ip6_vti: set netn= s_immutable on the fallback device. john1988 and Noam Rathaus reported that=
vti6_init_net() does not set the netns_immutable flag on the per-netns fal= lback tunnel device (ip6_vti0). Other similar tunnel drivers (like ip6_tunn= el, sit, ip6_gre, and ip_tunnel) correctly set this flag during their fallb= ack device initialization to prevent them from being moved to another netwo=
rk namespace. 2026-06-19 not yet calculated CVE-2026-52909 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-52909 ] Linux--Linux In the Linux kernel, the=
following vulnerability has been resolved: bpf: Free reuseport cBPF prog a= fter RCU grace period. Eulgyu Kim reported the splat below with a repro. [0=
] The repro sets up a UDP reuseport group with a cBPF prog and replaces it = with a new one while another thread is sending a UDP packet to the group. T=
he reuseport prog is freed by sk_reuseport_prog_free(). bpf_prog_put() is c= alled for "e"BPF prog to destruct through multiple stages while cBPF prog i=
s freed immediately by bpf_release_orig_filter() and bpf_prog_free(). If a = reuseport prog is detached from the setsockopt() path (reuseport_attach_pro= g() or reuseport_detach_prog()), sk_reuseport_prog_free() is called without=
waiting for RCU readers to complete, resulting in various bugs. Let's defe=
r freeing the reuseport cBPF prog after one RCU grace period. Note "e"BPF p= rog is safe as is unless the fast path starts to touch fields destroyed in = bpf_prog_put_deferred() and __bpf_prog_put_noref(). [0]: BUG: KASAN: vmallo= c-out-of-bounds in reuseport_select_sock+0xedc/0x1220 net/core/sock_reusepo= rt.c:596 Read of size 4 at addr ffffc9000051e004 by task slowme/10208 CPU: =
6 UID: 1000 PID: 10208 Comm: slowme Not tainted 7.0.0-geb7ac95ff75e #32 PRE= EMPT(full) Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps=
fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <IRQ> dump_= stack_lvl+0xe8/0x150 lib/dump_stack.c:120 print_address_description mm/kasa= n/report.c:378 [inline] print_report+0xca/0x240 mm/kasan/report.c:482 kasan= _report+0x118/0x150 mm/kasan/report.c:595 reuseport_select_sock+0xedc/0x122=
0 net/core/sock_reuseport.c:596 udp4_lib_lookup2+0x3bc/0x950 net/ipv4/udp.c= :495 __udp4_lib_lookup+0x768/0xe20 net/ipv4/udp.c:723 __udp4_lib_lookup_skb= +0x297/0x390 net/ipv4/udp.c:752 __udp4_lib_rcv+0x1312/0x2620 net/ipv4/udp.c= :2752 ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207 ip_local_= deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241 NF_HOOK+0x30c/0x3a0 incl= ude/linux/netfilter.h:318 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318=
__netif_receive_skb_one_core net/core/dev.c:6181 [inline] __netif_receive_= skb net/core/dev.c:6294 [inline] process_backlog+0xaa4/0x1960 net/core/dev.= c:6645 __napi_poll+0xae/0x340 net/core/dev.c:7709 napi_poll net/core/dev.c:= 7772 [inline] net_rx_action+0x5d7/0xf50 net/core/dev.c:7929 handle_softirqs= +0x22b/0x870 kernel/softirq.c:622 do_softirq+0x76/0xd0 kernel/softirq.c:523=
</IRQ> <TASK> __local_bh_enable_ip+0xf8/0x130 kernel/softirq.c:450 local_b= h_enable include/linux/bottom_half.h:33 [inline] rcu_read_unlock_bh include= /linux/rcupdate.h:924 [inline] __dev_queue_xmit+0x1dd7/0x3710 net/core/dev.= c:4890 neigh_output include/net/neighbour.h:556 [inline] ip_finish_output2+= 0xca9/0x1070 net/ipv4/ip_output.c:237 NF_HOOK_COND include/linux/netfilter.= h:307 [inline] ip_output+0x29f/0x450 net/ipv4/ip_output.c:438 ip_send_skb+0= x45/0xc0 net/ipv4/ip_output.c:1508 udp_send_skb+0xb04/0x1510 net/ipv4/udp.c= :1195 udp_sendmsg+0x1a71/0x2350 net/ipv4/udp.c:1485 sock_sendmsg_nosec net/= socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] __sys_sendto= +0x554/0x680 net/socket.c:2206 __do_sys_sendto net/socket.c:2213 [inline] _= _se_sys_sendto net/socket.c:2209 [inline] __x64_sys_sendto+0xde/0x100 net/s= ocket.c:2209 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_sysc= all_64+0x160/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hw= frame+0x77/0x7f RIP: 0033:0x415a2d Code: b3 66 2e 0f 1f 84 00 00 00 00 00 6=
6 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8=
b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64=
89 01 48 RSP: 002b:00007f6bc31e41e8 EFLAGS: 00000212 ORIG_RAX: 00000000000= 0002c RAX: ffffffffffffffda RBX: 00007f6bc31e4cdc RCX: 0000000000415a2d RDX=
: 0000000000000001 RSI: 00007f6bc31e421f RDI: 0000000000000003 RBP: 00007f6= bc31e4240 R08: 00007f6bc31e4220 R09: 0000000000000010 R10: 0000000000000000=
R11: ---truncated--- 2026-06-19 not yet calculated CVE-2026-52910 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-52910 ] Linux--Linux In the Linux ker= nel, the following vulnerability has been resolved: ksmbd: scope conn->bind= ing slowpath to bound sessions only When the binding SESSION_SETUP sets con= n->binding =3D true, the flag stays set after the call so that the global s= ession lookup in ksmbd_session_lookup_all() can find the session, which was=
not added to conn->sessions. Because the flag is connection-wide, the glob=
al lookup path will also resolve any other session by id if asked. Tighten = the global lookup so that the returned session must have this connection re= gistered in its channel xarray (sess->ksmbd_chann_list). The channel entry =
is installed by the existing binding_session path in ntlm_authenticate()/kr= b5_authenticate() when a SESSION_SETUP completes successfully, so this cond= ition is a strict equivalent of "this connection has been accepted as a cha= nnel of this session". Connections that have not bound to a given session c= annot reach it via the global table. The existing conn->binding gate for en= tering the slowpath is preserved so that non-binding connections keep the f= ast-path-only behavior, and the session->state check is unchanged. 2026-06-=
21 not yet calculated CVE-2026-52911 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-52911 ] liquidfiles--liquidfiles Liquidfiles versions before 4.2.12=
are affected by a broken access control vulnerability resulting in privile=
ge escalation from an Admin in a secondary domain to a Sysadmin by modifyin=
g a group in their managed secondary (non-default) group. 2026-06-20 not ye=
t calculated CVE-2026-12673 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 2673 ] LLDAP--LLDAP v0.6.2 An input handling flaw in the HTTP refresh token=
process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS=
) via sending a crafted refresh-token header. 2026-06-15 not yet calculated=
CVE-2026-50889 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50889 ] LMS--= LMS An SQL Injection vulnerability exists in LMS (LAN Management System) be= fore commit=C2=A04cb30a7=C2=A0within the "tarifflist.php" module due to ins= ufficient sanitization of the POST "tg[]" parameter. The application direct=
ly concatenates user-supplied array values into an SQL query using "implode= ()", allowing authenticated attackers to perform Error-Based SQL injection = and extract sensitive database information. 2026-06-18 not yet calculated C= VE-2026-40455 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40455 ] LMS--LM=
S An OS Command Injection vulnerability exists in LMS (LAN Management Syste= m)=C2=A0before commit 9fcb4de due to an IP address parameter being passed t=
o the "exec()" function without proper validation, allowing attackers to ex= ecute arbitrary operating system commands. 2026-06-18 not yet calculated CV= E-2026-40456 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40456 ] LMS--LMS=
A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Ma= nagement System)=C2=A0before commit 9c5651b in the "dbrecover.php" and "net= remap.php" modules where unsanitized GET parameters are directly embedded i= nto HTML output. This allows an attacker to inject arbitrary JavaScript whe=
n an authenticated user clicks a crafted link, provided the required condit= ions (such as a network defined in the system) are met. 2026-06-18 not yet = calculated CVE-2026-40457 [
https://www.cve.org/CVERecord?id=3DCVE-2026-404=
57 ] LY Corporation--Armeria A vulnerability has been identified in armeria= -xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS modu=
le can resolve control-plane-supplied filenames and environment variables w= ithout restriction, allowing a compromised or semi-trusted xDS control plan=
e to read arbitrary local files and environment variables on the xDS client=
host. 2026-06-19 not yet calculated CVE-2026-11752 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-11752 ] matze--wastebin v3.4.1 An HTML injection vul= nerability in the /src/highlight.rs component of matze wastebin v3.4.1 allo=
ws attackers to execute arbitrary scripts via a crafted payload. 2026-06-15=
not yet calculated CVE-2026-50883 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-50883 ] mcp-tool-shop-org--backpropagate Backpropagate is a Python li= brary for fine-tuning large language models on a single GPU. In versions 1.= 1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane = without authentication: dataset upload, model load, training start/stop, mu= lti-run orchestration, GGUF export, and HuggingFace Hub push. The CLI accep=
ts two operator-facing flags intended as security controls: --auth user:pas=
s - documented as "require HTTP Basic authentication on every request to th=
e UI." and--share - documented as "expose the UI on a public address; requi= res --auth." When --auth user:pass is passed, the CLI prints Auth: enabled = (user: <username>) to confirm to the operator that authentication is active=
, then exports BACKPROPAGATE_UI_AUTH=3Duser:pass to the subprocess that lau= nches the Reflex backend. The Reflex backend (backpropagate/ui_app/**) neve=
r reads BACKPROPAGATE_UI_AUTH. No authentication middleware is registered. =
No request-level guard runs. No WebSocket upgrade guard runs. Any client th=
at reaches the bound port - local or remote, depending on whether --share i=
s used - has full UI access. An inline comment at backpropagate/cli.py:1217= -1218 in the v1.1.0 source documents the gap: "For Phase 1 the variable is = exported but Reflex doesn't read it yet." This comment was internal-facing;=
the user-facing documentation (README, CHANGELOG, SHIP_GATE) advertised th=
e contract as enforced. An attacker who reaches the bound port can read upl= oaded datasets, trigger arbitrary training runs against any local base mode=
ls as well as read their paths, trigger HuggingFace Hub pushes and cause di= sk-fill DoS. This issue has been fixed in version 1.2.0. If developers cann=
ot immediately upgrade to 1.2.0 run backprop ui with no flags so it binds t=
o localhost, use SSH port-forwarding (ssh -L 7860:localhost:7860 <training-= host>) instead of --share for remote access, and audit any host previously = launched with --share, re-issuing any HF tokens used during those sessions.=
2026-06-16 not yet calculated CVE-2026-48797 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-48797 ] Micro-Star International Co., Ltd.--RadiX AX6600 W= iFi 6 Tri-Band Gaming Router RadiX AX6600 WiFi 6 Tri-Band Gaming Router con= tains an OS command injection vulnerability, which may lead to arbitrary co= mmand execution with the root privilege by a user who logs in to the web co= nsole as an administrator. 2026-06-17 not yet calculated CVE-2026-53876 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-53876 ] Microchip--GridTime 3000=
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross= -site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Sit=
e Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through = 1.1r0.0. 2026-06-19 not yet calculated CVE-2026-12619 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-12619 ] Microchip--GridTime 3000 The GridTime 3000=
GNSS Time Server leaks the access token in the URL parameters of some endp= oints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0. 202= 6-06-19 not yet calculated CVE-2026-12620 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-12620 ] Microchip--GridTime 3000 Improper neutralization of in= put during web page generation XSS vulnerability in the GridTime 3000 (pass= word reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.0=
3 before 1.2r0.0. 2026-06-19 not yet calculated CVE-2026-12621 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-12621 ] Microchip--GridTime 3000 The Grid= Time 3000 GNSS Time Server has an open redirect vulnerability in the passwo=
rd change form submission. This issue affects GridTime 3000: from 1.0r0.03 = through 1.1r0.0. 2026-06-19 not yet calculated CVE-2026-12622 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-12622 ] Microsoft--HEIF Image Extensions M= icrosoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because C= HEIFItemInfoEntry_GetDataSize can return success while leaving the reported=
data size as 0. This causes a caller to make a 1-byte allocation. Later, C= opyPixels computes copy_size =3D stride * abs(roi_height) but does not chec=
k the source buffer length before a memmove call. 2026-06-19 not yet calcul= ated CVE-2025-62821 [
https://www.cve.org/CVERecord?id=3DCVE-2025-62821 ] m= icrosoft--kiota-typescript @microsoft/kiota-http-fetchlibrary provides Type= Script libraries for Kiota-generated API clients. In versions 1.0.0-preview= .97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `Redi= rectHandler` is documented as stripping `Authorization` and `Cookie` from c= ross-origin redirect targets, but the default `scrubSensitiveHeaders` callb= ack in `RedirectHandlerOptions` uses case-sensitive property deletion (`del= ete headers.Authorization`, `delete headers.Cookie`) on a headers object th=
at `FetchRequestAdapter.getRequestFromRequestInformation` has already lower= -cased. The delete therefore targets keys that do not exist, the scrub is a=
no-op, and any Bearer token or Cookie attached by a kiota-generated SDK is=
forwarded to an attacker-controlled host across a 30x redirect. This is re= achable in the default middleware chain (`MiddlewareFactory.getDefaultMiddl= ewares`) with no custom configuration, and applies to every kiota-generated=
TypeScript SDK that uses `BaseBearerTokenAuthenticationProvider` or any ot= her authentication provider that sets the `Authorization` request header. V= ersion 1.0.0-preview.102 patches the issue. 2026-06-19 not yet calculated C= VE-2026-49336 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49336 ] Microve= rt--MEmu Android Emulator 9.2.7.0 An issue in Microvirt MEmu Android Emulat=
or 9.2.7.0 allows a local attacker to escalate privileges via the MemuServi= ce.exe component. 2026-06-15 not yet calculated CVE-2026-36213 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-36213 ] Mitsubishi Electric Corporation--= Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP I= nteger Overflow or Wraparound vulnerability in the EtherNet/IP function of = Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP v= ersions 1.000 and prior allows a remote attacker to cause a denial-of-servi=
ce (DoS) condition in the affected product by rapidly establishing a large = number of TCP connections to it, resulting in an inconsistency in the produ= ct's internal connection management process and triggering improper memory = access. 2026-06-19 not yet calculated CVE-2026-8805 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-8805 ] Mitsubishi Electric Corporation--Mitsubishi E= lectric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP Expected=
Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series=
FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attac= ker to cause a denial-of-service (DoS) condition in the affected product by=
continuously sending a large number of communication packets to the Ethern=
et port of the product in a short period of time, increasing the processing=
load of the product, preventing the internal anomaly-detection processing = from being performed, and causing the communication function to stop. 2026-= 06-19 not yet calculated CVE-2026-8806 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-8806 ] Mitsubishi Electric Corporation--Room Air Conditioners (= for Japan) MSZ-BKR2223-W Use of Hard-coded Credentials vulnerability in Mit= subishi Electric Room Air Conditioners (for Japan and outside Japan); Wirel= ess LAN Adapters for Room Air Conditioners (for Japan and outside Japan); W= ireless LAN Adapters for Packaged Air Conditioners (for Japan and outside J= apan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible=
Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ve= ntilation Systems (for Japan); Adapters for Airflow Ventilation Systems, He=
at Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning Sys= tem Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan=
); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking = Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within=
Wi-Fi radio range of an affected product to access the affected product us= ing a hard-coded SSID and password, thereby obtaining device data such as o= peration status, room set temperature, and room temperature; changing the a= ir-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a=
denial-of-service (DoS) condition. 2026-06-17 not yet calculated CVE-2026-= 5667 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5667 ] Moxa--NPort 6000 = Series A denial-of-service vulnerability exists in NPort devices because of=
improper access control on the command port. The command interface does no=
t properly validate whether a sender is associated with a valid data port s= ession before accepting break signal commands. A remote attacker with netwo=
rk access can send crafted requests to disrupt serial communication for an = active user session. 2026-06-16 not yet calculated CVE-2026-10831 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-10831 ] Moxa--NPort 6000-G2 Series A d= enial-of-service vulnerability exists in the WebSocket API due to insuffici= ent validation and handling of JSON-based requests. A low-privileged authen= ticated attacker can send a specially crafted request that causes service d= isruption and may result in an unexpected device reboot. 2026-06-16 not yet=
calculated CVE-2026-10825 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10= 825 ] Moxa--NPort W2150A-W4/W2250A-W4 Series A format string vulnerability = has been found in the "alias" parameter of the Serial Param configuration p= age in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vul= nerability stems from insufficient input validation and improper handling o=
f externally supplied format strings. An attacker could exploit this vulner= ability by sending crafted input to the web service, causing unintended mem= ory disclosure. Successful exploitation may allow an attacker to leak sensi= tive memory contents and determine critical memory addresses, potentially b= ypassing Address Space Layout Randomization (ASLR) protections. 2026-06-16 = not yet calculated CVE-2026-10828 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-10828 ] Moxa--NPort W2150A-W4/W2250A-W4 Series A stack-based buffer ov= erflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series=
version 1.5 and earlier. This vulnerability stems from insufficient input = validation of=C2=A0user-supplied input in the "Server location" parameter o=
n the Basic settings page.=C2=A0An attacker could exploit this vulnerabilit=
y by sending crafted input to the web service, resulting in memory corrupti= on. Successful exploitation of this vulnerability could allow remote code e= xecution on the target system with root privileges. 2026-06-16 not yet calc= ulated CVE-2026-10829 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10829 ]=
Mozilla--Firefox Privilege escalation in the Graphics: WebRender component=
. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox = ESR 115.37, Thunderbird 152, and Thunderbird 140.12. 2026-06-16 not yet cal= culated CVE-2026-12289 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12289 =
] Mozilla--Firefox Memory safety bug fixed in Firefox 152. This vulnerabili=
ty was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunde= rbird 152, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-1= 2290 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12290 ] Mozilla--Firefox=
Use-after-free in the Networking: HTTP component. This vulnerability was f= ixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 15=
2, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-12291 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-12291 ] Mozilla--Firefox Incorre=
ct boundary conditions in the Web Audio component. This vulnerability was f= ixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 1= 40.12. 2026-06-16 not yet calculated CVE-2026-12292 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-12292 ] Mozilla--Firefox Use-after-free in the Graph= ics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thun= derbird 152. 2026-06-16 not yet calculated CVE-2026-12293 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12293 ] Mozilla--Firefox Sandbox escape in the=
DOM: Workers component. This vulnerability was fixed in Firefox 152, Firef=
ox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.=
2026-06-16 not yet calculated CVE-2026-12294 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-12294 ] Mozilla--Firefox Sandbox escape in the DOM: Naviga= tion component. This vulnerability was fixed in Firefox 152, Firefox ESR 14= 0.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. 2026-06-=
16 not yet calculated CVE-2026-12295 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-12295 ] Mozilla--Firefox Sandbox escape in the Security: Process Sa= ndboxing component. This vulnerability was fixed in Firefox 152, Firefox ES=
R 140.12, Thunderbird 152, and Thunderbird 140.12. 2026-06-16 not yet calcu= lated CVE-2026-12296 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12296 ] = Mozilla--Firefox Sandbox escape due to incorrect boundary conditions in the=
Networking component. This vulnerability was fixed in Firefox 152, Firefox=
ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. 2= 026-06-16 not yet calculated CVE-2026-12297 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-12297 ] Mozilla--Firefox Memory safety bug fixed in Firefox = 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thund= erbird 152, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-= 12298 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12298 ] Mozilla--Firefo=
x JIT miscompilation in the DOM: Core & HTML component. This vulnerability = was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbi=
rd 152, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-1229=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12299 ] Mozilla--Firefox Me= mory safety bug fixed in Firefox 152. This vulnerability was fixed in Firef=
ox 152 and Thunderbird 152. 2026-06-16 not yet calculated CVE-2026-12300 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-12300 ] Mozilla--Firefox Memory=
safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 1=
52 and Thunderbird 152. 2026-06-16 not yet calculated CVE-2026-12301 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-12301 ] Mozilla--Firefox Mitigation=
bypass in the DOM: Security component. This vulnerability was fixed in Fir= efox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thun= derbird 140.12. 2026-06-16 not yet calculated CVE-2026-12302 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-12302 ] Mozilla--Firefox Information disclo= sure due to incorrect boundary conditions in the Graphics: WebGPU component=
. This vulnerability was fixed in Firefox 152 and Thunderbird 152. 2026-06-=
16 not yet calculated CVE-2026-12303 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-12303 ] Mozilla--Firefox Same-origin policy bypass in the Networkin=
g: Cookies component. This vulnerability was fixed in Firefox 152, Firefox = ESR 140.12, Thunderbird 152, and Thunderbird 140.12. 2026-06-16 not yet cal= culated CVE-2026-12304 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12304 =
] Mozilla--Firefox Memory safety bug fixed in Firefox 152. This vulnerabili=
ty was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thund= erbird 140.12. 2026-06-16 not yet calculated CVE-2026-12305 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-12305 ] Mozilla--Firefox Memory safety bug f= ixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox E=
SR 140.12, Thunderbird 152, and Thunderbird 140.12. 2026-06-16 not yet calc= ulated CVE-2026-12306 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12306 ]=
Mozilla--Firefox Memory safety bug fixed in Firefox 152. This vulnerabilit=
y was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunde= rbird 140.12. 2026-06-16 not yet calculated CVE-2026-12307 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-12307 ] Mozilla--Firefox Memory safety bug fi= xed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ES=
R 140.12, Thunderbird 152, and Thunderbird 140.12. 2026-06-16 not yet calcu= lated CVE-2026-12308 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12308 ] = Mozilla--Firefox Memory safety bug fixed in Firefox 152. This vulnerability=
was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunder= bird 140.12. 2026-06-16 not yet calculated CVE-2026-12309 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12309 ] Mozilla--Firefox Memory safety bug fix=
ed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR=
140.12, Thunderbird 152, and Thunderbird 140.12. 2026-06-16 not yet calcul= ated CVE-2026-12310 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12310 ] M= ozilla--Firefox Information disclosure, sandbox escape in the Security: Pro= cess Sandboxing component. This vulnerability was fixed in Firefox 152, Fir= efox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. 2026-06-16 not ye=
t calculated CVE-2026-12311 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 2311 ] Mozilla--Firefox Memory safety bug fixed in Firefox 152. This vulner= ability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and = Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-12312 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-12312 ] Mozilla--Firefox Information di= sclosure, sandbox escape in the Security: Process Sandboxing component. Thi=
s vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 1= 52, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-12313 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-12313 ] Mozilla--Firefox Memory=
safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 1= 52, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. 2026-06-16=
not yet calculated CVE-2026-12314 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-12314 ] Mozilla--Firefox Mitigation bypass in the DOM: Security compo= nent. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thun= derbird 152, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026= -12315 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12315 ] Mozilla--Firef=
ox Mitigation bypass in the DOM: Security component. This vulnerability was=
fixed in Firefox 152 and Thunderbird 152. 2026-06-16 not yet calculated CV= E-2026-12316 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12316 ] Mozilla-= -Firefox Memory safety bug fixed in Firefox 152. This vulnerability was fix=
ed in Firefox 152 and Thunderbird 152. 2026-06-16 not yet calculated CVE-20= 26-12317 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12317 ] Mozilla--Fir= efox Incorrect boundary conditions in the Libraries component in NSS. This = vulnerability was fixed in Firefox 152 and Thunderbird 152. 2026-06-16 not = yet calculated CVE-2026-12318 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -12318 ] Mozilla--Firefox Denial-of-service in the Audio/Video: Playback co= mponent. This vulnerability was fixed in Firefox 152 and Thunderbird 152. 2= 026-06-16 not yet calculated CVE-2026-12319 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-12319 ] Mozilla--Firefox Information disclosure in the Passw= ord Manager component. This vulnerability was fixed in Firefox 152 and Thun= derbird 152. 2026-06-16 not yet calculated CVE-2026-12320 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12320 ] Mozilla--Firefox JIT miscompilation in=
the JavaScript: WebAssembly component. This vulnerability was fixed in Fir= efox 152 and Thunderbird 152. 2026-06-16 not yet calculated CVE-2026-12321 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12321 ] Mozilla--Firefox Clic= kjacking issue in the Widget: Gtk component. This vulnerability was fixed i=
n Firefox 152 and Thunderbird 152. 2026-06-16 not yet calculated CVE-2026-1= 2322 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12322 ] Mozilla--Firefox=
Spoofing issue in the DOM: Core & HTML component. This vulnerability was f= ixed in Firefox 152 and Thunderbird 152. 2026-06-16 not yet calculated CVE-= 2026-12323 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12323 ] Mozilla--F= irefox Incorrect boundary conditions in the Graphics: CanvasWebGL component=
. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb= ird 152, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-123=
24 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12324 ] Mozilla--Firefox D= enial-of-service in the Graphics: ImageLib component. This vulnerability wa=
s fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird=
152, and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-12325 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12325 ] Mozilla--Firefox Memo=
ry safety bugs present in Firefox 151 and Thunderbird 151. Some of these bu=
gs showed evidence of memory corruption and we presume that with enough eff= ort some of these could have been exploited to run arbitrary code. This vul= nerability was fixed in Firefox 152 and Thunderbird 152. 2026-06-16 not yet=
calculated CVE-2026-12326 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12= 326 ] Mozilla--Firefox Memory safety bugs present in Firefox ESR 140.11, Th= underbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs s= howed evidence of memory corruption and we presume that with enough effort = some of these could have been exploited to run arbitrary code. This vulnera= bility was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and T= hunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-12327 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-12327 ] Mozilla--Firefox Memory safety b= ugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.= 11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of = memory corruption and we presume that with enough effort some of these coul=
d have been exploited to run arbitrary code. This vulnerability was fixed i=
n Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and=
Thunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-12328 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-12328 ] Mozilla--Firefox Memory safety=
bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firef=
ox ESR 140.12 and Thunderbird 140.12. 2026-06-16 not yet calculated CVE-202= 6-12329 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12329 ] Mozilla--Fire= fox Incorrect boundary conditions in the Internationalization component. Th=
is vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and T= hunderbird 140.12. 2026-06-16 not yet calculated CVE-2026-12330 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-12330 ] Mozilla--Firefox for iOS Firefox=
for iOS used partial domain matching when attaching cookies to PDF request=
s, allowing a malicious site on a suffix domain to receive cookies belongin=
g to the target site. This vulnerability was fixed in Firefox for iOS 152.0=
. 2026-06-16 not yet calculated CVE-2026-53899 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-53899 ] Mozilla--Firefox for iOS Firefox for iOS preserve=
d cookies set on the initial PDF request across cross-origin HTTP redirects=
in TemporaryDocument, allowing a malicious site to inject arbitrary cookie=
s into requests to an unrelated target domain. This vulnerability was fixed=
in Firefox for iOS 152.0. 2026-06-16 not yet calculated CVE-2026-53900 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-53900 ] Netskope--Netskope Clien=
t Netskope was notified about a potential gap in its Netskope Client for Wi= ndows systems where a malicious insider with administrative privileges can = potentially tamper with the customer IOCTL by sending crafted IOCTL request=
s to the driver. A successful exploit can result in the bypassing of all an= ti-tampering protections for the NSClient.Affected Product(s) and Version(s=
) * Product Name: Netskope Client * Affected Platform: Windows * Affected V= ersion: All version below R138 2026-06-17 not yet calculated CVE-2025-15641=
[
https://www.cve.org/CVERecord?id=3DCVE-2025-15641 ] Netskope--Netskope C= lient Netskope is notified about a potential gap in its Netskoped Client fo=
r Windows systems where a malicious insider with admin privileges can lead =
to bypassing the NSClient Tamper Protections due to weak Discretionary Acce=
ss Control List (DACLs) on the service object and related registry keys,. *=
Product Name: Netskope Client * Affected Platform: Windows * Affected Vers= ion: All version below R138 2026-06-17 not yet calculated CVE-2025-15642 [ =
https://www.cve.org/CVERecord?id=3DCVE-2025-15642 ] Nginx--Nginx Proxy Mana= ger v2.14.0 Incorrect access control in the "Let's Encrypt" certificate dow= nload endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attacker=
s to obtain the TLS private key material via a crafted GET request. 2026-06= -15 not yet calculated CVE-2026-50892 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-50892 ] nltk--nltk/nltk A vulnerability in `nltk.app.wordnet_app` =
up to version 3.9.3 allows unauthenticated remote shutdown of the local Wor= dNet Browser HTTP server when started in its default mode. The server liste=
ns on all interfaces and processes a specific unauthenticated GET request (= `/SHUTDOWN%20THE%20SERVER`) to terminate the process immediately via `os._e= xit(0)`. This results in a denial of service, impacting service availabilit=
y. The issue arises due to insufficient authentication and protection mecha= nisms for critical server functions. 2026-06-17 not yet calculated CVE-2026= -12199 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12199 ] nodejs--node A=
flaw in Node.js Permission Model enforcement allows Bypass via `process.re= port.writeReport()` Path Misvalidation. This can lead to confidentiality im= pact or bypass of the intended security boundary under affected configurati= ons. This vulnerability affects all supported release lines: **Node.js 22**=
, **Node.js 24**, and **Node.js 26**. 2026-06-18 not yet calculated CVE-202= 6-48617 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48617 ] nodejs--node =
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting dat=
a even after sending a `GOAWAY` frame. This vulnerability affects two suppo= rted release lines: **Node.js 22** and **Node.js 24**. 2026-06-18 not yet c= alculated CVE-2026-48937 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4893=
7 ] Nokia--Nokia SR Linux Nokia SR Linux is vulnerable to a local privilege=
escalation vulnerability. Successful exploitation of this vulnerability ma=
y allow an authenticated user to execute arbitrary commands with superuser = privilege. 2026-06-16 not yet calculated CVE-2025-9912 [
https://www.cve.or= g/CVERecord?id=3DCVE-2025-9912 ] Nokia--SR Linux Nokia SR Linux is vulnerab=
le to local privilege escalation vulnerability due to unsanitized format va= lidation. Successful exploitation of this vulnerability may allow an authen= ticated user to execute arbitrary commands with superuser privileges. 2026-= 06-16 not yet calculated CVE-2025-10262 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-10262 ] Nuxt--Nuxt Nuxt before 4.4.7 (and the 3.x branch before=
3.21.7) contains a cross-site scripting vulnerability in the NoScript comp= onent that writes slot content to innerHTML without escaping. Attackers can=
inject malicious scripts through untrusted data in NoScript slots, such as=
route.query parameters, which execute in the document context when the nos= cript tag is implicitly closed by script tags. 2026-06-20 not yet calculate=
d CVE-2026-56317 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56317 ] Obse= rveinc--Observeinc's Observe An issue in Observeinc's Observe v.2026-01-28 = and before allows a remote attacker to obtain sensitive information via the=
CSV Log export component. 2026-06-15 not yet calculated CVE-2026-39007 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-39007 ] OCaml--OCaml-tar In OCam= l-tar before 3.4.0, a crafted archive with ../ path segments in its name al= lows escaping the current working directory. This is not desired behavior, = and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. = The impact is that it allows arbitrary file writes outside of the desired e= xtraction directory (to an attacker that can reach a tar decompression endp= oint). 2026-06-15 not yet calculated CVE-2026-45390 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-45390 ] OCaml--OCaml-TLS In OCaml-TLS before 2.1.0, = the client implementation does insufficient checks of the certificate provi= ded by the server, which allows impersonation with certificates that are no=
t meant for server authentication (because of KeyUsage and ExtendedKeyUsage=
). 2026-06-15 not yet calculated CVE-2026-45388 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-45388 ] OCaml--OCaml-TLS In OCaml-TLS before 2.1.0, the = server implementation does insufficient checks of the certificate provided =
by the client (when doing client authentication), which allows impersonatio=
n with certificates that are not meant for client authentication (because o=
f KeyUsage and ExtendedKeyUsage). 2026-06-15 not yet calculated CVE-2026-45= 389 [
https://www.cve.org/CVERecord?id=3DCVE-2026-45389 ] Octopus Deploy--O= ctopus Server In affected versions of Octopus Server with certain access le= vels it was possible to embed a Cross-Site Scripting Payload via artifacts.=
2026-06-19 not yet calculated CVE-2026-8296 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-8296 ] OpenCPN--OpenCPN A code injection vulnerability in t=
he wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbi= trary code via embedding shell metacharacters. 2026-06-15 not yet calculate=
d CVE-2025-56814 [
https://www.cve.org/CVERecord?id=3DCVE-2025-56814 ] Open= SIPS--OpenSIPS Control Panel A Time-Based Blind SQL Injection vulnerability=
in the alias_management module of OpenSIPS Control Panel (opensips-cp) pri=
or to version 9.3.3 allows authenticated attackers to execute arbitrary SQL=
commands via the 'table' GET parameter in alias_management.php. 2026-06-15=
not yet calculated CVE-2026-36670 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-36670 ] OpenSolution--Quick.CMS Quick.CMS deserializes user-controlle=
d data received over plaintext HTTP without ensuring integrity or authentic= ity. This allows attackers to tamper with serialized payloads in transit an=
d inject malicious objects. Because deserialization is performed without pr= oper validation or class restrictions, crafted payloads can trigger dangero=
us magic methods (e.g., __wakeup() and __destruct()) and leverage gadget ch= ains, resulting in arbitrary code execution. Exploitation is triggered auto= matically when an administrator accesses the admin panel. When successfully=
exploited, this vulnerability allows attackers to execute arbitrary code o=
n the server via manipulated serialized data transmitted over an unprotecte=
d channel. This issue was mitigated by limiting the communication to HTTPS =
in a patch for version 6.8 published on 14.05.2026, deployments without thi=
s patch remain vulnerable. 2026-06-15 not yet calculated CVE-2026-11860 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-11860 ] Password Manager--Passwo=
rd Manager Improper handling of HTTP headers that allows a remote attacker =
to manipulate the value of the Host header using specially crafted requests=
. A successful exploit could result in the generation of manipulated links =
or responses, potentially leading to limited information disclosure or comp= romising the integrity of dependent services. 2026-06-17 not yet calculated=
CVE-2026-10836 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10836 ] Passw= ord Manager--Password Manager Open redirection vulnerability due to insuffi= cient validation of the X-Forwarded-Host HTTP header. An attacker could cre= ate manipulated links that, when opened by a victim, cause the victim to be=
redirected to domains controlled by the attacker, enabling phishing or dec= eption attacks with limited impact on confidentiality and integrity. 2026-0= 6-17 not yet calculated CVE-2026-10837 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-10837 ] Password Manager--Password Manager Open redirection vul= nerability in the authentication system allows an attacker to use manipulat=
ed values in the X-Forwarded-Host header to alter the URLs generated by the=
application. A successful exploit could redirect authenticated users to ma= licious sites following login procedures or interaction with the interface,=
resulting in limited impact on confidentiality and integrity. 2026-06-17 n=
ot yet calculated CVE-2026-10839 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-10839 ] PEVANS--Socket Socket versions before 2.041 for Perl have an ou= t-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the lengt=
h of its source argument before the argument is read, so the check tests th=
e byte length carried over from the preceding multiaddr argument instead. B= oth addresses occupy a 4-byte field, so a valid multiaddr lets a source of = any length pass the check, and the source is then copied into the 4-byte im= r_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is=
not rejected, and the copy reads up to 3 bytes past the end of its buffer.=
Calling pack_ip_mreq_source() with a source value shorter than 4 bytes cop= ies adjacent heap memory into the returned packed structure. 2026-06-15 not=
yet calculated CVE-2026-12087 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-12087 ] picklescan--picklescan picklescan before 0.0.25 fails to detect m= alicious pickle files that use timeit.timeit() in the __reduce__ method, al= lowing remote code execution. Attackers can craft pickle files that import = dangerous libraries like os and execute arbitrary system commands, which ev= ade picklescan detection and execute when pickle.load() is called. 2026-06-=
21 not yet calculated CVE-2025-71351 [
https://www.cve.org/CVERecord?id=3DC= VE-2025-71351 ] picklescan--picklescan picklescan before 1.0.3 contains a s= canning bypass vulnerability in the scan_pytorch function that allows attac= kers to embed malicious magic numbers via dynamic eval using the __reduce__=
trick. Attackers can craft malicious PyTorch payloads that evade picklesca=
n detection while remaining executable, enabling arbitrary code execution w= hen loaded with torch.load(). 2026-06-17 not yet calculated CVE-2026-53875 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-53875 ] Plane--Plane Plane CE=
1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS i=
n the description_html field when creating an intake work item through the = API v1 intake endpoint. 2026-06-17 not yet calculated CVE-2026-10850 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-10850 ] PowerSchool--Employee Acces=
s Center Improper Neutralization of Input During Web Page Generation (XSS o=
r 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Cent=
er allows Cross-Site Scripting (XSS).=C2=A0This issue affects Employee Acce=
ss Center: 23.10.=C2=A0It is possible to add in javascript code after the l= ogin URL and have it be eval()'d in the page and execute in the context of = the user. 2026-06-16 not yet calculated CVE-2026-12425 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12425 ] pragdave--earmark Improper Neutralization=
of Script in Attributes in a Web Page vulnerability in pragdave earmark al= lows stored cross-site scripting via unescaped HTML attribute values. 'Elix= ir.Earmark.Transform':_make_att1/2 in lib/earmark/transform.ex splices attr= ibute values verbatim between two literal " bytes: [" ", name, "=3D\"", val= ue, "\""]. Text nodes are routed through the existing escape function which=
encodes " as ", but attribute values never visit that path. A markdow=
n link whose URL or title contains a bare " closes the attribute early and = lets the trailing bytes be parsed by the browser as fresh HTML attributes. = For example, [click](
http://example.com/?a=3Dx" onerror=3D"alert(1)) render=
s as <a href=3D"
http://example.com/?a=3Dx" onerror=3D"alert(1)">click</a>, = executing arbitrary JavaScript in the victim's browser. The earmark library=
is no longer maintained and has been retired on Hex. No patched version wi=
ll be released. All releases from 1.4.1 onward are affected, and users shou=
ld migrate to a maintained Markdown library such as MDEx. This issue affect=
s earmark from 1.4.1 onward. 2026-06-17 not yet calculated CVE-2026-48591 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-48591 ] prefecthq--prefecthq/p= refect Prefect version 3.6.23 is vulnerable to remote code execution due to=
improper handling of user-controlled input in the `GitRepository` storage = class. The `commit_sha` parameter, which is passed to git commands, lacks v= alidation and does not include a `--` separator to distinguish user input f= rom git flags. This allows attackers to inject arbitrary git flags, such as=
`--upload-pack`, enabling execution of external programs. Additionally, th=
e `directories` parameter can be exploited to inject git flags during spars= e-checkout operations. These vulnerabilities allow any user with deployment=
creation permissions to execute arbitrary commands on worker machines, com= promising shared work pools in multi-tenant environments. 2026-06-20 not ye=
t calculated CVE-2026-5366 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53=
66 ] Progress Chef--Chef360 Impact A security issue has been identified in = Chef 360 that could allow unauthorized access to protected API endpoints un= der specific conditions.=C2=A0This issue is due to improper handling of URL= -encoded paths during request processing. In certain scenarios, an authenti= cated request may bypass standard access controls gaining additional privil= eges, potentially allowing access to API endpoints that are intended to be = restricted to higher-permissioned roles.=C2=A0The impact is limited to envi= ronments where the affected request patterns can be triggered and depends o=
n specific deployment configuration and access controls in place. Resolutio=
n The issue has been addressed through product updates that improve request=
validation and enforce strict path normalization before authorization chec= ks.=C2=A0 Customers are advised to update to the latest available version c= ontaining the fix, version 1.7.1 or later. 2026-06-18 not yet calculated CV= E-2026-8100 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8100 ] Progress C= hef--Chef360 A static credential embedded in Chef 360 prior to v1.7.0 permi= tted unauthenticated access to internal message queues. =C2=A0Queue message=
s contained tenant-specific identifiers. =C2=A0The credential has been rota= ted and replaced with per-tenant access in subsequent versions, eliminating=
this access method entirely. 2026-06-18 not yet calculated CVE-2026-8668 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-8668 ] Project Firefly III--Pr= oject Firefly III v6.5.9 Incorrect access control in the webhook management=
component of Project Firefly III v6.5.9 allows attackers to scan internal = resources via a crafted POST request. 2026-06-15 not yet calculated CVE-202= 6-50886 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50886 ] PTC--Windchil=
l PDMLink A critical remote code execution (RCE) vulnerability has been rep= orted in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be ex= ploited through the deserialization of untrusted data.=C2=A0 * This advisor=
y also applies to all CPS versions * The identified vulnerability also impa= cts Windchill and FlexPLM releases prior to 11.0 M030 2026-06-18 not yet ca= lculated CVE-2026-12569 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12569=
] PublicCMS--PublicCMS PublicCMS V5.202506.d has a Cross Site Scripting (X= SS) vulnerability in the site configuration management module. 2026-06-15 n=
ot yet calculated CVE-2026-36521 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-36521 ] Python Software Foundation--CPython To allow builds of Python t=
o be run from an in-tree layout (rather than an installed file layout), the=
VPATH variable is defined at build time and used to locate certain landmar=
ks - specifically, Modules/setup.local. When this landmark is found relativ=
e to VPATH relative to the executable, Python assumes it is running in a so= urce tree and generates a different default sys.path. This code remains in = release builds, so that release-ready builds can be built in-tree. On Windo= ws, since builds are written to 'PCbuild/', the value of VPATH is set to '.= .\..', which results in a landmark of '..\..\Modules\setup.local'. This pat=
h is outside the install directory of Python, and may have different permis= sions, potentially allowing a low-privilege user to create the landmark and=
an alternative `Lib` folder that will be discovered by an otherwise restri= cted install. Such a setup occurs with the legacy default install location = for all users (in the now superseded EXE installer), due to how Windows all= ows all users to create folders in the root directory of their OS drive. Ou=
r recommended mitigation on Windows is to migrate away from the legacy inst= aller and use the new [Python install manager](
https://www.python.org/downl= oads/latest/pymanager/) to install for the current user. Installs where the=
directory two levels above the Python installation directory have equivale=
nt permissions are unaffected (in general, a per-user install cannot be mod= ified at all by other users, removing any escalation of privilege risk, and=
could be directly modified by a privileged user, making the potential tamp= ering irrelevant). Alternative mitigations might include preemptively creat= ing and restricting access to a `Modules` directory. Be aware that only 3.1=
3 and 3.14 will receive updated legacy installers - earlier fixes are only = provided as sources. Platforms other than Windows allow VPATH to be overrid= den, but as they don't usually use a separated directory in the build for b= inaries, are unlikely to have a landmark reference outside of the install d= irectory. The landmark detection involving VPATH is a fallback for when a m= ore specific landmark - .\pybuilddir.txt - is absent, and was included for = compatibility. Future releases of Python will no longer include the fallbac=
k, and so builds will need to generate or preserve the pybuilddir.txt file =
in order to work in-tree. This landmark file has been generated on Windows = since 3.11, and on other platforms for longer. 2026-06-16 not yet calculate=
d CVE-2026-12003 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12003 ] Quan=
os Solutions GmbH--SCHEMA ST4 Quanos SCHEMA ST4 on-premises contains a loca=
l privilege escalation vulnerability in the Client Update Service due to in= secure deserialization in the .NET Remoting service. The service is configu= red with TypeFilterLevel.Full and is bound to local interfaces only through=
named pipes. A local authenticated attacker can connect to the local named=
pipe, obtain the .NET Remoting endpoint, and send specially crafted serial= ized objects. Successful exploitation results in arbitrary code execution i=
n the context of the update process with NT AUTHORITY\SYSTEM privileges. Ne= twork-only exploitation is not possible and local host access with an authe= nticated user session is required. 2026-06-17 not yet calculated CVE-2026-1= 1857 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11857 ] Quanos Solutions=
GmbH--SCHEMA ST4 Quanos SCHEMA ST4 on-premises contains a local privilege = escalation vulnerability in the Client Update Service. The update service r= uns as NT AUTHORITY\SYSTEM and exposes a .NET Remoting interface over a nam=
ed pipe without sufficient access controls or authorization. A local authen= ticated low-privileged user can connect to the interface and invoke privile= ged update methods such as Update(). This allows arbitrary file write and d= elete operations with SYSTEM privileges and can be used to achieve local pr= ivilege escalation. 2026-06-17 not yet calculated CVE-2026-11858 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-11858 ] radvd-project--radvdump radvd i=
s a router advertisement daemon for IPv6. Prior to version 2.21, the `radvd= ump` utility shipped with radvd contains a stack buffer overflow in the Rou=
te Information option parser. When processing a crafted ICMPv6 Router Adver= tisement, `print_ff()` copies up to 2032 bytes from attacker-controlled pac= ket data into a 16-byte `struct in6_addr` on the stack, overflowing by up t=
o 2016 bytes. Note that the main `radvd` daemon is not affected by the vuln= erability. Version 2.21 patches the issue. 2026-06-19 not yet calculated CV= E-2026-48715 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48715 ] Rakuten-= -Send Anywhere An issue was discovered in Rakuten Send Anywhere (File Trans= fer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerabilit=
y allows untrusted applications (with no permissions) to force arbitrary fi=
le downloads into the app's scoped storage. The resulting files appear in t=
he application's trusted Received interface. These conditions establish a v= ector for arbitrary code execution if the payload is an APK file, or a deni= al-of-service condition through resource exhaustion from oversized transfer=
s. 2026-06-15 not yet calculated CVE-2025-68713 [
https://www.cve.org/CVERe= cord?id=3DCVE-2025-68713 ] remotion-dev remotion--remotion-dev remotion v4.= 0.409 remotion-dev remotion v4.0.409 was discovered to contain a remote cod=
e execution (RCE) vulnerability. 2026-06-15 not yet calculated CVE-2026-301=
20 [
https://www.cve.org/CVERecord?id=3DCVE-2026-30120 ] remotion-dev remot= ion--remotion-dev remotion v4.0.409 remotion-dev remotion v4.0.409 was disc= overed to contain an arbitrary file write vulnerability. 2026-06-15 not yet=
calculated CVE-2026-30121 [
https://www.cve.org/CVERecord?id=3DCVE-2026-30= 121 ] Ricoh Company, Ltd.--Multiple printer drivers Multiple printer driver=
s provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a = privilege escalation vulnerability. If this vulnerability is exploited, an = attacker who can log in to a computer running an affected printer driver co= uld elevate privileges by using a specially crafted driver. 2026-06-15 not = yet calculated CVE-2026-50100 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -50100 ] Rocket.Chat--Rocket.Chat Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6=
, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability =
in Livechat files. Protected file downloads at /file-upload/:fileId/:name a= uthorize livechat access using rc_room_type=3Dl with rc_rid+rc_token, but t=
he authorization path does not verify that rc_rid matches the requested fil= e's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, an=
d :name can be anything, allowing unauthenticated discovery of all uploaded=
files. 2026-06-16 not yet calculated CVE-2026-48616 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-48616 ] Rocket.Chat--Rocket.Chat Rocket.Chat in ver= sions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13=
is vulnerable to unauthenticated file deletion. The deleteFileMessage Mete=
or method permanently deletes any uploaded file by ID without requiring aut= hentication. When called via an unauthenticated DDP WebSocket connection, M= eteor.userId() returns null, causing the authorization check to be skipped.=
Execution falls through to FileUpload.getStore('Uploads').deleteById(fileI= D), which removes the file from storage and database unconditionally. File = IDs are discoverable from public channel message payloads and download URLs=
. 2026-06-16 not yet calculated CVE-2026-48929 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-48929 ] Rockwell Automation--CompactLogix 5370 A security=
issue exists within=C2=A01769 CompactLogix controllers=C2=A0due to the=C2= =A0missing validation of sequence numbers and source IP addresses in the CI=
P protocol. This allows attacker to abuse the exposed Connection ID's visib=
le on the web interface to perform denial-of-service attacks, resulting in = a=C2=A0minor fault. 2026-06-16 not yet calculated CVE-2025-11694 [
https://= www.cve.org/CVERecord?id=3DCVE-2025-11694 ] Rockwell Automation--CompactLog=
ix 5370 A sensitive information disclosure security issue exists within the=
affected CompactLogix controllers. The=C2=A0controller's=C2=A0web server e= xposes CIP Connection IDs on the diagnostics webpage, which are accessible =
to any unauthenticated user on the network. This information can be=C2=A0le= veraged=C2=A0by an attacker to construct malicious packets, leading to Deni= al-of-Service. 2026-06-16 not yet calculated CVE-2026-9307 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-9307 ] Rockwell Automation--CompactLogix, Con= trolLogix A denial of service security issue exists in the affected product=
. The security issue stems from a fault occurring when a crafted CIP messag=
e is sent. Devices with less memory are more likely to be affected. This ca=
n result in a major nonrecoverable fault (MNRF). A program download is requ= ired to recover. 2026-06-16 not yet calculated CVE-2026-11317 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-11317 ] Rockwell Automation--FactoryTalk A= nalytics PavilionX A security issue was=C2=A0identified=C2=A0in Pavilion du=
e to improper=C2=A0authorization=C2=A0enforcement in API endpoints.=C2=A0Th=
is vulnerability can=C2=A0allow an unauthorized actor to execute privileged=
operations, including user/role management and other administrative action=
s. 2026-06-16 not yet calculated CVE-2025-14272 [
https://www.cve.org/CVERe= cord?id=3DCVE-2025-14272 ] Rockwell Automation--FactoryTalk Historian SE An=
authentication bypass security issue exists within FactoryTalk Historian S= ite Edition. By continually sending requests to the login endpoint, an atta= cker may obtain a valid authentication token. 2026-06-16 not yet calculated=
CVE-2025-13036 [
https://www.cve.org/CVERecord?id=3DCVE-2025-13036 ] Rockw= ell Automation--FLEX I/O EtherNet/IP Adapters A denial-of-service security = issue exists within the 1794-AENTR adapter due to improper=C2=A0memory hand= ling=C2=A0of CIP protocol requests. This=C2=A0vulnerability=C2=A0can result=
in the=C2=A0adapter=C2=A0faulting and losing connection to=C2=A0its=C2=A0a= ssociated I/O modules, requiring a manual reset to recover. 2026-06-16 not = yet calculated CVE-2026-0646 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 0646 ] Rockwell Automation--FLEX I/O EtherNet/IP Adapters An improper authe= ntication security issue exists within the 1794-AENTR adapter's embedded we=
b server. The vulnerability allows an unauthenticated attacker to change th=
e device's web interface password by sending a crafted HTTP GET request to =
a specific endpoint, without any prior authentication being=C2=A0required. =
If exploited, this could lead to unauthorized access, account takeover, and=
loss of=C2=A0the=C2=A0device's embedded web server's=C2=A0availability. 20= 26-06-16 not yet calculated CVE-2026-0647 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-0647 ] Roy Marples--NetworkConfiguartion/dhcpcd A NULL pointer=
dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while=
parsing configuration options. In parse_option() (src/if-options.c:1886), = the code performs a member access on a NULL pointer of type 'struct dhcp_op=
t' when an unexpected/invalid option token or parsing state causes the look=
up to yield NULL. The instrumented fuzzing build reports 'runtime error: me= mber access within null pointer of type struct dhcp_opt' and aborts. 2026-0= 6-15 not yet calculated CVE-2025-70102 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-70102 ] RTI--Connext Micro Out-of-bounds Read vulnerability in = RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affec=
ts Connext Micro: from 4.0.0 before 4.3.0. 2026-06-17 not yet calculated CV= E-2026-30802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-30802 ] RTI--Con= next Micro Integer Underflow (Wrap or Wraparound) vulnerability in RTI Conn= ext Micro (Core Libraries) allows Overread Buffers.This issue affects Conne=
xt Micro: from 4.0.0 before 4.3.0. 2026-06-17 not yet calculated CVE-2026-3= 0803 [
https://www.cve.org/CVERecord?id=3DCVE-2026-30803 ] RTI--Connext Pro= fessional Heap-based Buffer Overflow vulnerability in RTI Connext Professio= nal (Core Libraries) allows Overflow Variables and Tags.This issue affects = Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, f= rom 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, f= rom 5.0.0 before 5.2.*. 2026-06-17 not yet calculated CVE-2026-2467 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-2467 ] RTI--Connext Professional Out= -of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in=
RTI Connext Professional (Queueing Service,Core Libraries,Persistence Serv= ice) allows Overflow Buffers, Overflow Buffers, Overflow Buffers.This issue=
affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7= .3.1.3, from 6.1.0 before 6.1.*. 2026-06-17 not yet calculated CVE-2026-267=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-2674 ] RTI--Connext Profess= ional Missing Authentication for Critical Function vulnerability in RTI Con= next Professional (Security Plugins) allows Fake the Source of Data.This is= sue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 befor=
e 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 bef= ore 5.3.*. 2026-06-17 not yet calculated CVE-2026-2675 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-2675 ] RTI--Connext Professional Missing Authenti= cation for Critical Function vulnerability in RTI Connext Professional (Sec= urity Plugins) allows Identity Spoofing.This issue affects Connext Professi= onal: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.*, from 6.1.0 before 6= .1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*. 2026-06-17 not yet = calculated CVE-2026-30799 [
https://www.cve.org/CVERecord?id=3DCVE-2026-307=
99 ] RTI--Connext Professional Out-of-bounds Read vulnerability in RTI Conn= ext Professional (Core Libraries) allows Overread Buffers.This issue affect=
s Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3,=
from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*,=
from 5.0.0 before 5.2.*. 2026-06-17 not yet calculated CVE-2026-3894 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-3894 ] RTI--Connext Professional B= uffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulne= rability in RTI Connext Professional (Web Integration Service) allows Filte=
r Failure through Buffer Overflow.This issue affects Connext Professional: = from 7.4.0 before 7.*, from 7.0.0 before 7.3.1.3, from 6.1.2 before 6.1.*. = 2026-06-17 not yet calculated CVE-2026-7300 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-7300 ] rui314--8cc 8cc is vulnerable to an Out of Bounds Rea=
d due to improper handling of #line directives and GNU linemarkers. The com= piler accepts attacker-controlled filename and line number metadata and lat=
er uses it without validation when accessing source line arrays. By supplyi=
ng invalid or oversized line numbers, an attacker can trigger out-of-bounds=
memory access and a crash. Maintainer of this project was notified early a= bout this vulnerability, but didn't respond with the details of vulnerabili=
ty or vulnerable version range. Version corresponding to the commit b480958=
was tested and confirmed as vulnerable, other versions were not tested but=
might also be vulnerable. 2026-06-18 not yet calculated CVE-2026-50643 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-50643 ] Ruoyi--Ruoyi 4.8.2 Ruoyi=
4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system= /notice/add. 2026-06-15 not yet calculated CVE-2026-37216 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-37216 ] Ruoyi--Ruoyi v.4.8.2 RuoYi v4.8.2 is v= ulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issu=
e affects the code generation module and may allow an authenticated attacke=
r with administrative privileges to access sensitive database information. = 2026-06-15 not yet calculated CVE-2026-38812 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-38812 ] SEPPmail AG--Secure Email Gateway SEPPmail versions=
before 15.0.5 allow improper handling of attachment filenames during encry= pted PDF generation. An attacker can exploit this to create new files outsi=
de the intended directory, potentially placing files in web-accessible loca= tions. 2026-06-18 not yet calculated CVE-2026-8811 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-8811 ] Shenzhen Liandian Communication Technology LTD= --V380 IP Camera / AppFHE1_V1.0.6.0 A broken authorization boundary in the = RTSP media delivery pipeline of Shenzhen Liandian Communication Technology = LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticate=
d network actors to bypass the device's credential-enforced live-view workf= low and directly retrieve real-time video stream data. 2026-06-18 not yet c= alculated CVE-2026-12527 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1252=
7 ] shlink--shlink v5.0.1 A Server-Side Request Forgery (SSRF) in the autom= atic short URL title resolution component of shlink v5.0.1 allows attackers=
to scan internal resources via supplying a crafted longUrl. 2026-06-15 not=
yet calculated CVE-2026-50887 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-50887 ] SignalRGB--SignalRGB kernel driver In SignalRGB versions prior to=
1.3.7.0, the \.\SignalIo device object is created without an explicit SDDL=
security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in o= verly permissive default access control, allowing any authenticated local u= ser to obtain a handle to the device and issue privileged IOCTLs. 2026-06-1=
7 not yet calculated CVE-2026-8049 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-8049 ] SignalRGB--SignalRGB kernel driver In SignalRGB versions prior=
to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuf= fer pointer without first verifying that it is non-NULL. Sending an IOCTL w= ith an empty input buffer causes a NULL pointer dereference, resulting in a=
kernel crash. 2026-06-17 not yet calculated CVE-2026-8050 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-8050 ] Significant-Gravitas--AutoGPT AutoGPT =
is a workflow automation platform for creating, deploying, and managing con= tinuous artificial intelligence agents. Prior to 0.6.63, AutoGPT's LoopVide= oBLock allows users to input a video file and process the video, such as lo= oping it 5 times or extending the time, and finally writing it to disk. How= ever, there is no limit on the resources that can be allocated during execu= tion. For example, the number of loops is user-controllable and unlimited. = When a malicious attacker loops too many times, the generated video is too = large, and after writing it to disk, the disk space is exhausted, eventuall=
y causing DoS. Version 0.6.63 patches the issue. 2026-06-18 not yet calcula= ted CVE-2025-32392 [
https://www.cve.org/CVERecord?id=3DCVE-2025-32392 ] Si= gnificant-Gravitas--AutoGPT AutoGPT is a workflow automation platform for c= reating, deploying, and managing continuous artificial intelligence agents.=
Prior to 0.6.63, `StepThroughItemsBlock` can iterate all the contents in a=
list and send them to `FileStoreBlock` for downloading one by one. Althoug=
h `FileStoreBlock` has access time limits for downloading files, `StepThrou= ghItemsBlock` can be used to slowly iterate and download relatively small f= iles (e.g., 100M) multiple times. `StepThroughItemsBlock` does not limit th=
e number of loops. In addition, `FileStoreBlock` does not limit the amount =
of disk space consumed in the current working directory. When a malicious u= ser chooses to download too many videos, the disk space will eventually run=
out, causing a DoS. Version 0.6.63 patches the issue. 2026-06-18 not yet c= alculated CVE-2025-32422 [
https://www.cve.org/CVERecord?id=3DCVE-2025-3242=
2 ] Significant-Gravitas--AutoGPT AutoGPT is a workflow automation platform=
for creating, deploying, and managing continuous artificial intelligence a= gents. Prior to 0.6.63, ScreenshotWebPageBlock will store the captured scre= enshots in a temporary directory. `StepThroughItemsBlock` can be used to it= erate `ScreenshotWebPageBlock` multiple times. `StepThroughItemsBlock` does=
not limit the number of loops. In addition, `ScreenshotWebPageBlock` does = not limit the amount of disk space consumed in the current working director=
y. When a malicious user chooses to screen shot many web pages, the disk sp= ace will eventually run out, causing a DoS. Version 0.6.63 patches the issu=
e. 2026-06-18 not yet calculated CVE-2025-32424 [
https://www.cve.org/CVERe= cord?id=3DCVE-2025-32424 ] Significant-Gravitas--AutoGPT AutoGPT is a workf= low automation platform for creating, deploying, and managing continuous ar= tificial intelligence agents. Prior to 0.6.63, `AddAudioToVideoBlock` will = download and store the video and audio in a temporary directory without del= eting before all noded are done. `StepThroughItemsBlock` can be used to ite= rate `MediaDurationBlock` multiple times. `StepThroughItemsBlock` does not = limit the number of loops. In addition, `AddAudioToVideoBlock` does not lim=
it the amount of disk space consumed in the current working directory and d= oes not delete the video after outputing the result. When a malicious user = chooses to screen shot many web pages, the disk space will eventually run o= ut, causing a DoS. Version 0.6.63 patches the issue. 2026-06-18 not yet cal= culated CVE-2025-32436 [
https://www.cve.org/CVERecord?id=3DCVE-2025-32436 =
] Significant-Gravitas--AutoGPT AutoGPT is a workflow automation platform f=
or creating, deploying, and managing continuous artificial intelligence age= nts. Prior to 0.6.63, `MediaDurationBlock` will download and store the vide=
o in a temporary directory without deleting before all noded are done. `Ste= pThroughItemsBlock` can be used to iterate `MediaDurationBlock` multiple ti= mes. `StepThroughItemsBlock` does not limit the number of loops. In additio=
n, `MediaDurationBlock ` does not limit the amount of disk space consumed i=
n the current working directory and does not delete the video after outputi=
ng the result. When a malicious user chooses to screen shot many web pages,=
the disk space will eventually run out, causing a DoS. Version 0.6.63 patc= hes the issue. 2026-06-18 not yet calculated CVE-2025-32437 [
https://www.c= ve.org/CVERecord?id=3DCVE-2025-32437 ] Silver Leaf Technologies, Inc.--Work= snaps.net Worksnaps Worksnaps before version 1.6.20260201 contains hardcode=
d cloud credentials and related secret material in the Worksnaps client app= lication binaries. The exposed credentials included AWS access keys, S3 buc= ket names, and related cloud access information. The originally exposed AWS=
credentials authenticated as the AWS account root identity and provided ac= cess to Worksnaps production cloud resources, including S3 buckets containi=
ng sensitive data such as screenshots of user desktops. An attacker with ac= cess to the affected client binaries could extract or recover the credentia=
ls and use them to access affected Worksnaps cloud resources. 2026-06-18 no=
t yet calculated CVE-2025-10560 [
https://www.cve.org/CVERecord?id=3DCVE-20= 25-10560 ] SIMA GmbH--Bondix Server OS command injection in the environment=
and tunnel configuration functionality in SIMA GmbH Bondix through version=
1.25.7.5 on Linux allows an authenticated attacker with configuration writ=
e access to execute arbitrary operating-system commands via crafted configu= ration values passed to server-side scripts. 2026-06-19 not yet calculated = CVE-2026-12104 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12104 ] simplc= ommerce--SimplCommerce Stored cross-site scripting (XSS) in NewsItemApiCont= roller=C2=A0In SimplCommerce prior to commit 6142d3b5=C2=A0allows an authen= ticated administrator to execute arbitrary JavaScript via the ShortContent = and FullContent fields, which are stored without HTML=C2=A0sanitization and=
rendered unencoded via @Html.Raw() 2026-06-17 not yet calculated CVE-2026-= 11975 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11975 ] simplcommerce--= SimplCommerce Cross-site request forgery (CSRF) in NewsItemApiController in=
SimplCommerce prior to commit 6233d73e allows an unauthenticated remote at= tacker to create or modify news items as an administrator via a crafted for=
m submitted to `/api/news-items`, due to missing anti-CSRF protection. 2026= -06-17 not yet calculated CVE-2026-9591 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-9591 ] Sismics--Sismics Docs v.1.11 Incorrect access control in=
the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unautho= rized attackers to access sensitive endpoints via a crafted request. 2026-0= 6-15 not yet calculated CVE-2026-50885 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-50885 ] SNMP4J-Agent--SNMP4J-Agent 3.8.3 An issue in SNMP4J-Age=
nt 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jC= fgStoragePath component. 2026-06-15 not yet calculated CVE-2026-39006 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-39006 ] Sonatype--Nexus Repository=
An authenticated user with the nx-licensing-create privilege can upload a = specially crafted license file to execute arbitrary operating system comman=
ds as the Nexus process user in Sonatype Nexus Repository 3 versions before=
3.92.0. 2026-06-16 not yet calculated CVE-2026-10748 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-10748 ] Sonatype--Nexus Repository Manager Sonatyp=
e Nexus Repository Manager before 3.93.0 contains an authorization vulnerab= ility in the proxy repository configuration that allows a delegated reposit= ory administrator to disclose stored upstream proxy credentials. 2026-06-17=
not yet calculated CVE-2026-10741 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-10741 ] Sony Corporation--Optical Disc Archive Software for Windows I= ncorrect default permissions issue exists in Optical Disc Archive Software = for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrar=
y code may be executed with SYSTEM privileges. 2026-06-16 not yet calculate=
d CVE-2026-50255 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50255 ] sour= centis--mercator Mercator is an open source web application that enables ma= pping of the information system. Prior to version 2025.05.19, Mercator's Qu= ery Engine (`/admin/queries/execute`) accepts a JSON DSL (`from` / `select`=
/ `filters` / `traverse` / `output`), translates it into an Eloquent query=
, and returns results as JSON. The controller method `QueryController::exec= ute()` does not enforce an authorization gate, unlike `store()` and `massDe= stroy()` in the same controller which are correctly protected. As a result,=
any authenticated account - including the read-only Auditor role - can que=
ry models beyond its intended scope, including the `User` model. Additional= ly, the `password` column, although declared `$hidden`, is not excluded fro=
m filter predicates, which allows it to be used in `LIKE` conditions. The `= schema()` and `schemaModel()` endpoints of the same controller are similarl=
y unguarded. The Query Engine is read-only; integrity and availability are = not affected. Version 2025.05.19 patches the issue. 2026-06-19 not yet calc= ulated CVE-2026-49344 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49344 ]=
sourcentis--mercator Mercator is an open source web application that enabl=
es mapping of the information system. Prior to version 2025.05.19, a Server= -Side Request Forgery (SSRF) vulnerability exists in Mercator's CVE configu= ration panel (`/admin/config/parameters`). The `testProvider()` method in `= ConfigurationController` passes user-supplied input directly to `curl_init(=
)` without validating the scheme, hostname, or destination IP address. An a= uthenticated user with the `configure` permission can force the Mercator se= rver to issue arbitrary outbound network requests. The suffix `/api/dbInfo`=
appended to the URL can be bypassed by injecting a `#` fragment character = (e.g. `
http://TARGET/PATH#`), allowing full control over the target URL. No=
scheme whitelist, host whitelist, or private/loopback IP block is applied.=
The `
telnet://` scheme can be used for internal port scanning; the `gopher= ://` scheme enables interaction with unauthenticated internal services (Red= is, Memcached), potentially leading to Remote Code Execution under specific=
deployment conditions. Version 2025.05.19 patches the issue. 2026-06-19 no=
t yet calculated CVE-2026-49345 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-49345 ] statping-ng--statping-ng v0.93.0 Incorrect access control in sta= tping-ng v0.93.0 allows attackers to escalate privileges to Administrator a=
nd access sensitive components. 2026-06-15 not yet calculated CVE-2026-5088=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50884 ] SUSE--Rancher A com= mand injection vulnerability in the Rancher Manager cluster before 2.14.2 i= mport endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML=
parameters could allow remote attackers to break out of an image, and exec= ute e.g. malicious containers. 2026-06-19 not yet calculated CVE-2026-44939=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-44939 ] syracom AG--Secure L= ogin (2FA) for Jira syracom AG Secure Login (2FA) for Atlassian Jira, Confl= uence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerabilit=
y. An attacker with valid credentials for a user account can bypass the two= -factor authentication flow by sending HTTP requests with a crafted User-Ag= ent header containing specific strings such as AtlassianMobileApp or JIRA. = When such a User-Agent is present, the plugin does not enforce the configur=
ed 2FA checks for protected web resources. Successful exploitation allows t=
he attacker to access the affected Atlassian application as the compromised=
user without completing 2FA. If the compromised account has administrative=
privileges, the attacker can access administrative functionality and may d= isable the 2FA plugin or make arbitrary administrative changes. The issue i=
s fixed in version 3.5.0.0. 2026-06-16 not yet calculated CVE-2026-12225 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-12225 ] team-alembic--ash_authe= ntication Authentication Bypass by Spoofing vulnerability in team-alembic A= shAuthentication allows account takeover of local users via OAuth2/OIDC sig= n-in. AshAuthentication's OAuth2 and OIDC family strategies matched the loc=
al user by email address (an upsert on the email field, or a user-defined s= ign-in filter) rather than by the OpenID Connect iss/sub claim combination.=
Per OpenID Connect Core =C3=82=C2=A75.7, only iss/sub uniquely and stably = identifies an end-user; other claims, including email, MUST NOT be used as = unique identifiers. A provider login presenting a victim's email, including=
an unverified email, a reused email, or an account with email_verified: fa= lse, resolved to and signed in as the victim's existing local account. An u= nauthenticated attacker who can register an account on any accepted OAuth p= rovider with the victim's email (or who benefits from provider-side email r= euse or reclamation) obtains the victim's full local privileges. The fix re= solves users by the (strategy, sub) identity stored in a user identity reso= urce, and only links a new sub to an existing local account by email when t=
he provider's email_verified claim is trusted (trust_email_verified?). This=
issue affects ash_authentication from 0.1.0 before 4.14.0 and from 5.0.0-r= c.0 before 5.0.0-rc.10. 2026-06-15 not yet calculated CVE-2026-49757 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-49757 ] Tecrail--Responsive FileMan= ager Responsive FileManager's allows an unauthenticated=C2=A0attacker to up= load files of any type and extension without restriction using dialog.php e= ndpoint, leading to Remote Code Execution.=C2=A0 This project is unmaintain=
ed at the time of CVE assignment. The vulnerability was found in the latest=
release=C2=A09.14.0 2026-06-15 not yet calculated CVE-2026-5482 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-5482 ] Teldat--Regesta Smart HD-PLC - T= LDPH16D2 An attacker with access via network to the Regesta Smart HD-PLC of=
the provider Teldat (in this case, NO registration action is required) who=
has the vulnerable software could obtain privilege information by using th=
e command Version via the path: /upgrade/query.php?cmd=3Dp+3&3Bversion=C2= =A0resulting in a information disclosure.=C2=A0This issue affects Regesta S= mart HD-PLC - TLDPH16D2: 11.02.05.10.02. 2026-06-17 not yet calculated CVE-= 2026-27868 [
https://www.cve.org/CVERecord?id=3DCVE-2026-27868 ] Teldat--Re= gesta Smart HD-PLC - TLDPH16D2 An attacker with access via network to the R= egesta Smart HD-PLC of the provider Teldat (in this case, NO registration a= ction is required) who has the vulnerable software could, with a Slow Loris=
attack, cause Denial of Service (DoS) on the web interface of the device.= =C2=A0This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02. = 2026-06-17 not yet calculated CVE-2026-27869 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-27869 ] Teldat--Regesta Smart HD-PLC - TLDPH16D2 An attacke=
r with access via network to the Regesta Smart HD-PLC of the provider Telda=
t (in this case, registration action IS required) who has the vulnerable so= ftware could, introduce arbitrary JavaScript by injecting a=C2=A0Cross-site=
Scripting (XSS)=C2=A0 payload into the 'Hostname' field of the configurati=
on file resulting in a=C2=A0XSS=C2=A0in the path /upgrade/query.php?cmd=3Dp= +3%3Bversion.=C2=A0This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.= 02.05.10.02. 2026-06-17 not yet calculated CVE-2026-27870 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-27870 ] Tenda --AC7 v15.03.06.44 Tenda AC7 v15= .03.06.44 contains a stack buffer overflow vulnerability in the /goform/Adv= SetMacMtuWan interface via the wanMTU parameter. 2026-06-19 not yet calcula= ted CVE-2026-51843 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51843 ] Te= nda --AC7 v15.03.06.44 Tenda AC7 v15.03.06.44 contains a stack buffer overf= low vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneTyp=
e parameter. 2026-06-19 not yet calculated CVE-2026-51844 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-51844 ] Tenda --AC7 v15.03.06.44 Tenda AC7 v15= .03.06.44 contains a stack buffer overflow vulnerability in the /goform/Adv= SetMacMtuWan interface via the mac parameter. 2026-06-19 not yet calculated=
CVE-2026-51845 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51845 ] Tenda=
--AC7 v15.03.06.44 In Tenda AC7 v15.03.06.44, the wanSpeed parameter of th=
e route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability t= hat can lead to remote arbitrary code execution. 2026-06-19 not yet calcula= ted CVE-2026-51846 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51846 ] Te= nda--Tenda 5G03 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comm= and injection in the function action_unlock_sim via the pin parameter. 2026= -06-15 not yet calculated CVE-2026-38060 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-38060 ] Tenda--Tenda 5G03 Tenda 5G03 V05.03.02.04 (Version 1.0)=
is vulnerable to Command injection in the function action_set_volume via t=
he volume parameter. 2026-06-15 not yet calculated CVE-2026-38061 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-38061 ] Tenda--Tenda 5G03 Tenda 5G03 V= 05.03.02.04 (Version 1.0) is vulnerable to Command injection in the functio=
n action_set_rat_mode via the ratMode parameter. 2026-06-15 not yet calcula= ted CVE-2026-38062 [
https://www.cve.org/CVERecord?id=3DCVE-2026-38062 ] Te= nda--Tenda 5G03 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comm= and injection in the function action_radio_on_with_ia_apn via the ia parame= ter. 2026-06-15 not yet calculated CVE-2026-38063 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-38063 ] Tenda--Tenda 5G03 Tenda 5G03 V05.03.02.04 (Ver= sion 1.0) is vulnerable to Command injection in the function action_dial_ca=
ll via the dialNumber parameter. 2026-06-15 not yet calculated CVE-2026-380=
64 [
https://www.cve.org/CVERecord?id=3DCVE-2026-38064 ] Tenda--Tenda 5G03 = Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in=
the function action_ims_on_with_apn via the ims_apn parameter. 2026-06-15 = not yet calculated CVE-2026-38065 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-38065 ] The Document Foundation--LibreOffice LibreOffice can import dr= awings in the DXF format used by CAD software. A heap buffer overflow exist=
ed when importing a DXF polyline. The point count taken from the file was t= runcated to a 16-bit value when the point buffer was sized, while the full = count was used to fill it, so a polyline whose point count exceeded the 16-= bit range was written past the end of the buffer. In fixed versions such ov= ersized polylines are rejected. 2026-06-15 not yet calculated CVE-2026-6039=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-6039 ] The Document Foundati= on--LibreOffice A heap use-after-free existed when importing the blank-widt=
h characters of an ODF number format. A position value read from the docume=
nt was not checked against the length of the format-code string, so a malfo= rmed number format could be processed against memory outside that string. I=
n fixed versions the position is bounds-checked before use. 2026-06-15 not = yet calculated CVE-2026-6040 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 6040 ] The Document Foundation--LibreOffice LibreOffice can import EMF+ gra= phics, which may be embedded in documents. A heap buffer overflow existed w= hen importing an EMF+ gradient brush. The number of gradient blend points w=
as read from the file and used to compute an allocation size, but that mult= iplication could overflow, so a small buffer was allocated and then filled =
as if it were large, writing past its end. In fixed versions the blend-poin=
t count is checked against the data actually available before allocating. 2= 026-06-15 not yet calculated CVE-2026-6045 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-6045 ] The Document Foundation--LibreOffice LibreOffice can i= mport documents in the OOXML format (DOCX). A heap buffer overflow existed = when replaying deferred parser events for a text box element. A handler obj= ect was assumed to be of one type and written to at that type's field layou=
t, but it could be a smaller object, so the write landed past the end of th=
e allocation. In fixed versions the type is checked before the write. 2026-= 06-15 not yet calculated CVE-2026-6047 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-6047 ] The Document Foundation--LibreOffice LibreOffice can imp= ort presentations in the legacy binary PPT format. A stack buffer overflow = existed when importing a colour-replacement record. Two fixed-size colour t= ables were filled from the file, but the write position was not reset betwe=
en the two passes over the record, so a file whose combined colour counts e= xceeded the table size wrote past the end of the tables on the stack. In fi= xed versions the unused second pass is no longer read into those tables. 20= 26-06-15 not yet calculated CVE-2026-8356 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-8356 ] The Document Foundation--LibreOffice LibreOffice Calc c= ompiles cell formulas when opening a spreadsheet. A heap buffer overflow ex= isted when compiling a very long formula made up of many opening tokens. Th=
e array that tracks nesting depth was allocated one element too small for t= hat worst case, so such a formula wrote one element past its end. In fixed = versions the array is sized to hold the largest possible nesting. 2026-06-1=
5 not yet calculated CVE-2026-8357 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-8357 ] The Document Foundation--LibreOffice LibreOffice Calc can impo=
rt tracked changes from a spreadsheet document. A heap buffer overflow exis= ted when a document reused the same change identifier for two different kin=
ds of change. The importer then treated one change object as a different, l= arger type and wrote past the end of its allocation. In fixed versions reco= rds with a duplicate identifier are rejected. 2026-06-15 not yet calculated=
CVE-2026-8358 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8358 ] theoned= ev--onedev OneDev is a Git server with CI/CD, kanban, and packages. In vers= ions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim fro=
m TAR entry getLinkName() without validating whether the target is an absol= ute path. A subsequent file entry in the same archive traverses the symlink=
, writing to arbitrary server-side locations. This is exploitable by any au= thenticated user with CI Job write access - no admin interaction required. = This is an incomplete fix bypass of CVE-2021-21251 (GHSA-2w6j-wc8c-9mq2): t= hat patch blocked .. path segments but did not address absolute symlink tar= gets. This issue has been fixed in version 15.0.7. 2026-06-18 not yet calcu= lated CVE-2026-49248 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49248 ] = ThingsBoard--ThingsBoard ThingsBoard contains a prototype pollution vulnera= bility which may lead to arbitrary code execution within a sandboxed contex=
t by a user who can log in to the affected product with the tenant administ= rator privilege (TENANT_ADMIN). 2026-06-17 not yet calculated CVE-2026-5367=
6 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53676 ] ThingsBoard--Things= Board v4.3.0.1 ThingsBoard v4.3.0.1 is vulnerable to an authentication bypa=
ss during the OAuth authorization code exchange. The application improperly=
trusts user-supplied identity data within the user parameter of the /login= /oauth2/code/ endpoint. By manipulating the email address in this JSON obje= ct, a remote attacker can bypass authentication and gain full access to any=
existing user account on the platform without possessing the target user's=
credentials. This results in a complete account takeover. 2026-06-15 not y=
et calculated CVE-2026-36537 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 36537 ] TIMLEGGE--Crypt::DSA Crypt::DSA versions before 1.21 for Perl reuse=
d the nonce across signatures, leading to private-key recovery. Crypt::DSA:= :sign caches the per-signature nonce material in the Key object without eve=
r clearing it. The first sign() on a Key object picks a nonce, and every la= ter sign() on that same object reuses it, producing an identical "r". Keys = used to sign more than once with an affected version should be considered c= ompromised. 2026-06-15 not yet calculated CVE-2026-12205 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-12205 ] TP-Link Systems Inc.--TL-WR940N v6 An a= uthenticated OS command injection vulnerability exists in the IPv6 PPPoE co= nfiguration handler in TL-WR940N v6 due to improper sanitization of user in= put. An attacker with administrative access may exploit this issue to execu=
te arbitrary system commands with elevated privileges. 2026-06-16 not yet c= alculated CVE-2026-11409 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1140=
9 ] TP-Link Systems Inc.--TL-WR940N v6 An authenticated OS command injectio=
n vulnerability exists in the BigPond Cable (BPA) WAN configuration module =
in TL-WR940N v6 due to improper sanitization of user input. An attacker wit=
h administrative access may exploit this issue to execute arbitrary system = commands with elevated privileges. 2026-06-16 not yet calculated CVE-2026-1= 1410 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11410 ] UBB Systems--UBB= .threads UBB.threads is vulnerable to Stored XSS via user posts and user pr= ofile fields. The application fails to properly sanitize user input, allowi=
ng low privileged attackers to inject arbitrary JavaScript that executes in=
a victim's browser upon viewing. Because vendor contact attempts were unsu= ccessful, the vulnerability has only been confirmed in version 7.7.5 but ma=
y also affect other versions. 2026-06-18 not yet calculated CVE-2026-54219 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-54219 ] UBB Systems--UBB.thre= ads uBB.threads is vulnerable to a=C2=A0Cross-Site Request Forgery (CSRF) d=
ue to a lack of protective mechanisms. This allows an attacker to trick an = authenticated user into executing unintended actions. Because vendor contac=
t attempts were unsuccessful, the vulnerability has only been confirmed in = version 7.7.5 but may also affect other versions. 2026-06-18 not yet calcul= ated CVE-2026-54220 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54220 ] U=
BB Systems--UBB.threads UBB.threads is vulnerable to=C2=A0Reflected XSS. Th=
e application improperly handles user input in certain requests, enabling a= ttackers to execute arbitrary JavaScript in the context of a victim's brows=
er by tricking them into clicking a crafted link.=C2=A0 Because vendor cont= act attempts were unsuccessful, the vulnerability has only been confirmed i=
n version 7.7.5 but may also affect other versions. 2026-06-18 not yet calc= ulated CVE-2026-54221 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54221 ]=
UBB Systems--UBB.threads UBB.threads is vulnerable to Blind SQL Injection,= =C2=A0allowing attackers with access to=C2=A0the Members in Control Panel= =C2=A0to interact with the underlying database. Due to insufficient input s= anitization, an attacker can extract sensitive information, such as user cr= edentials, by manipulating SQL queries through time-based or boolean-based = techniques. Because vendor contact attempts were unsuccessful, the vulnerab= ility has only been confirmed in version 7.7.5 but may also affect other ve= rsions. 2026-06-18 not yet calculated CVE-2026-54222 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-54222 ] UBB Systems--UBB.threads UBB.threads is vul= nerable to Path traversal, allowing attackers with privilege to edit templa= tes to read and write any file on the application's server that application=
has privileges to, what results in Remote Code Execution.=C2=A0 Because ve= ndor contact attempts were unsuccessful, the vulnerability has only been co= nfirmed in version 7.7.5 but may also affect other versions. 2026-06-18 not=
yet calculated CVE-2026-54223 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-54223 ] UBB Systems--UBB.threads UBB.threads is vulnerable to Denial of S= ervice (DoS). By sending multiple concurrent requests to view any user prof= ile on instances with many registered users, an authenticated attacker can = easily exhaust database resources and completely deny access to the applica= tion for other users. Because vendor contact attempts were unsuccessful, th=
e vulnerability has only been confirmed in version 7.7.5 but may also affec=
t other versions. 2026-06-18 not yet calculated CVE-2026-54224 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-54224 ] umputun--remark42 Remark42 is a s= elf-hosted comment engine for blogs, articles, or any other place where rea= ders can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site S= cripting (XSS) vulnerability exploitable through content-type spoofing. The=
Remark42 image proxy fetches an arbitrary remote URL and re-serves the res= ponse from Remark42's own origin. During the download phase, the proxy dete= rmines whether the resource is an image by inspecting only the Content-Type=
header advertised by the remote server, never examining the actual bytes; = during the serving phase, it instead derives the response Content-Type by s= niffing those bytes with http.DetectContentType. An attacker can exploit th=
is inconsistency by hosting a URL that advertises Content-Type: image/png w= hile returning an HTML/JavaScript body: the download check accepts it as an=
image, the serving path sniffs the body and emits Content-Type: text/html,=
and the browser renders the attacker-controlled HTML/JavaScript as a docum= ent within Remark42's origin. Exploitation requires no Remark42 account on = the target instance; the attacker only needs to host the malicious upstream=
URL and deliver the proxy link to a victim by any means, such as email, di= rect message, or a link on another website. This issue has been fixed in ve= rsion 1.16.0. 2026-06-16 not yet calculated CVE-2026-48788 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-48788 ] Unknown--Form Builder CP The Form Bui= lder CP WordPress plugin before 1.2.47 does not properly sanitize a form co= nfiguration value before storing it and using it as part of a client-side s= cript execution, allowing authenticated users with Editor-level access and = above to perform Stored Cross-Site Scripting attacks against any visitor of=
a page rendering the affected form, even when the `unfiltered_html` capabi= lity is disallowed (e.g. in a multisite network). 2026-06-15 not yet calcul= ated CVE-2026-9278 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9278 ] Unk= nown--LearnPress The LearnPress WordPress plugin before 4.3.7 does not gate=
the `edit` context on one of its REST endpoint behind the `edit_users` cap= ability, allowing unauthenticated visitors to retrieve each returned user's=
roles, full capabilities map, extra capabilities, locale, and registration=
date via a crafted request 2026-06-17 not yet calculated CVE-2026-8383 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-8383 ] Unknown--MagicForm The Ma= gicForm WordPress plugin through 0.1.3 does not properly validate the type =
of files uploaded through an unauthenticated AJAX action when a form's per-= field extension allowlist is left empty, allowing unauthenticated attackers=
to upload PHP files and execute arbitrary code on the server. 2026-06-18 n=
ot yet calculated CVE-2026-9815 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-9815 ] Unknown--Taskbuilder The Taskbuilder WordPress plugin before 5.0.=
8 does not properly sanitise a URL parameter before echoing it into inline = JavaScript on a frontend page containing one of its shortcodes, leading to =
a Reflected Cross-Site Scripting vulnerability that can be triggered agains=
t any logged-in user. 2026-06-17 not yet calculated CVE-2026-9570 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-9570 ] Unknown--weMail: Email Marketin=
g, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerc=
e The weMail: Email Marketing, Email Automation, Newsletters, Subscribers &=
Email Optins for WooCommerce WordPress plugin before 2.1.3 does not proper=
ly escape a user-supplied parameter before reflecting it into an HTML attri= bute on a non-nonce-protected AJAX response, allowing unauthenticated attac= kers to deliver Reflected Cross-Site Scripting against any authenticated us=
er (including administrators) via a crafted URL. 2026-06-17 not yet calcula= ted CVE-2026-8089 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8089 ] Unkn= own--WP Go Maps The WP Go Maps WordPress plugin before 10.0.10 does not pro= perly enforce the marker approval filter on the admin-ajax fallback for its=
datatables route, allowing unauthenticated visitors to retrieve marker rec= ords that the site owner has not approved for public display, including the=
ir title, category, address and description fields. 2026-06-15 not yet calc= ulated CVE-2026-8385 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8385 ] U= nknown--WP Go Maps The WP Go Maps WordPress plugin before 10.0.10 does not = perform any approval-state filtering on its public single-marker REST endpo= int, allowing unauthenticated users to retrieve marker records that an admi= nistrator has not yet approved for public display, including any PII placed=
in the address and description fields and the marker's geographic coordina= tes. 2026-06-15 not yet calculated CVE-2026-8386 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-8386 ] Unknown--WP Hotel Booking The WP Hotel Booking W= ordPress plugin before 2.3.1 does not enforce capability checks in several =
of its AJAX handlers, allowing authenticated users with Subscriber-level ac= cess to read other users' booking line items, enumerate active coupons, and=
read pricing data. 2026-06-19 not yet calculated CVE-2026-9822 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-9822 ] Unknown--WP Magnific Popup The WP=
Magnific Popup WordPress plugin through 1.0 does not properly escape user-= controlled link URLs before injecting them into the DOM when displaying ima=
ge load error messages, allowing authenticated attackers with Author-level = access or above to perform Stored Cross-Site Scripting attacks against any = visiting user. 2026-06-17 not yet calculated CVE-2026-7850 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-7850 ] Unknown--WP MAPS PRO The WP MAPS PRO W= ordPress plugin before 6.1.1 registers an unauthenticated AJAX action which=
, given a valid nonce that is publicly emitted on any frontend page enqueui=
ng its map script, unconditionally creates an administrator account and ret= urns a magic-login URL granting interactive admin access. 2026-06-15 not ye=
t calculated CVE-2026-8935 [
https://www.cve.org/CVERecord?id=3DCVE-2026-89=
35 ] urllib3--urllib3/urllib3 urllib3 version 2.6.3 is vulnerable to a deco= mpression bomb bypass in its streaming API (`preload_content=3DFalse`) when=
using Brotli support. The issue arises due to three independent code paths=
in `response.py` that bypass the `max_length` protection introduced in ver= sion 2.6.0 to mitigate CVE-2025-66471. Specifically, negative `max_length` = values can be produced due to buffer arithmetic in `read()`, `flush_decoder=
` unconditionally overrides `max_length` to `-1`, and `_flush_decoder()` pa= sses no limit at all, defaulting to unlimited decompression. This allows a = malicious HTTP server to trigger an out-of-memory (OOM) condition by decomp= ressing large payloads into memory, leading to a denial of service (DoS). T=
he vulnerability affects urllib3 2.6.3 and Brotli 1.2.0 and impacts applica= tions and libraries using `requests` or `urllib3` to stream content from un= trusted sources. 2026-06-19 not yet calculated CVE-2026-9375 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-9375 ] vantage6--vantage6 vantage6 is an op= en-source infrastructure for privacy preserving analysis. Prior to version = 5.0.0, users can reset their MFA token via API routes that send them an ema= il. Currently the number of emails that is sent is not limited. This gives = attackers the option to flood someones mailbox with a lot of emails, and wo= uld have adverse effects on the SMTP server which may be seen as spam sende=
r. Note resetting the MFA token requires a correct password, so the potenti=
al impact for this is very low. Version 5.0.0 fixes the issue. No known wor= karounds are available. 2026-06-17 not yet calculated CVE-2024-24769 [ http= s://www.cve.org/CVERecord?id=3DCVE-2024-24769 ] vantage6--vantage6 vantage6=
is an open-source infrastructure for privacy preserving analysis. Prior to=
version 5.0.0, if an attacker hacks into a vantage6 user's email account, = they can 1) reset the password via email and then 2) reset the 2FA token vi=
a email. This way they reduce 2FA to 1FA (email access). Note that most ema=
il providers require 2FA to access email, so this issue is not very likely =
to cause issues. Version 5.0.0 fixes the issue. No known workarounds are av= ailable. 2026-06-17 not yet calculated CVE-2024-27928 [
https://www.cve.org= /CVERecord?id=3DCVE-2024-27928 ] vantage6--vantage6 vantage6 is an open-sou= rce infrastructure for privacy preserving analysis. Versions prior to 5.0.0=
provide an initial user with username `root` and password `root`. This is = not ideal because attackers know that almost all vantage6 servers have a us=
er with username `root` that probably has admin rights, and the initial pas= sword is very weak and it is possible that administrators forget to reset i=
t. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete=
the `root` user after it has been used to create other users. 2026-06-17 n=
ot yet calculated CVE-2026-54445 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-54445 ] vantage6--vantage6 vantage6 is an open-source infrastructure fo=
r privacy preserving analysis. Prior to version 5.0.0, malicious algorithms=
can potentially access other algorithms input and output files. Version 5.= 0.0 fixes the issue. As a workaround, verify and restrict the algorithm con= tainers that are allowed to run on the node. 2026-06-17 not yet calculated = CVE-2026-54533 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54533 ] Werthe=
im GmbH--Wertheim SafeController 5400 Hardware for VAULT ROOMS (Safe Deposi=
t Locker System - Microcontroller) The Wertheim SafeController 5400, Contro= ller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication betw= een the server and the microcontroller without cryptographic protection. An=
attacker with access to the communication path between the server and the = microcontroller can sniff RS-485 messages and replay previously observed me= ssages. This can be used, for example, to spoof a "quit alarm" message and = continuously deactivate the safe alarm. 2026-06-15 not yet calculated CVE-2= 026-34021 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34021 ] Wertheim Gm= bH--Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Dep= osit Locker System - Microcontroller) The=C2=A0Wertheim SafeController Fami=
ly 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak cus= tom cryptographic algorithms with hard-coded cryptographic keys to protect = communication. An attacker in an adversary-in-the-middle position can decry=
pt the data traffic. During reassessment, it was possible to break the encr= yption/decryption routine and decrypt messages without knowledge of the enc= ryption key. It was also possible to gain knowledge about the encryption ke=
y by intercepting enough messages. 2026-06-15 not yet calculated CVE-2026-3= 4022 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34022 ] Wertheim GmbH--W= ertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System=
) The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, co= ntains an incorrect authorization vulnerability in the WebSocket communicat= ion used by the SafeController WebMessageBroker. An authenticated attacker = with valid low-privileged branch user credentials can manipulate WebSocket = messages by specifying controller identifiers belonging to other branches. = This allows the attacker to access restricted functions and resources in ot= her branches, including activating boxes outside of the user's authorized b= ranch. 2026-06-15 not yet calculated CVE-2026-34023 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-34023 ] Wertheim GmbH--Wertheim SafeController Softw= are for VAULT ROOMS (Safe Deposit Locker System) The Wertheim SafeControlle=
r Software, AssemblyVersion 6.15.8328.28014, contains missing authorization=
checks on multiple web application endpoints. An authenticated attacker wi=
th minimal privileges can access endpoints that are not visible in the fron= tend but remain directly reachable. This allows the attacker to perform res= tricted actions such as switching the user's branch, uploading arbitrary fi= les, downloading arbitrary files, and viewing details of arbitrary branches=
. 2026-06-15 not yet calculated CVE-2026-34024 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-34024 ] Wertheim GmbH--Wertheim SafeController Software f=
or VAULT ROOMS (Safe Deposit Locker System) The Wertheim SafeController Sof= tware, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass v= ulnerability in the login process. The application restricts user logins ba= sed on the IP address associated with a branch location, but the client IP = address is derived from the HTTP X-Forwarded-For header when that header is=
present. An attacker with valid branch user credentials can manipulate the=
X-Forwarded-For header during login to spoof the expected branch IP addres=
s and obtain a valid authenticated session from an unauthorized network loc= ation. 2026-06-15 not yet calculated CVE-2026-34025 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-34025 ] Wertheim GmbH--Wertheim SafeController Softw= are for VAULT ROOMS (Safe Deposit Locker System) Wertheim SafeController So= ftware, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerab= ility in the documentName parameter of the /safe/selfservice/openselfservic= edocument endpoint. The application constructs a file path using attacker-c= ontrolled input without sufficient validation, allowing an authenticated at= tacker with any role or permission level to traverse out of the intended do= cument directory and download arbitrary files accessible to the application=
. This includes, but is not limited to, application log files containing se= nsitive information and application binaries. 2026-06-15 not yet calculated=
CVE-2026-34026 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34026 ] Werth= eim GmbH--Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Lo= cker System) The Wertheim SafeController Software, AssemblyVersion 6.15.832= 8.28014, contains insufficient server-side file type validation in the /saf= e/contract/uploadcustomdocuments endpoint. The application validates upload=
ed files based on the user-controlled HTTP Content-Type value and accepts t=
he upload if this value contains an allowed string such as pdf, jpeg, tiff,=
or png. An authenticated attacker with any role or permission level can sp= oof the Content-Type value and upload arbitrary file content. 2026-06-15 no=
t yet calculated CVE-2026-34027 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-34027 ] Wertheim GmbH--Wertheim SafeController Software for VAULT ROOMS = (Safe Deposit Locker System) The Wertheim SafeController Software, Assembly= Version 6.15.8328.28014, exposes web-accessible file paths that are not pro= tected by an authorization scheme. An unauthenticated attacker can directly=
access HTTP endpoints to download files from locations such as /Resources/= CompanyId_[ID]/Audio/ and /SafeData/. 2026-06-15 not yet calculated CVE-202= 6-34028 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34028 ] Wertheim GmbH= --Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker Sys= tem) The=C2=A0Wertheim SafeController Software, AssemblyVersion 6.15.8328.2= 8014, contains a hard-coded cryptographic key in the SafeSystem.Infrastruct= ure.Security.dll component. An attacker with access to the application file=
s can reverse engineer the DLL and recover the hard-coded cryptographic key=
. This key can be used to decrypt the licence.whs file, which contains sens= itive information about the licensing party and a second key that can be us=
ed to decrypt other configuration files. 2026-06-15 not yet calculated CVE-= 2026-34029 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34029 ] Wertheim G= mbH--Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker = System) The=C2=A0Wertheim SafeController Software, AssemblyVersion 6.15.832= 8.28014, does not sufficiently validate the branch code when a new branch i=
s created. The branch code is later used in multiple application functions,=
including filesystem path generation for uploaded files, profile pictures,=
and settings. An authenticated attacker with the settings_branches_manage = privilege can include path traversal sequences in the branch code and influ= ence the final filesystem location used by affected file operations. This c=
an allow files to be stored in unintended locations, subject to service-acc= ount write permissions and branch-code length restrictions. 2026-06-15 not = yet calculated CVE-2026-34030 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -34030 ] woodpecker-ci--woodpecker Woodpecker is a CI/CD engine. Starting i=
n version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker = CI's gRPC layer allowed any authenticated agent to impersonate any other ag= ent on the same server by injecting a forged `agent_id` value into outgoing=
gRPC metadata. The server correctly verified the JWT token but then discar= ded the verified agent identity in favor of the client-supplied value. Vers= ion 3.14.1 patches the issue. As a workaround, disable org agents (`WOODPEC= KER_DISABLE_USER_AGENT_REGISTRATION=3Dtrue`) and delete existing ones. 2026= -06-18 not yet calculated CVE-2026-50141 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-50141 ] Xen--Xen HVM guest I/O port accesses are subject to eit= her emulation or at least translation. Translations are managed by the devi=
ce model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used ma=
y changed at any time. Traversal of those lists (while handling guest I/O p= ort accesses) therefore needs synchronizing with updates, which was missing=
so far. 2026-06-18 not yet calculated CVE-2026-42487 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-42487 ] Xen--Xen Some shadow paging errors paths w= ill switch the page-tables without updating the currently running vCPU refe= rence. This causes a mismatch between the loaded page-tables and the mapcac=
he metadata which can lead to corruption of the mapcache. 2026-06-18 not ye=
t calculated CVE-2026-42488 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4= 2488 ] Xen--Xen [This CNA information record relates to multiple CVEs; the = text explains which aspects/vulnerabilities correspond to which CVE.] To cr= eate and manage guests, domctl operations are used by the control domain, a=
possible Xenstore domain, or by a domain controlling a particular guest. S= ome of these operations may not be executed in parallel, so a system-wide l= ock is used. The way that lock is acquired is, however, not providing any f= airness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lo=
ck acquire will, for some operations, occur ahead of any permission checkin=
g. This is CVE-2026-42490. 2026-06-18 not yet calculated CVE-2026-42489 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-42489 ] Xen--Xen [This CNA infor= mation record relates to multiple CVEs; the text explains which aspects/vul= nerabilities correspond to which CVE.] To create and manage guests, domctl = operations are used by the control domain, a possible Xenstore domain, or b=
y a domain controlling a particular guest. Some of these operations may not=
be executed in parallel, so a system-wide lock is used. The way that lock =
is acquired is, however, not providing any fairness. This is CVE-2026-42489=
. Furthermore, with XSM/Flask in use, the lock acquire will, for some opera= tions, occur ahead of any permission checking. This is CVE-2026-42490. 2026= -06-18 not yet calculated CVE-2026-42490 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-42490 ] YouTransfer--YouTransfer v1.0.6 An issue in the sendmai=
l transport integration component of YouTransfer v1.0.6 allows attackers to=
execute arbitrary code via supplying a crafted request. 2026-06-15 not yet=
calculated CVE-2026-50880 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50= 880 ] Zhoros--SuperBin v1.0.0 An issue in Zhoros SuperBin v1.0.0 allows att= ackers to execute a directory traversal via supplying files with names cont= aining traversal characters. 2026-06-15 not yet calculated CVE-2026-50877 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-50877 ]=20
Back to top [ #top ]
body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
: normal; font-style: normal; color: #333333; }=20
Having trouble viewing this message?=C2=A0View it as a webpage [
https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/41d32ec ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]
You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [
https://www.cisa.gov ] (CISA)
Manage Subscriptions [
https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [
https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]
Connect with CISA:=20
Facebook [
https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [
https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [
https://Instagram.com/cisag=
ov ]=C2=A0 |=C2=A0 LinkedIn [
https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]
________________________________________________________________________
This email was sent to
cisa@toolazy.synchro.net using GovDelivery Communica= tions Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency=
=C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ =
https://subscriberhelp.granicus.com/ ]=20
body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}
--===============1754896695755606665==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns=3D"
http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
<title> Vulnerability Summary for the Week of June 15, 2026
</title>
</head>
<body style=3D"">
<table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
align=3D"center">
<tr>
<td>
<!--[if (gte mso 9)|(IE)]>
<table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
<![endif]-->
<a name=3D"gd_top" id=3D"gd_top"></a>
=20
<p><img src=3D"
https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
<p>You are subscribed to Vulnerability Bulletins for Cybersecurity and In= frastructure Security Agency. This information has recently been updated an=
d is now available.</p>
<p>The CISA Vulnerability Bulletin provides a summary of new vulnerabilitie=
s that have been recorded in the past week. In some cases, the vulnerabilit= ies in the bulletin may not yet have assigned CVSS scores.</p> <p>Vulnerabilities are based on the=C2=A0<a href=3D"
https://www.cve.org/" t= arget=3D"_blank" title=3D"Common Vulnerabilities and Exposures" class=3D"ex=
t" data-extlink=3D"" rel=3D"noopener">Common Vulnerabilities and Exposures<= /a>=C2=A0(CVE) vulnerability naming standard and are organized according to=
severity, determined by the=C2=A0<a href=3D"
https://www.cve.org/about/rela= tedefforts" target=3D"_blank" title=3D"Common Vulnerability Scoring System"=
rel=3D"noopener">Common Vulnerability Scoring System</a>=C2=A0(CVSS) stand= ard. The division of high, medium, and low severities correspond to the fol= lowing scores:</p>
<strong>High</strong>: vulnerabilities with a CVSS base score of 7.0=E2=80= =9310.0</li>
<strong>Medium</strong>: vulnerabilities with a CVSS base score of 4.0=E2= =80=936.9</li>
<strong>Low</strong>: vulnerabilities with a CVSS base score of 0.0=E2=80= =933.9</li>
</ul>
<p>Entries may include additional information provided by organizations and=
efforts sponsored by CISA. This information may include identifying inform= ation, values, definitions, and related links. Patch information is provide=
d when available. Please note that some of the information in the bulletin =
is compiled from external, open-source reports and is not a direct result o=
f CISA analysis.</p>
<p>=C2=A0</p>
<div class=3D"rss_item" style=3D"margin-bottom: 2em;">
<div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
n: 0 0 0.3em; padding: 0;"><a href=3D"
https://www.cisa.gov/news-events/bull= etins/sb26-173" target=3D"_blank" title=3D"Vulnerability Summary for the We=
ek of June 15, 2026" rel=3D"noopener">Vulnerability Summary for the Week of=
June 15, 2026</a></div>
<div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">06/22/2026 03:30 PM EDT</div>
<div class=3D"rss_description" style=3D"margin: 0 0 0.3em; padding: 0;">
<div id=3D"high_v">
<h2 id=3D"high_v_title">High Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"High Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">10Web--Form Maker by 10Web</td> <td>Unauthenticated SQL Injection in Form Maker by 10Web <=3D 1.15.38 ve= rsions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39502" target=3D= "_blank" rel=3D"noopener">CVE-2026-39502</a></td>
</tr>
<td class=3D"vendor-product">404-redirection-manager--404 Redirection Manag= er</td>
<td>The 404 Redirection Manager plugin version 1.0 for WordPress contains a=
n unauthenticated SQL injection vulnerability that allows remote attackers =
to execute arbitrary SQL queries by injecting malicious code through unsani= tized user input. Attackers can craft GET requests with SQL injection paylo= ads to manipulate database queries and extract sensitive information from t=
he WordPress database.</td>
<td>2026-06-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20071" target=3D= "_blank" rel=3D"noopener">CVE-2016-20071</a></td>
</tr>
<td class=3D"vendor-product">A WP Life--Webenvo</td>
<td>Subscriber Arbitrary File Upload in Webenvo <=3D 0.0.6 versions.</td=
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39589" target=3D= "_blank" rel=3D"noopener">CVE-2026-39589</a></td>
</tr>
<td class=3D"vendor-product">AA-Team--Premium Age Verification / Restrictio=
n for WordPress</td>
<td>Unauthenticated Arbitrary File Download in Premium Age Verification / R= estriction for WordPress <=3D 3.0.2 versions.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-49403" target=3D= "_blank" rel=3D"noopener">CVE-2025-49403</a></td>
</tr>
<td class=3D"vendor-product">ACPT--ACPT (Pro) - Custom Post Types Plugin fo=
r WordPress</td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability=
in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote = Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin fo=
r WordPress: from n/a through 2.0.47.</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25470" target=3D= "_blank" rel=3D"noopener">CVE-2026-25470</a></td>
</tr>
<td class=3D"vendor-product">activity-log.com--WP Sessions Time Monitoring = Full Automatic</td>
<td>Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic = <=3D 1.1.4 versions.</td>
<td>2026-06-16</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39581" target=3D= "_blank" rel=3D"noopener">CVE-2026-39581</a></td>
</tr>
<td class=3D"vendor-product">Adobe--Adobe Acrobat PDF Extension (Chrome)</t=
<td>Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are = affected by a UXSS-class cross-origin data disclosure vulnerability. An att= acker could exploit this vulnerability to gain access to data regarding the=
victim's session. Exploitation of this issue requires user interaction in = that a victim must visit a maliciously crafted URL or interact with a compr= omised web page. Scope is changed.</td>
<td>2026-06-16</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48294" target=3D= "_blank" rel=3D"noopener">CVE-2026-48294</a></td>
</tr>
<td class=3D"vendor-product">Adobe--DNG SDK</td>
<td>DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Bu= ffer Overflow vulnerability that could result in arbitrary code execution i=
n the context of the current user. Exploitation of this issue requires user=
interaction in that a victim must open a malicious file.</td> <td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47964" target=3D= "_blank" rel=3D"noopener">CVE-2026-47964</a></td>
</tr>
<td class=3D"vendor-product">Advanced Ads GmbH--Advanced Ads Tracking</td> <td>Unauthenticated SQL Injection in Advanced Ads - Tracking < 3.0.7 ver= sions.</td>
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59554" target=3D= "_blank" rel=3D"noopener">CVE-2025-59554</a></td>
</tr>
<td class=3D"vendor-product">aguilatechnologies--WP Customer Area</td> <td>Custom role Path Traversal in WP Customer Area <=3D 8.3.4 versions.<=
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42661" target=3D= "_blank" rel=3D"noopener">CVE-2026-42661</a></td>
</tr>
<td class=3D"vendor-product">Ahmad--GeekyBot</td>
<td>Unauthenticated Arbitrary File Upload in GeekyBot <=3D 1.2.2 version= s.</td>
<td>2026-06-15</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40772" target=3D= "_blank" rel=3D"noopener">CVE-2026-40772</a></td>
</tr>
<td class=3D"vendor-product">Ahmad--GeekyBot</td>
<td>Unauthenticated SQL Injection in GeekyBot <=3D 1.2.0 versions.</td> <td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39519" target=3D= "_blank" rel=3D"noopener">CVE-2026-39519</a></td>
</tr>
<td class=3D"vendor-product">Ahmad--JS Help Desk</td>
<td>Unauthenticated SQL Injection in JS Help Desk <=3D 3.0.9 versions.</=
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48886" target=3D= "_blank" rel=3D"noopener">CVE-2026-48886</a></td>
</tr>
<td class=3D"vendor-product">AivahThemes--Car Zone</td>
<td>Unauthenticated Arbitrary File Deletion in Car Zone <=3D 3.7 version= s.</td>
<td>2026-06-16</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69139" target=3D= "_blank" rel=3D"noopener">CVE-2025-69139</a></td>
</tr>
<td class=3D"vendor-product">Al Monsor--ABC Crypto Checkout</td> <td>Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <=3D = 1.8.2 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52695" target=3D= "_blank" rel=3D"noopener">CVE-2026-52695</a></td>
</tr>
<td class=3D"vendor-product">Alberto Hornero--Clean Login</td> <td>Unauthenticated Insecure Direct Object References (IDOR) in Clean Login=
<=3D 1.15 versions.</td>
<td>2026-06-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54184" target=3D= "_blank" rel=3D"noopener">CVE-2026-54184</a></td>
</tr>
<td class=3D"vendor-product">Aman--FunnelKit Automations</td>
<td>Subscriber Broken Authentication in FunnelKit Automations <=3D 3.7.3=
versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39450" target=3D= "_blank" rel=3D"noopener">CVE-2026-39450</a></td>
</tr>
<td class=3D"vendor-product">Anydesk--AnyDesk</td>
<td>AnyDesk 2.5.0 contains an unquoted service path vulnerability that allo=
ws local users to execute arbitrary code with SYSTEM privileges by exploiti=
ng the service installation. Attackers can insert malicious executables in = the system root path that execute with elevated privileges during applicati=
on startup or system reboot.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20094" target=3D= "_blank" rel=3D"noopener">CVE-2016-20094</a></td>
</tr>
<td class=3D"vendor-product">AOMEI--Backupper</td>
<td>A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted=
is an unknown function in the library amwrtdrv.sys of the component Kernel=
Driver. Executing a manipulation can lead to improper access controls. The=
attack needs to be launched locally. The exploit has been publicly disclos=
ed and may be utilized. The vendor was contacted early about this disclosur=
e but did not respond in any way.</td>
<td>2026-06-21</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12780" target=3D= "_blank" rel=3D"noopener">CVE-2026-12780</a></td>
</tr>
<td class=3D"vendor-product">AOMEI--Dynamic Disk Manager</td>
<td>A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. = This issue affects some unknown processing in the library ddmdrv.sys of the=
component Kernel Driver. Performing a manipulation results in improper acc= ess controls. The attack must be initiated from a local position. The explo=
it has been made public and could be used. The vendor was contacted early a= bout this disclosure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12779" target=3D= "_blank" rel=3D"noopener">CVE-2026-12779</a></td>
</tr>
<td class=3D"vendor-product">AOMEI--Partition Assistant</td>
<td>A vulnerability has been found in AOMEI Partition Assistant up to 10.10= .1. This vulnerability affects unknown code in the library ampa10.sys of th=
e component Kernel Driver. Such manipulation leads to improper access contr= ols. The attack must be carried out locally. The exploit has been disclosed=
to the public and may be used. The vendor was contacted early about this d= isclosure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12778" target=3D= "_blank" rel=3D"noopener">CVE-2026-12778</a></td>
</tr>
<td class=3D"vendor-product">Archetyped--Favicon Rotator</td> <td>Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <=3D 1= .2.11 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42649" target=3D= "_blank" rel=3D"noopener">CVE-2026-42649</a></td>
</tr>
<td class=3D"vendor-product">ArrayHQ--Okay Toolkit</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <=3D 2.3 = versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-68851" target=3D= "_blank" rel=3D"noopener">CVE-2025-68851</a></td>
</tr>
<td class=3D"vendor-product">Arraytics--WP Event SOlution</td> <td>Unauthenticated Broken Access Control in WP Event SOlution <=3D 4.1.=
12 versions.</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-68045" target=3D= "_blank" rel=3D"noopener">CVE-2025-68045</a></td>
</tr>
<td class=3D"vendor-product">Arraytics--WP Event SOlution</td> <td>Unauthenticated Broken Access Control in WP Event SOlution <=3D 4.1.=
8 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40776" target=3D= "_blank" rel=3D"noopener">CVE-2026-40776</a></td>
</tr>
<td class=3D"vendor-product">artbees--JupiterX Core</td>
<td>Unauthenticated Broken Access Control in JupiterX Core <=3D 4.14.1 v= ersions.</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39490" target=3D= "_blank" rel=3D"noopener">CVE-2026-39490</a></td>
</tr>
<td class=3D"vendor-product">Artio--Joomla! com_booking component</td> <td>Joomla com_booking component 2.4.9 contains an information disclosure v= ulnerability that allows unauthenticated attackers to enumerate user accoun=
ts by exploiting the getUserData function in the customer controller. Attac= kers can send GET requests to index.php with option=3Dcom_booking, controll= er=3Dcustomer, task=3DgetUserData, and an id parameter to retrieve user nam= es, usernames, and email addresses through brute force enumeration.</td> <td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-54357" target=3D= "_blank" rel=3D"noopener">CVE-2023-54357</a></td>
</tr>
<td class=3D"vendor-product">Avast--AVAST Antivirus</td>
<td>AVAST Antivirus 25.11 contains an unquoted service path vulnerability i=
n the SecureLine service that allows local non-privileged users to execute = code with elevated SYSTEM privileges. Attackers can exploit the unquoted bi= nary path in the service configuration to inject malicious executables that=
execute with high-level system permissions.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71326" target=3D= "_blank" rel=3D"noopener">CVE-2025-71326</a></td>
</tr>
<td class=3D"vendor-product">AVer--PTC500S</td>
<td>Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+=
cameras may allow a remote, unauthenticated attacker to achieve arbitrary = code execution via a specially crafted web request.</td>
<td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40624" target=3D= "_blank" rel=3D"noopener">CVE-2026-40624</a></td>
</tr>
<td class=3D"vendor-product">AVideo--AVideo</td>
<td>AVideo through 29.0 contains an authorization bypass vulnerability in t=
he Meet plugin's uploadRecordedVideo.json.php endpoint that derives the tar= get users_id from the uploaded filename without verification. An attacker w= ith knowledge of the Meet shared secret can craft a malicious file upload w= ith a filename containing an arbitrary users_id to invoke passwordless User= ->login() and establish an authenticated session as any user including a= dmin. Attackers can obtain the Meet shared secret through path-traversal vu= lnerabilities or timing attacks against checkToken.json.php, then POST a cr= afted file to uploadRecordedVideo.json.php with a filename like '1-anything= .mp4' to hijack admin sessions and gain full account takeover.</td> <td>2026-06-20</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56345" target=3D= "_blank" rel=3D"noopener">CVE-2026-56345</a></td>
</tr>
<td class=3D"vendor-product">AVideo--AVideo</td>
<td>AVideo through version 26.0 contains multiple unauthenticated list.json= .php endpoints in payment plugins lacking authorization checks, exposing Pa= yPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unaut= henticated attackers can retrieve all payment transaction data including ag= reement IDs, user financial records, and API responses via direct GET reque= sts to vulnerable endpoints.</td>
<td>2026-06-20</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56341" target=3D= "_blank" rel=3D"noopener">CVE-2026-56341</a></td>
</tr>
<td class=3D"vendor-product">Awesomemotive--Contact Form by WPForms</td> <td>Unauthenticated Broken Access Control in Contact Form by WPForms <=
=3D 1.10.0.4 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48835" target=3D= "_blank" rel=3D"noopener">CVE-2026-48835</a></td>
</tr>
<td class=3D"vendor-product">Awesomemotive--Easy Digital Downloads</td> <td>Unauthenticated Broken Access Control in Easy Digital Downloads <=3D=
3.6.5 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39503" target=3D= "_blank" rel=3D"noopener">CVE-2026-39503</a></td>
</tr>
<td class=3D"vendor-product">AWS--bedrock-agentcore</td>
<td>Improper neutralization of argument delimiters in the install_packages(=
) method in AWS Bedrock AgentCore Python SDK versions >=3D 1.1.3 and <=
; 1.6.1 might allow a remote authenticated user to execute arbitrary comman=
ds within the Code Interpreter sandbox via crafted package name arguments. =
To mitigate this issue, users should upgrade to version 1.6.1.</td> <td>2026-06-17</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12530" target=3D= "_blank" rel=3D"noopener">CVE-2026-12530</a></td>
</tr>
<td class=3D"vendor-product">AxiomThemes--Promo</td>
<td>Unauthenticated Local File Inclusion in Promo <=3D 1.3.0 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22325" target=3D= "_blank" rel=3D"noopener">CVE-2026-22325</a></td>
</tr>
<td class=3D"vendor-product">AxiomThemes--Reprizo</td>
<td>Unauthenticated Local File Inclusion in Reprizo <=3D 1.0.8 versions.= </td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22326" target=3D= "_blank" rel=3D"noopener">CVE-2026-22326</a></td>
</tr>
<td class=3D"vendor-product">Ays Pro--Popup box</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Popup box <=3D 6.2.9 v= ersions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54192" target=3D= "_blank" rel=3D"noopener">CVE-2026-54192</a></td>
</tr>
<td class=3D"vendor-product">Azuriom--Azuriom CMS</td>
<td>Missing Authorization in the server management routes (routes/admin.php=
) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authentic= ated attacker with the admin.access permission to create AzLink server toke=
ns and take over non-admin user accounts by changing their passwords and em= ail addresses via crafted HTTP requests to /admin/servers/create and the Az= Link API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/us= er/{id}).</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54415" target=3D= "_blank" rel=3D"noopener">CVE-2026-54415</a></td>
</tr>
<td class=3D"vendor-product">baptisteArno--typebot.io</td>
<td>TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST=
/api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses = unsanitized fileName input to construct public/ S3 object keys, while issui=
ng presigned PUT URLs that do not bind Content-Type. As a result, any anony= mous visitor to a published bot with a file input can upload attacker-contr= olled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants=
' publicly served result paths, enabling arbitrary content hosting and pote= ntial stored XSS on the storage origin. ../ traversal is blocked by S3/MinI=
O canonicalization (signature mismatch), but forward-slash path injection i=
s exploitable. This issue has been fixed in version 3.17.0.</td> <td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48768" target=3D= "_blank" rel=3D"noopener">CVE-2026-48768</a></td>
</tr>
<td class=3D"vendor-product">baptisteArno--typebot.io</td>
<td>TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF va= lidation is implemented by resolving a hostname once and checking whether t=
he resolved IP belongs to a forbidden range allowing for DNS rebinding bypa= ss. The root cause is a time-of-check to time-of-use gap in the SSRF guard.=
The validator resolves the hostname and approves it, but the later request=
path performs a fresh resolution and connects to whatever IP the hostname = maps to at that moment. The actual outbound request is then performed later=
using the original hostname, without pinning the validated IP to the netwo=
rk connection. An attacker who can supply a URL to a public bot that perfor=
ms a server-side HTTP Request block or server-side script fetch can use DNS=
rebinding to pass the initial validation and still force the server to con= nect to a private or metadata address during the real request. This enables=
server-side access to private network services, cloud metadata endpoints, = and other internal HTTP targets that the validator was intended to block. T=
he exact downstream impact depends on the reachable internal services. Conc= rete consequences include metadata disclosure, access to internal admin pan= els, credential theft from metadata services, and further compromise throug=
h internal-only HTTP interfaces. This issue has been fixed in version 3.17.= 2.</td>
<td>2026-06-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48764" target=3D= "_blank" rel=3D"noopener">CVE-2026-48764</a></td>
</tr>
<td class=3D"vendor-product">baptisteArno--typebot.io</td>
<td>TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an In= secure Direct Object Reference vulnerability through cross-workspace Theme = Template modification and deletion. The handleSaveThemeTemplate and handleD= eleteThemeTemplate handlers validate that the authenticated user is a non-g= uest member of the provided workspaceId, but then operate on themeTemplateI=
d via Prisma queries that do NOT include workspaceId in the WHERE clause. T= his allows any authenticated user to modify or delete theme templates belon= ging to any other workspace and may expose Template IDs via shared typebots=
or network traffic. This issue has been fixed in version 3.16.0.</td> <td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48759" target=3D= "_blank" rel=3D"noopener">CVE-2026-48759</a></td>
</tr>
<td class=3D"vendor-product">Barn2 Media Ltd--WooCommerce Product Filters</=
<td>Unauthenticated PHP Object Injection in WooCommerce Product Filters <=
; 2.0.6 versions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40725" target=3D= "_blank" rel=3D"noopener">CVE-2026-40725</a></td>
</tr>
<td class=3D"vendor-product">bbsetheme--BBS e-Franchise</td>
<td>BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vu= lnerability that allows unauthenticated attackers to execute arbitrary SQL = queries by injecting malicious code through the uid parameter. Attackers ca=
n craft requests to pages using the plugin's shortcode with UNION-based SQL=
injection in the uid parameter to extract sensitive data from the WordPres=
s database including user information and taxonomy terms.</td> <td>2026-06-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20072" target=3D= "_blank" rel=3D"noopener">CVE-2016-20072</a></td>
</tr>
<td class=3D"vendor-product">BdThemes--Element Pack Pro</td>
<td>Contributor Local File Inclusion in Element Pack Pro <=3D 9.0.6 vers= ions.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40721" target=3D= "_blank" rel=3D"noopener">CVE-2026-40721</a></td>
</tr>
<td class=3D"vendor-product">BDthemes--SigmaForms Pro AI Generated Forms</t=
<td>Unauthenticated Arbitrary File Upload in SigmaForms Pro - AI Generated = Forms <=3D 1.4.5 versions.</td>
<td>2026-06-17</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52705" target=3D= "_blank" rel=3D"noopener">CVE-2026-52705</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A weakness has been identified in BerriAI litellm up to 1.59.8. Affecte=
d is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mc= p_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executin=
g a manipulation can lead to improper authentication. The attack may be lau= nched remotely. The exploit has been made available to the public and could=
be used for attacks. The vendor was contacted early about this disclosure.= </td>
<td>2026-06-21</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12773" target=3D= "_blank" rel=3D"noopener">CVE-2026-12773</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A vulnerability was determined in BerriAI litellm up to 1.82.2. This af= fects the function json.dumps of the file litellm/proxy/management_endpoint= s/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can l= ead to missing authentication. The attack can be executed remotely. The exp= loit has been publicly disclosed and may be utilized. The vendor was contac= ted early about this disclosure.</td>
<td>2026-06-21</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12795" target=3D= "_blank" rel=3D"noopener">CVE-2026-12795</a></td>
</tr>
<td class=3D"vendor-product">betterdocs--BetterDocs Pro</td>
<td>The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inc= lusion in versions up to, and including, 3.8.0 via the `doc_style` paramete=
r. This makes it possible for unauthenticated attackers to include and exec= ute arbitrary .php files on the server, allowing the execution of any PHP c= ode in those files. This can be used to bypass access controls, obtain sens= itive data, or achieve code execution in cases where .php file types can be=
uploaded and included.</td>
<td>2026-06-19</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7515" target=3D"= _blank" rel=3D"noopener">CVE-2026-7515</a></td>
</tr>
<td class=3D"vendor-product">bgermann--CformsII</td>
<td>Unauthenticated Cross Site Scripting (XSS) in CformsII <=3D 15.1.3 v= ersions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39435" target=3D= "_blank" rel=3D"noopener">CVE-2026-39435</a></td>
</tr>
<td class=3D"vendor-product">Bhavin Thummar--Product Filter Widget for Elem= entor</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for=
Elementor <=3D 1.0.6 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45437" target=3D= "_blank" rel=3D"noopener">CVE-2026-45437</a></td>
</tr>
<td class=3D"vendor-product">Binisoft--Windows Firewall Control</td> <td>Windows Firewall Control 4.8.6.0 contains an unquoted service path vuln= erability that allows local attackers to escalate privileges by inserting m= alicious executables in the service path. Attackers can place executable fi= les in unquoted path directories that the wfcs.exe service will execute wit=
h LocalSystem privileges upon service restart or system reboot.</td> <td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20091" target=3D= "_blank" rel=3D"noopener">CVE-2016-20091</a></td>
</tr>
<td class=3D"vendor-product">Bitnami--bitnami/cassandra</td>
<td>Bitnami Cassandra container images are affected by a retained default s= uperuser vulnerability. When a custom administrator account is configured v=
ia the CASSANDRA_USER environment variable, the container initialization sc= ript creates the new superuser account but fails to drop the built-in cassa= ndra account in certain scenarios. This leaves the default cassandra:cassan= dra superuser active as an unintended access path. Affected versions - Cont= ainer image: 4.0.x prior to 4.0.20-photon-5-r7; 4.1.x prior to 4.1.11-photo= n-5-r7; 5.0.x prior to 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3.</td> <td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47846" target=3D= "_blank" rel=3D"noopener">CVE-2026-47846</a></td>
</tr>
<td class=3D"vendor-product">Blubrry Podcasting--PowerPress Podcasting</td> <td>Contributor SQL Injection in PowerPress Podcasting <=3D 11.15.10 ver= sions.</td>
<td>2026-06-15</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24637" target=3D= "_blank" rel=3D"noopener">CVE-2026-24637</a></td>
</tr>
<td class=3D"vendor-product">BoldThemes--Nifty</td>
<td>Unauthenticated PHP Object Injection in Nifty <=3D 1.4.1 versions.</=
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27429" target=3D= "_blank" rel=3D"noopener">CVE-2026-27429</a></td>
</tr>
<td class=3D"vendor-product">Bookly--Bookly</td>
<td>Unauthenticated Sensitive Data Exposure in Bookly <=3D 27.4 versions= .</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42667" target=3D= "_blank" rel=3D"noopener">CVE-2026-42667</a></td>
</tr>
<td class=3D"vendor-product">bPlugins--B Blocks</td>
<td>Contributor Privilege Escalation in B Blocks <=3D 2.0.31 versions.</=
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39579" target=3D= "_blank" rel=3D"noopener">CVE-2026-39579</a></td>
</tr>
<td class=3D"vendor-product">Brainstorm Force--OttoKit</td>
<td>Unauthenticated PHP Object Injection in OttoKit <=3D 1.1.27 versions= .</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49781" target=3D= "_blank" rel=3D"noopener">CVE-2026-49781</a></td>
</tr>
<td class=3D"vendor-product">Brainstorm Force--SureDash</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL I= njection. This issue affects SureDash: from n/a through 1.8.0.</td> <td>2026-06-17</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54813" target=3D= "_blank" rel=3D"noopener">CVE-2026-54813</a></td>
</tr>
<td class=3D"vendor-product">Brainstorm Force--WooCommerce Cart Abandonment=
Recovery</td>
<td>Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recov= ery < 2.1.0 versions.</td>
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39470" target=3D= "_blank" rel=3D"noopener">CVE-2026-39470</a></td>
</tr>
<td class=3D"vendor-product">Bricksforge--Bricksforge</td>
<td>Unauthenticated Sensitive Data Exposure in Bricksforge <=3D 3.1.8.4 = versions.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34888" target=3D= "_blank" rel=3D"noopener">CVE-2026-34888</a></td>
</tr>
<td class=3D"vendor-product">Brother--SAPSprint</td>
<td>Brother SAPSprint 7.60 contains an unquoted service path vulnerability =
in the SAPSprint service binary that allows local attackers to escalate pri= vileges. Attackers can place a malicious executable in the Program Files di= rectory path to be executed with LocalSystem privileges when the service st= arts automatically.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47985" target=3D= "_blank" rel=3D"noopener">CVE-2021-47985</a></td>
</tr>
<td class=3D"vendor-product">browserstack--browserstack-cypress-cli</td> <td>The browserstack-cypress-cli is BrowserStack's CLI which allows users t=
o run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerabl=
e to OS command injection via the cypress_config_file configuration paramet= er. In readCypressConfigUtil.js, the loadJsFile() function constructs a she=
ll command by interpolating the user-controlled cypress_config_filepath val=
ue into a template literal, then executes it via child_process.execSync(). = Shell metacharacters in the config path (specifically " and ;) allow breaki=
ng out of the quoted argument and injecting arbitrary commands. This issue = has been fixed in version 1.36.6.</td>
<td>2026-06-15</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48723" target=3D= "_blank" rel=3D"noopener">CVE-2026-48723</a></td>
</tr>
<td class=3D"vendor-product">bytecodealliance--wasmtime</td>
<td>Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.= 0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and Fi= lePerms::READ without FilePerms::WRITE, this access control mechanism can b=
e bypassed via the wasip2 descriptor.open-at or wasip1 path_open interfaces=
by opening a file with only the OpenFlags::TRUNCATE oflag. The root cause =
is that the clause handling OpenFlags::TRUNCATE in crates/wasi/src/filesyst= em.rs (Dir::open_at, lines 967-969) did not set open_mode |=3D OpenMode::WR= ITE;, which is later used for the access control check against FilePerms to=
determine whether opening the file is permitted; the single-line fix adds = that missing assignment, after which the affected calls correctly fail with=
error-code.not-permitted and ERRNO_PERM respectively. Only wasmtime-wasi e= mbeddings that combine DirPerms::MUTATE with FilePerms::READ are affected b=
y this bug. In particular, the Wasmtime project's wasmtime-cli's use of was= mtime-wasi is not affected, because it always sets FilePerms::all() for all=
preopens. This issue has been fixed in versions 24.0.9, 36.0.10 and44.0.2.= </td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47261" target=3D= "_blank" rel=3D"noopener">CVE-2026-47261</a></td>
</tr>
<td class=3D"vendor-product">CactusThemes--Truemag</td>
<td>Unauthenticated Local File Inclusion in Truemag <=3D 4.3.14.2 versio= ns.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69178" target=3D= "_blank" rel=3D"noopener">CVE-2025-69178</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Cap-go before 12.128.2 contains an authentication bypass vulnerability =
in OTP verification that allows attackers to bypass email verification by m= odifying server responses. Attackers can intercept OTP verification request=
s and manipulate HTTP responses to falsely mark verification successful, en= abling unauthorized 2FA enablement and account takeover.</td> <td>2026-06-19</td>
<td>9.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56073" target=3D= "_blank" rel=3D"noopener">CVE-2026-56073</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Cap-go before 12.128.2 contains an authentication logic flaw that lets =
an attacker register and control an account bound to a victim's email addre=
ss before that email is verified. By enabling two-factor authentication on = the pre-registered account, the attacker gains control over the account cla= imed under the victim's identity, allowing them to read and modify its stat=
e and enforce organization-level policies, while the legitimate user is den= ied access to the account tied to their own email.</td>
<td>2026-06-19</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56081" target=3D= "_blank" rel=3D"noopener">CVE-2026-56081</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Capgo (Cap-go/capgo) before 12.128.2 contains an improper access contro=
l vulnerability in the SECURITY DEFINER PostgREST RPC function public.recor= d_build_time, which is granted to the anon role and callable with only the = public Supabase publishable (sb_publishable_*) anon key. An unauthenticated=
attacker can insert rows into public.build_logs for arbitrary organization=
s and, because the function uses ON CONFLICT (build_id, org_id) DO UPDATE, = can overwrite existing usage/billing records by reusing the same build_id f=
or a target org. This enables cross-tenant tampering of billing build logs = and financial-impact denial of service by inflating billable build time.</t=
<td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56082" target=3D= "_blank" rel=3D"noopener">CVE-2026-56082</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.12 allows authenticated users to modify their mutab=
le public.users.email to arbitrary addresses, which the SSO provisioning en= dpoint trusts as an account-merge key. Attackers can pre-position their acc= ount with a victim's corporate SSO email, causing the provision-user endpoi=
nt to merge the victim's SSO identity into the attacker-controlled account.= </td>
<td>2026-06-20</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56215" target=3D= "_blank" rel=3D"noopener">CVE-2026-56215</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a scope escalation vulnerability in the = POST /functions/v1/apikey endpoint that allows app-limited API keys to mint=
unrestricted keys by setting empty limits. Attackers with a compromised ap= p-limited key can create an unrestricted key with org-wide access to resour= ces like app listings and other protected endpoints.</td>
<td>2026-06-20</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56216" target=3D= "_blank" rel=3D"noopener">CVE-2026-56216</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an information disclosure vulnerability =
in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that all= ows unauthenticated attackers to enumerate organizations and disclose billi=
ng status using the public sb_publishable key. Attackers can invoke these e= ndpoints to determine organization existence via distinguishable return val= ues and identify paying customers for targeted profiling.</td> <td>2026-06-20</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56214" target=3D= "_blank" rel=3D"noopener">CVE-2026-56214</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a potential privilege escalation vulnera= bility in the public.apply_usage_overage SECURITY DEFINER function, which p= erforms sensitive billing operations without enforcing internal authorizati=
on checks (no validation of auth.uid(), org membership, or check_min_rights=
). Because the function runs with the owner's privileges, it bypasses Row L= evel Security. If EXECUTE permission is available to the authenticated or a= non roles (explicitly or via default privileges), an authenticated user cou=
ld invoke it via Supabase RPC to manipulate billing data for arbitrary orga= nizations, including unauthorized credit depletion and fraudulent overage e= vent insertion.</td>
<td>2026-06-21</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56239" target=3D= "_blank" rel=3D"noopener">CVE-2026-56239</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an unauthenticated security definer RPC = function get_identity_apikey_only that returns the owning user_id for suppl= ied API keys, creating an API key validity oracle and user identity disclos= ure primitive. Attackers can call this endpoint with valid or invalid API k= eys to confirm key validity and map keys to user identifiers, then chain re= sults into other exposed RPCs like get_orgs_v6 to retrieve organization mem= bership and management email PII.</td>
<td>2026-06-21</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56242" target=3D= "_blank" rel=3D"noopener">CVE-2026-56242</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an improper access control vulnerability=
in the public.get_org_members RPC function that allows unauthenticated att= ackers to enumerate organization members. Attackers can invoke the endpoint=
using only the public sb_publishable_* key and an organization UUID to ret= rieve sensitive member information including email addresses, user IDs, rol= es, and pending invitations.</td>
<td>2026-06-21</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56253" target=3D= "_blank" rel=3D"noopener">CVE-2026-56253</a></td>
</tr>
<td class=3D"vendor-product">Cargo RD--Cargo Shipping Location for WooComme= rce</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in Cargo RD Cargo Shipping Location for WooComm= erce allows Blind SQL Injection. This issue affects Cargo Shipping Location=
for WooCommerce: from n/a through 5.6.</td>
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54815" target=3D= "_blank" rel=3D"noopener">CVE-2026-54815</a></td>
</tr>
<td class=3D"vendor-product">Chatway Live Chat--Chatway Live Chat =E2=80=9C=
AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Ch=
at Buttons</td>
<td>Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI = Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp=
; Chat Buttons <=3D 1.4.8 versions.</td>
<td>2026-06-15</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49082" target=3D= "_blank" rel=3D"noopener">CVE-2026-49082</a></td>
</tr>
<td class=3D"vendor-product">Cherryframework--Cherry Framework Themes</td> <td>WordPress CherryFramework Themes 3.1.4 contains an information disclosu=
re vulnerability that allows unauthenticated attackers to download sensitiv=
e backup files by accessing the download_backup.php endpoint. Attackers can=
directly access the download_backup.php script in the admin/data_managemen=
t directory to obtain ZIP archives containing the entire wp-content/themes = directory contents.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25437" target=3D= "_blank" rel=3D"noopener">CVE-2018-25437</a></td>
</tr>
<td class=3D"vendor-product">ChrisHurst--Simple Backup</td>
<td>WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that a= llow unauthenticated attackers to delete arbitrary files and download sensi= tive files by manipulating the delete_backup_file and download_backup_file = parameters in tools.php. Attackers can exploit insufficient input validatio=
n using directory traversal techniques to access wp-config.php, database du= mps, and other sensitive files, or delete critical files .htaccess to expos=
e backup directories.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20076" target=3D= "_blank" rel=3D"noopener">CVE-2016-20076</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Identity Services Engine Software= </td>
<td>A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, = remote attacker to execute arbitrary commands on the underlying operating s= ystem of an affected device. To exploit this vulnerability, the attacker mu=
st have valid administrative credentials. This vulnerability is due to insu= fficient validation of user-supplied input. An attacker could exploit this = vulnerability by sending a crafted HTTP request to an affected device. A su= ccessful exploit could allow the attacker to obtain user-level access to th=
e underlying operating system and then elevate privileges to root. In singl= e-node deployments, successful exploitation of this vulnerability could cau=
se the affected ISE node to become unavailable, resulting in a denial of se= rvice (DoS) condition. In that condition, endpoints that have not already a= uthenticated would be unable to access the network until the node is restor= ed.</td>
<td>2026-06-17</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20181" target=3D= "_blank" rel=3D"noopener">CVE-2026-20181</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Identity Services Engine Software= </td>
<td>A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated=
, remote attacker to view sensitive information on an affected device. This=
vulnerability is due to improper authorization checks when a resource is a= ccessed. An attacker could exploit this vulnerability by sending crafted tr= affic to an affected device. A successful exploit could allow the attacker =
to gain access to sensitive information, including hashed credentials that = could be used in future attacks.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20190" target=3D= "_blank" rel=3D"noopener">CVE-2026-20190</a></td>
</tr>
<td class=3D"vendor-product">claudiopizzillo--PIAF-HMS</td>
<td>claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no re= leased versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) co= ntains multiple unauthenticated SQL injection vulnerabilities. The applicat= ion has no authentication mechanism and passes user-supplied HTTP parameter=
s directly into deprecated mysql_query() calls via string concatenation, wi= thout sanitization, escaping, or parameterization. Affected sinks include r= ooms.php (DELETE FROM Rooms WHERE ID =3D $_GET['ID'], unquoted numeric cont= ext), checkuser.php (WHERE Ext =3D '$_GET["Ext"]'), ec.php (date/extension = parameters in a WHERE), checkin.php and wakeup.php ($_POST values into INSE=
RT statements), bills.php ($_POST fields built into a WHERE clause), and ra= tes.php and checkout.php. A remote, unauthenticated attacker can inject arb= itrary SQL to read, modify, or delete arbitrary records in the backing data= base (e.g. rooms.php?ID=3D1 OR 1=3D1 deletes all room records). Note: queri=
es run via the legacy mysql_* extension, which does not permit stacked stat= ements.</td>
<td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54419" target=3D= "_blank" rel=3D"noopener">CVE-2026-54419</a></td>
</tr>
<td class=3D"vendor-product">CMSJunkie WordPress Business Directory Plugins= --WP-BusinessDirectory</td>
<td>Subscriber Arbitrary File Upload in WP-BusinessDirectory <=3D 4.0.0 = versions.</td>
<td>2026-06-15</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39591" target=3D= "_blank" rel=3D"noopener">CVE-2026-39591</a></td>
</tr>
<td class=3D"vendor-product">Cmsjunkie--ClassifiedsManager</td>
<td>Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection v= ulnerability that allows unauthenticated attackers to execute arbitrary SQL=
queries by injecting malicious code through POST parameters. Attackers can=
submit crafted SQL payloads in the categorySearch, adType, and citySearch = parameters to the displayads component to extract sensitive database inform= ation including usernames, databases, and version details.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25751" target=3D= "_blank" rel=3D"noopener">CVE-2019-25751</a></td>
</tr>
<td class=3D"vendor-product">Cmsjunkie--J-BusinessDirectory</td>
<td>Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection v= ulnerability that allows unauthenticated attackers to execute arbitrary SQL=
queries by injecting malicious code through the type parameter. Attackers = can send GET requests to index.php with the option=3Dcom_jbusinessdirectory= &task=3Dcategories.getCategories parameters and inject UNION-based SQL = statements in the type parameter to extract database information including = schema names and sensitive data.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25752" target=3D= "_blank" rel=3D"noopener">CVE-2019-25752</a></td>
</tr>
<td class=3D"vendor-product">Cmsjunkie--J-CruisePortal</td>
<td>Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability tha=
t allows authenticated attackers to execute arbitrary SQL queries by inject= ing malicious code through the guest_adult parameter. Attackers can send PO=
ST requests to the cruises endpoint with crafted SQL payloads in the guest_= adult parameter to extract sensitive database information or manipulate dat= abase records.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25749" target=3D= "_blank" rel=3D"noopener">CVE-2019-25749</a></td>
</tr>
<td class=3D"vendor-product">Cmsjunkie--JHotelReservation</td>
<td>Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability = that allows unauthenticated attackers to execute arbitrary SQL queries by i= njecting malicious code through the rooms parameter. Attackers can send POS=
T requests to the search-hotels endpoint with crafted SQL payloads in the r= ooms parameter to extract sensitive database information including version = details.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25748" target=3D= "_blank" rel=3D"noopener">CVE-2019-25748</a></td>
</tr>
<td class=3D"vendor-product">Cmsjunkie--MultipleHotelReservation</td> <td>Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injec= tion vulnerability that allows unauthenticated attackers to execute arbitra=
ry SQL queries by injecting malicious code through the hotel_id parameter. = Attackers can send POST requests to the search-hotels endpoint with crafted=
SQL UNION SELECT statements to extract sensitive database information incl= uding table names and column data.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25750" target=3D= "_blank" rel=3D"noopener">CVE-2019-25750</a></td>
</tr>
<td class=3D"vendor-product">codepeople--WP Time Slots Booking Form</td> <td>Subscriber SQL Injection in WP Time Slots Booking Form <=3D 1.2.50 v= ersions.</td>
<td>2026-06-15</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48882" target=3D= "_blank" rel=3D"noopener">CVE-2026-48882</a></td>
</tr>
<td class=3D"vendor-product">codepeople--WP Time Slots Booking Form</td> <td>Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking For=
m <=3D 1.2.46 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40791" target=3D= "_blank" rel=3D"noopener">CVE-2026-40791</a></td>
</tr>
<td class=3D"vendor-product">codesupplyco--Uppercase</td>
<td>Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39559" target=3D= "_blank" rel=3D"noopener">CVE-2026-39559</a></td>
</tr>
<td class=3D"vendor-product">collectchat--collectchat</td>
<td>Unauthenticated Cross Site Scripting (XSS) in collectchat <=3D 2.4.9=
versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40765" target=3D= "_blank" rel=3D"noopener">CVE-2026-40765</a></td>
</tr>
<td class=3D"vendor-product">cometd--cometd</td>
<td>CometD is a scalable comet implementation for web messaging. In version=
s 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0=
.0 through 8.0.8, bad clients that always send a fixed batch value when the=
server is using the acknowledgement extension may cause the unacknowledged=
message queue to grow indefinitely, eventually causing an `OutOfMemoryErro= r`. Versions 5.0.23, 6.0.19, 7.0.19, and 8.0.9 patch the issue. As a workar= ound, disable the acknowledgement extension.</td>
<td>2026-06-18</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-53114" target=3D= "_blank" rel=3D"noopener">CVE-2025-53114</a></td>
</tr>
<td class=3D"vendor-product">Comodo--Chromodo Browser</td>
<td>Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path = vulnerability in the ChromodoUpdater service that runs with SYSTEM privileg= es. A local attacker can insert a malicious executable in the service path = and execute arbitrary code with elevated privileges upon service restart or=
system reboot.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20088" target=3D= "_blank" rel=3D"noopener">CVE-2016-20088</a></td>
</tr>
<td class=3D"vendor-product">Comodo--Dragon Browser</td>
<td>Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege e= scalation vulnerability in the DragonUpdater service due to an unquoted ser= vice path running with SYSTEM privileges. A local attacker can insert a mal= icious executable in the service path and execute arbitrary code with eleva= ted privileges upon service restart or system reboot.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20090" target=3D= "_blank" rel=3D"noopener">CVE-2016-20090</a></td>
</tr>
<td class=3D"vendor-product">conda-forge--conda-smithy</td>
<td>conda-smithy is a tool for combining a conda recipe with configurations=
to build using freely hosted CI services into a single repository. Prior t=
o version 3.61.0, a vulnerability in the conda-forge automated webservices = allowed unintended write access to feedstock repositories through GitHub us= ername takeover. The root cause is the use of mutable GitHub usernames as i= dentifiers for repository invitation routing, rather than stable, immutable=
GitHub user IDs. Version 3.61.0 fixes the issue.</td>
<td>2026-06-18</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46699" target=3D= "_blank" rel=3D"noopener">CVE-2026-46699</a></td>
</tr>
<td class=3D"vendor-product">Conekta Group--Conekta Payment Gateway</td> <td>Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= =3D 6.0.0 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49066" target=3D= "_blank" rel=3D"noopener">CVE-2026-49066</a></td>
</tr>
<td class=3D"vendor-product">contest-gallery--Contest Gallery Upload & = Vote Photos, Media, Sell with PayPal & Stripe</td>
<td>The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal=
& Stripe plugin for WordPress is vulnerable to Privilege Escalation in=
all versions up to, and including, 30.0.2 via the `RegistryUserRole` param= eter. This is due to the plugin's admin menu being registered at the `edit_= posts` capability level - granting Contributor-level users access to the pl= ugin's admin pages and a valid `cg_admin` nonce - while the option-saving h= andler in `change-options-and-sizes.php` performs no `current_user_can()` c= apability check beyond `check_admin_referer('cg_admin')`, and the `Registry= UserRole` value is processed only through `sanitize_text_field()` and `html= entities()` without restriction to an allowlist of permitted role names. Th=
is makes it possible for authenticated attackers, with author-level access = and above, to overwrite the plugin's stored `RegistryUserRole` option with = `administrator`, which the `cg_create_wp_user_from_google_user` function th=
en reads back from the `contest_gal1ery_registry_and_login_options` databas=
e table without any allowlist validation and passes directly to `wp_update_= user()`, effectively promoting a newly registered Google sign-in account to=
Administrator.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12165" target=3D= "_blank" rel=3D"noopener">CVE-2026-12165</a></td>
</tr>
<td class=3D"vendor-product">Cotonti--Cotonti</td>
<td>Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-S= ite Request Forgery in the administration rights handler. In system/admin/a= dmin.rights.php, the rights update action ('a=3Dupdate') modifies group acc= ess rights (including via cot_auth_add_group) without calling cot_check_xg(=
) to validate the anti-CSRF token. A remote attacker who lures an authentic= ated administrator into visiting a malicious page can force the browser to = submit a forged request that grants elevated permissions to an attacker-con= trolled group, escalating privileges to administrator. Because Cotonti admi= nistrators can modify templates and configuration, this can be further leve= raged toward remote code execution.</td>
<td>2026-06-18</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55742" target=3D= "_blank" rel=3D"noopener">CVE-2026-55742</a></td>
</tr>
<td class=3D"vendor-product">Cotonti--Cotonti</td>
<td>Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-S= ite Request Forgery in the administration configuration handler. In system/= admin/admin.config.php, the configuration update action ('a=3Dupdate') proc= esses POST data via cot_config_update_options() without calling cot_check_x= g() to validate the anti-CSRF token (the 'x' parameter), unlike other admin=
handlers (e.g. admin.structure.php, admin.cache.php). A remote attacker wh=
o lures an authenticated administrator into visiting a malicious page can f= orce the browser to submit a forged request that modifies arbitrary core, m= odule, or plugin configuration options, which can be leveraged to weaken se= curity or enable further compromise.</td>
<td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55741" target=3D= "_blank" rel=3D"noopener">CVE-2026-55741</a></td>
</tr>
<td class=3D"vendor-product">Cotonti--Cotonti</td>
<td>Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-S= ite Request Forgery in the Personal File Storage (PFS) module. In modules/p= fs/inc/pfs.main.php, the file upload action ('a=3Dupload') processes upload=
ed files without calling cot_check_xg() to validate the anti-CSRF token, ev=
en though sibling actions such as 'delete' (line 272) do. A remote attacker=
who lures an authenticated user into visiting a malicious page can force t=
he browser to submit a forged multipart request that uploads arbitrary file=
s into the victim's PFS storage.</td>
<td>2026-06-18</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55744" target=3D= "_blank" rel=3D"noopener">CVE-2026-55744</a></td>
</tr>
<td class=3D"vendor-product">Cotonti--Cotonti</td>
<td>Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored = Cross-Site Scripting in the Personal File Storage (PFS) module. A folder ti= tle (pff_title) is imported with the 'TXT' filter, which does not strip or = encode HTML (the tag check in cot_import is disabled), so an authenticated = user can store HTML/JavaScript in a folder title. In modules/pfs/inc/pfs.ma= in.php the title is assigned to the template variable PFF_ROW_TITLE without=
htmlspecialchars(), and modules/pfs/tpl/pfs.tpl outputs {PFF_ROW_TITLE} un= escaped. When the folder listing is viewed (including by other users for pu= blic folders), the injected script executes in the victim's browser.</td> <td>2026-06-18</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55746" target=3D= "_blank" rel=3D"noopener">CVE-2026-55746</a></td>
</tr>
<td class=3D"vendor-product">coturn--coturn</td>
<td>Coturn is a free open source implementation of TURN and STUN Server. Ve= rsions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_toke= n_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth ac= cess token (0-65535) is passed directly to memcpy() as the copy length into=
a 256-byte stack buffer (oauth_encrypted_block.nonce[256]) without bounds = checking. The overflow occurs before AES-GCM authentication is verified, th=
e attacker does not need to know the OAuth key or produce a valid AES-GCM t= oken. Up to 735 bytes of attacker-controlled data are written past the buff= er, may corrupt adjacent stack data, including control-flow data depending =
on compiler, ABI, and mitigations. Requires --oauth mode (non-default). Thi=
s may provide a plausible RCE primitive depending on exploit mitigations; b= ecause coturn is widely deployed for WebRTC TURN/STUN and --oauth is common=
ly recommended, impact can be broad. This issue has been fixed in version 4= .10.0.</td>
<td>2026-06-18</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43994" target=3D= "_blank" rel=3D"noopener">CVE-2026-43994</a></td>
</tr>
<td class=3D"vendor-product">Cozmoslabs--Paid Member Subscriptions</td> <td>Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions=
<=3D 2.17.3 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39514" target=3D= "_blank" rel=3D"noopener">CVE-2026-39514</a></td>
</tr>
<td class=3D"vendor-product">Cozmoslabs--Profile Builder Pro</td> <td>Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <=
=3D 3.15.0 versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42385" target=3D= "_blank" rel=3D"noopener">CVE-2026-42385</a></td>
</tr>
<td class=3D"vendor-product">Cozy Vision Technologies Pvt. Ltd.--SMS Alert = Order Notifications</td>
<td>Subscriber Privilege Escalation in SMS Alert Order Notifications <=
=3D 3.9.4 versions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54803" target=3D= "_blank" rel=3D"noopener">CVE-2026-54803</a></td>
</tr>
<td class=3D"vendor-product">Cozy Vision Technologies Pvt. Ltd.--SMS Alert = Order Notifications</td>
<td>Unauthenticated Broken Authentication in SMS Alert Order Notifications = <=3D 3.9.3 versions.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54802" target=3D= "_blank" rel=3D"noopener">CVE-2026-54802</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS (composer package craftcms/cms) versions >=3D 5.5.0 and &l= t;=3D 5.9.13 contain a remote code execution vulnerability in the FieldsCon= troller::actionRenderCardPreview() method, which passes the fieldLayoutConf=
ig POST parameter directly to Fields::createLayout() without calling Compon= ent::cleanseConfig(). An authenticated admin user can inject Yii2 event han= dlers (e.g., 'on init' keys) via the fieldLayoutConfig parameter to execute=
arbitrary PHP code and disclose sensitive information (such as environment=
variables containing database credentials and CRAFT_SECURITY_KEY). The iss=
ue is fixed in version 5.9.14.</td>
<td>2026-06-21</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56382" target=3D= "_blank" rel=3D"noopener">CVE-2026-56382</a></td>
</tr>
<td class=3D"vendor-product">Crawl4AI--Crawl4AI</td>
<td>Crawl4AI before 0.8.7 contains an authentication bypass vulnerability d=
ue to a hardcoded default JWT signing key in the Docker API server. Attacke=
rs who know the default key can forge valid authentication tokens for any u= ser, bypassing authentication and gaining full access to protected function= ality.</td>
<td>2026-06-21</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56265" target=3D= "_blank" rel=3D"noopener">CVE-2026-56265</a></td>
</tr>
<td class=3D"vendor-product">Creative Themes--Blocksy Companion Pro</td> <td>Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 vers= ions.</td>
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39596" target=3D= "_blank" rel=3D"noopener">CVE-2026-39596</a></td>
</tr>
<td class=3D"vendor-product">Creative Themes--Blocksy Companion Pro</td> <td>Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <=
=3D 2.1.37 versions.</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40783" target=3D= "_blank" rel=3D"noopener">CVE-2026-40783</a></td>
</tr>
<td class=3D"vendor-product">CRM Perks--Integration for ActiveCampaign and = Contact Form 7, WPForms, Elementor, Ninja Forms</td>
<td>Unauthenticated PHP Object Injection in Integration for ActiveCampaign = and Contact Form 7, WPForms, Elementor, Ninja Forms <=3D 1.1.1 versions.= </td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9691" target=3D"= _blank" rel=3D"noopener">CVE-2026-9691</a></td>
</tr>
<td class=3D"vendor-product">CRM Perks--Integration for Contact Form 7 and = Constant Contact</td>
<td>Unauthenticated PHP Object Injection in Integration for Contact Form 7 = and Constant Contact <=3D 1.1.6 versions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49106" target=3D= "_blank" rel=3D"noopener">CVE-2026-49106</a></td>
</tr>
<td class=3D"vendor-product">CRM Perks--Integration for Contact Form 7 HubS= pot</td>
<td>Unauthenticated PHP Object Injection in Integration for Contact Form 7 = HubSpot <=3D 1.3.7 versions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49763" target=3D= "_blank" rel=3D"noopener">CVE-2026-49763</a></td>
</tr>
<td class=3D"vendor-product">CRM Perks--Integration for Keap/infusionsoft a=
nd Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms</td> <td>Unauthenticated PHP Object Injection in Integration for Keap/infusionso=
ft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <=3D = 1.2.1 versions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49104" target=3D= "_blank" rel=3D"noopener">CVE-2026-49104</a></td>
</tr>
<td class=3D"vendor-product">CRM Perks--Integration for Mailchimp and Conta=
ct Form 7, WPForms, Elementor, Ninja Forms</td>
<td>Unauthenticated PHP Object Injection in Integration for Mailchimp and C= ontact Form 7, WPForms, Elementor, Ninja Forms <=3D 1.1.8 versions.</td> <td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49765" target=3D= "_blank" rel=3D"noopener">CVE-2026-49765</a></td>
</tr>
<td class=3D"vendor-product">crm perks--Integration for Salesforce and Cont= act Form 7, WPForms, Elementor, Formidable, Ninja Forms</td> <td>Unauthenticated PHP Object Injection in Integration for Salesforce and = Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <=3D 1.4.3 v= ersions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49109" target=3D= "_blank" rel=3D"noopener">CVE-2026-49109</a></td>
</tr>
<td class=3D"vendor-product">CRM Perks--WP Insightly for Contact Form 7, WP= Forms, Elementor, Formidable and Ninja Forms</td>
<td>Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7=
, WPForms, Elementor, Formidable and Ninja Forms <=3D 1.1.4 versions.</t=
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49085" target=3D= "_blank" rel=3D"noopener">CVE-2026-49085</a></td>
</tr>
<td class=3D"vendor-product">CRM Perks--WP Zendesk for Contact Form 7, WPFo= rms, Elementor, Formidable and Ninja Forms</td>
<td>Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, = WPForms, Elementor, Formidable and Ninja Forms <=3D 1.1.4 versions.</td> <td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49105" target=3D= "_blank" rel=3D"noopener">CVE-2026-49105</a></td>
</tr>
<td class=3D"vendor-product">crmperks--Database for Contact Form 7, WPforms=
, Elementor forms</td>
<td>The Database for Contact Form 7, WPforms, Elementor forms plugin for Wo= rdPress is vulnerable to arbitrary file deletion due to insufficient file p= ath validation in the view_page function in all versions up to, and includi= ng, 1.5.1. This makes it possible for unauthenticated attackers to delete a= rbitrary files on the server, which can easily lead to remote code executio=
n when the right file is deleted (such as wp-config.php). Successful exploi= tation requires an administrator to view or edit the poisoned form entry, a=
t which point PHP's bracket parser reshapes the attacker-crafted JSON key t=
o bypass the stored-path isset check and trigger deletion of the traversal-= specified file.</td>
<td>2026-06-20</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9843" target=3D"= _blank" rel=3D"noopener">CVE-2026-9843</a></td>
</tr>
<td class=3D"vendor-product">Crocoblock--JetEngine</td>
<td>The JetEngine plugin for WordPress is vulnerable to SQL injection in al=
l versions up to and including 3.8.10.1. The listing_load_more AJAX handler=
accepts a filtered_query parameter that is intentionally excluded from the=
HMAC query signature check to support front-end filter integration. Howeve=
r, meta_query row values within filtered_query are not sanitized before bei=
ng merged into SQL construction. This makes it possible for unauthenticated=
attackers to perform time-based or boolean blind SQL injection by appendin=
g a malicious meta_query value to a Load More AJAX request captured from an=
y public Listing Grid page.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12360" target=3D= "_blank" rel=3D"noopener">CVE-2026-12360</a></td>
</tr>
<td class=3D"vendor-product">CurlyThemes--Events Schedule - WordPress Event=
s Calendar Plugin</td>
<td>Subscriber SQL Injection in Events Schedule - WordPress Events Calendar=
Plugin <=3D 2.7.2 versions.</td>
<td>2026-06-17</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69135" target=3D= "_blank" rel=3D"noopener">CVE-2025-69135</a></td>
</tr>
<td class=3D"vendor-product">Dassault Systmes--SOLIDWORKS Visualize</td>
<td>A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLI= DWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could a= llow an attacker to write arbitrary files on the server.</td> <td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10094" target=3D= "_blank" rel=3D"noopener">CVE-2026-10094</a></td>
</tr>
<td class=3D"vendor-product">Datalogics--Datalogics Ecommerce Delivery</td> <td>Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery &= lt;=3D 2.6.62 versions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39583" target=3D= "_blank" rel=3D"noopener">CVE-2026-39583</a></td>
</tr>
<td class=3D"vendor-product">David Lingren--Media LIbrary Assistant</td> <td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in David Lingren Media LIbrary Assistant allows=
Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a = through 3.35.</td>
<td>2026-06-18</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56012" target=3D= "_blank" rel=3D"noopener">CVE-2026-56012</a></td>
</tr>
<td class=3D"vendor-product">David Lingren--Media LIbrary Assistant</td> <td>Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant &= lt;=3D 3.35 versions.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54198" target=3D= "_blank" rel=3D"noopener">CVE-2026-54198</a></td>
</tr>
<td class=3D"vendor-product">dbgate--dbgate</td>
<td>DbGate is cross-platform database manager. In versions 7.1.8 and prior,=
the POST /runners/load-reader endpoint in DbGate accepts a functionName pa= rameter that is directly interpolated into a JavaScript code template witho=
ut any sanitization or validation. An authenticated user (with basic access=
, no special permissions required) can inject arbitrary JavaScript code tha=
t executes on the server with full process privileges, bypassing the requir= e=3Dnull sandbox restriction. An authenticated user with basic access (no a= dmin role, no run-shell-script permission required) can: execute arbitrary =
OS commands on the DbGate server with the privileges of the Node.js process=
, read/write any file accessible to the process, pivot to connected databas=
es by reading connection credentials from DbGate's storage, and compromise = the host system - in Docker deployments, this typically means root access w= ithin the container.</td>
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48017" target=3D= "_blank" rel=3D"noopener">CVE-2026-48017</a></td>
</tr>
<td class=3D"vendor-product">deepstreamIO--deepstream.io</td>
<td>deepstream is a server that allows clients and backend services to sync=
data, send messages and make rpcs at scale. Versions prior to 10.0.5 are v= ulnerable to Prototype Pollution. Exploitation can lead to potential privil= ege escalation from any authenticated user with write permission to any rec= ord. This issue has been fixed in version 10.0.5.</td>
<td>2026-06-18</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49252" target=3D= "_blank" rel=3D"noopener">CVE-2026-49252</a></td>
</tr>
<td class=3D"vendor-product">Dell--AIOps</td>
<td>Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default=
Credentials" vulnerability. A low privileged attacker with console access = could potentially exploit this vulnerability to gain Filesystem access. Thi=
s vulnerability only affects fresh installations of Collector versions earl= ier than 1.18.3. Systems that have been upgraded (either manually or automa= tically) to version 1.18.3 or later are not impacted, even if they were ori= ginally installed on an earlier version.</td>
<td>2026-06-17</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32652" target=3D= "_blank" rel=3D"noopener">CVE-2026-32652</a></td>
</tr>
<td class=3D"vendor-product">Dell--Dell EMC VxRail Appliance</td> <td>update_disk_psu_baseline.sh requires password in plain text</td> <td>2026-06-16</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-39575" target=3D= "_blank" rel=3D"noopener">CVE-2024-39575</a></td>
</tr>
<td class=3D"vendor-product">Dell--EMC VxRail Appliance</td>
<td>api-gateway container running with root privilege would allow an attack=
er to escape the container and access host system to perform unintended act= ions.</td>
<td>2026-06-16</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-38487" target=3D= "_blank" rel=3D"noopener">CVE-2024-38487</a></td>
</tr>
<td class=3D"vendor-product">Dell--OpenManage</td>
<td>Dell OpenManage Integration with Microsoft Windows Admin Center contain=
s a Remote Code Execution vulnerability in the gateway plugin. A remote aut= henticated user could potentially exploit this vulnerability to escalate pr= ivileges. The malicious user may gain the ability to run arbitrary code rem= otely. This is a high severity vulnerability so Dell recommends customers t=
o upgrade at the earliest opportunity.</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-24909" target=3D= "_blank" rel=3D"noopener">CVE-2024-24909</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper A= uthentication vulnerability. An unauthenticated attacker with adjacent netw= ork access could potentially exploit this vulnerability, leading to Unautho= rized access.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32804" target=3D= "_blank" rel=3D"noopener">CVE-2026-32804</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) a Missing Aut= hentication for Critical Function vulnerability. An unauthenticated attacke=
r with adjacent network access could potentially exploit this vulnerability=
, leading to Code execution, Denial of service, Information disclosure, Inf= ormation tampering, Remote execution, Script injection, and Unauthorized ac= cess.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35065" target=3D= "_blank" rel=3D"noopener">CVE-2026-35065</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) Version prior to 4.8, contain(s) an = Inclusion of Functionality from Untrusted Control Sphere vulnerability. An = unauthenticated attacker with remote access could potentially exploit this = vulnerability, leading to Information disclosure.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22283" target=3D= "_blank" rel=3D"noopener">CVE-2026-22283</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper A= ccess Control vulnerability. A low privileged attacker with remote access c= ould potentially exploit this vulnerability, leading to denial of service.<=
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35066" target=3D= "_blank" rel=3D"noopener">CVE-2026-35066</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper A= uthentication vulnerability. An unauthenticated attacker with adjacent netw= ork access could potentially exploit this vulnerability, leading to Informa= tion disclosure, Information tampering, and Unauthorized access.</td> <td>2026-06-17</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49502" target=3D= "_blank" rel=3D"noopener">CVE-2026-49502</a></td>
</tr>
<td class=3D"vendor-product">Dell--Server Hardware Manager</td>
<td>Dell Server Hardware Manager, versions prior to 3.2.2, contains an Impr= oper Access Control vulnerability. A low privileged attacker with local acc= ess could potentially exploit this vulnerability, leading to Elevation of p= rivileges.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46461" target=3D= "_blank" rel=3D"noopener">CVE-2026-46461</a></td>
</tr>
<td class=3D"vendor-product">Dev4Press--GD Rating System</td> <td>Unauthenticated SQL Injection in GD Rating System <=3D 3.6.2 version= s.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42639" target=3D= "_blank" rel=3D"noopener">CVE-2026-42639</a></td>
</tr>
<td class=3D"vendor-product">Dimitri Grassi--Salon booking system</td> <td>Unauthenticated Insecure Direct Object References (IDOR) in Salon booki=
ng system <=3D 10.30.24 versions.</td>
<td>2026-06-17</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40768" target=3D= "_blank" rel=3D"noopener">CVE-2026-40768</a></td>
</tr>
<td class=3D"vendor-product">Dimitri Grassi--Salon booking system</td> <td>Unauthenticated Broken Access Control in Salon booking system <=3D 1= 0.30.25 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42666" target=3D= "_blank" rel=3D"noopener">CVE-2026-42666</a></td>
</tr>
<td class=3D"vendor-product">Discuz!--Discuz! X5.0</td>
<td>Discuz! X5.0 releases 20260320 through 20260501 contains an authenticat= ion bypass vulnerability that allows unauthenticated remote attackers to ga=
in unauthorized access to database backup and restore functionality by expl= oiting a shared cryptographic key between UCenter integration and the datab= ase backup API exposed by dbbak.php. Attackers can inject a crafted payload=
through the username parameter during login to abuse the encryption oracle=
in logging_ctl::logging_more(), obtain a legitimately signed token, and us=
e it to bypass authorization for database export and import operations, wit=
h the additional ability to trigger a race condition to impersonate arbitra=
ry users.</td>
<td>2026-06-15</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49952" target=3D= "_blank" rel=3D"noopener">CVE-2026-49952</a></td>
</tr>
<td class=3D"vendor-product">Discuz!--Discuz! X5.0</td>
<td>Discuz! X5.0 releases 20260320 through 20260610 contain a local file in= clusion vulnerability that allows authenticated administrators to execute a= rbitrary code by importing a specially crafted plugin configuration contain= ing path traversal sequences in the directory attribute. Attackers can trig= ger an exception during plugin installation to bypass sanitization routines=
, causing malicious paths to be stored unsanitized and subsequently passed =
to include(), which combined with file upload functionality escalates to ar= bitrary code execution in the context of the web server user.</td> <td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49954" target=3D= "_blank" rel=3D"noopener">CVE-2026-49954</a></td>
</tr>
<td class=3D"vendor-product">Dokan, Inc.--Dokan</td>
<td>Customer Privilege Escalation in Dokan <=3D 5.0.2 versions.</td> <td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49780" target=3D= "_blank" rel=3D"noopener">CVE-2026-49780</a></td>
</tr>
<td class=3D"vendor-product">doobidoo--mcp-memory-service</td> <td>mcp-memory-service is a semantic memory layer for AI applications. Prio=
r to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires onl=
y OAuth `read` scope for all requests, then dispatches `tools/call` directl=
y to handlers that include mutating tools. A read-only OAuth client can cal=
l `store_memory` and `delete_memory` through MCP even though the correspond= ing REST endpoints require `write` scope. Version 10.65.3 patches the issue= .</td>
<td>2026-06-19</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49291" target=3D= "_blank" rel=3D"noopener">CVE-2026-49291</a></td>
</tr>
<td class=3D"vendor-product">DVDFab--Virtual Drive</td>
<td>A security vulnerability has been detected in DVDFab Virtual Drive 2.0.= 0.5. Impacted is an unknown function in the library dvdfabio.sys of the com= ponent Signed Kernel Driver. The manipulation leads to improper privilege m= anagement. An attack has to be approached locally. The exploit has been dis= closed publicly and may be used. The vendor was contacted early about this = disclosure but did not respond in any way.</td>
<td>2026-06-15</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12217" target=3D= "_blank" rel=3D"noopener">CVE-2026-12217</a></td>
</tr>
<td class=3D"vendor-product">dwbooster--Booking Calendar Contact</td> <td>WordPress appointment-booking-calendar 1.1.24 contains multiple privile=
ge escalation vulnerabilities that allow unauthenticated attackers to modif=
y calendar settings and inject persistent cross-site scripting payloads thr= ough the admin.php page parameters. Attackers can inject malicious JavaScri=
pt into the 'ict' and 'ics' options or the calendar 'name' parameter via GE=
T requests to execute arbitrary scripts when the calendar is displayed or a= ccessed in the administration interface.</td>
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20084" target=3D= "_blank" rel=3D"noopener">CVE-2016-20084</a></td>
</tr>
<td class=3D"vendor-product">dwbooster--Booking Calendar Contact Form</td> <td>WordPress Booking Calendar Contact Form version 1.0.23 contains an unau= thenticated blind SQL injection vulnerability that allows remote attackers =
to execute arbitrary SQL queries by injecting malicious code through the 'i=
d' parameter. Attackers can send requests to the admin-ajax.php endpoint wi=
th the action parameter set to 'dex_bccf_calendar_ajaxevent' and supply cra= fted SQL commands in the 'id' parameter to extract sensitive database infor= mation.</td>
<td>2026-06-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20068" target=3D= "_blank" rel=3D"noopener">CVE-2016-20068</a></td>
</tr>
<td class=3D"vendor-product">dwbooster--Booking Calendar Contact Form</td> <td>WordPress Booking Calendar Contact Form 1.0.23 contains an unauthentica= ted blind SQL injection vulnerability in the shortcode function that fails =
to sanitize the calendar parameter before using it in database queries. Att= ackers can inject SQL commands through the calendar shortcode parameter to = execute arbitrary SQL queries and extract sensitive database information.</=
<td>2026-06-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20069" target=3D= "_blank" rel=3D"noopener">CVE-2016-20069</a></td>
</tr>
<td class=3D"vendor-product">dwbooster--CP Polls</td>
<td>WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vul= nerability that allows attackers to inject malicious scripts through unsani= tized file upload functionality. Attackers can upload files containing scri=
pt payloads with event handlers like onerror attributes to execute arbitrar=
y JavaScript in the browsers of users viewing the affected content.</td> <td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20066" target=3D= "_blank" rel=3D"noopener">CVE-2016-20066</a></td>
</tr>
<td class=3D"vendor-product">Dylan Kuhn--Geo Mashup</td>
<td>Subscriber SQL Injection in Geo Mashup <=3D 1.13.19 versions.</td> <td>2026-06-17</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48967" target=3D= "_blank" rel=3D"noopener">CVE-2026-48967</a></td>
</tr>
<td class=3D"vendor-product">e107inc--e107</td>
<td>e107 is a content management system (CMS). Versions 2.3.5 and earlier c= ontain a command injection vulnerability in the ImageMagick resize destinat= ion path. In resize_image(), the source path is escaped with escapeshellarg= (), but the destination path is inserted inside raw double quotes in the co= nvert command; in the submit-news upload flow, that destination filename in= cludes the first six characters of user-controlled news title input. Becaus=
e the title filter removes literal spaces but not tab characters, and shell=
expansions such as $(...) and backticks can survive into the quoted destin= ation argument, /bin/sh -c may evaluate attacker-controlled input. Exploita= tion is possible only when all of the following non-default settings are en= abled: resize_method=3DImageMagick, subnews_attach=3D1, upload_enabled=3D1,=
subnews_resize is numeric between 30 and 5000, and the attacker is a non-a= dmin in classes permitted by both subnews_class and upload_class. This issu=
e has been fixed in version 2.3.6.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48997" target=3D= "_blank" rel=3D"noopener">CVE-2026-48997</a></td>
</tr>
<td class=3D"vendor-product">e4jvikwp--VikRentCar</td>
<td>Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar = <=3D 1.4.5 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52699" target=3D= "_blank" rel=3D"noopener">CVE-2026-52699</a></td>
</tr>
<td class=3D"vendor-product">EaseUS--Partition Master</td>
<td>A vulnerability was identified in EaseUS Partition Master up to 14.5. T=
he affected element is an unknown function in the library epmntdrv.sys of t=
he component Kernel Driver. The manipulation leads to improper access contr= ols. The attack needs to be performed locally. The exploit is publicly avai= lable and might be used. You should upgrade the affected component. The ven= dor explains: "We have confirmed that this issue was present only in older = versions of the product. Our product has since been updated, and the issue = has been resolved in the latest version, so it no longer exists."</td> <td>2026-06-21</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12781" target=3D= "_blank" rel=3D"noopener">CVE-2026-12781</a></td>
</tr>
<td class=3D"vendor-product">EaseUS--Partition Master</td>
<td>A security flaw has been discovered in EaseUS Partition Master up to 14= .5. The impacted element is an unknown function in the library EUEDKEPM.sys=
of the component Kernel Driver. The manipulation results in improper acces=
s controls. The attack requires a local approach. The exploit has been rele= ased to the public and may be used for attacks. The affected component shou=
ld be upgraded. The vendor explains: "We have confirmed that this issue was=
present only in older versions of the product. Our product has since been = updated, and the issue has been resolved in the latest version, so it no lo= nger exists."</td>
<td>2026-06-21</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12782" target=3D= "_blank" rel=3D"noopener">CVE-2026-12782</a></td>
</tr>
<td class=3D"vendor-product">Easy Appointments--Easy Appointments</td> <td>Unauthenticated Broken Access Control in Easy Appointments <=3D 3.12= .21 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39513" target=3D= "_blank" rel=3D"noopener">CVE-2026-39513</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse ThreadX - NetX Duo= </td>
<td>The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactor=
s error handling in the HTTP server PUT process to use a shared cleanup lab= el, but this unified cleanup path unconditionally calls=C2=A0fx_file_close(= )=C2=A0even when the file was never successfully opened. Multiple error bra= nches jump to the shared cleanup label before any file open operation has o= ccurred, causing=C2=A0fx_file_close()=C2=A0to operate on an uninitialized f= ile handle, leading to undefined behavior, double-close issues, or memory c= orruption.</td>
<td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11576" target=3D= "_blank" rel=3D"noopener">CVE-2026-11576</a></td>
</tr>
<td class=3D"vendor-product">Edgar Rojas--WooCommerce PDF Invoice Builder</=
<td>Improper Control of Generation of Code ('Code Injection') vulnerability=
in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusio=
n. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0= .8.</td>
<td>2026-06-15</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52704" target=3D= "_blank" rel=3D"noopener">CVE-2026-52704</a></td>
</tr>
<td class=3D"vendor-product">Edge-Themes--Alloggio - Hotel Booking</td> <td>Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <=
=3D 2.1.2 versions.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39539" target=3D= "_blank" rel=3D"noopener">CVE-2026-39539</a></td>
</tr>
<td class=3D"vendor-product">Edge-Themes--Behold</td>
<td>Unauthenticated PHP Object Injection in Behold <=3D 1.5 versions.</t=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40760" target=3D= "_blank" rel=3D"noopener">CVE-2026-40760</a></td>
</tr>
<td class=3D"vendor-product">Edge-Themes--Eldon</td>
<td>Unauthenticated PHP Object Injection in Eldon <=3D 1.4.1 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40738" target=3D= "_blank" rel=3D"noopener">CVE-2026-40738</a></td>
</tr>
<td class=3D"vendor-product">Edge-Themes--Laurits</td>
<td>Unauthenticated PHP Object Injection in Laurits <=3D 1.5.1 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40736" target=3D= "_blank" rel=3D"noopener">CVE-2026-40736</a></td>
</tr>
<td class=3D"vendor-product">Edge-Themes--Reina</td>
<td>Unauthenticated PHP Object Injection in Reina <=3D 2.1 versions.</td=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40735" target=3D= "_blank" rel=3D"noopener">CVE-2026-40735</a></td>
</tr>
<td class=3D"vendor-product">Edge-Themes--Valeska</td>
<td>Unauthenticated PHP Object Injection in Valeska <=3D 1.2.2 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40761" target=3D= "_blank" rel=3D"noopener">CVE-2026-40761</a></td>
</tr>
<td class=3D"vendor-product">Edimax--BR-6478AC V2</td>
<td>A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacte=
d element is the function formWlSiteSurvey of the file /goform/formWlSiteSu= rvey of the component POST Request Handler. The manipulation of the argumen=
t selSSID leads to buffer overflow. It is possible to initiate the attack r= emotely. The exploit has been disclosed to the public and may be used. The = vendor was contacted early about this disclosure but did not respond in any=
way.</td>
<td>2026-06-21</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12806" target=3D= "_blank" rel=3D"noopener">CVE-2026-12806</a></td>
</tr>
<td class=3D"vendor-product">eemitch--Simple File List</td>
<td>The Simple File List plugin for WordPress is vulnerable to arbitrary fi=
le deletion due to insufficient file path validation in the eeSFL_DeleteFil=
e function in all versions up to, and including, 6.3.7. This makes it possi= ble for unauthenticated attackers to delete arbitrary files on the server, = which can easily lead to remote code execution when the right file is delet=
ed (such as wp-config.php). The simplefilelist_edit_job AJAX action is regi= stered via wp_ajax_nopriv_, making it accessible without authentication, an=
d the is_admin() guard that would otherwise restrict access is bypassed bec= ause is_admin() always returns true for requests to the admin-ajax.php endp= oint.</td>
<td>2026-06-20</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11911" target=3D= "_blank" rel=3D"noopener">CVE-2026-11911</a></td>
</tr>
<td class=3D"vendor-product">eemitch--Simple File List</td>
<td>The Simple File List plugin for WordPress is vulnerable to arbitrary fi=
le modification due to insufficient authorization checks in all versions up=
to, and including, 6.3.7. This makes it possible for unauthenticated attac= kers to delete and modify files on the serve. This vulnerability is exploit= able even when the administrator has not enabled the AllowFrontManage setti= ng, because the is_admin() check unconditionally short-circuits the guard b= efore that setting is evaluated.</td>
<td>2026-06-20</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11912" target=3D= "_blank" rel=3D"noopener">CVE-2026-11912</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Aperitif</td>
<td>Unauthenticated Local File Inclusion in Aperitif <=3D 1.5 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39549" target=3D= "_blank" rel=3D"noopener">CVE-2026-39549</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Fidalgo</td>
<td>Unauthenticated PHP Object Injection in Fidalgo <=3D 1.2.2 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39554" target=3D= "_blank" rel=3D"noopener">CVE-2026-39554</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Konsept</td>
<td>Unauthenticated PHP Object Injection in Konsept <=3D 1.9 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39556" target=3D= "_blank" rel=3D"noopener">CVE-2026-39556</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Lonie</td>
<td>Unauthenticated PHP Object Injection in L=C3=83=C2=A9onie <=3D 1.2.1=
versions.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40758" target=3D= "_blank" rel=3D"noopener">CVE-2026-40758</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Malm</td>
<td>Unauthenticated Local File Inclusion in Malm=C3=83=C2=B6 <=3D 2.2 ve= rsions.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39558" target=3D= "_blank" rel=3D"noopener">CVE-2026-39558</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Mr. SEO</td>
<td>Unauthenticated Local File Inclusion in Mr. SEO <=3D 2.0 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39568" target=3D= "_blank" rel=3D"noopener">CVE-2026-39568</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--NeoBeat</td>
<td>Unauthenticated PHP Object Injection in NeoBeat <=3D 1.7 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39557" target=3D= "_blank" rel=3D"noopener">CVE-2026-39557</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Playroom</td>
<td>Unauthenticated PHP Object Injection in Playroom <=3D 1.4.1 versions= .</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39577" target=3D= "_blank" rel=3D"noopener">CVE-2026-39577</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Roisin</td>
<td>Unauthenticated PHP Object Injection in Roisin <=3D 1.4 versions.</t=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40754" target=3D= "_blank" rel=3D"noopener">CVE-2026-40754</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--SingleMalt</td>
<td>Unauthenticated PHP Object Injection in SingleMalt <=3D 1.5 versions= .</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39576" target=3D= "_blank" rel=3D"noopener">CVE-2026-39576</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Solene</td>
<td>Unauthenticated Local File Inclusion in Solene <=3D 3.4 versions.</t=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39522" target=3D= "_blank" rel=3D"noopener">CVE-2026-39522</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Solene Core</td> <td>Unauthenticated Local File Inclusion in Solene Core <=3D 2.3.2 versi= ons.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39523" target=3D= "_blank" rel=3D"noopener">CVE-2026-39523</a></td>
</tr>
<td class=3D"vendor-product">Elated-Themes--Valiance</td>
<td>Unauthenticated PHP Object Injection in Valiance <=3D 1.2 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39578" target=3D= "_blank" rel=3D"noopener">CVE-2026-39578</a></td>
</tr>
<td class=3D"vendor-product">ELEXtensions--ELEX WordPress HelpDesk & Cu= stomer Ticketing System</td>
<td>Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Tick= eting System <=3D 3.3.6 versions.</td>
<td>2026-06-15</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48964" target=3D= "_blank" rel=3D"noopener">CVE-2026-48964</a></td>
</tr>
<td class=3D"vendor-product">Eli Scheetz--Anti-Malware Security and Brute-F= orce Firewall</td>
<td>Contributor PHP Object Injection in Anti-Malware Security and Brute-For=
ce Firewall <=3D 4.23.87 versions.</td>
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39478" target=3D= "_blank" rel=3D"noopener">CVE-2026-39478</a></td>
</tr>
<td class=3D"vendor-product">Eli--Eli's WordCents adSense Widget with Analy= tics</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents = adSense Widget with Analytics <=3D 1.3.03.27 versions.</td> <td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-68872" target=3D= "_blank" rel=3D"noopener">CVE-2025-68872</a></td>
</tr>
<td class=3D"vendor-product">Emraan Cheema--ListingPro</td>
<td>Unauthenticated SQL Injection in ListingPro <=3D 2.9.10 versions.</t=
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39438" target=3D= "_blank" rel=3D"noopener">CVE-2026-39438</a></td>
</tr>
<td class=3D"vendor-product">EMV--Creatify</td>
<td>Deserialization of Untrusted Data vulnerability in EMV Creatify allows = Object Injection. This issue affects Creatify: from n/a through 1.5.</td> <td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60236" target=3D= "_blank" rel=3D"noopener">CVE-2025-60236</a></td>
</tr>
<td class=3D"vendor-product">EMV--JobBank</td>
<td>Missing Authorization vulnerability in EMV JobBank allows Exploiting In= correctly Configured Access Control Security Levels. This issue affects Job= Bank: from n/a through 1.2.3.</td>
<td>2026-06-17</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69189" target=3D= "_blank" rel=3D"noopener">CVE-2025-69189</a></td>
</tr>
<td class=3D"vendor-product">EMV--JobCareer</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') vulnerability in EMV JobCareer allows Path Traversal. This issue af= fects JobCareer: from n/a through 7.3.</td>
<td>2026-06-17</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69128" target=3D= "_blank" rel=3D"noopener">CVE-2025-69128</a></td>
</tr>
<td class=3D"vendor-product">EMV--The Hospital</td>
<td>Deserialization of Untrusted Data vulnerability in EMV The Hospital nrg= hospital allows Object Injection. This issue affects The Hospital: from n/a=
through 1.8.1.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60231" target=3D= "_blank" rel=3D"noopener">CVE-2025-60231</a></td>
</tr>
<td class=3D"vendor-product">envoyproxy--envoy</td>
<td>Envoy is an open source edge and service proxy designed for cloud-nativ=
e applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vu= lnerability in Envoy's HTTP/2 downstream request processing allows an unaut= henticated remote client to trigger excessive memory consumption, potential=
ly resulting in OOM termination of the Envoy process and denial of service.=
The issue arises from the combination of two behaviors. First, cookie head=
er bytes are not fully accounted for during request header size validation =
in Envoy. Second, HPACK header block limits in oghttp2/quiche are enforced =
on encoded bytes without a corresponding limit on total decoded header size=
. Together, these behaviors allow a malicious client to cause large decoded=
header allocations while bypassing the intended request header size protec= tions. Versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1 contain a fix. No compl= ete workaround is known short of applying a fix. Possible temporary mitigat= ions include disabling downstream HTTP/2 where operationally feasible; enfo= rcing stricter request header and cookie limits before traffic reaches Envo=
y; and monitoring Envoy memory usage for abnormal growth under HTTP/2 traff= ic.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47774" target=3D= "_blank" rel=3D"noopener">CVE-2026-47774</a></td>
</tr>
<td class=3D"vendor-product">error311--FileRise</td>
<td>FileRise before 3.16.0 is vulnerable to path traversal in the shared-fo= lder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arb= itrary file write and administrator account takeover. The upload filename i=
s validated by FolderController with basename() and REGEX_FILE_NAME, which = permit URL-encoded sequences (the regex blocks / and \ but not %). The raw = filename is then passed to UploadModel::handleUpload, where it is reconstru= cted as trim(urldecode(basename($fileName))), re-introducing path separator=
s after validation (e.g. ..%2fusers%2fusers.txt becomes ../users/users.txt)=
. UploadNamePolicy::isAllowedForWrite() applies basename() internally and t= herefore only evaluates the final component (users.txt), allowing the trave= rsal sequence to pass the extension policy. The destination path is then us=
ed directly in move_uploaded_file() with no realpath containment check, all= owing a write outside the intended upload directory. An attacker who posses= ses a valid, non-expired, upload-enabled shared-folder link/token (which ar=
e designed to be shared publicly) can overwrite users/users.txt to create a=
n administrator account, resulting in unauthenticated admin takeover and, d= epending on configuration, remote code execution. Exploitation requires pos= session of a valid, non-expired, upload-enabled shared-folder link/token. T= his issue is fixed in 3.16.0, which URL-decodes before validation and rejec=
ts any path separators in the upload filename.</td>
<td>2026-06-19</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54414" target=3D= "_blank" rel=3D"noopener">CVE-2026-54414</a></td>
</tr>
<td class=3D"vendor-product">Etoilewebdesign--Ultimate Product Catalog</td> <td>WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upl= oad vulnerability that allows authenticated users with contributor, editor,=
author, or administrator roles to upload malicious files by exploiting the=
custom fields functionality. Attackers can upload PHP shells through the P= roducts tab custom file field and access them via the upcp-product-file-upl= oads directory to execute arbitrary code on the server.</td> <td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20075" target=3D= "_blank" rel=3D"noopener">CVE-2016-20075</a></td>
</tr>
<td class=3D"vendor-product">EventPrime--EventPrime</td>
<td>Unauthenticated PHP Object Injection in EventPrime <=3D 4.3.2.1 vers= ions.</td>
<td>2026-06-15</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42687" target=3D= "_blank" rel=3D"noopener">CVE-2026-42687</a></td>
</tr>
<td class=3D"vendor-product">EventPrime--EventPrime</td>
<td>Subscriber Insecure Direct Object References (IDOR) in EventPrime <=
=3D 4.3.0.0 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39518" target=3D= "_blank" rel=3D"noopener">CVE-2026-39518</a></td>
</tr>
<td class=3D"vendor-product">EventPrime--EventPrime</td>
<td>Subscriber Cross Site Scripting (XSS) in EventPrime <=3D 4.3.2.1 ver= sions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42686" target=3D= "_blank" rel=3D"noopener">CVE-2026-42686</a></td>
</tr>
<td class=3D"vendor-product">ExpressTech--Quiz And Survey Master</td> <td>Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master &l= t;=3D 11.0.0 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40787" target=3D= "_blank" rel=3D"noopener">CVE-2026-40787</a></td>
</tr>
<td class=3D"vendor-product">ExpressTech--Quiz And Survey Master</td> <td>Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master &l= t;=3D 11.1.2 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48867" target=3D= "_blank" rel=3D"noopener">CVE-2026-48867</a></td>
</tr>
<td class=3D"vendor-product">Extendons--WordPress & WooCommerce Scraper=
Plugin, Import Data from Any Site</td>
<td>Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Sc= raper Plugin, Import Data from Any Site <=3D 1.0.7 versions.</td> <td>2026-06-17</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69129" target=3D= "_blank" rel=3D"noopener">CVE-2025-69129</a></td>
</tr>
<td class=3D"vendor-product">extendons--WordPress & WooCommerce Scraper=
Plugin, Import Data from Any Site</td>
<td>Unauthenticated Arbitrary File Download in WordPress & WooCommerce = Scraper Plugin, Import Data from Any Site <=3D 1.0.7 versions.</td> <td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69131" target=3D= "_blank" rel=3D"noopener">CVE-2025-69131</a></td>
</tr>
<td class=3D"vendor-product">Extensions--Joomla Payage</td>
<td>Joomla Payage 2.05 contains an SQL injection vulnerability that allows = unauthenticated attackers to manipulate database queries by injecting SQL c= ode through the aid parameter. Attackers can send GET requests to index.php=
with malicious aid values in the make_payment task to extract sensitive da= tabase information using boolean-based blind or time-based blind techniques= .</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20279" target=3D= "_blank" rel=3D"noopener">CVE-2017-20279</a></td>
</tr>
<td class=3D"vendor-product">Extro--RPC</td>
<td>Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL inject= ion vulnerability that allows unauthenticated attackers to execute arbitrar=
y SQL queries by injecting malicious code through the id parameter. Attacke=
rs can send GET requests to index.php with option=3Dcom_pofos&view=3Dpo= fo&id=3D[SQL] to extract sensitive database information.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20258" target=3D= "_blank" rel=3D"noopener">CVE-2017-20258</a></td>
</tr>
<td class=3D"vendor-product">Eyal Fitoussi--GEO my WordPress</td> <td>Unauthenticated SQL Injection in GEO my WordPress <=3D 4.5.5 version= s.</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52715" target=3D= "_blank" rel=3D"noopener">CVE-2026-52715</a></td>
</tr>
<td class=3D"vendor-product">EyeCix Technologies--JobSearch</td> <td>Unauthenticated Broken Access Control in JobSearch <=3D 3.2.7 versio= ns.</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49057" target=3D= "_blank" rel=3D"noopener">CVE-2026-49057</a></td>
</tr>
<td class=3D"vendor-product">eyecix--JobSearch</td>
<td>Unauthenticated SQL Injection in JobSearch <=3D 3.2.9 versions.</td> <td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54186" target=3D= "_blank" rel=3D"noopener">CVE-2026-54186</a></td>
</tr>
<td class=3D"vendor-product">Ezbsystems--UltraISO Premium Edition</td>
<td>A vulnerability has been found in Ezbsystems UltraISO Premium Edition u=
p to 9.76. Affected by this issue is some unknown functionality in the libr= ary bootpt64.sys of the component Kernel Driver. The manipulation leads to = improper access controls. Local access is required to approach this attack.=
The exploit has been disclosed to the public and may be used. The vendor w=
as contacted early about this disclosure but did not respond in any way.</t=
<td>2026-06-21</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12786" target=3D= "_blank" rel=3D"noopener">CVE-2026-12786</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Gateway Fabric</td>
<td>When NGINX Plus is configured as the data plane for NGINX Gateway Fabri=
c, an injection vulnerability exists in the NGINX configuration generator c= omponent of NGINX Gateway Fabric. User-supplied string values from the Ngin= xProxy=C2=A0Custom Resource Definition serverTokens=C2=A0field and the Auth= enticationFilter=C2=A0Custom Resource Definition extraAuthArgs=C2=A0field a=
re rendered directly into NGINX configuration templates without sanitizatio=
n or escaping. An authenticated attacker with permission to create or modif=
y these Custom Resource Definitions may craft values that inject arbitrary = NGINX configuration directives. This is a control plane issue; there is no = data plane exposure from the vulnerability trigger itself. Note: Software v= ersions which have reached End of Technical Support (EoTS) are not evaluate= d.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11311" target=3D= "_blank" rel=3D"noopener">CVE-2026-11311</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Gateway Fabric</td>
<td>When NGINX Plus or NGINX Open Source is configured as the data plane fo=
r NGINX Gateway Fabric, an injection vulnerability exists in the NGINX conf= iguration generator component of NGINX Gateway Fabric. User-supplied string=
values from the NginxProxy=C2=A0Custom Resource Definition (CRD) access lo=
g format setting are rendered directly into NGINX configuration templates w= ithout sanitization or escaping. An authenticated attacker with permission =
to create or modify these CRDs may craft values that inject arbitrary NGINX=
configuration directives. This is a control plane issue; there is no data = plane exposure from the vulnerability trigger itself. Note: Software versio=
ns which have reached End of Technical Support (EoTS) are not evaluated.</t=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50107" target=3D= "_blank" rel=3D"noopener">CVE-2026-50107</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Open Source</td>
<td>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_p= roxy_v2_module=C2=A0and ngx_http_grpc_module=C2=A0modules. This vulnerabili=
ty exists when the proxy_http_version to 2=C2=A0or grpc_pass=C2=A0directive=
s are used to proxy HTTP/2 traffic, the ignore_invalid_headers=C2=A0directi=
ve is set to off, and the large_client_header_buffers=C2=A0directive size i=
s larger than 2 megabytes. A remote, unauthenticated attacker, along with c= onditions beyond their control, could send large headers while creating an = upstream request. This may cause a heap-based buffer overflow in the NGINX = worker process leading to a restart. Additionally, attackers can execute co=
de on systems with Address Space Layout Randomization (ASLR) disabled or wh=
en the attacker can bypass ASLR. Note: Software versions which have reached=
End of Technical Support (EoTS) are not evaluated.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42055" target=3D= "_blank" rel=3D"noopener">CVE-2026-42055</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Open Source</td>
<td>NGINX Open Source has a vulnerability in the ngx_http_v3_module=C2=A0mo= dule. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a=
remote unauthenticated attacker along with conditions beyond their control=
can use a specially crafted HTTP/3 session to reopen a QPACK encoder strea=
m. This may cause a Use-after-Free in the NGINX worker process leading to a=
restart. Additionally, attackers can execute code on systems with Address = Space Layout Randomization (ASLR) disabled or when the attacker can bypass = ASLR. Note: Software versions which have reached End of Technical Support (= EoTS) are not evaluated.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42530" target=3D= "_blank" rel=3D"noopener">CVE-2026-42530</a></td>
</tr>
<td class=3D"vendor-product">Faboba--Ultimate Property Listing</td>
<td>Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulner= ability that allows unauthenticated attackers to execute arbitrary SQL quer= ies by injecting malicious code through the sf_selectuser_id parameter. Att= ackers can send GET requests to index.php with the option=3Dcom_upl and vie= w=3Dpropertylisting parameters to extract sensitive database information in= cluding table names and column structures.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20272" target=3D= "_blank" rel=3D"noopener">CVE-2017-20272</a></td>
</tr>
<td class=3D"vendor-product">FFmpeg--FFmpeg</td>
<td>An out-of-bounds write vulnerability in FFmpeg's libavcodec library, sp= ecifically in the MagicYUV decoder, allows denial-of-service and, in some c= ases, can be exploited for remote code execution. This vulnerability is ass= ociated with the file libavcodec/magicyuv.C. This issue affects FFmpeg befo=
re version 8.1.2.</td>
<td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8461" target=3D"= _blank" rel=3D"noopener">CVE-2026-8461</a></td>
</tr>
<td class=3D"vendor-product">fgmacedo--python-statemachine</td>
<td>Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code = execution vulnerability that allows attackers to execute arbitrary code by = supplying malicious SCXML documents containing crafted `<data expr=3D"..= .">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-c= ontrolled expression strings through a call chain ending in Python's built-=
in eval() without sandboxing, enabling arbitrary code execution in the cont= ext of the hosting process.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47103" target=3D= "_blank" rel=3D"noopener">CVE-2026-47103</a></td>
</tr>
<td class=3D"vendor-product">Filipe Nasc--RD Station</td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability=
in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects=
RD Station: from n/a through 5.6.0.</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49774" target=3D= "_blank" rel=3D"noopener">CVE-2026-49774</a></td>
</tr>
<td class=3D"vendor-product">Flipper Code WordPress Development Company--WP=
Maps</td>
<td>Unauthenticated SQL Injection in WP Maps <=3D 4.9.1 versions.</td> <td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39492" target=3D= "_blank" rel=3D"noopener">CVE-2026-39492</a></td>
</tr>
<td class=3D"vendor-product">Flowise--Flowise</td>
<td>Flowise before 2.1.4 allows configuration to be injected into the Chain= flow during execution via the overrideConfig option, supported in both the = frontend web integration and the backend Prediction API. Because this featu=
re is enabled by default with no allow-list of permitted variables and reli=
es on vm2 for sandboxing, an attacker can abuse it to achieve remote code e= xecution and sandbox escape, denial of service by crashing the server, serv= er-side request forgery, prompt injection, and server variable and data exf= iltration. These issues are self-targeted and do not persist to other users= .</td>
<td>2026-06-20</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-58351" target=3D= "_blank" rel=3D"noopener">CVE-2024-58351</a></td>
</tr>
<td class=3D"vendor-product">Focalpointx--FocalPoint Pro / Free</td> <td>Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection v= ulnerability that allows unauthenticated attackers to execute arbitrary SQL=
queries by injecting malicious code through the id parameter. Attackers ca=
n send GET requests to index.php with option=3Dcom_focalpoint, view=3Dlocat= ion, and a crafted id parameter containing SQL commands to extract sensitiv=
e database information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20263" target=3D= "_blank" rel=3D"noopener">CVE-2017-20263</a></td>
</tr>
<td class=3D"vendor-product">forem--forem</td>
<td>Forem is open source software for building communities. Prior to commit=
a2ab6d4, a maliciously crafted email address could allow an attacker to by= pass domain allowlist or denylist restrictions and gain access to invite-on=
ly forem deployments. The issue is patched as of `a2ab6d4`. As a workaround=
, some SMTP servers and email delivery providers may drop or refuse to send=
maliciously crafted email addresses.</td>
<td>2026-06-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48780" target=3D= "_blank" rel=3D"noopener">CVE-2026-48780</a></td>
</tr>
<td class=3D"vendor-product">Fortra--Core Privileged Access Manager (BoKS)<=
<td>Fortra's=C2=A0 Core Privileged Access Manager (BoKS)=C2=A0contains an O=
S command injection vulnerability in the boks_autoregisterd service. A remo=
te attacker with network access to the service may be able to cause command=
s to be executed with the privileges of the service during the autoregistra= tion processing.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9862" target=3D"= _blank" rel=3D"noopener">CVE-2026-9862</a></td>
</tr>
<td class=3D"vendor-product">Fortra--Core Privileged Access Manager (BoKS)<=
<td>Fortra BoKS Manager contains an OS command injection vulnerability in t=
he client upgrade and patch tooling for legacy tar-based client installatio= ns. A malicious or compromised legacy tar-installed client selected for upg= rade or patching may be able to cause commands to be executed on the BoKS M= aster during client version handling.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9863" target=3D"= _blank" rel=3D"noopener">CVE-2026-9863</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit AI</td>
<td>When the application executes the JavaScript script embedded in the PDF=
within the sandbox, it fails to intercept some dangerous interfaces, which=
allows remote scripts to be loaded, resulting in arbitrary code execution.= </td>
<td>2026-06-15</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12057" target=3D= "_blank" rel=3D"noopener">CVE-2026-12057</a></td>
</tr>
<td class=3D"vendor-product">fs-code--Booknetic</td>
<td>Unauthenticated Broken Authentication in Booknetic <=3D 4.8.5 versio= ns.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25439" target=3D= "_blank" rel=3D"noopener">CVE-2026-25439</a></td>
</tr>
<td class=3D"vendor-product">FunnelKit--Funnel Builder by FunnelKit</td> <td>Unauthenticated SQL Injection in Funnel Builder by FunnelKit <=3D 3.= 15.0.1 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42381" target=3D= "_blank" rel=3D"noopener">CVE-2026-42381</a></td>
</tr>
<td class=3D"vendor-product">FunnelKit--Funnel Builder by FunnelKit</td> <td>Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelK=
it <=3D 3.15.0.2 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48966" target=3D= "_blank" rel=3D"noopener">CVE-2026-48966</a></td>
</tr>
<td class=3D"vendor-product">Gegabyte--My Projects</td>
<td>Joomla! Component My Projects 2.0 contains an SQL injection vulnerabili=
ty that allows unauthenticated attackers to execute arbitrary SQL queries b=
y injecting malicious code through the VerAyari parameter. Attackers can cr= aft requests to the component endpoint with SQL injection payloads to extra=
ct sensitive database information including credentials and system data.</t=
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20253" target=3D= "_blank" rel=3D"noopener">CVE-2017-20253</a></td>
</tr>
<td class=3D"vendor-product">Gegabyte--User Bench</td>
<td>Joomla! Component User Bench 1.0 contains an SQL injection vulnerabilit=
y that allows unauthenticated attackers to execute arbitrary SQL queries by=
injecting malicious code through the userid parameter. Attackers can send = GET requests to index.php with the option=3Dcom_userbench&view=3Ddetail= &userid parameter containing SQL injection payloads to extract sensitiv=
e database information including credentials and configuration data.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20254" target=3D= "_blank" rel=3D"noopener">CVE-2017-20254</a></td>
</tr>
<td class=3D"vendor-product">geoserver--org.geoserver.extension:gs-db2</td> <td>GeoServer is an open source server that allows users to share and edit = geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Ext= ension, an administrator can perform a JNDI attack through specially crafte=
d DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fi= xes the issue.</td>
<td>2026-06-18</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27511" target=3D= "_blank" rel=3D"noopener">CVE-2025-27511</a></td>
</tr>
<td class=3D"vendor-product">geoserver--org.geoserver.web:gs-web-app</td> <td>GeoServer is an open source server that allows users to share and edit = geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exist=
s that allows an authenticated administrator with access to GeoServer's sec= urity system to pass arbitrary file names to the Master Password Dump web p= age and create files containing the master password in plaintext. The provi= ded file name must be an absolute path to the target file, the target file = can not already exist and all parent directories must already exist. Versio=
ns 2.26.4 and 2.27.3 contain a fix. GeoServer installations where the web i= nterface is either disabled or completely removed are not affected since th=
e vulnerability exists in one of the web pages.</td>
<td>2026-06-18</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-52465" target=3D= "_blank" rel=3D"noopener">CVE-2025-52465</a></td>
</tr>
<td class=3D"vendor-product">gitroomhq--postiz-app</td>
<td>Postiz is an AI social media scheduling tool. In versions prior to 2.21= .8, the Skool integration callback signed an attacker-controlled JSON blob = into a session-shape JWT using the application's JWT_SECRET, and the auth m= iddleware trusted every claim in that JWT without re-resolving the user fro=
m the database. Any authenticated Postiz user could forge a SUPERADMIN sess= ion and impersonate arbitrary organizations. This allowed Full Access to th=
e following: all parts of Postiz, including users registered to the specifi=
c instance and the ability to post in the name of the victim's social media=
channels added to that Postiz instance. This issue has been fixed in versi=
on 2.21.8.</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48781" target=3D= "_blank" rel=3D"noopener">CVE-2026-48781</a></td>
</tr>
<td class=3D"vendor-product">Glen Don Mongaya--Drag and Drop Multiple File = Upload Contact Form 7</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple Fi=
le Upload - Contact Form 7 <=3D 1.3.9.7 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49055" target=3D= "_blank" rel=3D"noopener">CVE-2026-49055</a></td>
</tr>
<td class=3D"vendor-product">Government Accountability Office--Electronic P= rotest Docketing System (EPDS)</td>
<td>The U.S. Government Accountability Office (GAO) Electronic Protest Dock= eting System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electroni=
c Docketing System (EDS) does not authenticate password change requests to = the '/update-profile/N' API endpoint. A remote, unauthenticated attacker co= uld change an arbitrary user's password.</td>
<td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54103" target=3D= "_blank" rel=3D"noopener">CVE-2026-54103</a></td>
</tr>
<td class=3D"vendor-product">Government Accountability Office--Electronic P= rotest Docketing System (EPDS)</td>
<td>The U.S. Government Accountability Office (GAO) Electronic Protest Dock= eting System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electroni=
c Docketing System (EDS) trusts client-provided values for the 'epds_role_i=
d' parameter without verification, allowing a remote, authenticated attacke=
r to escalate their own privileges.</td>
<td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54104" target=3D= "_blank" rel=3D"noopener">CVE-2026-54104</a></td>
</tr>
<td class=3D"vendor-product">Groundhogg--Groundhogg</td>
<td>Sales Representative Arbitrary File Deletion in Groundhogg <=3D 4.4 = versions.</td>
<td>2026-06-15</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40727" target=3D= "_blank" rel=3D"noopener">CVE-2026-40727</a></td>
</tr>
<td class=3D"vendor-product">Groundhogg--HollerBox</td>
<td>Unauthenticated Cross Site Scripting (XSS) in HollerBox <=3D 2.3.10.=
1 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48885" target=3D= "_blank" rel=3D"noopener">CVE-2026-48885</a></td>
</tr>
<td class=3D"vendor-product">Hakan Ozevin--WP BASE Booking</td> <td>Unauthenticated Privilege Escalation in WP BASE Booking <=3D 5.9.0 v= ersions.</td>
<td>2026-06-15</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39587" target=3D= "_blank" rel=3D"noopener">CVE-2026-39587</a></td>
</tr>
<td class=3D"vendor-product">Happyforms--Happyforms</td>
<td>Unauthenticated PHP Object Injection in Happyforms <=3D 1.26.13 vers= ions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49768" target=3D= "_blank" rel=3D"noopener">CVE-2026-49768</a></td>
</tr>
<td class=3D"vendor-product">haproxy--haproxy</td>
<td>HAProxy through 3.4.0, fixed in commit 5985276, contains an integer ove= rflow vulnerability in the fcgi_conn structure's drl field that allows buff=
er misparse as new FCGI record headers. When contentLength is 65535 and pad= dingLength is 1 or more, the drl field wraps to 0, causing incorrect record=
consumption and allowing malicious FastCGI backends to desynchronize the F= CGI framing parser, potentially causing request routing errors, response sm= uggling, or memory safety issues.</td>
<td>2026-06-18</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55203" target=3D= "_blank" rel=3D"noopener">CVE-2026-55203</a></td>
</tr>
<td class=3D"vendor-product">haproxy--haproxy</td>
<td>HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer=
dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c tha=
t fails to validate the return value of hpack_dht_defrag() when the memory = pool is exhausted. An attacker can trigger HPACK dynamic table insertions u= nder memory pressure to dereference a NULL pointer and crash HAProxy worker=
processes, causing denial of service.</td>
<td>2026-06-18</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55204" target=3D= "_blank" rel=3D"noopener">CVE-2026-55204</a></td>
</tr>
<td class=3D"vendor-product">harttle--liquidjs</td>
<td>LiquidJS is a Shopify/GitHub Pages compatible template engine written i=
n pure JavaScript. In versions 10.25.7 and below, the date filter's strftim=
e implementation parses width specifiers like %9999999d and forwards the ca= ptured width unchecked into pad()/padStart(), leading to memory and render = limit bypass. In src/util/underscore.ts, the pad loop performs unbounded st= ring concatenation without consulting the Context's memoryLimit or renderLi= mit, so a single small template ({{ x | date: '%5000000d' }}) produces mega= bytes of output and unbounded CPU. The memoryLimit and renderLimit options = the docs (src/liquid-options.ts:87-92) advertise as DoS controls - and whic=
h the docstring explicitly mentions for strftime - are entirely bypassed. E= xploitation can cause large memory allocations, high CPU usage, or OOM cras= hes per render. This issue has been fixed in version 10.26.0.</td> <td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45357" target=3D= "_blank" rel=3D"noopener">CVE-2026-45357</a></td>
</tr>
<td class=3D"vendor-product">harttle--liquidjs</td>
<td>LiquidJS is a Shopify/GitHub Pages compatible template engine written i=
n pure JavaScript. In versions 10.25.7 and below, the built-in strip_html f= ilter uses a regex containing four flawed lazy-quantified alternatives, lea= ding to ReDoS via quadratic backtracking. When the input contains many <= script, <style, or <!-- opener tokens without matching closers, the V=
8 regex engine performs O(N=C3=82=C2=B2) backtracking, blocking the Node.js=
event loop. A single ~350 KB request ('<script'.repeat(50000)) stalls t=
he process for ~10 seconds; cost grows quadratically with input size. The d= efault memoryLimit: Infinity does not bound regex CPU, and even when config= ured strip_html only charges str.length to the limit - the regex itself run=
s unbounded. A single unauthenticated request containing crafted untrusted = input can cause severe event-loop blocking and CPU amplification that satur= ates Node.js workers while bypassing memoryLimit protections. This issue ha=
s been fixed in version 10.26.0.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45617" target=3D= "_blank" rel=3D"noopener">CVE-2026-45617</a></td>
</tr>
<td class=3D"vendor-product">Henryschorradt--Bridge</td>
<td>Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerabil= ity that allows unauthenticated attackers to execute arbitrary SQL queries =
by injecting malicious code through the id parameter. Attackers can send GE=
T requests to index.php with option=3Dcom_phpbridge&view=3Dphpview para= meters and inject SQL code in the id parameter to extract database informat= ion including table and column names.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20275" target=3D= "_blank" rel=3D"noopener">CVE-2017-20275</a></td>
</tr>
<td class=3D"vendor-product">hermes-webui--hermes-webui</td>
<td>Hermes WebUI before 0.51.409 contains an authentication bypass vulnerab= ility in passkey registration endpoints that allows unauthenticated remote = attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=3D1 is = enabled with no existing credentials, POST /api/auth/passkey/register/optio=
ns and POST /api/auth/passkey/register endpoints are accessible without aut= hentication, allowing attackers to claim the first passkey and gain permane=
nt administrative control.</td>
<td>2026-06-17</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55196" target=3D= "_blank" rel=3D"noopener">CVE-2026-55196</a></td>
</tr>
<td class=3D"vendor-product">hippooo--Hippoo Mobile App for WooCommerce</td=
<td>Unauthenticated Broken Access Control in Hippoo Mobile App for WooComme= rce <=3D 1.9.5 versions.</td>
<td>2026-06-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49065" target=3D= "_blank" rel=3D"noopener">CVE-2026-49065</a></td>
</tr>
<td class=3D"vendor-product">Hitachi--Hitachi Virtual Storage Platform E990=
, E1090, E1090H</td>
<td>DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Pla= tform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E10= 90H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, befo=
re DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DKCMAI=
N Ver.93-06-82-80/00-06, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-= 06-63-80/00-04, CHB(iSCSI) Ver.88-01-02-04; Hitachi Virtual Storage Platfor=
m E390, E590, E790, E390H, E590H, E790H: before DKCMAIN Ver.93-07-21-x0/00-= 05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-x0/00-07, CHB(i= SCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-82-x0/00-06, CHB(iSCSI) Ver= .88-01-02-04, before DKCMAIN Ver.93-06-63-x0/00-04, CHB(iSCSI) Ver.88-01-02= -04, before DKCMAIN Ver.93-07-24-x0/00-02, CHB(iSCSI) Ver.88-01-02-04, befo=
re DKCMAIN Ver.93-07-02-x0/00-02, CHB(iSCSI) Ver.88-01-02-04; Hitachi Virtu=
al Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F= 900: before DKCMAIN Ver.88-08-10-x0/00-05, CHB(iSCSI) Ver.88-01-02-04; Hita= chi Virtual Storage Platform G100, G200, G400, G600, G800, F400, F600, F800=
: before DKCMAIN Ver.83-06-20-x0/00-05, CHB(iSCSI) Ver.83-01-01-29; Hitachi=
Virtual Storage Platform VX8, 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H,=
5600H: before DKCMAIN Ver.90-09-01-00/01-01, CHB(iSCSI) Ver.90-01-01-07, b= efore DKCMAIN Ver.90-08-83-00/01-01, CHB(iSCSI) Ver.90-01-01-07, before DKC= MAIN Ver.90-08-63-00/01-01, CHB(iSCSI) Ver.90-01-01-07; Hitachi Virtual Sto= rage Platform VX7, G1000, G1500, F1500: before DKCMAIN Ver.80-06-93-00/00-0=
4, ISFC Ver.80-01-17.</td>
<td>2026-06-19</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-7737" target=3D"= _blank" rel=3D"noopener">CVE-2025-7737</a></td>
</tr>
<td class=3D"vendor-product">HKUDS--nanobot</td>
<td>nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, = the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path = using the fileName field from an incoming WhatsApp document message without=
sanitization. The WhatsApp bridge downloads media attachments and writes t= hem to disk using a filename derived from the sender's message via document= Message.fileName, which is concatenated with a prefix and its raw value is = passed directly to path.join(mediaDir, outFilename). Node.js path.join reso= lves .. components, allowing an attacker to escape the intended media/ dire= ctory by sending a document with a crafted fileName such as ../../../.ssh/a= uthorized_keys. Because the attacker also controls the file content (the do= wnloaded buffer), this is a write-anywhere primitive - both path and conten=
t are attacker-controlled. A fix for this issue is planned for version 0.1.= 5.post4.</td>
<td>2026-06-18</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48716" target=3D= "_blank" rel=3D"noopener">CVE-2026-48716</a></td>
</tr>
<td class=3D"vendor-product">
https://wpreviewslider.com/--WP Review Slider = Pro</td>
<td>The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrar=
y File Deletion in versions up to and including 12.6.8. This is due to miss= ing authorization checks on the wpfb_hide_review and wprp_save_review_admin=
AJAX handlers combined with insufficient path validation in the wpfb_hider= eview_ajax() function, which uses strpos() to check that a stored media URL=
starts with the expected prefix but fails to sanitize path traversal seque= nces in the remaining relative path before passing it to unlink(). This mak=
es it possible for authenticated attackers, with subscriber-level access an=
d above, to delete arbitrary files on the affected site's server which may = make remote code execution possible.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8442" target=3D"= _blank" rel=3D"noopener">CVE-2026-8442</a></td>
</tr>
<td class=3D"vendor-product">
https://wpreviewslider[.]com/--WP Review Slide=
r Pro</td>
<td>The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Inje= ction via the 'stypes' and 'slocations' parameters of the wppro_get_overall= _chart_data AJAX action in versions up to, and including, 12.6.8. This is d=
ue to the use of stripslashes() on user-supplied JSON strings prior to json= _decode(), which removes the escaping applied by WordPress's wp_magic_quote=
s; the resulting decoded array values are then concatenated directly into S=
QL WHERE clauses without parameterization, and the constructed query is exe= cuted via $wpdb->get_results() without $wpdb->prepare(). This makes i=
t possible for authenticated attackers, with Subscriber-level access and ab= ove, to append additional SQL queries into already existing queries that ca=
n be used to extract sensitive information from the database. The handler a= lso returns the executed SQL string in its JSON response, which simplifies = oracle construction for blind exploitation.</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8443" target=3D"= _blank" rel=3D"noopener">CVE-2026-8443</a></td>
</tr>
<td class=3D"vendor-product">
https://wpreviewslider[.]com/--WP Review Slide=
r Pro</td>
<td>The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Inje= ction via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action=
in versions up to, and including, 12.6.8. This is due to the handler readi=
ng $_POST['curselrevs'] raw with no sanitization or type casting, then conc= atenating each array element directly into a `WHERE id IN ( ... )` clause w= ithout quoting and executing via $wpdb->get_results() without $wpdb->= prepare(). This makes it possible for authenticated attackers, with Subscri= ber-level access and above, to append additional SQL queries into already e= xisting queries that can be used to extract sensitive information from the = database.</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8444" target=3D"= _blank" rel=3D"noopener">CVE-2026-8444</a></td>
</tr>
<td class=3D"vendor-product">Husain--HB Audio Gallery Lite</td>
<td>WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal = vulnerability that allows unauthenticated attackers to download arbitrary f= iles by manipulating the file_path parameter. Attackers can send requests t=
o the audio-download.php endpoint with directory traversal sequences to acc= ess sensitive files like wp-config.php outside the intended gallery directo= ry.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20081" target=3D= "_blank" rel=3D"noopener">CVE-2016-20081</a></td>
</tr>
<td class=3D"vendor-product">i18next--i18next-fs-backend</td>
<td>Versions prior to 2.6.6 are vulnerable to prototype pollution via craft=
ed missing-key strings when used to persist missing translation keys (e.g. = via i18next-http-middleware's missingKeyHandler exposed to untrusted input)=
. Backend.writeFile() splits each queued missing-key string on the configur=
ed keySeparator (default .) before calling the internal setPath() walker. T=
he walker (getLastOfPath in lib/utils.js) did not guard against unsafe segm= ents, so a key like "__proto__.polluted" was split into ["__proto__", "poll= uted"] and walked straight into Object.prototype, allowing an attacker to w= rite arbitrary properties onto the global object prototype. Depending on th=
e host application, polluted prototype properties may cause crashes, corrup= ted translation behaviour, configuration poisoning, or bypasses of property= -based security checks. Applications are affected only if the missingKeyHan= dler (or another route that forwards untrusted request bodies to i18next.t(= ..., { ... }) with saveMissing: true) is reachable by untrusted users and t=
he default behaviour of splitting missing-key strings on keySeparator is in=
use (i.e. keySeparator is not false). Apps that do not expose missing-key = persistence to untrusted input are not directly affected through this attac=
k path. This issue has been fixed in version 2.6.6. If developers using the=
library are unable to upgrade immediately, they should take the following = precautions: do not expose i18next-http-middleware's missingKeyHandler to u= ntrusted users (mount it behind authentication, or remove the route), disab=
le missing-key persistence (saveMissing: false, or no backend.create implem= entation) when accepting writes from untrusted input, and set keySeparator:=
false in their i18next options to disable backend key splitting (note: thi=
s also disables nested translation keys).</td>
<td>2026-06-15</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48713" target=3D= "_blank" rel=3D"noopener">CVE-2026-48713</a></td>
</tr>
<td class=3D"vendor-product">i18next--i18next-http-middleware</td> <td>i18next-http-middleware is a middleware to be used with Node.js web fra= meworks like express or Fastify and also for Deno. In versions prior to 3.9= .7, the missingKeyHandler blocked the literal request-body keys __proto__, = constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but d=
id not reject dotted variants such as "__proto__.polluted". Downstream back= ends that split the missing-key string on a configured keySeparator (notabl=
y i18next-fs-backend =C3=A2=E2=80=B0=C2=A4 2.6.5) hand these keys to an ung= uarded setPath() walker that writes to Object.prototype. Applications that = expose missingKeyHandler to untrusted input AND use i18next-fs-backend =C3= =A2=E2=80=B0=C2=A4 2.6.5 are directly exploitable for remote prototype poll= ution. Other downstream backends that split the missing-key string the same=
way may be similarly affected. Depending on the host application, polluted=
prototype properties may cause crashes, corrupted translation behaviour, c= onfiguration poisoning, or bypasses of property-based security checks. This=
issue has been fixed in version 3.9.7. If developers cannot upgrade immedi= ately, they should do the following: do not expose missingKeyHandler to unt= rusted users (mount it behind authentication, or remove the route), add a r= equest-body filter ahead of the handler that rejects any top-level key cont= aining __proto__, constructor, or prototype after splitting on their config= ured keySeparator, and disable missing-key persistence (saveMissing: false)=
when accepting writes from untrusted input.</td>
<td>2026-06-15</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48714" target=3D= "_blank" rel=3D"noopener">CVE-2026-48714</a></td>
</tr>
<td class=3D"vendor-product">iba--ibaPDA</td>
<td>A remote, unauthenticated attacker may exploit a deserialization of unt= rusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full acces=
s to the affected systems.</td>
<td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8024" target=3D"= _blank" rel=3D"noopener">CVE-2026-8024</a></td>
</tr>
<td class=3D"vendor-product">IDPay--IDPay Payment Gateway for Woocommerce</=
<td>Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Wo= ocommerce <=3D 2.2.5 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34891" target=3D= "_blank" rel=3D"noopener">CVE-2026-34891</a></td>
</tr>
<td class=3D"vendor-product">IM-Magic--Partition Resizer</td>
<td>A weakness has been identified in IM-Magic Partition Resizer up to 7.9.=
0. This affects an unknown function in the library MDA_NTDRV.sys of the com= ponent Kernel Driver. This manipulation causes improper access controls. Th=
e attack requires local access. The exploit has been made available to the = public and could be used for attacks. The vendor was contacted early about = this disclosure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12784" target=3D= "_blank" rel=3D"noopener">CVE-2026-12784</a></td>
</tr>
<td class=3D"vendor-product">impleCode--eCommerce Product Catalog</td> <td>Unauthenticated SQL Injection in eCommerce Product Catalog <=3D 3.5.=
5 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52693" target=3D= "_blank" rel=3D"noopener">CVE-2026-52693</a></td>
</tr>
<td class=3D"vendor-product">Inisev--Backup Migration</td>
<td>Unauthenticated Sensitive Data Exposure in Backup Migration <=3D 2.1=
.1 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39480" target=3D= "_blank" rel=3D"noopener">CVE-2026-39480</a></td>
</tr>
<td class=3D"vendor-product">Iperiusremote--Iperius Remote</td>
<td>Iperius Remote 1.7.0 contains an unquoted service path vulnerability th=
at allows local users to execute arbitrary code with SYSTEM privileges by e= xploiting the service installation path. When installed from directories co= ntaining spaces, attackers can place malicious executables in the path to b=
e executed with elevated privileges during service startup or system reboot= .</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20089" target=3D= "_blank" rel=3D"noopener">CVE-2016-20089</a></td>
</tr>
<td class=3D"vendor-product">IT Path Solutions--Contact Form to Any API</td=
<td>Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API &= lt;=3D 3.0.3 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39449" target=3D= "_blank" rel=3D"noopener">CVE-2026-39449</a></td>
</tr>
<td class=3D"vendor-product">Jacob N. Breetvelt--WP Photo Album Plus</td> <td>Unauthenticated SQL Injection in WP Photo Album Plus <=3D 9.1.08.001=
versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39511" target=3D= "_blank" rel=3D"noopener">CVE-2026-39511</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--GoLand</td>
<td>In JetBrains GoLand before 2026.1.3 remote code execution was possible = via untrusted project configuration</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53915" target=3D= "_blank" rel=3D"noopener">CVE-2026-53915</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--Hub</td>
<td>In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 202= 5.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct d= atabase access leading to administrative access was possible</td> <td>2026-06-19</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50242" target=3D= "_blank" rel=3D"noopener">CVE-2026-50242</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--Hub</td>
<td>In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 202= 5.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable r= estore codes was possible</td>
<td>2026-06-19</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56141" target=3D= "_blank" rel=3D"noopener">CVE-2026-56141</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--Hub</td>
<td>In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 202= 5.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching = authentication details to accounts was possible</td>
<td>2026-06-19</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56142" target=3D= "_blank" rel=3D"noopener">CVE-2026-56142</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetBlog</td>
<td>Unauthenticated Sensitive Data Exposure in JetBlog <=3D 2.4.8 versio= ns.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52696" target=3D= "_blank" rel=3D"noopener">CVE-2026-52696</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Contributor PHP Object Injection in JetEngine <=3D 3.8.9.1 versions.= </td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49075" target=3D= "_blank" rel=3D"noopener">CVE-2026-49075</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Unauthenticated SQL Injection in JetEngine <=3D 3.8.9.1 versions.</t=
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49076" target=3D= "_blank" rel=3D"noopener">CVE-2026-49076</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.</td> <td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49084" target=3D= "_blank" rel=3D"noopener">CVE-2026-49084</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Unauthenticated PHP Object Injection in JetEngine <=3D 3.8.10 versio= ns.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52706" target=3D= "_blank" rel=3D"noopener">CVE-2026-52706</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Unauthenticated SQL Injection in JetEngine <=3D 3.8.10.1 versions.</=
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54187" target=3D= "_blank" rel=3D"noopener">CVE-2026-54187</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Unauthenticated Cross Site Scripting (XSS) in JetEngine <=3D 3.8.9.1=
versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49074" target=3D= "_blank" rel=3D"noopener">CVE-2026-49074</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Unauthenticated Cross Site Scripting (XSS) in JetEngine <=3D 3.8.10 = versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54188" target=3D= "_blank" rel=3D"noopener">CVE-2026-54188</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetEngine</td>
<td>Unauthenticated Cross Site Scripting (XSS) in JetEngine <=3D 3.8.10 = versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54189" target=3D= "_blank" rel=3D"noopener">CVE-2026-54189</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetSearch</td>
<td>Unauthenticated SQL Injection in JetSearch <=3D 3.5.17 versions.</td=
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49079" target=3D= "_blank" rel=3D"noopener">CVE-2026-49079</a></td>
</tr>
<td class=3D"vendor-product">Jetimpex Inc.--JetSmartFilters</td> <td>Unauthenticated SQL Injection in JetSmartFilters <=3D 3.8.1 versions= .</td>
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48875" target=3D= "_blank" rel=3D"noopener">CVE-2026-48875</a></td>
</tr>
<td class=3D"vendor-product">Jetmonsters--JetFormBuilder</td> <td>Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <=3D 3.= 6.0.1 versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54195" target=3D= "_blank" rel=3D"noopener">CVE-2026-54195</a></td>
</tr>
<td class=3D"vendor-product">JExtensions Store--GPTranslate Multilingual AI=
Translation for WordPress: Automatically Translate Websites</td> <td>Unauthenticated SQL Injection in GPTranslate - Multilingual AI Translat= ion for WordPress: Automatically Translate Websites <=3D 2.32.6 versions= .</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49776" target=3D= "_blank" rel=3D"noopener">CVE-2026-49776</a></td>
</tr>
<td class=3D"vendor-product">jkdevstudio--Qreatix</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Qreatix <=3D 1.9.4 ver= sions.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69104" target=3D= "_blank" rel=3D"noopener">CVE-2025-69104</a></td>
</tr>
<td class=3D"vendor-product">Jobster Marketplace--WPJobster</td> <td>Unauthenticated SQL Injection in WPJobster <=3D 6.3.5 versions.</td> <td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22340" target=3D= "_blank" rel=3D"noopener">CVE-2026-22340</a></td>
</tr>
<td class=3D"vendor-product">Jobster Marketplace--WPJobster</td> <td>Unauthenticated Cross Site Scripting (XSS) in WPJobster <=3D 6.3.5 v= ersions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22339" target=3D= "_blank" rel=3D"noopener">CVE-2026-22339</a></td>
</tr>
<td class=3D"vendor-product">Joombooking--JB Visa</td>
<td>Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability t= hat allows unauthenticated attackers to execute arbitrary SQL queries by in= jecting malicious code through the visatype parameter. Attackers can send G=
ET requests to index.php with the option=3Dcom_bookpro and view=3Dpopup par= ameters, injecting SQL commands in the visatype parameter to extract sensit= ive database information including credentials and table contents.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20255" target=3D= "_blank" rel=3D"noopener">CVE-2017-20255</a></td>
</tr>
<td class=3D"vendor-product">Joomboost--JoomCRM</td>
<td>Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability=
that allows authenticated attackers to execute arbitrary SQL queries by in= jecting malicious code through the deal_id parameter. Attackers can send GE=
T requests to index.php with option=3Dcom_joomcrm&view=3Dcontacts and i= nject SQL code in the deal_id parameter to extract sensitive database infor= mation including table names and schemas.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25761" target=3D= "_blank" rel=3D"noopener">CVE-2019-25761</a></td>
</tr>
<td class=3D"vendor-product">Joomboost--Joomla JoomRecipe</td>
<td>Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulner= ability in the search_author parameter on the search results page. Attacker=
s can inject SQL code through POST requests to the search endpoint to extra=
ct database information using boolean-based blind SQL injection techniques.= </td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20277" target=3D= "_blank" rel=3D"noopener">CVE-2017-20277</a></td>
</tr>
<td class=3D"vendor-product">Joomboost--JoomProject</td>
<td>Joomla! Component JoomProject 1.1.3.2 contains an information disclosur=
e vulnerability that allows unauthenticated attackers to access sensitive u= ser data by exploiting the projects endpoint. Attackers can send requests t=
o index.php with option=3Dcom_jpprojects&view=3Dprojects&tmpl=3Dcom= ponent&format=3Djson parameters to retrieve user IDs, names, and email = addresses in JSON format.</td>
<td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25762" target=3D= "_blank" rel=3D"noopener">CVE-2019-25762</a></td>
</tr>
<td class=3D"vendor-product">Joomboost--JoomRecipe</td>
<td>Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerabili=
ty that allows unauthenticated attackers to manipulate database queries by = injecting SQL code through the category parameter. Attackers can send GET r= equests to the all-recipes endpoint with malicious SQL payloads in the cate= gory path segment to extract sensitive database information.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20278" target=3D= "_blank" rel=3D"noopener">CVE-2017-20278</a></td>
</tr>
<td class=3D"vendor-product">Joomlaboat--Extra Search</td>
<td>Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerab= ility that allows unauthenticated attackers to manipulate database queries =
by injecting SQL code through the establename parameter. Attackers can send=
GET requests to index.php with the option=3Dcom_extrasearch parameter and = malicious SQL in the establename field to extract sensitive database inform= ation.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20281" target=3D= "_blank" rel=3D"noopener">CVE-2017-20281</a></td>
</tr>
<td class=3D"vendor-product">Joomlashack--OSDownloads</td>
<td>Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that a= llows unauthenticated attackers to execute arbitrary SQL queries by injecti=
ng malicious code through the id parameter. Attackers can send GET requests=
to index.php with option=3Dcom_osdownloads&view=3Ditem&id=3D[SQL] =
to extract sensitive database information including credentials and configu= ration data.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20259" target=3D= "_blank" rel=3D"noopener">CVE-2017-20259</a></td>
</tr>
<td class=3D"vendor-product">Joomlashowroom--Event Registration Pro Calenda= r</td>
<td>Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection = vulnerability that allows unauthenticated attackers to execute arbitrary SQ=
L queries by injecting malicious code through the id parameter. Attackers c=
an send GET requests to index.php with option=3Dcom_registrationpro&vie= w=3Dcategory&id parameter containing SQL injection payloads to extract = sensitive database information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20273" target=3D= "_blank" rel=3D"noopener">CVE-2017-20273</a></td>
</tr>
<td class=3D"vendor-product">Joomlathat--Calendar Planner</td>
<td>Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vuln= erability that allows unauthenticated attackers to inject SQL commands thro= ugh the category_id parameter. Attackers can send GET requests to the event=
s view with malicious SQL code in the category_id parameter to extract sens= itive database information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20267" target=3D= "_blank" rel=3D"noopener">CVE-2017-20267</a></td>
</tr>
<td class=3D"vendor-product">Joomplace--Quiz Deluxe</td>
<td>Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerabi= lity that allows unauthenticated attackers to execute arbitrary SQL command=
s through the ajaxaction.flag_question task. Attackers can inject malicious=
SQL code via the stu_quiz_id or flag_quest parameters to manipulate databa=
se queries and extract sensitive information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20257" target=3D= "_blank" rel=3D"noopener">CVE-2017-20257</a></td>
</tr>
<td class=3D"vendor-product">Joomplace--Survey Force Deluxe</td>
<td>Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerabilit=
y that allows unauthenticated attackers to execute arbitrary SQL queries by=
injecting malicious code through the invite parameter. Attackers can send = GET requests to the component with crafted SQL payloads in the invite param= eter to extract sensitive database information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20256" target=3D= "_blank" rel=3D"noopener">CVE-2017-20256</a></td>
</tr>
<td class=3D"vendor-product">Joomshaper--SP Movie Database</td>
<td>Joomla SP Movie Database 1.3 contains an SQL injection vulnerability th=
at allows unauthenticated attackers to execute arbitrary SQL queries by inj= ecting malicious code through the searchword parameter. Attackers can send = GET requests to the searchresults view with crafted SQL payloads in the sea= rchword parameter to extract sensitive database information.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20266" target=3D= "_blank" rel=3D"noopener">CVE-2017-20266</a></td>
</tr>
<td class=3D"vendor-product">Joomunited--WP Media folder Addon</td> <td>Unauthenticated Arbitrary File Download in WP Media folder Addon <=
=3D 4.0.1 versions.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9690" target=3D"= _blank" rel=3D"noopener">CVE-2026-9690</a></td>
</tr>
<td class=3D"vendor-product">Jose Conti--Redsys for WooCommerce Light</td> <td>Unauthenticated Broken Access Control in Redsys for WooCommerce Light &= lt;=3D 7.0.0 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40741" target=3D= "_blank" rel=3D"noopener">CVE-2026-40741</a></td>
</tr>
<td class=3D"vendor-product">Jovancoding--Network-AI</td>
<td>Network-AI is a TypeScript/Node.js multi-agent orchestrator. In version=
s 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin=
MCP tool invocation due to an empty default secret. This issue was partial=
ly addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (w= ith Access-Control-Allow-Origin now set only for localhost origins), but th=
e empty-default-secret flaw described in the title remained: the SSE MCP se= rver still defaulted to an empty secret, _isAuthorized() still returned tru=
e when the secret was empty, and a non-loopback bind only produced a warnin=
g. As a result, the server still ran fully unauthenticated by default. Any = non-browser caller (for example, curl, SSRF, or a 0.0.0.0 bind) could invok=
e all 22 MCP tools (config_set, agent_spawn, blackboard_write, token_*) wit=
h no credentials. This issue was fixed in version 5.7.2.</td> <td>2026-06-17</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48814" target=3D= "_blank" rel=3D"noopener">CVE-2026-48814</a></td>
</tr>
<td class=3D"vendor-product">Jthemes--Genemy</td>
<td>Subscriber Privilege Escalation in Genemy <=3D 1.6.6 versions.</td> <td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69138" target=3D= "_blank" rel=3D"noopener">CVE-2025-69138</a></td>
</tr>
<td class=3D"vendor-product">JTL Software--JTL Shop</td>
<td>JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template i= njection vulnerability that allows unauthenticated attackers to inject mali= cious template syntax due to unsanitized user-supplied input passed to the = Smarty template engine. Attackers can exploit this flaw to read sensitive s= erver-side values such as database credentials and encryption keys, and on = versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers includin=
g unserialize and file_get_contents to write a webshell to the web root and=
execute arbitrary commands as the web server user.</td>
<td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54390" target=3D= "_blank" rel=3D"noopener">CVE-2026-54390</a></td>
</tr>
<td class=3D"vendor-product">jwsthemes--AI Lab</td>
<td>Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.</td=
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42380" target=3D= "_blank" rel=3D"noopener">CVE-2026-42380</a></td>
</tr>
<td class=3D"vendor-product">kilbot--WooCommerce POS</td>
<td>Unauthenticated Broken Access Control in WooCommerce POS <=3D 1.8.14=
versions.</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52711" target=3D= "_blank" rel=3D"noopener">CVE-2026-52711</a></td>
</tr>
<td class=3D"vendor-product">King-products--LMS King Professional</td> <td>Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerab= ility that allows unauthenticated attackers to manipulate database queries =
by injecting SQL code through the cp_id parameter. Attackers can send GET r= equests to index.php with the option=3Dcom_lmsking, view=3Dlmsking, layout= =3Dlearningpath, and task=3DlearningPath parameters to extract sensitive da= tabase information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20274" target=3D= "_blank" rel=3D"noopener">CVE-2017-20274</a></td>
</tr>
<td class=3D"vendor-product">Kludex--starlette</td>
<td>Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 an=
d earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such a=
s \attacker.com\share can cause os.path.realpath to initiate an outbound SM=
B connection before the path is rejected, exposing the service account's NT= LMv2 credentials for offline cracking or relay even though the HTTP respons=
e is only a 404. The issue affects default follow_symlink=3DFalse deploymen= ts, including frameworks built on Starlette such as FastAPI; POSIX systems = and follow_symlink=3DTrue are unaffected. The issue is fixed in 1.1.0.</td> <td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48818" target=3D= "_blank" rel=3D"noopener">CVE-2026-48818</a></td>
</tr>
<td class=3D"vendor-product">Knit Pay--Knit Pay</td>
<td>Unauthenticated Broken Access Control in Knit Pay <=3D 9.4.0.0 versi= ons.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49070" target=3D= "_blank" rel=3D"noopener">CVE-2026-49070</a></td>
</tr>
<td class=3D"vendor-product">Kodezen LLC--Academy LMS Pro</td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Kodeze=
n LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue=
affects Academy LMS Pro: from n/a before 3.5.2.</td>
<td>2026-06-16</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39598" target=3D= "_blank" rel=3D"noopener">CVE-2026-39598</a></td>
</tr>
<td class=3D"vendor-product">Kriesi--Enfold</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Enfold <=3D 7.1.4 vers= ions.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48869" target=3D= "_blank" rel=3D"noopener">CVE-2026-48869</a></td>
</tr>
<td class=3D"vendor-product">LatePoint--LatePoint</td>
<td>Contributor Privilege Escalation in LatePoint <=3D 5.5.1 versions.</=
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49083" target=3D= "_blank" rel=3D"noopener">CVE-2026-49083</a></td>
</tr>
<td class=3D"vendor-product">latepoint--LatePoint Calendar Booking Plugin f=
or Appointments and Events</td>
<td>The LatePoint - Calendar Booking Plugin for Appointments and Events plu= gin for WordPress is vulnerable to Privilege Escalation to Administrator in=
versions up to, and including, 5.5.1. The plugin chains three independent = flaws that together allow an authenticated Agent (Agent+) to overwrite a Wo= rdPress Administrator's password without ever invoking an Administrator-onl=
y API. This makes it possible for authenticated attackers, with Agent acces=
s and above, to elevate their privileges to Administrator.</td> <td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8176" target=3D"= _blank" rel=3D"noopener">CVE-2026-8176</a></td>
</tr>
<td class=3D"vendor-product">leejet--stable-diffusion.cpp</td> <td>stable-diffusion.cpp is a pure C/C++ library for running diffusion mode=
l (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. I=
n versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/mode= l.cpp contained a heap buffer overflow vulnerability in the BINUNICODE opco=
de handler. The issue was caused by sign confusion on the opcode length fie= ld. A crafted .ckpt file could trigger memcpy with a very large length deri= ved from a negative signed value, causing immediate heap corruption. The is= sue has been resolved in version master-584-0a7ae07. If developers are unab=
le to immediately update their applications they can work around this issue=
by only loading .ckpt checkpoint files from trusted sources and preferring=
trusted model sources and safer formats such as .safetensors where possibl= e.</td>
<td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47747" target=3D= "_blank" rel=3D"noopener">CVE-2026-47747</a></td>
</tr>
<td class=3D"vendor-product">leejet--stable-diffusion.cpp</td> <td>stable-diffusion.cpp is a pure C/C++ library for running diffusion mode=
l (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. V= ersions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow =
in SHORT_BINUNICODE parsing for PyTorch checkpoint files. The pickle .ckpt = parser in src/model.cpp contained a heap buffer overflow vulnerability in t=
he SHORT_BINUNICODE opcode handler. The issue was caused by sign confusion =
on the opcode length field. A crafted .ckpt file could trigger memcpy with =
a very large length derived from a negative signed value, causing immediate=
heap corruption. Any application using affected stable-diffusion.cpp relea= ses to load untrusted .ckpt model files could be vulnerable. A malicious ch= eckpoint file could cause heap corruption through memcpy with an attacker-c= ontrolled length. This may lead to process crash and could potentially be l= everaged for code execution depending on heap layout. The attack requires t=
he victim or application to load a .ckpt file from an untrusted source, suc=
h as a downloaded model from a model sharing site. The issue has been resol= ved in version master-584-0a7ae07. If developers are unable to immediately = update their applications they can work around this issue by not loading .c= kpt checkpoint files from untrusted sources, and referring to trusted model=
sources and safer formats such as .safetensors where possible.</td> <td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47749" target=3D= "_blank" rel=3D"noopener">CVE-2026-47749</a></td>
</tr>
<td class=3D"vendor-product">leejet--stable-diffusion.cpp</td> <td>stable-diffusion.cpp is a pure C/C++ library for running diffusion mode=
l (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. I=
n versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/mode= l.cpp contained a heap buffer overflow vulnerability in the GLOBAL opcode h= andler. The issue was caused by missing validation when searching for newli= ne-delimited fields. A crafted .ckpt file without the expected newline coul=
d cause the parser to use -1 as a copy length, resulting in immediate heap = corruption. The attack requires the victim or application to load a .ckpt f= ile from an untrusted source, such as a downloaded model from a model shari=
ng site. The issue has been resolved in version master-584-0a7ae07. If deve= lopers are unable to immediately update their applications they can work ar= ound this issue by following these instructions: do not load .ckpt checkpoi=
nt files from untrusted sources, and prefer trusted model sources and safer=
formats such as .safetensors where possible.</td>
<td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47750" target=3D= "_blank" rel=3D"noopener">CVE-2026-47750</a></td>
</tr>
<td class=3D"vendor-product">libssh2--libssh2</td>
<td>libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-boun=
ds write vulnerability in ssh2_transport_read() that fails to enforce upper=
bounds on packet_length field. Remote attackers can send crafted SSH packe=
ts with excessively large packet_length values to corrupt heap memory and a= chieve remote code execution.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55200" target=3D= "_blank" rel=3D"noopener">CVE-2026-55200</a></td>
</tr>
<td class=3D"vendor-product">Liquid Web / StellarWP--GiveWP</td> <td>Unauthenticated Cross Site Scripting (XSS) in GiveWP <=3D 4.14.2 ver= sions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34900" target=3D= "_blank" rel=3D"noopener">CVE-2026-34900</a></td>
</tr>
<td class=3D"vendor-product">Liquid Web / StellarWP--The Events Calendar</t=
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in Liquid Web / StellarWP The Events Calendar a= llows Blind SQL Injection. This issue affects The Events Calendar: from 6.1= 5.12 through 6.16.2.</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49772" target=3D= "_blank" rel=3D"noopener">CVE-2026-49772</a></td>
</tr>
<td class=3D"vendor-product">LoginPress--LoginPress Pro</td> <td>Unauthenticated Privilege Escalation in LoginPress Pro <=3D 6.2.2 ve= rsions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49058" target=3D= "_blank" rel=3D"noopener">CVE-2026-49058</a></td>
</tr>
<td class=3D"vendor-product">Magepeople inc.--WpEvently</td> <td>Unauthenticated Other Vulnerability Type in WpEvently <=3D 5.3.3 ver= sions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45441" target=3D= "_blank" rel=3D"noopener">CVE-2026-45441</a></td>
</tr>
<td class=3D"vendor-product">Magepeople inc.--WpTravelly</td> <td>Unauthenticated Bypass Vulnerability in WpTravelly <=3D 2.1.7 versio= ns.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27089" target=3D= "_blank" rel=3D"noopener">CVE-2026-27089</a></td>
</tr>
<td class=3D"vendor-product">Malwarebytes--Malwarebytes</td>
<td>Malwarebytes 4.5 contains an unquoted service path vulnerability in the=
MBAMService executable that allows local attackers to escalate privileges =
by injecting malicious code into the system root path. Attackers can place = executable files in unquoted path directories that execute with LocalSystem=
privileges during service startup or system reboot.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-50971" target=3D= "_blank" rel=3D"noopener">CVE-2022-50971</a></td>
</tr>
<td class=3D"vendor-product">Mamunur Rashid--Classified Listing</td> <td>Unauthenticated Cross Site Scripting (XSS) in Classified Listing <=
=3D 5.3.8 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42658" target=3D= "_blank" rel=3D"noopener">CVE-2026-42658</a></td>
</tr>
<td class=3D"vendor-product">ManageWP--ManageWP Worker</td>
<td>Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <=3D 4= .9.31 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39463" target=3D= "_blank" rel=3D"noopener">CVE-2026-39463</a></td>
</tr>
<td class=3D"vendor-product">MantraBrain--Easy Invoice</td>
<td>Unauthenticated Remote Code Execution (RCE) in Easy Invoice <=3D 2.1= .19 versions.</td>
<td>2026-06-15</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48836" target=3D= "_blank" rel=3D"noopener">CVE-2026-48836</a></td>
</tr>
<td class=3D"vendor-product">mariovalney--CF7 to Webhook</td>
<td>The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Re= quest Forgery in all versions up to, and including, 5.0.0 via the pull_the_= trigger. This makes it possible for unauthenticated attackers to make web r= equests to arbitrary locations originating from the web application and can=
be used to query and modify information from internal services. Exploitati=
on requires that the admin-configured webhook URL contains a Contact Form 7=
field placeholder in the host segment of the URL, and that the affected fo=
rm is publicly accessible.</td>
<td>2026-06-18</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11395" target=3D= "_blank" rel=3D"noopener">CVE-2026-11395</a></td>
</tr>
<td class=3D"vendor-product">markbeljaars--iRobots.txt SEO</td> <td>Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <=3D 1= .1.2 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-68840" target=3D= "_blank" rel=3D"noopener">CVE-2025-68840</a></td>
</tr>
<td class=3D"vendor-product">mastodon--mastodon</td>
<td>Mastodon is a free, open-source social network server based on Activity= Pub. In versions there is a missing condition in the check if remote accoun=
ts consented to be featured in a remote Collection could lead to attackers = bypassing the check and faking consent. An attacker could forge the Feature= Authorization object that is used to verify consent to be featured in a Col= lection and thus make it appear as if an account is allowed to be in a Coll= ection when it actually is not. While the FeatureAuthorization must reside =
on the same domain as the object it is for, a check is missing to make sure=
said object is actually the same as in the Collection item. This allows an=
attacker to forge the authorization. Mastodon servers are affected only if=
running the main branch or nightly builds who have opted into testing the = experimental "Collections" feature by setting the environment variable EXPE= RIMENTAL_FEATURES to a value including collections. This has been patched i=
n version 4.6.0-beta.1.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47777" target=3D= "_blank" rel=3D"noopener">CVE-2026-47777</a></td>
</tr>
<td class=3D"vendor-product">Matrix42--Matrix42 Remote Control Host</td> <td>Matrix42 Remote Control Host 3.20.0031 contains an unquoted service pat=
h vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy se= rvices that allows local users to execute arbitrary code with SYSTEM privil= eges. Attackers can place a malicious executable in the Program Files direc= tory with a crafted name to be executed by the service during startup, gain= ing elevated privileges.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20095" target=3D= "_blank" rel=3D"noopener">CVE-2016-20095</a></td>
</tr>
<td class=3D"vendor-product">mattkaye--Answer My Question</td>
<td>Answer My Question 1.3 plugin for WordPress contains an SQL injection v= ulnerability that allows unauthenticated attackers to execute arbitrary SQL=
queries by injecting malicious code through the 'id' POST parameter. Attac= kers can submit crafted SQL statements to the modal.php endpoint to extract=
sensitive database information including WordPress terms and configuration=
data.</td>
<td>2026-06-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20073" target=3D= "_blank" rel=3D"noopener">CVE-2016-20073</a></td>
</tr>
<td class=3D"vendor-product">Melapress--WP Activity Log</td> <td>Unauthenticated PHP Object Injection in WP Activity Log <=3D 5.6.3.1=
versions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54806" target=3D= "_blank" rel=3D"noopener">CVE-2026-54806</a></td>
</tr>
<td class=3D"vendor-product">melhorenvio--Melhor Envio</td>
<td>Subscriber Broken Authentication in Melhor Envio <=3D 2.16.3 version= s.</td>
<td>2026-06-17</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54804" target=3D= "_blank" rel=3D"noopener">CVE-2026-54804</a></td>
</tr>
<td class=3D"vendor-product">Meow Apps--AI Engine</td>
<td>Editor Privilege Escalation in AI Engine <=3D 3.4.9 versions.</td> <td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27407" target=3D= "_blank" rel=3D"noopener">CVE-2026-27407</a></td>
</tr>
<td class=3D"vendor-product">Metagauss--RegistrationMagic</td> <td>Unauthenticated Broken Authentication in RegistrationMagic <=3D 6.0.= 8.6 versions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49764" target=3D= "_blank" rel=3D"noopener">CVE-2026-49764</a></td>
</tr>
<td class=3D"vendor-product">metaphorcreations--Post Duplicator</td> <td>Contributor PHP Object Injection in Post Duplicator <=3D 3.0.10 vers= ions.</td>
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39474" target=3D= "_blank" rel=3D"noopener">CVE-2026-39474</a></td>
</tr>
<td class=3D"vendor-product">MetaSlider--Responsive Slider by MetaSlider</t=
<td>Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider &= lt;=3D 3.106.0 versions.</td>
<td>2026-06-15</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39465" target=3D= "_blank" rel=3D"noopener">CVE-2026-39465</a></td>
</tr>
<td class=3D"vendor-product">MIA Technology Inc.--Pizzy Library</td> <td>Improper neutralization of formula elements in a CSV file vulnerability=
in MIA Technology Inc. Pizzy Library allows Code Injection. This issue aff= ects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.</td> <td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5242" target=3D"= _blank" rel=3D"noopener">CVE-2026-5242</a></td>
</tr>
<td class=3D"vendor-product">MIA Technology Inc.--Pizzy Library</td> <td>Improper Access Control, Missing Authorization vulnerability in MIA Tec= hnology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access = Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250=
before 1.3.9.26250.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5230" target=3D"= _blank" rel=3D"noopener">CVE-2026-5230</a></td>
</tr>
<td class=3D"vendor-product">MIA Technology Inc.--Pizzy Library</td> <td>Improper Control of Interaction Frequency vulnerability in MIA Technolo=
gy Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: fr=
om 1.0.0.26250 before 1.3.9.26250.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5233" target=3D"= _blank" rel=3D"noopener">CVE-2026-5233</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Azure Active Directory</td> <td>Improper authentication in Azure Active Directory allows an unauthorize=
d attacker to elevate privileges over a network.</td>
<td>2026-06-19</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45480" target=3D= "_blank" rel=3D"noopener">CVE-2026-45480</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Azure AI Bot Service</td>
<td>Improper authentication in Azure Bot Service allows an authorized attac= ker to elevate privileges over a network.</td>
<td>2026-06-18</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32174" target=3D= "_blank" rel=3D"noopener">CVE-2026-32174</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Azure Synapse</td>
<td>Execution with unnecessary privileges in Azure Synapse allows an author= ized attacker to elevate privileges over a network.</td>
<td>2026-06-19</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48584" target=3D= "_blank" rel=3D"noopener">CVE-2026-48584</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft 365 Copilot</td>
<td>Missing authentication for critical function in M365 Copilot allows an = unauthorized attacker to disclose information over a network.</td> <td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54130" target=3D= "_blank" rel=3D"noopener">CVE-2026-54130</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft 365 Copilot</td>
<td>Url redirection to untrusted site ('open redirect') in Microsoft 365 Co= pilot's Business Chat allows an unauthorized attacker to elevate privileges=
over a network.</td>
<td>2026-06-19</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47645" target=3D= "_blank" rel=3D"noopener">CVE-2026-47645</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Cost Management</td> <td>Exposure of sensitive information to an unauthorized actor in Cost Mana= gement Interactive Experiences allows an unauthorized attacker to disclose = information over a network.</td>
<td>2026-06-18</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47633" target=3D= "_blank" rel=3D"noopener">CVE-2026-47633</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Dynamics 365</td> <td>Improper access control in Microsoft Dynamics 365 allows an authorized = attacker to elevate privileges over a network.</td>
<td>2026-06-18</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47647" target=3D= "_blank" rel=3D"noopener">CVE-2026-47647</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Edge (Chromium-based)</td=
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') in Microsoft Edge (Chromium-based) allows an authorized attac= ker to perform spoofing over a network.</td>
<td>2026-06-19</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32208" target=3D= "_blank" rel=3D"noopener">CVE-2026-32208</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Exchange Online</td> <td>Missing authorization in Microsoft Exchange Online allows an authorized=
attacker to elevate privileges over a network.</td>
<td>2026-06-19</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48582" target=3D= "_blank" rel=3D"noopener">CVE-2026-48582</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Malware Protection Engine= </td>
<td>Microsoft is aware of an elevation of privilege in the Microsoft Malwar=
e Protection Engine in Microsoft Defender publicly referred to as &quot= ;RoguePlanet &quot;. We are working to provide a high quality security = update that addresses this vulnerability. We will provide information in th=
is CVE when the update is available.</td>
<td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50656" target=3D= "_blank" rel=3D"noopener">CVE-2026-50656</a></td>
</tr>
<td class=3D"vendor-product">Microweber--Microweber</td>
<td>A weakness has been identified in Microweber up to 2.0.20. This affects=
the function userfiles_path of the file /api_nosession/thumbnail_img of th=
e component API Endpoint. Executing a manipulation of the argument cache_pa= th_relative can lead to path traversal. It is possible to launch the attack=
remotely. The exploit has been made available to the public and could be u= sed for attacks. The vendor was contacted early about this disclosure but d=
id not respond in any way.</td>
<td>2026-06-15</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12198" target=3D= "_blank" rel=3D"noopener">CVE-2026-12198</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--Ashtanga</td>
<td>Unauthenticated PHP Object Injection in Ashtanga <=3D 1.2 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40751" target=3D= "_blank" rel=3D"noopener">CVE-2026-40751</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--ChapterOne</td>
<td>Unauthenticated Local File Inclusion in ChapterOne <=3D 1.7 versions= .</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40731" target=3D= "_blank" rel=3D"noopener">CVE-2026-40731</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--Chteau</td>
<td>Unauthenticated PHP Object Injection in Ch=C3=83=C2=A2teau <=3D 1.2.=
1 versions.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40757" target=3D= "_blank" rel=3D"noopener">CVE-2026-40757</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--EasyMeals</td>
<td>Unauthenticated PHP Object Injection in EasyMeals <=3D 1.5.1 version= s.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40753" target=3D= "_blank" rel=3D"noopener">CVE-2026-40753</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--Esme</td>
<td>Unauthenticated PHP Object Injection in Esm=C3=83=C2=A9e <=3D 1.4 ve= rsions.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40759" target=3D= "_blank" rel=3D"noopener">CVE-2026-40759</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--Kastell</td>
<td>Unauthenticated Local File Inclusion in Kastell <=3D 2.0 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52707" target=3D= "_blank" rel=3D"noopener">CVE-2026-52707</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--LuxeDrive</td>
<td>Unauthenticated PHP Object Injection in LuxeDrive <=3D 1.4 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40739" target=3D= "_blank" rel=3D"noopener">CVE-2026-40739</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--Mikado Core</td> <td>Unauthenticated Local File Inclusion in Mikado Core <=3D 1.6 version= s.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39537" target=3D= "_blank" rel=3D"noopener">CVE-2026-39537</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--ShiftUp</td>
<td>Unauthenticated PHP Object Injection in ShiftUp <=3D 1.3 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40733" target=3D= "_blank" rel=3D"noopener">CVE-2026-40733</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--TechLink</td>
<td>Unauthenticated PHP Object Injection in TechLink <=3D 1.3 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40755" target=3D= "_blank" rel=3D"noopener">CVE-2026-40755</a></td>
</tr>
<td class=3D"vendor-product">Mikado-Themes--Zoya</td>
<td>Unauthenticated PHP Object Injection in Zoya <=3D 1.4 versions.</td> <td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40756" target=3D= "_blank" rel=3D"noopener">CVE-2026-40756</a></td>
</tr>
<td class=3D"vendor-product">Monetizemore--Advanced Ads</td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability=
in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affe= cts Advanced Ads: from n/a through 2.0.21.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54816" target=3D= "_blank" rel=3D"noopener">CVE-2026-54816</a></td>
</tr>
<td class=3D"vendor-product">Montodel--House-Rental-Management</td>
<td>A vulnerability was detected in Montodel House-Rental-Management up to = 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some un= known functionality of the file /login.php. The manipulation of the argumen=
t Username results in sql injection. The attack can be executed remotely. T=
he exploit is now public and may be used. This product implements a rolling=
release for ongoing delivery, which means version information for affected=
or updated releases is unavailable. The vendor was contacted early about t= his disclosure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12775" target=3D= "_blank" rel=3D"noopener">CVE-2026-12775</a></td>
</tr>
<td class=3D"vendor-product">Montonio--Montonio for WooCommerce</td> <td>Unauthenticated Broken Access Control in Montonio for WooCommerce <=
=3D 10.1.2 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48873" target=3D= "_blank" rel=3D"noopener">CVE-2026-48873</a></td>
</tr>
<td class=3D"vendor-product">Motive Commerce Search--AI Product Search for = WooCommerce Motive Commerce Search</td>
<td>Unauthenticated Broken Access Control in AI Product Search for WooComme= rce &#8211; Motive Commerce Search <=3D 1.38.2 versions.</td> <td>2026-06-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42664" target=3D= "_blank" rel=3D"noopener">CVE-2026-42664</a></td>
</tr>
<td class=3D"vendor-product">mra13 / Team Tips and Tricks HQ--Simple Shoppi=
ng Cart</td>
<td>Unauthenticated Insecure Direct Object References (IDOR) in Simple Shop= ping Cart <=3D 5.2.9 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48868" target=3D= "_blank" rel=3D"noopener">CVE-2026-48868</a></td>
</tr>
<td class=3D"vendor-product">multer--multer</td>
<td>Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulne= rable to a Denial of Service via deeply nested field names in multipart for=
m data. The append-field dependency parses bracket notation in field names = with no limit on nesting depth, allowing an attacker to force allocation of=
deeply nested object structures that consume CPU and memory. A single HTTP=
request with a crafted multipart body is sufficient to exploit this. Patch= es: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x p= rerelease) and configure the new limits.fieldNestingDepth option to the min= imum depth their application requires. Workarounds: Set limits.fields to a = reasonable value to reduce the number of fields an attacker can send per re= quest. This does not fully mitigate the issue but limits the impact.</td> <td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5079" target=3D"= _blank" rel=3D"noopener">CVE-2026-5079</a></td>
</tr>
<td class=3D"vendor-product">Myportfolio--Myportfolio</td>
<td>Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerabil= ity that allows unauthenticated attackers to manipulate database queries by=
injecting SQL code through the pid parameter. Attackers can send GET reque= sts to index.php with malicious pid values in the task=3Dproject&view= =3Dgrid endpoint to extract sensitive database information.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20280" target=3D= "_blank" rel=3D"noopener">CVE-2017-20280</a></td>
</tr>
<td class=3D"vendor-product">Mythemes--my flatonica</td>
<td>Unauthenticated Cross Site Scripting (XSS) in my flatonica <=3D 0.0.=
8 versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-49269" target=3D= "_blank" rel=3D"noopener">CVE-2024-49269</a></td>
</tr>
<td class=3D"vendor-product">Naked Cat Plugins (by Webdados)--Feed KuantoKu= sta for WooCommerce Free</td>
<td>Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce - Fre=
e <=3D 5.3 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39441" target=3D= "_blank" rel=3D"noopener">CVE-2026-39441</a></td>
</tr>
<td class=3D"vendor-product">NCEAS--metacat</td>
<td>Metacat is data repository software that helps researchers preserve, sh= are, and discover data. Versions 2.0.0 and and above contain an unauthentic= ated SQL injection in the /harvesterRegistration endpoint. HarvesterRegistr= ation.dbInsert() builds an INSERT against HARVEST_SITE_SCHEDULE via string = concatenation, using a quoteString() helper that performs raw single-quote = wrapping without escaping. Three request parameters reach the sink: unit, c= ontactEmail, and documentListURL. The servlet does not verify a real LDAP i= dentity. Allowing the vulnerable insert to proceed. Since the PostgreSQL ba= ckend permits stacked queries via Statement.executeUpdate(), this vulnerabi= lity allows full read/write/execute access in the Metacat database context.=
The vulnerability was remediated in Metacat 3.0.0.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48114" target=3D= "_blank" rel=3D"noopener">CVE-2026-48114</a></td>
</tr>
<td class=3D"vendor-product">nesquena--hermes-webui</td>
<td>Hermes WebUI before 0.51.368 contains an authorization bypass vulnerabi= lity in the get_profile_cookie() function that accepts unauthenticated prof= ile names from the hermes_profile cookie. An authenticated attacker can for=
ge the hermes_profile cookie value to bypass profile-scoped authorization c= hecks and access sessions, files, and resources across different profiles.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53871" target=3D= "_blank" rel=3D"noopener">CVE-2026-53871</a></td>
</tr>
<td class=3D"vendor-product">Netdrive--NetDrive</td>
<td>NetDrive 2.6.12 contains an unquoted service path vulnerability in the = Netdrive2_Service_Netdrive2 service that allows local users to execute arbi= trary code with SYSTEM privileges. Attackers can insert malicious executabl=
es in the system root path that will be executed during service startup or = system reboot, resulting in privilege escalation.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20092" target=3D= "_blank" rel=3D"noopener">CVE-2016-20092</a></td>
</tr>
<td class=3D"vendor-product">Network-Inventory-Advisor--Network Inventory A= dvisor</td>
<td>Network Inventory Advisor 5.0.26.0 installs the niaservice service with=
an unquoted binary path that allows local attackers to escalate privileges=
by placing malicious executables in intermediate directories. Attackers ca=
n exploit the unquoted path in the service configuration to execute arbitra=
ry code with LocalSystem privileges when the service starts or restarts.</t=
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25747" target=3D= "_blank" rel=3D"noopener">CVE-2019-25747</a></td>
</tr>
<td class=3D"vendor-product">Networkdls--Fortitude HTTP</td>
<td>Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability = that allows local users to execute arbitrary code with elevated privileges =
by exploiting the service binary path. Attackers can insert malicious execu= tables in the system root path that execute with SYSTEM privileges during s= ervice startup or system reboot.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20087" target=3D= "_blank" rel=3D"noopener">CVE-2016-20087</a></td>
</tr>
<td class=3D"vendor-product">Nexi Payments--Nexi XPay</td>
<td>Missing Authorization vulnerability in Nexi Payments Nexi XPay allows E= xploiting Incorrectly Configured Access Control Security Levels. This issue=
affects Nexi XPay: from n/a through 8.3.1.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54810" target=3D= "_blank" rel=3D"noopener">CVE-2026-54810</a></td>
</tr>
<td class=3D"vendor-product">nextgeneditor--NextGen Editor</td>
<td>Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability tha=
t allows unauthenticated attackers to execute arbitrary SQL commands throug=
h the plname parameter. Attackers can send GET requests to index.php with o= ption=3Dcom_nge&view=3Dconfig and inject malicious SQL code in the plna=
me parameter to extract sensitive database information.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20252" target=3D= "_blank" rel=3D"noopener">CVE-2017-20252</a></td>
</tr>
<td class=3D"vendor-product">NI--grpc-device</td>
<td>There is an untrusted pointer dereference vulnerability in the NI grpc-= device sideband streaming API that may allow an attacker to cause an arbitr= ary memory dereference, potentially resulting in remote code execution.=C2=
=A0 Successful exploitation requires an attacker=C2=A0 to supply a speciall=
y crafted=C2=A0Moniker protobuf message.=C2=A0 This affects NI grpc-device = 2.17.0 and prior versions.</td>
<td>2026-06-19</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48137" target=3D= "_blank" rel=3D"noopener">CVE-2026-48137</a></td>
</tr>
<td class=3D"vendor-product">NI--grpc-device</td>
<td>There is an insecure default credentials vulnerability in NI grpc-devic=
e when TLS configuration is not present and the server is bound beyond loop= back.=C2=A0 This may allow an unauthenticated user access to the server on = the local network.=C2=A0 This affects NI grpc-device 2.17.0 and prior versi= ons.</td>
<td>2026-06-19</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9142" target=3D"= _blank" rel=3D"noopener">CVE-2026-9142</a></td>
</tr>
<td class=3D"vendor-product">NI--grpc-device</td>
<td>There is an out-of-bounds read vulnerability in the NI grpc-device stre= aming API due to a missing bounds check that may result in a denial of serv= ice. Successful exploitation requires an attacker to supply a specially cra= fted write request. This affects NI grpc-device 2.17.0 and prior versions.<=
<td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48138" target=3D= "_blank" rel=3D"noopener">CVE-2026-48138</a></td>
</tr>
<td class=3D"vendor-product">NI--grpc-device</td>
<td>There is a NULL pointer dereference vulnerability in NI grpc-device in = the data moniker service that may allow an attacker to cause a denial of se= rvice by triggering a crash.=C2=A0 Successful exploitation requires an atta= cker to provide an unknown=C2=A0value to the data moniker service. This aff= ects NI grpc-device 2.17.0 and prior versions.</td>
<td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48139" target=3D= "_blank" rel=3D"noopener">CVE-2026-48139</a></td>
</tr>
<td class=3D"vendor-product">Ninja Team--FastDup</td>
<td>Unauthenticated Path Traversal in FastDup <=3D 2.7.2 versions.</td> <td>2026-06-15</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52703" target=3D= "_blank" rel=3D"noopener">CVE-2026-52703</a></td>
</tr>
<td class=3D"vendor-product">Nordmograph--StreetGuessr Game</td>
<td>Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability = that allows unauthenticated attackers to execute arbitrary SQL queries by i= njecting malicious code through the catid parameter. Attackers can send GET=
requests to index.php with the option=3Dcom_streetguess&view=3Dmaps pa= rameters and inject SQL code in the catid parameter to extract sensitive da= tabase information including version and database names.</td> <td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20271" target=3D= "_blank" rel=3D"noopener">CVE-2017-20271</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in We= bSocket endpoints that allows remote attackers to bypass Host and Origin va= lidation. FastAPI HTTP middleware does not execute for WebSocket upgrade re= quests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling = attackers to exploit DNS rebinding and inject malicious commands or read te= rminal output.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53869" target=3D= "_blank" rel=3D"noopener">CVE-2026-53869</a></td>
</tr>
<td class=3D"vendor-product">NSquared--Simply Schedule Appointments</td> <td>Unauthenticated SQL Injection in Simply Schedule Appointments <=3D 1= .6.9.27 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39493" target=3D= "_blank" rel=3D"noopener">CVE-2026-39493</a></td>
</tr>
<td class=3D"vendor-product">NSquared--Simply Schedule Appointments</td> <td>Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointme= nts <=3D 1.6.10.6 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39447" target=3D= "_blank" rel=3D"noopener">CVE-2026-39447</a></td>
</tr>
<td class=3D"vendor-product">NSquared--Simply Schedule Appointments</td> <td>Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments=
< 1.6.11.2 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42384" target=3D= "_blank" rel=3D"noopener">CVE-2026-42384</a></td>
</tr>
<td class=3D"vendor-product">Nur-Alam39--bus-ticket</td>
<td>Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99= c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vul= nerability in bus_info.php. The busid parameter received via HTTP POST is c= oncatenated directly into a MySQL query (select * from bus_info where id=3D= $busid) without sanitization, escaping, or parameterization, and in a numer=
ic (unquoted) context. A remote, unauthenticated attacker can inject arbitr= ary SQL - for example a UNION-based payload such as busid=3D-1 UNION SELECT=
1,2,3,4,5,6 - to read arbitrary data from the bus_service database. The ap= plication connects to the database as the MySQL root account with an empty = password, increasing the potential impact. The query is executed via mysqli= _query(), which does not permit stacked (semicolon-separated) statements.</=
<td>2026-06-18</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55740" target=3D= "_blank" rel=3D"noopener">CVE-2026-55740</a></td>
</tr>
<td class=3D"vendor-product">nv-tlabs--GEN3C</td>
<td>NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticat=
ed remote code execution vulnerability in the inference API server where th=
e /request-inference and /seed-model endpoints deserialize raw HTTP request=
bodies using Python's pickle.loads() without authentication or input valid= ation. Attackers can supply a crafted payload containing a __reduce__ gadge=
t to the inference API port to achieve remote code execution as the inferen=
ce process.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53805" target=3D= "_blank" rel=3D"noopener">CVE-2026-53805</a></td>
</tr>
<td class=3D"vendor-product">NVIDIA--NeMo Framework</td>
<td>NVIDIA NeMo Framework for all platforms contains a code injection vulne= rability. A successful exploit of this vulnerability might lead to code exe= cution, escalation of privileges, information disclosure, and data tamperin= g.</td>
<td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24155" target=3D= "_blank" rel=3D"noopener">CVE-2026-24155</a></td>
</tr>
<td class=3D"vendor-product">NVIDIA--NeMo Framework</td>
<td>NVIDIA NeMo Framework for Linux contains a vulnerability where an attac= ker may cause deserialization of untrusted data. A successful exploit of th=
is vulnerability may lead to code execution, escalation of privileges, data=
tampering, and information disclosure.</td>
<td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24228" target=3D= "_blank" rel=3D"noopener">CVE-2026-24228</a></td>
</tr>
<td class=3D"vendor-product">oleksandrz--E2Pdf Export Pdf Tool for WordPres= s</td>
<td>The E2Pdf - Export Pdf Tool for WordPress plugin for WordPress is vulne= rable to Missing Authorization in versions up to, and including, 1.32.26. T= his is due to the screen_action() function lacking a dedicated capability c= heck and nonce verification - when invoked via the ?action=3Dscreen routing=
path the controller's index_action() nonce gate is bypassed entirely - whi=
le reading an attacker-controlled option name and value from $_POST['wp_scr= een_options'] and passing them directly to update_option() with no allowlis=
t, relying solely on the page-level e2pdf_templates capability which the pl= ugin's own Permissions UI allows administrators to grant to any role includ= ing Subscriber, Contributor, Author, or Editor. This makes it possible for = authenticated attackers, with a custom role that has been granted the e2pdf= _templates capability, to overwrite arbitrary WordPress options such as def= ault_role and thereby escalate their privileges to administrator.</td> <td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12407" target=3D= "_blank" rel=3D"noopener">CVE-2026-12407</a></td>
</tr>
<td class=3D"vendor-product">OliveTin--OliveTin</td>
<td>OliveTin gives access to predefined shell commands from a web interface=
. In versions 3000.0.0 and prior, the template engine uses a single shared = text/template.Template instance (tpl package-level variable in service/inte= rnal/tpl/templates.go) across all goroutines. Every action execution calls = tpl.Parse(source) followed by t.Execute() on this shared instance with no s= ynchronization. When two or more actions execute concurrently (which is the=
normal case - each ExecRequest spawns a goroutine), a race condition occur=
s: one goroutine's Parse overwrites the template tree while another gorouti=
ne is calling Execute, causing cross-user command contamination, Go runtime=
panic, and incorrect command execution. This issue has been resolved in ve= rsion 3000.13.0.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48708" target=3D= "_blank" rel=3D"noopener">CVE-2026-48708</a></td>
</tr>
<td class=3D"vendor-product">Omnisend--Email Marketing for WooCommerce by O= mnisend</td>
<td>Unauthenticated Broken Authentication in Email Marketing for WooCommerc=
e by Omnisend <=3D 1.18.0 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42668" target=3D= "_blank" rel=3D"noopener">CVE-2026-42668</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is a self-hosted artificial intelligence platform designed t=
o operate entirely offline. Prior to 0.9.6, the terminal-server reverse pro=
xy in `backend/open_webui/routers/terminals.py` does not fully confine the = user-controlled `path` segment before forwarding it to an admin-configured = terminal server. An authenticated user who has been granted access to a ter= minal server can craft `path` values containing encoded `../` traversal seq= uences that escape the intended path (or policy) scope on that server, reac= hing unintended endpoints and files on the terminal-server host. Where the = terminal server fans requests out to internal services, this also gives SSR= F-style reach into those services. This is a separate code path from the `/= api/v1/retrieval/process/web` SSRF (GHSA-c6xv-rcvw-v685), with its own inpu=
t. Two distinct vectors are consolidated here: first, raw path forwarding /=
single-encoded traversal (original report); and second, a bypass of the su= bsequently-added `_sanitize_proxy_path` mitigation using double-encoded dot=
s (`%252e%252e`). The attacker-controlled input is the request `path`, supp= lied by the non-admin user, not anything an administrator configures, so th=
is is not an admin-trust / Rule-9 situation. Version 0.9.6 fixes the issue.= </td>
<td>2026-06-18</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54017" target=3D= "_blank" rel=3D"noopener">CVE-2026-54017</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.26 contains an authorization bypass vulnerabilit=
y where a surviving pairing-scoped device session can re-establish node tok=
en authority after revocation. Attackers with a paired device can regain We= bSocket node-level access without renewed approval, weakening revocation co= ntrols and maintaining unauthorized access longer than intended.</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53843" target=3D= "_blank" rel=3D"noopener">CVE-2026-53843</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.7 contains a privilege escalation vulnerability = where the allowFrom feature improperly validates Discord account identity u= sing mutable display names instead of immutable user IDs. Attackers with Di= scord accounts can change their display name to match a policy entry and ga=
in unauthorized agent access intended for another Discord identity.</td> <td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53849" target=3D= "_blank" rel=3D"noopener">CVE-2026-53849</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.12 contains an argument pattern validation bypas=
s in the exec allowlist that allows attackers to execute disallowed argumen=
ts for allowlisted executables on Linux and macOS systems. Attackers can by= pass configured argPattern restrictions by directly invoking allowlisted ex= ecutables with unrestricted arguments, potentially enabling unauthorized fi=
le access, network access, or command execution.</td>
<td>2026-06-16</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53853" target=3D= "_blank" rel=3D"noopener">CVE-2026-53853</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability a= llowing authenticated operators to weaken strict allowlist checks via shell=
positional parameters. Attackers can combine allowlisted tools with shell = positional arguments to place inline-eval content in shell carriers outside=
intended allowlist rules, enabling execution of unapproved shell-provided = content.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53855" target=3D= "_blank" rel=3D"noopener">CVE-2026-53855</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.3 contains a policy enforcement vulnerability wh= ere Zalo contacts with mutable display metadata could match allowFrom polic=
y entries through display name changes. Attackers with mutable display name=
s could receive agent responses intended for different Zalo identities when=
the feature is enabled.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53857" target=3D= "_blank" rel=3D"noopener">CVE-2026-53857</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.26 contains an insufficient sanitization vulnera= bility in the host environment sanitizer that allows Node.js control variab= les to bypass validation. Attackers with access to workspace .env files, to=
ol environment overrides, or skill environment blocks can pass malicious No= de.js control variables to influence child processes or coverage output pat= hs.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53864" target=3D= "_blank" rel=3D"noopener">CVE-2026-53864</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in=
shell inline-command parsing that allows authenticated operators to execut=
e unapproved commands. A command request using shell inline-command forms c= ould route through a parser case missing the expected allowlist decision, e= nabling shell content execution without intended approval prompts.</td> <td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53866" target=3D= "_blank" rel=3D"noopener">CVE-2026-53866</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.12 contains an information disclosure vulnerabil= ity in streamable-http MCP servers that forwards operator-configured custom=
headers during cross-origin redirects. Attackers controlling or compromisi=
ng an MCP endpoint can redirect requests to exfiltrate sensitive headers li=
ke API keys or tenant-routing credentials to attacker-controlled origins.</=
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53840" target=3D= "_blank" rel=3D"noopener">CVE-2026-53840</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.2 contains an environment variable injection vul= nerability allowing workspace .env files to influence Python runtime select= ion through CLOUDSDK_PYTHON during Gmail setup gcloud execution. Attackers = with repository access can manipulate the CLOUDSDK_PYTHON variable to execu=
te setup through unintended local Python paths, potentially enabling arbitr= ary code execution.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53842" target=3D= "_blank" rel=3D"noopener">CVE-2026-53842</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.4.29 contains a path traversal vulnerability in th=
e install helper that allows workspace .env files to override the npm_execp= ath configuration used for bundled runtime dependency installation. Attacke=
rs with workspace access can execute unintended local package-manager execu= tables during dependency setup to compromise the build environment.</td> <td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53846" target=3D= "_blank" rel=3D"noopener">CVE-2026-53846</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.2 contains an environment variable injection vul= nerability where workspace .env STATE_DIRECTORY could influence bundled run= time dependency roots. Attackers can manipulate the STATE_DIRECTORY variabl=
e to load runtime dependencies from unintended local paths, potentially exe= cuting malicious code during dependency resolution.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53858" target=3D= "_blank" rel=3D"noopener">CVE-2026-53858</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.4.25 contains an input validation vulnerability in=
tool group policy callers that accept unvalidated group IDs. Attackers who=
can supply a group ID to the policy resolver could trigger incorrect group= -policy decisions for tool invocations, potentially bypassing intended acce=
ss controls.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53863" target=3D= "_blank" rel=3D"noopener">CVE-2026-53863</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.2 contains a path traversal vulnerability in mai= ntenance task execution that allows workspace-derived service paths to infl= uence trash command selection. Attackers can execute unintended local execu= tables from operator-unintended paths during maintenance operations by mani= pulating workspace-derived environment paths.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53865" target=3D= "_blank" rel=3D"noopener">CVE-2026-53865</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--APM - Application Performa= nce Management</td>
<td>Vulnerability in the APM - Application Performance Management product o=
f Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported v= ersions that are affected are 13.5 and 24.1. Easily exploitable vulnerabili=
ty allows unauthenticated attacker with network access via HTTP to compromi=
se APM - Application Performance Management. Successful attacks of this vul= nerability can result in unauthorized creation, deletion or modification ac= cess to critical data or all APM - Application Performance Management acces= sible data and unauthorized ability to cause a hang or frequently repeatabl=
e crash (complete DOS) of APM - Application Performance Management. CVSS 3.=
1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3= .1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46858" target=3D= "_blank" rel=3D"noopener">CVE-2026-46858</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager</td> <td>Vulnerability in the Identity Manager product of Oracle Fusion Middlewa=
re (component: Core). Supported versions that are affected are 12.2.1.4.0 a=
nd 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attac= ker with network access via T3, IIOP to compromise Identity Manager. While = the vulnerability is in Identity Manager, attacks may significantly impact = additional products (scope change). Successful attacks of this vulnerabilit=
y can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.9 (Conf= identiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV= :N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35268" target=3D= "_blank" rel=3D"noopener">CVE-2026-35268</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager</td> <td>Vulnerability in the Identity Manager product of Oracle Fusion Middlewa=
re (component: OIM Legacy UI). Supported versions that are affected are 12.= 2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentic= ated attacker with network access via T3, IIOP to compromise Identity Manag= er. Successful attacks of this vulnerability can result in takeover of Iden= tity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Avail= ability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:= H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46807" target=3D= "_blank" rel=3D"noopener">CVE-2026-46807</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager</td> <td>Vulnerability in the Identity Manager product of Oracle Fusion Middlewa=
re (component: Security). Supported versions that are affected are 12.2.1.4=
.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged a= ttacker with network access via HTTP to compromise Identity Manager. Succes= sful attacks of this vulnerability can result in takeover of Identity Manag= er. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35265" target=3D= "_blank" rel=3D"noopener">CVE-2026-35265</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager</td> <td>Vulnerability in the Identity Manager product of Oracle Fusion Middlewa=
re (component: REST WebServices). Supported versions that are affected are = 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low priv= ileged attacker with network access via HTTP to compromise Identity Manager=
. Successful attacks of this vulnerability can result in takeover of Identi=
ty Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availab= ility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)= .</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35267" target=3D= "_blank" rel=3D"noopener">CVE-2026-35267</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager</td> <td>Vulnerability in the Identity Manager product of Oracle Fusion Middlewa=
re (component: REST WebServices). Supported versions that are affected are = 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthen= ticated attacker with network access via HTTP to compromise Identity Manage=
r. Successful attacks of this vulnerability can result in unauthorized crea= tion, deletion or modification access to critical data or all Identity Mana= ger accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vect= or: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35269" target=3D= "_blank" rel=3D"noopener">CVE-2026-35269</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager Connector= </td>
<td>Vulnerability in the Identity Manager Connector product of Oracle Fusio=
n Middleware (component: Mainframe Connectors). Supported versions that are=
affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability a= llows low privileged attacker with network access via HTTP to compromise Id= entity Manager Connector. While the vulnerability is in Identity Manager Co= nnector, attacks may significantly impact additional products (scope change=
). Successful attacks of this vulnerability can result in takeover of Ident= ity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C= :H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35294" target=3D= "_blank" rel=3D"noopener">CVE-2026-35294</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager Connector= </td>
<td>Vulnerability in the Identity Manager Connector product of Oracle Fusio=
n Middleware (component: Generic Unix Connector). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via HTTP to compromise = Identity Manager Connector. While the vulnerability is in Identity Manager = Connector, attacks may significantly impact additional products (scope chan= ge). Successful attacks of this vulnerability can result in takeover of Ide= ntity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrit=
y and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C= /C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46792" target=3D= "_blank" rel=3D"noopener">CVE-2026-46792</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager Connector= </td>
<td>Vulnerability in the Identity Manager Connector product of Oracle Fusio=
n Middleware (component: Database User). Supported versions that are affect=
ed are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows l=
ow privileged attacker with network access via HTTP to compromise Identity = Manager Connector. While the vulnerability is in Identity Manager Connector=
, attacks may significantly impact additional products (scope change). Succ= essful attacks of this vulnerability can result in takeover of Identity Man= ager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Ava= ilability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/= A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46793" target=3D= "_blank" rel=3D"noopener">CVE-2026-46793</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager Connector= </td>
<td>Vulnerability in the Identity Manager Connector product of Oracle Fusio=
n Middleware (component: Generic Unix Connector). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via SSH to compromise I= dentity Manager Connector. While the vulnerability is in Identity Manager C= onnector, attacks may significantly impact additional products (scope chang= e). Successful attacks of this vulnerability can result in takeover of Iden= tity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/= C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46794" target=3D= "_blank" rel=3D"noopener">CVE-2026-46794</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne A= ccounts Payable</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product =
of Oracle JD Edwards (component: Accounts Payable). The supported version t= hat is affected is 9.2. Easily exploitable vulnerability allows low privile= ged attacker with network access via HTTP to compromise JD Edwards Enterpri= seOne Accounts Payable. While the vulnerability is in JD Edwards Enterprise= One Accounts Payable, attacks may significantly impact additional products = (scope change). Successful attacks of this vulnerability can result in take= over of JD Edwards EnterpriseOne Accounts Payable. CVSS 3.1 Base Score 9.9 = (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3= .1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46908" target=3D= "_blank" rel=3D"noopener">CVE-2026-46908</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne A= ccounts Payable</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product =
of Oracle JD Edwards (component: Accounts Payable). The supported version t= hat is affected is 9.2. Easily exploitable vulnerability allows low privile= ged attacker with network access via HTTP to compromise JD Edwards Enterpri= seOne Accounts Payable. Successful attacks of this vulnerability can result=
in unauthorized creation, deletion or modification access to critical data=
or all JD Edwards EnterpriseOne Accounts Payable accessible data as well a=
s unauthorized access to critical data or complete access to all JD Edwards=
EnterpriseOne Accounts Payable accessible data. CVSS 3.1 Base Score 8.1 (C= onfidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= L/UI:N/S:U/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46891" target=3D= "_blank" rel=3D"noopener">CVE-2026-46891</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne G= eneral Ledger</td>
<td>Vulnerability in the JD Edwards EnterpriseOne General Ledger product of=
Oracle JD Edwards (component: E1 Foundation). The supported version that i=
s affected is 9.2. Easily exploitable vulnerability allows low privileged a= ttacker with network access via SMB to compromise JD Edwards EnterpriseOne = General Ledger. While the vulnerability is in JD Edwards EnterpriseOne Gene= ral Ledger, attacks may significantly impact additional products (scope cha= nge). Successful attacks of this vulnerability can result in takeover of JD=
Edwards EnterpriseOne General Ledger. CVSS 3.1 Base Score 9.9 (Confidentia= lity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L= /PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46893" target=3D= "_blank" rel=3D"noopener">CVE-2026-46893</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne H= uman Resources Management</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Human Resources Managemen=
t product of Oracle JD Edwards (component: Human Resources). The supported = version that is affected is 9.2. Easily exploitable vulnerability allows un= authenticated attacker with network access via HTTP to compromise JD Edward=
s EnterpriseOne Human Resources Management. Successful attacks of this vuln= erability can result in unauthorized creation, deletion or modification acc= ess to critical data or all JD Edwards EnterpriseOne Human Resources Manage= ment accessible data as well as unauthorized access to critical data or com= plete access to all JD Edwards EnterpriseOne Human Resources Management acc= essible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impact= s). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</td> <td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46892" target=3D= "_blank" rel=3D"noopener">CVE-2026-46892</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne O= rder Promising</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Order Promising product o=
f Oracle JD Edwards (component: Order Promising Integration). The supported=
version that is affected is 9.2. Easily exploitable vulnerability allows l=
ow privileged attacker with network access via HTTP to compromise JD Edward=
s EnterpriseOne Order Promising. While the vulnerability is in JD Edwards E= nterpriseOne Order Promising, attacks may significantly impact additional p= roducts (scope change). Successful attacks of this vulnerability can result=
in takeover of JD Edwards EnterpriseOne Order Promising. CVSS 3.1 Base Sco=
re 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: = (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46907" target=3D= "_blank" rel=3D"noopener">CVE-2026-46907</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne P= roject Costing</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Project Costing product o=
f Oracle JD Edwards (component: Job Costing). The supported version that is=
affected is 9.2. Easily exploitable vulnerability allows low privileged at= tacker with network access via JDENET to compromise JD Edwards EnterpriseOn=
e Project Costing. While the vulnerability is in JD Edwards EnterpriseOne P= roject Costing, attacks may significantly impact additional products (scope=
change). Successful attacks of this vulnerability can result in unauthoriz=
ed creation, deletion or modification access to critical data or all JD Edw= ards EnterpriseOne Project Costing accessible data as well as unauthorized = access to critical data or complete access to all JD Edwards EnterpriseOne = Project Costing accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality a=
nd Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I= :H/A:N).</td>
<td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46911" target=3D= "_blank" rel=3D"noopener">CVE-2026-46911</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via JDENET to compromi=
se JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability=
can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46878" target=3D= "_blank" rel=3D"noopener">CVE-2026-46878</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via JDENET to compromi=
se JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability=
can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46879" target=3D= "_blank" rel=3D"noopener">CVE-2026-46879</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via JDENET to compromi=
se JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability=
can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46880" target=3D= "_blank" rel=3D"noopener">CVE-2026-46880</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via JDENET to compromi=
se JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability=
can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46881" target=3D= "_blank" rel=3D"noopener">CVE-2026-46881</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via JDENET to compromi=
se JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability=
can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46882" target=3D= "_blank" rel=3D"noopener">CVE-2026-46882</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via JDENET to compromi=
se JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability=
can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46883" target=3D= "_blank" rel=3D"noopener">CVE-2026-46883</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via JDENET to compromi=
se JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability=
can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Sc= ore 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46904" target=3D= "_blank" rel=3D"noopener">CVE-2026-46904</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Web Runtime Security). Supported versions that are af= fected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauth= enticated attacker with network access via HTTP to compromise JD Edwards En= terpriseOne Tools. Successful attacks of this vulnerability can result in t= akeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confide= ntiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/= AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46905" target=3D= "_blank" rel=3D"noopener">CVE-2026-46905</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows low privileged attacker with network access via HTTP to compromise =
JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards En= terpriseOne Tools, attacks may significantly impact additional products (sc= ope change). Successful attacks of this vulnerability can result in unautho= rized creation, deletion or modification access to critical data or all JD = Edwards EnterpriseOne Tools accessible data as well as unauthorized access =
to critical data or complete access to all JD Edwards EnterpriseOne Tools a= ccessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impa= cts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).</td> <td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46906" target=3D= "_blank" rel=3D"noopener">CVE-2026-46906</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via HTTP to compromise=
JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability c=
an result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Scor=
e 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46909" target=3D= "_blank" rel=3D"noopener">CVE-2026-46909</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Enterprise Infrastructure Security). Supported versio=
ns that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via HTTP to compromise=
JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability c=
an result in unauthorized access to critical data or complete access to all=
JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to=
cause a hang or frequently repeatable crash (complete DOS) of JD Edwards E= nterpriseOne Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).</=
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46910" target=3D= "_blank" rel=3D"noopener">CVE-2026-46910</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Web Runtime Security). Supported versions that are af= fected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauth= enticated attacker with network access via HTTP to compromise JD Edwards En= terpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne T= ools, attacks may significantly impact additional products (scope change). = Successful attacks of this vulnerability can result in unauthorized access =
to critical data or complete access to all JD Edwards EnterpriseOne Tools a= ccessible data as well as unauthorized update, insert or delete access to s= ome of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score = 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC= :L/PR:N/UI:N/S:C/C:H/I:L/A:N).</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46912" target=3D= "_blank" rel=3D"noopener">CVE-2026-46912</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Installation Security). Supported versions that are a= ffected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unaut= henticated attacker with logon to the infrastructure where JD Edwards Enter= priseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. While=
the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may signif= icantly impact additional products (scope change). Successful attacks of th=
is vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. = CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impact= s). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46913" target=3D= "_blank" rel=3D"noopener">CVE-2026-46913</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--JD Edwards EnterpriseOne T= ools</td>
<td>Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle J=
D Edwards (component: Business Logic Infrastructure Security). Supported ve= rsions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerabi= lity allows low privileged attacker with network access via HTTP to comprom= ise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerabilit=
y can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base S= core 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46903" target=3D= "_blank" rel=3D"noopener">CVE-2026-46903</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL NDB Cluster</td> <td>Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (compone= nt: Cluster: NDB Operator). Supported versions that are affected are 8.0.11= -8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allo=
ws low privileged attacker with network access via HTTP to compromise MySQL=
NDB Cluster. While the vulnerability is in MySQL NDB Cluster, attacks may = significantly impact additional products (scope change). Successful attacks=
of this vulnerability can result in unauthorized creation, deletion or mod= ification access to critical data or all MySQL NDB Cluster accessible data =
as well as unauthorized access to critical data or complete access to all M= ySQL NDB Cluster accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality = and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/= I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46861" target=3D= "_blank" rel=3D"noopener">CVE-2026-46861</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL Router</td> <td>Vulnerability in the MySQL Router product of Oracle MySQL (component: R= outer: General). Supported versions that are affected are 9.0.0-9.7.0. Easi=
ly exploitable vulnerability allows unauthenticated attacker with network a= ccess via HTTP to compromise MySQL Router. Successful attacks of this vulne= rability can result in takeover of MySQL Router. CVSS 3.1 Base Score 9.8 (C= onfidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1= /AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46860" target=3D= "_blank" rel=3D"noopener">CVE-2026-46860</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL Router</td> <td>Vulnerability in the MySQL Router product of Oracle MySQL (component: R= outer: General). Supported versions that are affected are 8.4.0-8.4.9 and 9= .0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacke=
r with network access via TLS to compromise MySQL Router. Successful attack=
s of this vulnerability can result in unauthorized ability to cause a hang =
or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Bas=
e Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/U= I:N/S:U/C:N/I:N/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46862" target=3D= "_blank" rel=3D"noopener">CVE-2026-46862</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL Server</td> <td>Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQ=
L (component: Server: Connection Handling). Supported versions that are aff= ected are MySQL Server: 8.4.0-8.4.9, 9.0.0-9.7.0; MySQL Cluster: 8.0.11-8.0= .46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows u= nauthenticated attacker with network access via multiple protocols to compr= omise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability=
can result in unauthorized ability to cause a hang or frequently repeatabl=
e crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score = 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/= C:N/I:N/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46863" target=3D= "_blank" rel=3D"noopener">CVE-2026-46863</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL Shell</td> <td>Vulnerability in the MySQL Shell product of Oracle MySQL (component: Sh= ell for VS Code). The supported version that is affected is 2026.2.0+9.6.1.=
Easily exploitable vulnerability allows low privileged attacker with netwo=
rk access via HTTP to compromise MySQL Shell. While the vulnerability is in=
MySQL Shell, attacks may significantly impact additional products (scope c= hange). Successful attacks of this vulnerability can result in takeover of = MySQL Shell. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availa= bility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H= ).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46850" target=3D= "_blank" rel=3D"noopener">CVE-2026-46850</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL Shell</td> <td>Vulnerability in the MySQL Shell product of Oracle MySQL (component: Sh= ell for VS Code). The supported version that is affected is 2026.2.0+9.6.1.=
Difficult to exploit vulnerability allows low privileged attacker with net= work access via multiple protocols to compromise MySQL Shell. While the vul= nerability is in MySQL Shell, attacks may significantly impact additional p= roducts (scope change). Successful attacks of this vulnerability can result=
in takeover of MySQL Shell. CVSS 3.1 Base Score 8.5 (Confidentiality, Inte= grity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N= /S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46870" target=3D= "_blank" rel=3D"noopener">CVE-2026-46870</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Access Manager</td> <td>Vulnerability in the Oracle Access Manager product of Oracle Fusion Mid= dleware (component: Authentication Engine). Supported versions that are aff= ected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allow=
s low privileged attacker with network access via HTTP to compromise Oracle=
Access Manager. While the vulnerability is in Oracle Access Manager, attac=
ks may significantly impact additional products (scope change). Successful = attacks of this vulnerability can result in takeover of Oracle Access Manag= er. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35313" target=3D= "_blank" rel=3D"noopener">CVE-2026-35313</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Access Manager</td> <td>Vulnerability in the Oracle Access Manager product of Oracle Fusion Mid= dleware (component: Web Server Plugin). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows un= authenticated attacker with network access via HTTP to compromise Oracle Ac= cess Manager. Successful attacks of this vulnerability can result in unauth= orized update, insert or delete access to some of Oracle Access Manager acc= essible data as well as unauthorized read access to a subset of Oracle Acce=
ss Manager accessible data and unauthorized ability to cause a partial deni=
al of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7=
.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS= S:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</td>
<td>2026-06-16</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35314" target=3D= "_blank" rel=3D"noopener">CVE-2026-35314</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Advanced Outbound T= elephony</td>
<td>Vulnerability in the Oracle Advanced Outbound Telephony product of Orac=
le E-Business Suite (component: Internal Operations). Supported versions th=
at are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows=
unauthenticated attacker with network access via HTTP to compromise Oracle=
Advanced Outbound Telephony. Successful attacks of this vulnerability can = result in unauthorized creation, deletion or modification access to critica=
l data or all Oracle Advanced Outbound Telephony accessible data as well as=
unauthorized access to critical data or complete access to all Oracle Adva= nced Outbound Telephony accessible data. CVSS 3.1 Base Score 9.1 (Confident= iality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S= :U/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46949" target=3D= "_blank" rel=3D"noopener">CVE-2026-46949</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Advanced Outbound T= elephony</td>
<td>Vulnerability in the Oracle Advanced Outbound Telephony product of Orac=
le E-Business Suite (component: Internal Operations). Supported versions th=
at are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = Advanced Outbound Telephony. Successful attacks of this vulnerability can r= esult in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Scor=
e 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46947" target=3D= "_blank" rel=3D"noopener">CVE-2026-46947</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Advanced Outbound T= elephony</td>
<td>Vulnerability in the Oracle Advanced Outbound Telephony product of Orac=
le E-Business Suite (component: Internal Operations). Supported versions th=
at are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = Advanced Outbound Telephony. Successful attacks of this vulnerability can r= esult in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Scor=
e 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46950" target=3D= "_blank" rel=3D"noopener">CVE-2026-46950</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Agile PLM</td> <td>Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (c= omponent: Security). The supported version that is affected is 9.3.6. Easil=
y exploitable vulnerability allows unauthenticated attacker with network ac= cess via HTTP to compromise Oracle Agile PLM. Successful attacks of this vu= lnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score=
9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46859" target=3D= "_blank" rel=3D"noopener">CVE-2026-46859</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Application Develop= ment Framework (ADF)</td>
<td>Vulnerability in the Oracle Application Development Framework (ADF) pro= duct of Oracle Fusion Middleware (component: ADF Shared Components). Suppor= ted versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploi= table vulnerability allows high privileged attacker with network access via=
HTTP to compromise Oracle Application Development Framework (ADF). Success= ful attacks of this vulnerability can result in takeover of Oracle Applicat= ion Development Framework (ADF). CVSS 3.1 Base Score 7.2 (Confidentiality, = Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/= UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46769" target=3D= "_blank" rel=3D"noopener">CVE-2026-46769</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Applications Manage= r</td>
<td>Vulnerability in the Oracle Applications Manager product of Oracle E-Bu= siness Suite (component: Internal Operations). Supported versions that are = affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low pr= ivileged attacker with network access via HTTP to compromise Oracle Applica= tions Manager. While the vulnerability is in Oracle Applications Manager, a= ttacks may significantly impact additional products (scope change). Success= ful attacks of this vulnerability can result in takeover of Oracle Applicat= ions Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Avail= ability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:= H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46933" target=3D= "_blank" rel=3D"noopener">CVE-2026-46933</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Coherence</td> <td>Vulnerability in the Oracle Coherence product of Oracle Fusion Middlewa=
re (component: Core). Supported versions that are affected are 12.2.1.4.0, = 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability all= ows unauthenticated attacker with network access via HTTP to compromise Ora= cle Coherence. While the vulnerability is in Oracle Coherence, attacks may = significantly impact additional products (scope change). Successful attacks=
of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1=
Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVS=
S Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35307" target=3D= "_blank" rel=3D"noopener">CVE-2026-35307</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Coherence</td> <td>Vulnerability in the Oracle Coherence product of Oracle Fusion Middlewa=
re (component: Centralized Third Party Jars). Supported versions that are a= ffected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily explo= itable vulnerability allows unauthenticated attacker with network access vi=
a HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle=
Coherence, attacks may significantly impact additional products (scope cha= nge). Successful attacks of this vulnerability can result in takeover of Or= acle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Av= ailability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H= /A:H).</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35308" target=3D= "_blank" rel=3D"noopener">CVE-2026-35308</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Coherence</td> <td>Vulnerability in the Oracle Coherence product of Oracle Fusion Middlewa=
re (component: Core). Supported versions that are affected are 12.2.1.4.0, = 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability all= ows unauthenticated attacker with network access via HTTPS to compromise Or= acle Coherence. Successful attacks of this vulnerability can result in take= over of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integri=
ty and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:= U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35304" target=3D= "_blank" rel=3D"noopener">CVE-2026-35304</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Coherence</td> <td>Vulnerability in the Oracle Coherence product of Oracle Fusion Middlewa=
re (component: Centralized Third Party Jars). The supported version that is=
affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenti= cated attacker with network access via HTTP to compromise Oracle Coherence.=
While the vulnerability is in Oracle Coherence, attacks may significantly = impact additional products (scope change). Successful attacks of this vulne= rability can result in unauthorized access to critical data or complete acc= ess to all Oracle Coherence accessible data as well as unauthorized update,=
insert or delete access to some of Oracle Coherence accessible data. CVSS = 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35305" target=3D= "_blank" rel=3D"noopener">CVE-2026-35305</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Coherence</td> <td>Vulnerability in the Oracle Coherence product of Oracle Fusion Middlewa=
re (component: Centralized Third Party Jars). The supported version that is=
affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenti= cated attacker with network access via HTTP to compromise Oracle Coherence.=
While the vulnerability is in Oracle Coherence, attacks may significantly = impact additional products (scope change). Successful attacks of this vulne= rability can result in unauthorized access to critical data or complete acc= ess to all Oracle Coherence accessible data as well as unauthorized update,=
insert or delete access to some of Oracle Coherence accessible data. CVSS = 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35306" target=3D= "_blank" rel=3D"noopener">CVE-2026-35306</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Coherence</td> <td>Vulnerability in the Oracle Coherence product of Oracle Fusion Middlewa=
re (component: Centralized Third Party Jars). Supported versions that are a= ffected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily explo= itable vulnerability allows unauthenticated attacker with network access vi=
a HTTP to compromise Oracle Coherence. Successful attacks of this vulnerabi= lity can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (C= onfidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1= /AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35309" target=3D= "_blank" rel=3D"noopener">CVE-2026-35309</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Coherence</td> <td>Vulnerability in the Oracle Coherence product of Oracle Fusion Middlewa=
re (component: Core). Supported versions that are affected are 12.2.1.4.0, = 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability all= ows unauthenticated attacker with network access via HTTP to compromise Ora= cle Coherence. Successful attacks of this vulnerability can result in takeo= ver of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrit=
y and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U= /C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35310" target=3D= "_blank" rel=3D"noopener">CVE-2026-35310</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Complex Maintenance=
, Repair and Overhaul</td>
<td>Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul pr= oduct of Oracle E-Business Suite (component: Production). Supported version=
s that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability = allows low privileged attacker with network access via HTTP to compromise O= racle Complex Maintenance, Repair and Overhaul. While the vulnerability is =
in Oracle Complex Maintenance, Repair and Overhaul, attacks may significant=
ly impact additional products (scope change). Successful attacks of this vu= lnerability can result in takeover of Oracle Complex Maintenance, Repair an=
d Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availab= ility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)= .</td>
<td>2026-06-16</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46915" target=3D= "_blank" rel=3D"noopener">CVE-2026-46915</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Complex Maintenance=
, Repair and Overhaul</td>
<td>Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul pr= oduct of Oracle E-Business Suite (component: Internal Operations). Supporte=
d versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulne= rability allows low privileged attacker with network access via HTTP to com= promise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks=
of this vulnerability can result in takeover of Oracle Complex Maintenance=
, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C= :H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46934" target=3D= "_blank" rel=3D"noopener">CVE-2026-46934</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Complex Maintenance=
, Repair and Overhaul</td>
<td>Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul pr= oduct of Oracle E-Business Suite (component: Internal Operations). Supporte=
d versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulne= rability allows low privileged attacker with network access via HTTP to com= promise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks=
of this vulnerability can result in takeover of Oracle Complex Maintenance=
, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C= :H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46935" target=3D= "_blank" rel=3D"noopener">CVE-2026-46935</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Configure to Order<=
<td>Vulnerability in the Oracle Configure to Order product of Oracle E-Busi= ness Suite (component: Supply to Order Workbench). Supported versions that = are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Con= figure to Order. Successful attacks of this vulnerability can result in una= uthorized creation, deletion or modification access to critical data or all=
Oracle Configure to Order accessible data as well as unauthorized access t=
o critical data or complete access to all Oracle Configure to Order accessi= ble data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). = CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</td> <td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46939" target=3D= "_blank" rel=3D"noopener">CVE-2026-46939</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Cost Management</td=
<td>Vulnerability in the Oracle Cost Management product of Oracle E-Busines=
s Suite (component: Cost Planning). Supported versions that are affected ar=
e 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged at= tacker with network access via HTTP to compromise Oracle Cost Management. S= uccessful attacks of this vulnerability can result in takeover of Oracle Co=
st Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46929" target=3D= "_blank" rel=3D"noopener">CVE-2026-46929</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Cost Management</td=
<td>Vulnerability in the Oracle Cost Management product of Oracle E-Busines=
s Suite (component: Cost Planning). Supported versions that are affected ar=
e 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged at= tacker with network access via HTTP to compromise Oracle Cost Management. S= uccessful attacks of this vulnerability can result in takeover of Oracle Co=
st Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46940" target=3D= "_blank" rel=3D"noopener">CVE-2026-46940</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Cost Management</td=
<td>Vulnerability in the Oracle Cost Management product of Oracle E-Busines=
s Suite (component: Cost Planning). Supported versions that are affected ar=
e 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged a= ttacker with network access via HTTP to compromise Oracle Cost Management. = Successful attacks of this vulnerability can result in takeover of Oracle C= ost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Ava= ilability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/= A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46938" target=3D= "_blank" rel=3D"noopener">CVE-2026-46938</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Data Integrator</td=
<td>Vulnerability in the Oracle Data Integrator product of Oracle Fusion Mi= ddleware (component: Market Place). Supported versions that are affected ar=
e 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr= ivileged attacker with network access via HTTP to compromise Oracle Data In= tegrator. Successful attacks of this vulnerability can result in unauthoriz=
ed creation, deletion or modification access to critical data or all Oracle=
Data Integrator accessible data as well as unauthorized access to critical=
data or complete access to all Oracle Data Integrator accessible data and = unauthorized ability to cause a partial denial of service (partial DOS) of = Oracle Data Integrator. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/= C:H/I:H/A:L).</td>
<td>2026-06-16</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35262" target=3D= "_blank" rel=3D"noopener">CVE-2026-35262</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Asset Ma= nagement</td>
<td>Vulnerability in the Oracle Enterprise Asset Management product of Orac=
le E-Business Suite (component: Internal Operations). Supported versions th=
at are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = Enterprise Asset Management. Successful attacks of this vulnerability can r= esult in takeover of Oracle Enterprise Asset Management. CVSS 3.1 Base Scor=
e 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46931" target=3D= "_blank" rel=3D"noopener">CVE-2026-46931</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Asset Ma= nagement</td>
<td>Vulnerability in the Oracle Enterprise Asset Management product of Orac=
le E-Business Suite (component: Internal Operations). Supported versions th=
at are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = Enterprise Asset Management. Successful attacks of this vulnerability can r= esult in unauthorized access to critical data or complete access to all Ora= cle Enterprise Asset Management accessible data and unauthorized ability to=
cause a partial denial of service (partial DOS) of Oracle Enterprise Asset=
Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impa= cts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).</td> <td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46932" target=3D= "_blank" rel=3D"noopener">CVE-2026-46932</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle Enterprise=
Command Center Framework. While the vulnerability is in Oracle Enterprise = Command Center Framework, attacks may significantly impact additional produ= cts (scope change). Successful attacks of this vulnerability can result in = takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46895" target=3D= "_blank" rel=3D"noopener">CVE-2026-46895</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows high priv= ileged attacker with network access via HTTP to compromise Oracle Enterpris=
e Command Center Framework. While the vulnerability is in Oracle Enterprise=
Command Center Framework, attacks may significantly impact additional prod= ucts (scope change). Successful attacks of this vulnerability can result in=
takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Scor=
e 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46896" target=3D= "_blank" rel=3D"noopener">CVE-2026-46896</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle Enterprise=
Command Center Framework. While the vulnerability is in Oracle Enterprise = Command Center Framework, attacks may significantly impact additional produ= cts (scope change). Successful attacks of this vulnerability can result in = unauthorized creation, deletion or modification access to critical data or = all Oracle Enterprise Command Center Framework accessible data as well as u= nauthorized access to critical data or complete access to all Oracle Enterp= rise Command Center Framework accessible data and unauthorized ability to c= ause a partial denial of service (partial DOS) of Oracle Enterprise Command=
Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and = Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I= :H/A:L).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46897" target=3D= "_blank" rel=3D"noopener">CVE-2026-46897</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle Enterprise=
Command Center Framework. While the vulnerability is in Oracle Enterprise = Command Center Framework, attacks may significantly impact additional produ= cts (scope change). Successful attacks of this vulnerability can result in = unauthorized creation, deletion or modification access to critical data or = all Oracle Enterprise Command Center Framework accessible data as well as u= nauthorized access to critical data or complete access to all Oracle Enterp= rise Command Center Framework accessible data. CVSS 3.1 Base Score 9.6 (Con= fidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/= UI:N/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46899" target=3D= "_blank" rel=3D"noopener">CVE-2026-46899</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTPS to compromise Oracle Enterpris=
e Command Center Framework. While the vulnerability is in Oracle Enterprise=
Command Center Framework, attacks may significantly impact additional prod= ucts (scope change). Successful attacks of this vulnerability can result in=
takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Scor=
e 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46900" target=3D= "_blank" rel=3D"noopener">CVE-2026-46900</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle Enterprise=
Command Center Framework. While the vulnerability is in Oracle Enterprise = Command Center Framework, attacks may significantly impact additional produ= cts (scope change). Successful attacks of this vulnerability can result in = unauthorized creation, deletion or modification access to critical data or = all Oracle Enterprise Command Center Framework accessible data as well as u= nauthorized access to critical data or complete access to all Oracle Enterp= rise Command Center Framework accessible data and unauthorized ability to c= ause a partial denial of service (partial DOS) of Oracle Enterprise Command=
Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and = Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I= :H/A:L).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46901" target=3D= "_blank" rel=3D"noopener">CVE-2026-46901</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows unauthent= icated attacker with network access via HTTPS to compromise Oracle Enterpri=
se Command Center Framework. Successful attacks of this vulnerability can r= esult in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 B= ase Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS V= ector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46902" target=3D= "_blank" rel=3D"noopener">CVE-2026-46902</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Command = Center Framework</td>
<td>Vulnerability in the Oracle Enterprise Command Center Framework product=
of Oracle E-Business Suite (component: Core). Supported versions that are = affected are V15 and V16. Easily exploitable vulnerability allows unauthent= icated attacker with network access via HTTPS to compromise Oracle Enterpri=
se Command Center Framework. Successful attacks require human interaction f= rom a person other than the attacker. Successful attacks of this vulnerabil= ity can result in unauthorized creation, deletion or modification access to=
critical data or all Oracle Enterprise Command Center Framework accessible=
data as well as unauthorized access to critical data or complete access to=
all Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 B= ase Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3= .1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46898" target=3D= "_blank" rel=3D"noopener">CVE-2026-46898</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Discovery Framework). Supported vers= ions that are affected are 13.5 and 24.1. Easily exploitable vulnerability = allows low privileged attacker with network access via HTTPS to compromise = Oracle Enterprise Manager Base Platform. While the vulnerability is in Orac=
le Enterprise Manager Base Platform, attacks may significantly impact addit= ional products (scope change). Successful attacks of this vulnerability can=
result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Ba=
se Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Ve= ctor: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46832" target=3D= "_blank" rel=3D"noopener">CVE-2026-46832</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Metadata Plugin). Supported versions=
that are affected are 13.5 and 24.1. Easily exploitable vulnerability allo=
ws low privileged attacker with network access via HTTPS to compromise Orac=
le Enterprise Manager Base Platform. While the vulnerability is in Oracle E= nterprise Manager Base Platform, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base S= core 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46852" target=3D= "_blank" rel=3D"noopener">CVE-2026-46852</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Metadata Plugin). Supported versions=
that are affected are 13.5 and 24.1. Easily exploitable vulnerability allo=
ws unauthenticated attacker with network access via HTTP to compromise Orac=
le Enterprise Manager Base Platform. Successful attacks require human inter= action from a person other than the attacker and while the vulnerability is=
in Oracle Enterprise Manager Base Platform, attacks may significantly impa=
ct additional products (scope change). Successful attacks of this vulnerabi= lity can result in takeover of Oracle Enterprise Manager Base Platform. CVS=
S 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).=
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46853" target=3D= "_blank" rel=3D"noopener">CVE-2026-46853</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Target Management). Supported versio=
ns that are affected are 13.5 and 24.1. Easily exploitable vulnerability al= lows low privileged attacker with network access via HTTP to compromise Ora= cle Enterprise Manager Base Platform. While the vulnerability is in Oracle = Enterprise Manager Base Platform, attacks may significantly impact addition=
al products (scope change). Successful attacks of this vulnerability can re= sult in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base = Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vecto=
r: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46854" target=3D= "_blank" rel=3D"noopener">CVE-2026-46854</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Metadata Plugin). Supported versions=
that are affected are 13.5 and 24.1. Easily exploitable vulnerability allo=
ws low privileged attacker with network access via HTTPS to compromise Orac=
le Enterprise Manager Base Platform. While the vulnerability is in Oracle E= nterprise Manager Base Platform, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base S= core 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46855" target=3D= "_blank" rel=3D"noopener">CVE-2026-46855</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Metadata Plugin). Supported versions=
that are affected are 13.5 and 24.1. Easily exploitable vulnerability allo=
ws unauthenticated attacker with network access via HTTP to compromise Orac=
le Enterprise Manager Base Platform. Successful attacks require human inter= action from a person other than the attacker and while the vulnerability is=
in Oracle Enterprise Manager Base Platform, attacks may significantly impa=
ct additional products (scope change). Successful attacks of this vulnerabi= lity can result in takeover of Oracle Enterprise Manager Base Platform. CVS=
S 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).=
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46856" target=3D= "_blank" rel=3D"noopener">CVE-2026-46856</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Oracle Management Service). Supporte=
d versions that are affected are 13.5 and 24.1. Easily exploitable vulnerab= ility allows unauthenticated attacker with network access via HTTP to compr= omise Oracle Enterprise Manager Base Platform. Successful attacks of this v= ulnerability can result in takeover of Oracle Enterprise Manager Base Platf= orm. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability i= mpacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46857" target=3D= "_blank" rel=3D"noopener">CVE-2026-46857</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Install). Supported versions that ar=
e affected are 13.5 and 24.1. Easily exploitable vulnerability allows high = privileged attacker with network access via HTTPS to compromise Oracle Ente= rprise Manager Base Platform. While the vulnerability is in Oracle Enterpri=
se Manager Base Platform, attacks may significantly impact additional produ= cts (scope change). Successful attacks of this vulnerability can result in = unauthorized creation, deletion or modification access to critical data or = all Oracle Enterprise Manager Base Platform accessible data as well as unau= thorized read access to a subset of Oracle Enterprise Manager Base Platform=
accessible data and unauthorized ability to cause a hang or frequently rep= eatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CV=
SS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts)=
. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H).</td> <td>2026-06-16</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46872" target=3D= "_blank" rel=3D"noopener">CVE-2026-46872</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Deployment Library). Supported versi= ons that are affected are 13.5 and 24.1. Easily exploitable vulnerability a= llows high privileged attacker with network access via HTTPS to compromise = Oracle Enterprise Manager Base Platform. While the vulnerability is in Orac=
le Enterprise Manager Base Platform, attacks may significantly impact addit= ional products (scope change). Successful attacks of this vulnerability can=
result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Ba=
se Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Ve= ctor: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46875" target=3D= "_blank" rel=3D"noopener">CVE-2026-46875</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Agent Next Gen). Supported versions = that are affected are 13.5 and 24.1. Easily exploitable vulnerability allow=
s low privileged attacker with network access via SSH to compromise Oracle = Enterprise Manager Base Platform. Successful attacks of this vulnerability = can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1=
Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS=
Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46864" target=3D= "_blank" rel=3D"noopener">CVE-2026-46864</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Extensibility Framework). Supported = versions that are affected are 13.5 and 24.1. Easily exploitable vulnerabil= ity allows high privileged attacker with logon to the infrastructure where = Oracle Enterprise Manager Base Platform executes to compromise Oracle Enter= prise Manager Base Platform. While the vulnerability is in Oracle Enterpris=
e Manager Base Platform, attacks may significantly impact additional produc=
ts (scope change). Successful attacks of this vulnerability can result in t= akeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.2=
(Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:= 3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46865" target=3D= "_blank" rel=3D"noopener">CVE-2026-46865</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Agent Next Gen). Supported versions = that are affected are 13.5 and 24.1. Easily exploitable vulnerability allow=
s unauthenticated attacker with network access via HTTPS to compromise Orac=
le Enterprise Manager Base Platform. Successful attacks of this vulnerabili=
ty can result in unauthorized ability to cause a hang or frequently repeata= ble crash (complete DOS) of Oracle Enterprise Manager Base Platform as well=
as unauthorized update, insert or delete access to some of Oracle Enterpri=
se Manager Base Platform accessible data. CVSS 3.1 Base Score 8.2 (Integrit=
y and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U= /C:N/I:L/A:H).</td>
<td>2026-06-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46866" target=3D= "_blank" rel=3D"noopener">CVE-2026-46866</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Extensibility Framework). Supported = versions that are affected are 13.5 and 24.1. Easily exploitable vulnerabil= ity allows high privileged attacker with network access via HTTPS to compro= mise Oracle Enterprise Manager Base Platform. Successful attacks of this vu= lnerability can result in takeover of Oracle Enterprise Manager Base Platfo= rm. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46867" target=3D= "_blank" rel=3D"noopener">CVE-2026-46867</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Enterprise Manager = Base Platform</td>
<td>Vulnerability in the Oracle Enterprise Manager Base Platform product of=
Oracle Enterprise Manager (component: Extensibility Framework). Supported = versions that are affected are 13.5 and 24.1. Easily exploitable vulnerabil= ity allows high privileged attacker with network access via HTTPS to compro= mise Oracle Enterprise Manager Base Platform. Successful attacks of this vu= lnerability can result in takeover of Oracle Enterprise Manager Base Platfo= rm. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46868" target=3D= "_blank" rel=3D"noopener">CVE-2026-46868</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Financials for EMEA= </td>
<td>Vulnerability in the Oracle Financials for EMEA product of Oracle E-Bus= iness Suite (component: Internal Operations). Supported versions that are a= ffected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high pr= ivileged attacker with network access via HTTP to compromise Oracle Financi= als for EMEA. Successful attacks of this vulnerability can result in takeov=
er of Oracle Financials for EMEA. CVSS 3.1 Base Score 7.2 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H= /UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46969" target=3D= "_blank" rel=3D"noopener">CVE-2026-46969</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle HR Intelligence</td=
<td>Vulnerability in the Oracle HR Intelligence product of Oracle E-Busines=
s Suite (component: Internal Operations). Supported versions that are affec= ted are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privil= eged attacker with network access via HTTP to compromise Oracle HR Intellig= ence. Successful attacks of this vulnerability can result in takeover of Or= acle HR Intelligence. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity a=
nd Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:= H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46922" target=3D= "_blank" rel=3D"noopener">CVE-2026-46922</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle HR Intelligence</td=
<td>Vulnerability in the Oracle HR Intelligence product of Oracle E-Busines=
s Suite (component: Internal Operations). Supported versions that are affec= ted are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privil= eged attacker with network access via HTTP to compromise Oracle HR Intellig= ence. Successful attacks of this vulnerability can result in takeover of Or= acle HR Intelligence. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity a=
nd Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:= H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46970" target=3D= "_blank" rel=3D"noopener">CVE-2026-46970</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle HR Intelligence</td=
<td>Vulnerability in the Oracle HR Intelligence product of Oracle E-Busines=
s Suite (component: Internal Operations). Supported versions that are affec= ted are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle HR Intelli= gence. Successful attacks of this vulnerability can result in takeover of O= racle HR Intelligence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C= :H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46971" target=3D= "_blank" rel=3D"noopener">CVE-2026-46971</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle HRMS (UK)</td> <td>Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suit=
e (component: UK Payroll). Supported versions that are affected are 12.2.3-= 12.2.15. Easily exploitable vulnerability allows high privileged attacker w= ith network access via HTTP to compromise Oracle HRMS (UK). Successful atta= cks of this vulnerability can result in takeover of Oracle HRMS (UK). CVSS = 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). C= VSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46953" target=3D= "_blank" rel=3D"noopener">CVE-2026-46953</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Human Resources</td=
<td>Vulnerability in the Oracle Human Resources product of Oracle E-Busines=
s Suite (component: Person). Supported versions that are affected are 12.2.= 3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attack=
er with network access via HTTP to compromise Oracle Human Resources. Succe= ssful attacks require human interaction from a person other than the attack= er. Successful attacks of this vulnerability can result in takeover of Orac=
le Human Resources. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and=
Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/= I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46955" target=3D= "_blank" rel=3D"noopener">CVE-2026-46955</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle In-Memory Cost Mana= gement for Discrete Industries</td>
<td>Vulnerability in the Oracle In-Memory Cost Management for Discrete Indu= stries product of Oracle E-Business Suite (component: Internal Operations).=
Supported versions that are affected are 12.2.12-12.2.15. Easily exploitab=
le vulnerability allows unauthenticated attacker with network access via HT= TPS to compromise Oracle In-Memory Cost Management for Discrete Industries.=
Successful attacks of this vulnerability can result in unauthorized creati= on, deletion or modification access to critical data or all Oracle In-Memor=
y Cost Management for Discrete Industries accessible data as well as unauth= orized access to critical data or complete access to all Oracle In-Memory C= ost Management for Discrete Industries accessible data. CVSS 3.1 Base Score=
9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46930" target=3D= "_blank" rel=3D"noopener">CVE-2026-46930</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle iSetup</td> <td>Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (= component: General Ledger Update Transform, Reports). Supported versions th=
at are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = iSetup. Successful attacks of this vulnerability can result in takeover of = Oracle iSetup. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46937" target=3D= "_blank" rel=3D"noopener">CVE-2026-46937</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle iSupplier Portal</t=
<td>Vulnerability in the Oracle iSupplier Portal product of Oracle E-Busine=
ss Suite (component: Home Page). Supported versions that are affected are 1= 2.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attac= ker with network access via HTTPS to compromise Oracle iSupplier Portal. Su= ccessful attacks require human interaction from a person other than the att= acker. Successful attacks of this vulnerability can result in takeover of O= racle iSupplier Portal. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/= C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46894" target=3D= "_blank" rel=3D"noopener">CVE-2026-46894</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle iSupplier Portal</t=
<td>Vulnerability in the Oracle iSupplier Portal product of Oracle E-Busine=
ss Suite (component: Internal Operations). Supported versions that are affe= cted are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low priv= ileged attacker with network access via HTTP to compromise Oracle iSupplier=
Portal. Successful attacks of this vulnerability can result in takeover of=
Oracle iSupplier Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integri=
ty and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:= U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46957" target=3D= "_blank" rel=3D"noopener">CVE-2026-46957</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle iSupport</td> <td>Vulnerability in the Oracle iSupport product of Oracle E-Business Suite=
(component: Internal Operations). Supported versions that are affected are=
12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged at= tacker with network access via HTTP to compromise Oracle iSupport. While th=
e vulnerability is in Oracle iSupport, attacks may significantly impact add= itional products (scope change). Successful attacks of this vulnerability c=
an result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46944" target=3D= "_blank" rel=3D"noopener">CVE-2026-46944</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle iSupport</td> <td>Vulnerability in the Oracle iSupport product of Oracle E-Business Suite=
(component: Internal Operations). Supported versions that are affected are=
12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged at= tacker with network access via HTTP to compromise Oracle iSupport. While th=
e vulnerability is in Oracle iSupport, attacks may significantly impact add= itional products (scope change). Successful attacks of this vulnerability c=
an result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46945" target=3D= "_blank" rel=3D"noopener">CVE-2026-46945</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle iSupport</td> <td>Vulnerability in the Oracle iSupport product of Oracle E-Business Suite=
(component: Internal Operations). Supported versions that are affected are=
12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged at= tacker with network access via HTTP to compromise Oracle iSupport. While th=
e vulnerability is in Oracle iSupport, attacks may significantly impact add= itional products (scope change). Successful attacks of this vulnerability c=
an result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confiden= tiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46946" target=3D= "_blank" rel=3D"noopener">CVE-2026-46946</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Outsourced Mfg for = Discrete Industries</td>
<td>Vulnerability in the Oracle Outsourced Mfg for Discrete Industries prod= uct of Oracle E-Business Suite (component: Internal Operations). Supported = versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabi= lity allows low privileged attacker with network access via HTTP to comprom= ise Oracle Outsourced Mfg for Discrete Industries. Successful attacks of th=
is vulnerability can result in takeover of Oracle Outsourced Mfg for Discre=
te Industries. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46972" target=3D= "_blank" rel=3D"noopener">CVE-2026-46972</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Outsourced Mfg for = Discrete Industries</td>
<td>Vulnerability in the Oracle Outsourced Mfg for Discrete Industries prod= uct of Oracle E-Business Suite (component: Internal Operations). Supported = versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabi= lity allows low privileged attacker with network access via HTTP to comprom= ise Oracle Outsourced Mfg for Discrete Industries. Successful attacks of th=
is vulnerability can result in takeover of Oracle Outsourced Mfg for Discre=
te Industries. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46973" target=3D= "_blank" rel=3D"noopener">CVE-2026-46973</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Process Manufacturi=
ng Process Planning</td>
<td>Vulnerability in the Oracle Process Manufacturing Process Planning prod= uct of Oracle E-Business Suite (component: Internal Operations). Supported = versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabi= lity allows low privileged attacker with network access via HTTP to comprom= ise Oracle Process Manufacturing Process Planning. Successful attacks of th=
is vulnerability can result in takeover of Oracle Process Manufacturing Pro= cess Planning. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46942" target=3D= "_blank" rel=3D"noopener">CVE-2026-46942</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Process Manufacturi=
ng Product Development</td>
<td>Vulnerability in the Oracle Process Manufacturing Product Development p= roduct of Oracle E-Business Suite (component: Internal Operations). Support=
ed versions that are affected are 12.2.3-12.2.15. Easily exploitable vulner= ability allows low privileged attacker with network access via HTTP to comp= romise Oracle Process Manufacturing Product Development. While the vulnerab= ility is in Oracle Process Manufacturing Product Development, attacks may s= ignificantly impact additional products (scope change). Successful attacks =
of this vulnerability can result in takeover of Oracle Process Manufacturin=
g Product Development. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity = and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C= :H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46918" target=3D= "_blank" rel=3D"noopener">CVE-2026-46918</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Process Manufacturi=
ng Product Development</td>
<td>Vulnerability in the Oracle Process Manufacturing Product Development p= roduct of Oracle E-Business Suite (component: Quality Management Specs). Su= pported versions that are affected are 12.2.3-12.2.15. Easily exploitable v= ulnerability allows low privileged attacker with network access via HTTP to=
compromise Oracle Process Manufacturing Product Development. Successful at= tacks of this vulnerability can result in takeover of Oracle Process Manufa= cturing Product Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Inte= grity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N= /S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46916" target=3D= "_blank" rel=3D"noopener">CVE-2026-46916</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Project Portfolio A= nalysis</td>
<td>Vulnerability in the Oracle Project Portfolio Analysis product of Oracl=
e E-Business Suite (component: Internal Operations). Supported versions tha=
t are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows = low privileged attacker with network access via HTTP to compromise Oracle P= roject Portfolio Analysis. Successful attacks of this vulnerability can res= ult in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8=
.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS= S:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46961" target=3D= "_blank" rel=3D"noopener">CVE-2026-46961</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Project Portfolio A= nalysis</td>
<td>Vulnerability in the Oracle Project Portfolio Analysis product of Oracl=
e E-Business Suite (component: Internal Operations). Supported versions tha=
t are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows = low privileged attacker with network access via HTTP to compromise Oracle P= roject Portfolio Analysis. Successful attacks of this vulnerability can res= ult in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8=
.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS= S:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46962" target=3D= "_blank" rel=3D"noopener">CVE-2026-46962</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Project Portfolio A= nalysis</td>
<td>Vulnerability in the Oracle Project Portfolio Analysis product of Oracl=
e E-Business Suite (component: Internal Operations). Supported versions tha=
t are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows = high privileged attacker with network access via HTTP to compromise Oracle = Project Portfolio Analysis. Successful attacks of this vulnerability can re= sult in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score = 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CV= SS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46960" target=3D= "_blank" rel=3D"noopener">CVE-2026-46960</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Property Manager</t=
<td>Vulnerability in the Oracle Property Manager product of Oracle E-Busine=
ss Suite (component: Internal Operations). Supported versions that are affe= cted are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privi= leged attacker with network access via HTTP to compromise Oracle Property M= anager. Successful attacks of this vulnerability can result in takeover of = Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrit=
y and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U= /C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46956" target=3D= "_blank" rel=3D"noopener">CVE-2026-46956</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Public Sector Finan= cials (International)</td>
<td>Vulnerability in the Oracle Public Sector Financials (International) pr= oduct of Oracle E-Business Suite (component: Authorization). Supported vers= ions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability=
allows low privileged attacker with network access via HTTP to compromise = Oracle Public Sector Financials (International). Successful attacks of this=
vulnerability can result in takeover of Oracle Public Sector Financials (I= nternational). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A= :H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46967" target=3D= "_blank" rel=3D"noopener">CVE-2026-46967</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Public Sector Payro= ll</td>
<td>Vulnerability in the Oracle Public Sector Payroll product of Oracle E-B= usiness Suite (component: Internal Operations). Supported versions that are=
affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high = privileged attacker with network access via HTTP to compromise Oracle Publi=
c Sector Payroll. Successful attacks of this vulnerability can result in ta= keover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidenti= ality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:= L/PR:H/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46976" target=3D= "_blank" rel=3D"noopener">CVE-2026-46976</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Quality</td> <td>Vulnerability in the Oracle Quality product of Oracle E-Business Suite = (component: Internal Operations). Supported versions that are affected are = 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta= cker with network access via HTTP to compromise Oracle Quality. Successful = attacks of this vulnerability can result in takeover of Oracle Quality. CVS=
S 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).=
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46951" target=3D= "_blank" rel=3D"noopener">CVE-2026-46951</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Quality</td> <td>Vulnerability in the Oracle Quality product of Oracle E-Business Suite = (component: Internal Operations). Supported versions that are affected are = 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta= cker with network access via HTTP to compromise Oracle Quality. Successful = attacks of this vulnerability can result in takeover of Oracle Quality. CVS=
S 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).=
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46952" target=3D= "_blank" rel=3D"noopener">CVE-2026-46952</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Receivables</td> <td>Vulnerability in the Oracle Receivables product of Oracle E-Business Su= ite (component: Internal Operations). Supported versions that are affected = are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticat=
ed attacker with network access via SOAP to compromise Oracle Receivables. = Successful attacks of this vulnerability can result in takeover of Oracle R= eceivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availab= ility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)= .</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46927" target=3D= "_blank" rel=3D"noopener">CVE-2026-46927</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Solaris</td> <td>Vulnerability in the Oracle Solaris product of Oracle Systems (componen=
t: Remote Administration Daemon). The supported version that is affected is=
11.4. Easily exploitable vulnerability allows unauthenticated attacker wit=
h network access via HTTPS to compromise Oracle Solaris. While the vulnerab= ility is in Oracle Solaris, attacks may significantly impact additional pro= ducts (scope change). Successful attacks of this vulnerability can result i=
n unauthorized creation, deletion or modification access to critical data o=
r all Oracle Solaris accessible data as well as unauthorized access to crit= ical data or complete access to all Oracle Solaris accessible data. CVSS 3.=
1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CV= SS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46978" target=3D= "_blank" rel=3D"noopener">CVE-2026-46978</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Solaris</td> <td>Vulnerability in the Oracle Solaris product of Oracle Systems (componen=
t: Filesystem). The supported version that is affected is 11.4. Easily expl= oitable vulnerability allows low privileged attacker with logon to the infr= astructure where Oracle Solaris executes to compromise Oracle Solaris. Succ= essful attacks of this vulnerability can result in unauthorized access to c= ritical data or complete access to all Oracle Solaris accessible data and u= nauthorized ability to cause a hang or frequently repeatable crash (complet=
e DOS) of Oracle Solaris. CVSS 3.1 Base Score 7.1 (Confidentiality and Avai= lability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A= :H).</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46914" target=3D= "_blank" rel=3D"noopener">CVE-2026-46914</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Spares Management</=
<td>Vulnerability in the Oracle Spares Management product of Oracle E-Busin= ess Suite (component: Internal Operations). Supported versions that are aff= ected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTPS to compromise Oracle Spares Ma= nagement. Successful attacks of this vulnerability can result in takeover o=
f Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integ= rity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/= S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46928" target=3D= "_blank" rel=3D"noopener">CVE-2026-46928</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Subledger Accountin= g</td>
<td>Vulnerability in the Oracle Subledger Accounting product of Oracle E-Bu= siness Suite (component: Internal Operations). Supported versions that are = affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low = privileged attacker with network access via HTTP to compromise Oracle Suble= dger Accounting. Successful attacks of this vulnerability can result in tak= eover of Oracle Subledger Accounting. CVSS 3.1 Base Score 7.5 (Confidential= ity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/= PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46958" target=3D= "_blank" rel=3D"noopener">CVE-2026-46958</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Subledger Accountin= g</td>
<td>Vulnerability in the Oracle Subledger Accounting product of Oracle E-Bu= siness Suite (component: Internal Operations). Supported versions that are = affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low = privileged attacker with network access via HTTP to compromise Oracle Suble= dger Accounting. Successful attacks of this vulnerability can result in tak= eover of Oracle Subledger Accounting. CVSS 3.1 Base Score 7.5 (Confidential= ity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/= PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46959" target=3D= "_blank" rel=3D"noopener">CVE-2026-46959</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Unified Directory</=
<td>Vulnerability in the Oracle Unified Directory product of Oracle Fusion = Middleware (component: OUD Core). Supported versions that are affected are = 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthen= ticated attacker with network access via LDAP to compromise Oracle Unified = Directory. Successful attacks of this vulnerability can result in takeover =
of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Inte= grity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N= /S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46773" target=3D= "_blank" rel=3D"noopener">CVE-2026-46773</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Unified Directory</=
<td>Vulnerability in the Oracle Unified Directory product of Oracle Fusion = Middleware (component: OUD Core). Supported versions that are affected are = 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthen= ticated attacker with network access via RMI to compromise Oracle Unified D= irectory. Successful attacks of this vulnerability can result in takeover o=
f Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integ= rity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/= S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46774" target=3D= "_blank" rel=3D"noopener">CVE-2026-46774</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Unified Directory</=
<td>Vulnerability in the Oracle Unified Directory product of Oracle Fusion = Middleware (component: OUD Core). Supported versions that are affected are = 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthen= ticated attacker with network access via LDAP to compromise Oracle Unified = Directory. Successful attacks of this vulnerability can result in unauthori= zed creation, deletion or modification access to critical data or all Oracl=
e Unified Directory accessible data as well as unauthorized read access to =
a subset of Oracle Unified Directory accessible data and unauthorized abili=
ty to cause a partial denial of service (partial DOS) of Oracle Unified Dir= ectory. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availabilit=
y impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L).</t=
<td>2026-06-16</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46776" target=3D= "_blank" rel=3D"noopener">CVE-2026-46776</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Universal Work Queu= e</td>
<td>Vulnerability in the Oracle Universal Work Queue product of Oracle E-Bu= siness Suite (component: Work Provider Site Level Administration). Supporte=
d versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnera= bility allows low privileged attacker with network access via HTTP to compr= omise Oracle Universal Work Queue. While the vulnerability is in Oracle Uni= versal Work Queue, attacks may significantly impact additional products (sc= ope change). Successful attacks of this vulnerability can result in takeove=
r of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46963" target=3D= "_blank" rel=3D"noopener">CVE-2026-46963</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Universal Work Queu= e</td>
<td>Vulnerability in the Oracle Universal Work Queue product of Oracle E-Bu= siness Suite (component: Work Provider Site Level Administration). Supporte=
d versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnera= bility allows low privileged attacker with network access via HTTP to compr= omise Oracle Universal Work Queue. While the vulnerability is in Oracle Uni= versal Work Queue, attacks may significantly impact additional products (sc= ope change). Successful attacks of this vulnerability can result in takeove=
r of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46964" target=3D= "_blank" rel=3D"noopener">CVE-2026-46964</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Universal Work Queu= e</td>
<td>Vulnerability in the Oracle Universal Work Queue product of Oracle E-Bu= siness Suite (component: Work Provider Site Level Administration). Supporte=
d versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnera= bility allows low privileged attacker with network access via HTTP to compr= omise Oracle Universal Work Queue. Successful attacks of this vulnerability=
can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score=
8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46965" target=3D= "_blank" rel=3D"noopener">CVE-2026-46965</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Universal Work Queu= e</td>
<td>Vulnerability in the Oracle Universal Work Queue product of Oracle E-Bu= siness Suite (component: Work Provider Site Level Administration). Supporte=
d versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulne= rability allows low privileged attacker with network access via HTTP to com= promise Oracle Universal Work Queue. Successful attacks of this vulnerabili=
ty can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Sco=
re 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: = (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46966" target=3D= "_blank" rel=3D"noopener">CVE-2026-46966</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Virtual Directory</=
<td>Vulnerability in the Oracle Virtual Directory product of Oracle Fusion = Middleware (component: Virtual Directory Server). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via LDAP to compromise=
Oracle Virtual Directory. Successful attacks of this vulnerability can res= ult in takeover of Oracle Virtual Directory. CVSS 3.1 Base Score 9.8 (Confi= dentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:= N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35312" target=3D= "_blank" rel=3D"noopener">CVE-2026-35312</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: Shared Folders). The supported version that is affected is = 7.2.8. Difficult to exploit vulnerability allows low privileged attacker wi=
th logon to the infrastructure where Oracle VM VirtualBox executes to compr= omise Oracle VM VirtualBox. While the vulnerability is in Oracle VM Virtual= Box, attacks may significantly impact additional products (scope change). S= uccessful attacks of this vulnerability can result in unauthorized creation=
, deletion or modification access to critical data or all Oracle VM Virtual= Box accessible data as well as unauthorized access to critical data or comp= lete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Scor=
e 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/= AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35275" target=3D= "_blank" rel=3D"noopener">CVE-2026-35275</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: VMSVGA device). The supported version that is affected is 7= .2.8. Difficult to exploit vulnerability allows high privileged attacker wi=
th logon to the infrastructure where Oracle VM VirtualBox executes to compr= omise Oracle VM VirtualBox. While the vulnerability is in Oracle VM Virtual= Box, attacks may significantly impact additional products (scope change). S= uccessful attacks of this vulnerability can result in takeover of Oracle VM=
VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availa= bility impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H= ).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46873" target=3D= "_blank" rel=3D"noopener">CVE-2026-46873</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: Core). The supported version that is affected is 7.2.8. Dif= ficult to exploit vulnerability allows high privileged attacker with logon =
to the infrastructure where Oracle VM VirtualBox executes to compromise Ora= cle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in takeover of Oracle VM VirtualB= ox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46974" target=3D= "_blank" rel=3D"noopener">CVE-2026-46974</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows hi=
gh privileged attacker with network access via HTTP to compromise Oracle We= bCenter Content. While the vulnerability is in Oracle WebCenter Content, at= tacks may significantly impact additional products (scope change). Successf=
ul attacks of this vulnerability can result in takeover of Oracle WebCenter=
Content. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).<=
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35270" target=3D= "_blank" rel=3D"noopener">CVE-2026-35270</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows un= authenticated attacker with network access via HTTP to compromise Oracle We= bCenter Content. Successful attacks of this vulnerability can result in tak= eover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35286" target=3D= "_blank" rel=3D"noopener">CVE-2026-35286</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. While the vulnerability is in Oracle WebCenter Content, att= acks may significantly impact additional products (scope change). Successfu=
l attacks of this vulnerability can result in takeover of Oracle WebCenter = Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</=
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35316" target=3D= "_blank" rel=3D"noopener">CVE-2026-35316</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows un= authenticated attacker with network access via HTTP to compromise Oracle We= bCenter Content. Successful attacks of this vulnerability can result in tak= eover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35319" target=3D= "_blank" rel=3D"noopener">CVE-2026-35319</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows = unauthenticated attacker with network access via HTTP to compromise Oracle = WebCenter Content. While the vulnerability is in Oracle WebCenter Content, = attacks may significantly impact additional products (scope change). Succes= sful attacks of this vulnerability can result in takeover of Oracle WebCent=
er Content. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availab= ility impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)= .</td>
<td>2026-06-16</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35320" target=3D= "_blank" rel=3D"noopener">CVE-2026-35320</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. While the vulnerability is in Oracle WebCenter Content, att= acks may significantly impact additional products (scope change). Successfu=
l attacks of this vulnerability can result in takeover of Oracle WebCenter = Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</=
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35321" target=3D= "_blank" rel=3D"noopener">CVE-2026-35321</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. While the vulnerability is in Oracle WebCenter Content, att= acks may significantly impact additional products (scope change). Successfu=
l attacks of this vulnerability can result in takeover of Oracle WebCenter = Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</=
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35323" target=3D= "_blank" rel=3D"noopener">CVE-2026-35323</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows un= authenticated attacker with network access via HTTP to compromise Oracle We= bCenter Content. Successful attacks of this vulnerability can result in tak= eover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46766" target=3D= "_blank" rel=3D"noopener">CVE-2026-46766</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows un= authenticated attacker with network access via HTTP to compromise Oracle We= bCenter Content. Successful attacks of this vulnerability can result in una= uthorized creation, deletion or modification access to critical data or all=
Oracle WebCenter Content accessible data as well as unauthorized access to=
critical data or complete access to all Oracle WebCenter Content accessibl=
e data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CV=
SS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</td> <td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46777" target=3D= "_blank" rel=3D"noopener">CVE-2026-46777</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks require human interaction from a person other than th=
e attacker and while the vulnerability is in Oracle WebCenter Content, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in unauthorized creation, deletio=
n or modification access to critical data or all Oracle WebCenter Content a= ccessible data as well as unauthorized access to critical data or complete = access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score=
9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:N/UI:R/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46785" target=3D= "_blank" rel=3D"noopener">CVE-2026-46785</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks require human interaction from a person other than th=
e attacker and while the vulnerability is in Oracle WebCenter Content, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in takeover of Oracle WebCenter C= ontent. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availabilit=
y impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</t=
<td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46786" target=3D= "_blank" rel=3D"noopener">CVE-2026-46786</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks require human interaction from a person other than th=
e attacker and while the vulnerability is in Oracle WebCenter Content, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in takeover of Oracle WebCenter C= ontent. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availabilit=
y impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</t=
<td>2026-06-16</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46789" target=3D= "_blank" rel=3D"noopener">CVE-2026-46789</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks require human interaction from a person other than th=
e attacker and while the vulnerability is in Oracle WebCenter Content, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in unauthorized creation, deletio=
n or modification access to critical data or all Oracle WebCenter Content a= ccessible data as well as unauthorized access to critical data or complete = access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score=
9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:N/UI:R/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46795" target=3D= "_blank" rel=3D"noopener">CVE-2026-46795</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks require human interaction from a person other than th=
e attacker and while the vulnerability is in Oracle WebCenter Content, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in unauthorized creation, deletio=
n or modification access to critical data or all Oracle WebCenter Content a= ccessible data as well as unauthorized access to critical data or complete = access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score=
9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/A= C:L/PR:N/UI:R/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46805" target=3D= "_blank" rel=3D"noopener">CVE-2026-46805</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows un= authenticated attacker with network access via HTTP to compromise Oracle We= bCenter Content. Successful attacks of this vulnerability can result in tak= eover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46813" target=3D= "_blank" rel=3D"noopener">CVE-2026-46813</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. Successful attacks of this vulnerability can result in take= over of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35315" target=3D= "_blank" rel=3D"noopener">CVE-2026-35315</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. Successful attacks of this vulnerability can result in take= over of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35317" target=3D= "_blank" rel=3D"noopener">CVE-2026-35317</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. Successful attacks of this vulnerability can result in take= over of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35322" target=3D= "_blank" rel=3D"noopener">CVE-2026-35322</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. Successful attacks of this vulnerability can result in take= over of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35324" target=3D= "_blank" rel=3D"noopener">CVE-2026-35324</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTP to compromise Oracle Web= Center Content. Successful attacks of this vulnerability can result in take= over of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality,=
Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L= /UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35325" target=3D= "_blank" rel=3D"noopener">CVE-2026-35325</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticate=
d attacker with network access via HTTP to compromise Oracle WebCenter Cont= ent. Successful attacks require human interaction from a person other than = the attacker and while the vulnerability is in Oracle WebCenter Content, at= tacks may significantly impact additional products (scope change). Successf=
ul attacks of this vulnerability can result in unauthorized creation, delet= ion or modification access to critical data or all Oracle WebCenter Content=
accessible data as well as unauthorized access to critical data or complet=
e access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Sco=
re 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N= /AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46787" target=3D= "_blank" rel=3D"noopener">CVE-2026-46787</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows high privileged = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks require human interaction from a person other than th=
e attacker and while the vulnerability is in Oracle WebCenter Content, atta= cks may significantly impact additional products (scope change). Successful=
attacks of this vulnerability can result in takeover of Oracle WebCenter C= ontent. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availabilit=
y impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).</t=
<td>2026-06-16</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46788" target=3D= "_blank" rel=3D"noopener">CVE-2026-46788</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged a= ttacker with network access via HTTP to compromise Oracle WebCenter Content=
. Successful attacks require human interaction from a person other than the=
attacker and while the vulnerability is in Oracle WebCenter Content, attac=
ks may significantly impact additional products (scope change). Successful = attacks of this vulnerability can result in unauthorized creation, deletion=
or modification access to critical data or all Oracle WebCenter Content ac= cessible data as well as unauthorized access to critical data or complete a= ccess to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score = 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC= :L/PR:L/UI:R/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46804" target=3D= "_blank" rel=3D"noopener">CVE-2026-46804</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTPS to compromise Oracle WebCenter Conte= nt. Successful attacks require human interaction from a person other than t=
he attacker and while the vulnerability is in Oracle WebCenter Content, att= acks may significantly impact additional products (scope change). Successfu=
l attacks of this vulnerability can result in unauthorized access to critic=
al data or complete access to all Oracle WebCenter Content accessible data =
as well as unauthorized update, insert or delete access to some of Oracle W= ebCenter Content accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality = and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/= I:L/A:N).</td>
<td>2026-06-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46806" target=3D= "_blank" rel=3D"noopener">CVE-2026-46806</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged a= ttacker with network access via HTTP to compromise Oracle WebCenter Content=
. Successful attacks require human interaction from a person other than the=
attacker and while the vulnerability is in Oracle WebCenter Content, attac=
ks may significantly impact additional products (scope change). Successful = attacks of this vulnerability can result in unauthorized creation, deletion=
or modification access to critical data or all Oracle WebCenter Content ac= cessible data as well as unauthorized access to critical data or complete a= ccess to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score = 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC= :L/PR:L/UI:R/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46808" target=3D= "_blank" rel=3D"noopener">CVE-2026-46808</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows hi=
gh privileged attacker with network access via HTTP to compromise Oracle We= bCenter Content. Successful attacks of this vulnerability can result in tak= eover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= H/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35326" target=3D= "_blank" rel=3D"noopener">CVE-2026-35326</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). Supported versions that are affecte=
d are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows lo=
w privileged attacker with network access via HTTPS to compromise Oracle We= bCenter Content. Successful attacks require human interaction from a person=
other than the attacker and while the vulnerability is in Oracle WebCenter=
Content, attacks may significantly impact additional products (scope chang= e). Successful attacks of this vulnerability can result in unauthorized acc= ess to critical data or complete access to all Oracle WebCenter Content acc= essible data as well as unauthorized update, insert or delete access to som=
e of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Con= fidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/= UI:R/S:C/C:H/I:L/A:N).</td>
<td>2026-06-16</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35327" target=3D= "_blank" rel=3D"noopener">CVE-2026-35327</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks of this vulnerability can result in unauthorized acce=
ss to critical data or complete access to all Oracle WebCenter Content acce= ssible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector=
: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46791" target=3D= "_blank" rel=3D"noopener">CVE-2026-46791</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via RMI to compromise = Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle W= ebCenter Enterprise Capture, attacks may significantly impact additional pr= oducts (scope change). Successful attacks of this vulnerability can result =
in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.=
0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS= :3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46778" target=3D= "_blank" rel=3D"noopener">CVE-2026-46778</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows unauthenticated attacker with network access via RMI to compromise = Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle W= ebCenter Enterprise Capture, attacks may significantly impact additional pr= oducts (scope change). Successful attacks of this vulnerability can result =
in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.=
0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS= :3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46781" target=3D= "_blank" rel=3D"noopener">CVE-2026-46781</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via T3, IIOP to comprom= ise Oracle WebCenter Enterprise Capture. While the vulnerability is in Orac=
le WebCenter Enterprise Capture, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35280" target=3D= "_blank" rel=3D"noopener">CVE-2026-35280</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via T3, IIOP to comprom= ise Oracle WebCenter Enterprise Capture. While the vulnerability is in Orac=
le WebCenter Enterprise Capture, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35281" target=3D= "_blank" rel=3D"noopener">CVE-2026-35281</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via T3, IIOP to comprom= ise Oracle WebCenter Enterprise Capture. While the vulnerability is in Orac=
le WebCenter Enterprise Capture, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35282" target=3D= "_blank" rel=3D"noopener">CVE-2026-35282</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via T3, IIOP to comprom= ise Oracle WebCenter Enterprise Capture. While the vulnerability is in Orac=
le WebCenter Enterprise Capture, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35283" target=3D= "_blank" rel=3D"noopener">CVE-2026-35283</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via T3, IIOP to comprom= ise Oracle WebCenter Enterprise Capture. While the vulnerability is in Orac=
le WebCenter Enterprise Capture, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35284" target=3D= "_blank" rel=3D"noopener">CVE-2026-35284</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via T3, IIOP to comprom= ise Oracle WebCenter Enterprise Capture. While the vulnerability is in Orac=
le WebCenter Enterprise Capture, attacks may significantly impact additiona=
l products (scope change). Successful attacks of this vulnerability can res= ult in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score=
9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35285" target=3D= "_blank" rel=3D"noopener">CVE-2026-35285</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via T3 to compromise Or= acle WebCenter Enterprise Capture. While the vulnerability is in Oracle Web= Center Enterprise Capture, attacks may significantly impact additional prod= ucts (scope change). Successful attacks of this vulnerability can result in=
takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (= Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.= 1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46779" target=3D= "_blank" rel=3D"noopener">CVE-2026-46779</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Enterpris=
e Capture</td>
<td>Vulnerability in the Oracle WebCenter Enterprise Capture product of Ora= cle Fusion Middleware (component: Client Bundle). Supported versions that a=
re affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability=
allows low privileged attacker with network access via HTTP to compromise = Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle W= ebCenter Enterprise Capture, attacks may significantly impact additional pr= oducts (scope change). Successful attacks of this vulnerability can result =
in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9=
(Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:= 3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46782" target=3D= "_blank" rel=3D"noopener">CVE-2026-46782</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Security Framework). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
unauthenticated attacker with network access via HTTP to compromise Oracle=
WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, a= ttacks may significantly impact additional products (scope change). Success= ful attacks of this vulnerability can result in takeover of Oracle WebCente=
r Portal. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availabi= lity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).= </td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46803" target=3D= "_blank" rel=3D"noopener">CVE-2026-46803</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Security Framework). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
unauthenticated attacker with network access via HTTP to compromise Oracle=
WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, a= ttacks may significantly impact additional products (scope change). Success= ful attacks of this vulnerability can result in takeover of Oracle WebCente=
r Portal. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availabi= lity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).= </td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46846" target=3D= "_blank" rel=3D"noopener">CVE-2026-46846</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Composer). Supported versions that are affected are 1= 2.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle WebCenter = Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may = significantly impact additional products (scope change). Successful attacks=
of this vulnerability can result in takeover of Oracle WebCenter Portal. C= VSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts=
). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46765" target=3D= "_blank" rel=3D"noopener">CVE-2026-46765</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Composer). Supported versions that are affected are 1= 2.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privi= leged attacker with network access via HTTP to compromise Oracle WebCenter = Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may = significantly impact additional products (scope change). Successful attacks=
of this vulnerability can result in takeover of Oracle WebCenter Portal. C= VSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts=
). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46767" target=3D= "_blank" rel=3D"noopener">CVE-2026-46767</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Security Framework). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, at= tacks may significantly impact additional products (scope change). Successf=
ul attacks of this vulnerability can result in takeover of Oracle WebCenter=
Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</=
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46802" target=3D= "_blank" rel=3D"noopener">CVE-2026-46802</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Security Framework). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTP to compromise Oracle = WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, at= tacks may significantly impact additional products (scope change). Successf=
ul attacks of this vulnerability can result in takeover of Oracle WebCenter=
Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabili=
ty impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</=
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46814" target=3D= "_blank" rel=3D"noopener">CVE-2026-46814</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Security Framework). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTPS to compromise Oracle=
WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, a= ttacks may significantly impact additional products (scope change). Success= ful attacks of this vulnerability can result in takeover of Oracle WebCente=
r Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).<=
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46838" target=3D= "_blank" rel=3D"noopener">CVE-2026-46838</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Security Framework). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
low privileged attacker with network access via HTTPS to compromise Oracle=
WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, a= ttacks may significantly impact additional products (scope change). Success= ful attacks of this vulnerability can result in takeover of Oracle WebCente=
r Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availabil= ity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).<=
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46844" target=3D= "_blank" rel=3D"noopener">CVE-2026-46844</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Security Framework). Supported versions that are affe= cted are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows=
unauthenticated attacker with network access via HTTPS to compromise Oracl=
e WebCenter Portal. Successful attacks of this vulnerability can result in = takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiali= ty, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/P= R:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46845" target=3D= "_blank" rel=3D"noopener">CVE-2026-46845</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Portal</t=
<td>Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion M= iddleware (component: Runtime Tools). Supported versions that are affected = are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low = privileged attacker with network access via HTTPS to compromise Oracle WebC= enter Portal. While the vulnerability is in Oracle WebCenter Portal, attack=
s may significantly impact additional products (scope change). Successful a= ttacks of this vulnerability can result in takeover of Oracle WebCenter Por= tal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability i= mpacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46847" target=3D= "_blank" rel=3D"noopener">CVE-2026-46847</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via HTTP to compromise Oracle Web= Center Sites. While the vulnerability is in Oracle WebCenter Sites, attacks=
may significantly impact additional products (scope change). Successful at= tacks of this vulnerability can result in takeover of Oracle WebCenter Site=
s. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46798" target=3D= "_blank" rel=3D"noopener">CVE-2026-46798</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via HTTP to compromise Oracle Web= Center Sites. While the vulnerability is in Oracle WebCenter Sites, attacks=
may significantly impact additional products (scope change). Successful at= tacks of this vulnerability can result in takeover of Oracle WebCenter Site=
s. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46800" target=3D= "_blank" rel=3D"noopener">CVE-2026-46800</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). The supported version that is affect=
ed is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated a= ttacker with network access via HTTP to compromise Oracle WebCenter Sites. = Successful attacks of this vulnerability can result in takeover of Oracle W= ebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Ava= ilability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/= A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35293" target=3D= "_blank" rel=3D"noopener">CVE-2026-35293</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via HTTP to compromise Oracle Web= Center Sites. Successful attacks of this vulnerability can result in takeov=
er of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Int= egrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:= N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35296" target=3D= "_blank" rel=3D"noopener">CVE-2026-35296</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via HTTP to compromise Oracle Web= Center Sites. Successful attacks of this vulnerability can result in takeov=
er of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Int= egrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:= N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46797" target=3D= "_blank" rel=3D"noopener">CVE-2026-46797</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via HTTP to compromise Oracle Web= Center Sites. Successful attacks of this vulnerability can result in takeov=
er of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Int= egrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:= N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46799" target=3D= "_blank" rel=3D"noopener">CVE-2026-46799</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via HTTP to compromise Oracle Web= Center Sites. Successful attacks of this vulnerability can result in takeov=
er of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Int= egrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:= N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46801" target=3D= "_blank" rel=3D"noopener">CVE-2026-46801</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via HTTP to compromise Oracle Web= Center Sites. Successful attacks of this vulnerability can result in unauth= orized creation, deletion or modification access to critical data or all Or= acle WebCenter Sites accessible data as well as unauthorized access to crit= ical data or complete access to all Oracle WebCenter Sites accessible data.=
CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vect= or: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46809" target=3D= "_blank" rel=3D"noopener">CVE-2026-46809</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low=
privileged attacker with network access via HTTP to compromise Oracle WebC= enter Sites. Successful attacks of this vulnerability can result in takeove=
r of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Inte= grity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N= /S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35318" target=3D= "_blank" rel=3D"noopener">CVE-2026-35318</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low=
privileged attacker with network access via HTTP to compromise Oracle WebC= enter Sites. Successful attacks require human interaction from a person oth=
er than the attacker. Successful attacks of this vulnerability can result i=
n takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.0 (Confidential= ity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/= PR:L/UI:R/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46796" target=3D= "_blank" rel=3D"noopener">CVE-2026-46796</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Sites</td=
<td>Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Mi= ddleware (component: WebCenter Sites). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows l=
ow privileged attacker with network access via HTTP to compromise Oracle We= bCenter Sites. Successful attacks of this vulnerability can result in takeo= ver of Oracle WebCenter Sites. CVSS 3.1 Base Score 7.5 (Confidentiality, In= tegrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI= :N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35295" target=3D= "_blank" rel=3D"noopener">CVE-2026-35295</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise CS C= ampus Community</td>
<td>Vulnerability in the PeopleSoft Enterprise CS Campus Community product =
of Oracle PeopleSoft (component: Security). The supported version that is a= ffected is 9.2.38. Difficult to exploit vulnerability allows unauthenticate=
d attacker with network access via HTTP to compromise PeopleSoft Enterprise=
CS Campus Community. Successful attacks of this vulnerability can result i=
n takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Scor=
e 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46851" target=3D= "_blank" rel=3D"noopener">CVE-2026-46851</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise CS S= tudent Financials</td>
<td>Vulnerability in the PeopleSoft Enterprise CS Student Financials produc=
t of Oracle PeopleSoft (component: Other). The supported version that is af= fected is 9.2.38. Easily exploitable vulnerability allows low privileged at= tacker with network access via HTTP to compromise PeopleSoft Enterprise CS = Student Financials. Successful attacks of this vulnerability can result in = unauthorized creation, deletion or modification access to critical data or = all PeopleSoft Enterprise CS Student Financials accessible data as well as = unauthorized access to critical data or complete access to all PeopleSoft E= nterprise CS Student Financials accessible data. CVSS 3.1 Base Score 8.1 (C= onfidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:= L/UI:N/S:U/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46849" target=3D= "_blank" rel=3D"noopener">CVE-2026-46849</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Performance Monitor). Supported versions that a=
re affected are 8.61 and 8.62. Easily exploitable vulnerability allows unau= thenticated attacker with network access via HTTP to compromise PeopleSoft = Enterprise PT PeopleTools. Successful attacks of this vulnerability can res= ult in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Scor=
e 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (= CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35278" target=3D= "_blank" rel=3D"noopener">CVE-2026-35278</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Weblogic). Supported versions that are affected=
are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticat=
ed attacker with network access via HTTP to compromise PeopleSoft Enterpris=
e PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT Pe= opleTools, attacks may significantly impact additional products (scope chan= ge). Successful attacks of this vulnerability can result in unauthorized cr= eation, deletion or modification access to critical data or all PeopleSoft = Enterprise PT PeopleTools accessible data as well as unauthorized access to=
critical data or complete access to all PeopleSoft Enterprise PT PeopleToo=
ls accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity = impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).</td> <td>2026-06-16</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35271" target=3D= "_blank" rel=3D"noopener">CVE-2026-35271</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Deployment Package). Supported versions that ar=
e affected are 8.61 and 8.62. Easily exploitable vulnerability allows unaut= henticated attacker with logon to the infrastructure where PeopleSoft Enter= prise PT PeopleTools executes to compromise PeopleSoft Enterprise PT People= Tools. Successful attacks of this vulnerability can result in takeover of P= eopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.4 (Confidentiali= ty, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/P= R:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35272" target=3D= "_blank" rel=3D"noopener">CVE-2026-35272</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Deployment Package). Supported versions that ar=
e affected are 8.61 and 8.62. Easily exploitable vulnerability allows unaut= henticated attacker with network access via HTTP to compromise PeopleSoft E= nterprise PT PeopleTools. Successful attacks of this vulnerability can resu=
lt in unauthorized access to critical data or complete access to all People= Soft Enterprise PT PeopleTools accessible data as well as unauthorized upda= te, insert or delete access to some of PeopleSoft Enterprise PT PeopleTools=
accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</td> <td>2026-06-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35274" target=3D= "_blank" rel=3D"noopener">CVE-2026-35274</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Application Server). Supported versions that ar=
e affected are 8.61 and 8.62. Difficult to exploit vulnerability allows una= uthenticated attacker with network access via HTTP to compromise PeopleSoft=
Enterprise PT PeopleTools. Successful attacks of this vulnerability can re= sult in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Sco=
re 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: = (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35276" target=3D= "_blank" rel=3D"noopener">CVE-2026-35276</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Performance Monitor). Supported versions that a=
re affected are 8.61 and 8.62. Difficult to exploit vulnerability allows un= authenticated attacker with network access via HTTP to compromise PeopleSof=
t Enterprise PT PeopleTools. Successful attacks of this vulnerability can r= esult in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Sc= ore 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35279" target=3D= "_blank" rel=3D"noopener">CVE-2026-35279</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Deployment Package). Supported versions that ar=
e affected are 8.61 and 8.62. Easily exploitable vulnerability allows high = privileged attacker with logon to the infrastructure where PeopleSoft Enter= prise PT PeopleTools executes to compromise PeopleSoft Enterprise PT People= Tools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, = attacks may significantly impact additional products (scope change). Succes= sful attacks of this vulnerability can result in takeover of PeopleSoft Ent= erprise PT PeopleTools. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity=
and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/= C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35288" target=3D= "_blank" rel=3D"noopener">CVE-2026-35288</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise PT P= eopleTools</td>
<td>Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Or= acle PeopleSoft (component: Deployment Package). Supported versions that ar=
e affected are 8.61 and 8.62. Difficult to exploit vulnerability allows una= uthenticated attacker with network access via HTTPS to compromise PeopleSof=
t Enterprise PT PeopleTools. Successful attacks of this vulnerability can r= esult in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Sc= ore 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector:=
(CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35289" target=3D= "_blank" rel=3D"noopener">CVE-2026-35289</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel Apps - Marketing</t=
<td>Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel C=
RM (component: Marketing). Supported versions that are affected are 17.0-26= .5. Easily exploitable vulnerability allows unauthenticated attacker with n= etwork access via HTTP to compromise Siebel Apps - Marketing. Successful at= tacks of this vulnerability can result in takeover of Siebel Apps - Marketi= ng. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46884" target=3D= "_blank" rel=3D"noopener">CVE-2026-46884</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel Apps - Marketing</t=
<td>Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel C=
RM (component: Marketing). Supported versions that are affected are 17.0-26= .5. Easily exploitable vulnerability allows unauthenticated attacker with n= etwork access via HTTP to compromise Siebel Apps - Marketing. Successful at= tacks of this vulnerability can result in takeover of Siebel Apps - Marketi= ng. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46887" target=3D= "_blank" rel=3D"noopener">CVE-2026-46887</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel Apps - Marketing</t=
<td>Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel C=
RM (component: Marketing). Supported versions that are affected are 17.0-26= .5. Easily exploitable vulnerability allows unauthenticated attacker with n= etwork access via HTTP to compromise Siebel Apps - Marketing. Successful at= tacks of this vulnerability can result in takeover of Siebel Apps - Marketi= ng. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46889" target=3D= "_blank" rel=3D"noopener">CVE-2026-46889</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel Apps - Marketing</t=
<td>Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel C=
RM (component: Marketing). Supported versions that are affected are 17.0-26= .5. Easily exploitable vulnerability allows unauthenticated attacker with n= etwork access via HTTP to compromise Siebel Apps - Marketing. Successful at= tacks of this vulnerability can result in takeover of Siebel Apps - Marketi= ng. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46890" target=3D= "_blank" rel=3D"noopener">CVE-2026-46890</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel Apps - Marketing</t=
<td>Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel C=
RM (component: Marketing). Supported versions that are affected are 17.0-26= .5. Easily exploitable vulnerability allows low privileged attacker with ne= twork access via HTTP to compromise Siebel Apps - Marketing. Successful att= acks of this vulnerability can result in takeover of Siebel Apps - Marketin=
g. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability imp= acts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46886" target=3D= "_blank" rel=3D"noopener">CVE-2026-46886</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel CRM Cloud Applicati= ons</td>
<td>Vulnerability in the Siebel CRM Cloud Applications product of Oracle Si= ebel CRM (component: Siebel Cloud Manager). Supported versions that are aff= ected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticate=
d attacker with network access via HTTP to compromise Siebel CRM Cloud Appl= ications. Successful attacks of this vulnerability can result in takeover o=
f Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.8 (Confidentiality, = Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/= UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46919" target=3D= "_blank" rel=3D"noopener">CVE-2026-46919</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel CRM Cloud Applicati= ons</td>
<td>Vulnerability in the Siebel CRM Cloud Applications product of Oracle Si= ebel CRM (component: Siebel Cloud Manager). Supported versions that are aff= ected are 17.0-26.5. Difficult to exploit vulnerability allows unauthentica= ted attacker with network access via HTTP to compromise Siebel CRM Cloud Ap= plications. Successful attacks of this vulnerability can result in takeover=
of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.1 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:= N/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46920" target=3D= "_blank" rel=3D"noopener">CVE-2026-46920</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel CRM Cloud Applicati= ons</td>
<td>Vulnerability in the Siebel CRM Cloud Applications product of Oracle Si= ebel CRM (component: Siebel Cloud Manager). Supported versions that are aff= ected are 17.0-26.5. Easily exploitable vulnerability allows low privileged=
attacker with network access via HTTP to compromise Siebel CRM Cloud Appli= cations. Successful attacks of this vulnerability can result in takeover of=
Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, I= ntegrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/U= I:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46921" target=3D= "_blank" rel=3D"noopener">CVE-2026-46921</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel CRM Cloud Applicati= ons</td>
<td>Vulnerability in the Siebel CRM Cloud Applications product of Oracle Si= ebel CRM (component: Siebel Cloud Manager). Supported versions that are aff= ected are 17.0-26.5. Difficult to exploit vulnerability allows unauthentica= ted attacker with access to the physical communication segment attached to = the hardware where the Siebel CRM Cloud Applications executes to compromise=
Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cl= oud Applications, attacks may significantly impact additional products (sco=
pe change). Successful attacks of this vulnerability can result in takeover=
of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.3 (Confidentiality=
, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:= N/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46925" target=3D= "_blank" rel=3D"noopener">CVE-2026-46925</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel CRM Cloud Applicati= ons</td>
<td>Vulnerability in the Siebel CRM Cloud Applications product of Oracle Si= ebel CRM (component: Siebel Cloud Manager). Supported versions that are aff= ected are 17.0-26.5. Easily exploitable vulnerability allows low privileged=
attacker with logon to the infrastructure where Siebel CRM Cloud Applicati= ons executes to compromise Siebel CRM Cloud Applications. While the vulnera= bility is in Siebel CRM Cloud Applications, attacks may significantly impac=
t additional products (scope change). Successful attacks of this vulnerabil= ity can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base = Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vecto=
r: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46926" target=3D= "_blank" rel=3D"noopener">CVE-2026-46926</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel CRM Deployment</td> <td>Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM=
(component: Database Upgrade). Supported versions that are affected are 17= .0-26.5. Easily exploitable vulnerability allows low privileged attacker wi=
th logon to the infrastructure where Siebel CRM Deployment executes to comp= romise Siebel CRM Deployment. Successful attacks of this vulnerability can = result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confi= dentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:= L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46888" target=3D= "_blank" rel=3D"noopener">CVE-2026-46888</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Siebel CRM Integration</td=
<td>Vulnerability in the Siebel CRM Integration product of Oracle Siebel CR=
M (component: EAI). Supported versions that are affected are 17.0-26.5. Eas= ily exploitable vulnerability allows low privileged attacker with network a= ccess via HTTP to compromise Siebel CRM Integration. Successful attacks of = this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3=
.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CV=
SS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46885" target=3D= "_blank" rel=3D"noopener">CVE-2026-46885</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebCenter Content: Imaging= </td>
<td>Vulnerability in the WebCenter Content: Imaging product of Oracle Fusio=
n Middleware (component: Core). Supported versions that are affected are 12= .2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenti= cated attacker with network access via HTTP to compromise WebCenter Content=
: Imaging. Successful attacks of this vulnerability can result in takeover =
of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, In= tegrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI= :N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46783" target=3D= "_blank" rel=3D"noopener">CVE-2026-46783</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebCenter Content: Imaging= </td>
<td>Vulnerability in the WebCenter Content: Imaging product of Oracle Fusio=
n Middleware (component: Core). Supported versions that are affected are 12= .2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenti= cated attacker with network access via HTTP to compromise WebCenter Content=
: Imaging. Successful attacks of this vulnerability can result in unauthori= zed creation, deletion or modification access to critical data or all WebCe= nter Content: Imaging accessible data as well as unauthorized access to cri= tical data or complete access to all WebCenter Content: Imaging accessible = data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS=
Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</td> <td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46784" target=3D= "_blank" rel=3D"noopener">CVE-2026-46784</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebCenter Content: Imaging= </td>
<td>Vulnerability in the WebCenter Content: Imaging product of Oracle Fusio=
n Middleware (component: Core). Supported versions that are affected are 12= .2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil= eged attacker with network access via HTTP to compromise WebCenter Content:=
Imaging. Successful attacks of this vulnerability can result in takeover o=
f WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Int= egrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:= N/S:U/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46780" target=3D= "_blank" rel=3D"noopener">CVE-2026-46780</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 14.1.2.0.0=
and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated at= tacker with network access via HTTP to compromise WebLogic Server. While th=
e vulnerability is in WebLogic Server, attacks may significantly impact add= itional products (scope change). Successful attacks of this vulnerability c=
an result in takeover of WebLogic Server. CVSS 3.1 Base Score 10.0 (Confide= ntiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/= AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35292" target=3D= "_blank" rel=3D"noopener">CVE-2026-35292</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 12.2.1.4.0=
and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated at= tacker with network access via HTTP to compromise WebLogic Server. While th=
e vulnerability is in WebLogic Server, attacks may significantly impact add= itional products (scope change). Successful attacks of this vulnerability c=
an result in takeover of WebLogic Server. CVSS 3.1 Base Score 10.0 (Confide= ntiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/= AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35301" target=3D= "_blank" rel=3D"noopener">CVE-2026-35301</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Core). Supported versions that are affected are 14.1.2.0.0 an=
d 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attack=
er with network access via HTTP to compromise WebLogic Server. While the vu= lnerability is in WebLogic Server, attacks may significantly impact additio= nal products (scope change). Successful attacks of this vulnerability can r= esult in takeover of WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidential= ity, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/= PR:L/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35263" target=3D= "_blank" rel=3D"noopener">CVE-2026-35263</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Core). Supported versions that are affected are 12.2.1.4.0, 1= 4.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allo=
ws high privileged attacker with network access via HTTP to compromise WebL= ogic Server. While the vulnerability is in WebLogic Server, attacks may sig= nificantly impact additional products (scope change). Successful attacks of=
this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Bas=
e Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vec= tor: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35298" target=3D= "_blank" rel=3D"noopener">CVE-2026-35298</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Core). Supported versions that are affected are 12.2.1.4.0, 1= 4.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allo=
ws unauthenticated attacker with network access via TCP to compromise WebLo= gic Server. Successful attacks of this vulnerability can result in takeover=
of WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity an=
d Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H= /I:H/A:H).</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35300" target=3D= "_blank" rel=3D"noopener">CVE-2026-35300</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 14.1.2.0.0=
and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged att= acker with network access via HTTPS to compromise WebLogic Server. Successf=
ul attacks require human interaction from a person other than the attacker = and while the vulnerability is in WebLogic Server, attacks may significantl=
y impact additional products (scope change). Successful attacks of this vul= nerability can result in unauthorized creation, deletion or modification ac= cess to critical data or all WebLogic Server accessible data as well as una= uthorized access to critical data or complete access to all WebLogic Server=
accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity im= pacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).</td> <td>2026-06-16</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35258" target=3D= "_blank" rel=3D"noopener">CVE-2026-35258</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 14.1.2.0.0=
and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated at= tacker with network access via HTTPS to compromise WebLogic Server. Success= ful attacks require human interaction from a person other than the attacker=
. Successful attacks of this vulnerability can result in takeover of WebLog=
ic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availabi= lity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).= </td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35259" target=3D= "_blank" rel=3D"noopener">CVE-2026-35259</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 12.2.1.4.0=
and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged att= acker with network access via HTTP to compromise WebLogic Server. Successfu=
l attacks of this vulnerability can result in takeover of WebLogic Server. = CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impact= s). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35299" target=3D= "_blank" rel=3D"noopener">CVE-2026-35299</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 12.2.1.4.0=
and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated = attacker with network access via HTTP to compromise WebLogic Server. Succes= sful attacks require human interaction from a person other than the attacke=
r and while the vulnerability is in WebLogic Server, attacks may significan= tly impact additional products (scope change). Successful attacks of this v= ulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score=
8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (C= VSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</td>
<td>2026-06-16</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35302" target=3D= "_blank" rel=3D"noopener">CVE-2026-35302</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 12.2.1.4.0=
and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged att= acker with network access via HTTP to compromise WebLogic Server. Successfu=
l attacks of this vulnerability can result in takeover of WebLogic Server. = CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impact= s). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35303" target=3D= "_blank" rel=3D"noopener">CVE-2026-35303</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Core). Supported versions that are affected are 12.2.1.4.0 an=
d 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attack=
er with network access via HTTP to compromise WebLogic Server. Successful a= ttacks of this vulnerability can result in takeover of WebLogic Server. CVS=
S 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).=
CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35311" target=3D= "_blank" rel=3D"noopener">CVE-2026-35311</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 14.1.2.0.0=
and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged att= acker with logon to the infrastructure where WebLogic Server executes to co= mpromise WebLogic Server. Successful attacks require human interaction from=
a person other than the attacker and while the vulnerability is in WebLogi=
c Server, attacks may significantly impact additional products (scope chang= e). Successful attacks of this vulnerability can result in unauthorized cre= ation, deletion or modification access to critical data or all WebLogic Ser= ver accessible data as well as unauthorized access to critical data or comp= lete access to all WebLogic Server accessible data. CVSS 3.1 Base Score 7.9=
(Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/= PR:L/UI:R/S:C/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>7.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46848" target=3D= "_blank" rel=3D"noopener">CVE-2026-46848</a></td>
</tr>
<td class=3D"vendor-product">Ovatheme--BookPro</td>
<td>Unauthenticated Arbitrary File Deletion in BookPro <=3D 1.1.0 versio= ns.</td>
<td>2026-06-17</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27400" target=3D= "_blank" rel=3D"noopener">CVE-2026-27400</a></td>
</tr>
<td class=3D"vendor-product">Paolo--GeoDirectory</td>
<td>Unauthenticated SQL Injection in GeoDirectory <=3D 2.8.152 versions.= </td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39512" target=3D= "_blank" rel=3D"noopener">CVE-2026-39512</a></td>
</tr>
<td class=3D"vendor-product">park_of_ideas--Moderno</td>
<td>Unauthenticated PHP Object Injection in Moderno < 1.43 versions.</td=
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49108" target=3D= "_blank" rel=3D"noopener">CVE-2026-49108</a></td>
</tr>
<td class=3D"vendor-product">Passionate Programmer Peter--WP Data Access</t=
<td>Unauthenticated SQL Injection in WP Data Access <=3D 5.5.70 versions= .</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42665" target=3D= "_blank" rel=3D"noopener">CVE-2026-42665</a></td>
</tr>
<td class=3D"vendor-product">Paul--iControlWP</td>
<td>Unauthenticated Privilege Escalation in iControlWP <=3D 5.5.3 versio= ns.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34901" target=3D= "_blank" rel=3D"noopener">CVE-2026-34901</a></td>
</tr>
<td class=3D"vendor-product">PerryTS--perry</td>
<td>Perry before 0.5.1166 contains a JWT validation vulnerability that allo=
ws remote attackers to bypass token expiration by exploiting the unconditio= nal setting of validate_exp =3D false in the verify_decode helper within th=
e stdlib JWT verification path. Attackers in possession of a previously iss= ued bearer token can present expired tokens to any jwt.verify() call and re= tain authenticated access indefinitely, bypassing force-expired sessions su=
ch as user logout or administrative revocation.</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53776" target=3D= "_blank" rel=3D"noopener">CVE-2026-53776</a></td>
</tr>
<td class=3D"vendor-product">Personifyinc--Chromacam</td>
<td>Chromacam 4.0.3.0 contains an unquoted service path vulnerability in th=
e PsyFrameGrabberService that allows local attackers to execute arbitrary c= ode by placing malicious executables in unquoted path directories. Attacker=
s with write access to C:\ or subdirectories like C:\Program Files (x86)\Pe= rsonify\ can place a malicious Program.exe or PsyFrameGrabberService.exe fi=
le that executes with LocalSystem privileges when the service starts automa= tically at boot.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-54353" target=3D= "_blank" rel=3D"noopener">CVE-2023-54353</a></td>
</tr>
<td class=3D"vendor-product">pgadmin.org--pgAdmin 4</td>
<td>Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an at= tacker who can influence database content that the assistant reads to execu=
te arbitrary SQL with the privileges of the pgAdmin user's database role. T=
he AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BE= GIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-sup= plied query was forwarded to the database driver without restriction to a s= ingle statement or to read-only verbs, so a multi-statement payload beginni=
ng with COMMIT, END, ROLLBACK, or ABORT terminated the read-only transactio=
n and ran subsequent statements in autocommit mode. The trailing ROLLBACK t= hen had no effect. Delivery is via prompt injection: an attacker who can wr= ite content into any object the AI Assistant may inspect (a row, a column v= alue, a comment) can cause the LLM to emit the multi-statement payload as a=
tool call. With ordinary write privileges on the pgAdmin user's role the a= ttacker can perform unauthorised data modification. When the pgAdmin user's=
role is a PostgreSQL superuser or holds pg_execute_server_program, the cha=
in extends to remote code execution on the database server host via COPY ..=
. TO PROGRAM. Fix validates the LLM-supplied query up front: it must parse =
to exactly one non-empty / non-comment statement whose leading real token (= after stripping whitespace, comments, and punctuation) is one of SELECT, WI= TH, EXPLAIN, SHOW, VALUES, or TABLE. Transaction-control verbs, DML, DDL, C= ALL, COPY, DO, SET/RESET, and everything else are rejected before any datab= ase work happens. PostgreSQL's READ ONLY mode continues to backstop data-mo= difying CTEs, EXPLAIN ANALYZE on writes, and volatile side effects. This is= sue affects pgAdmin 4: from 9.13 before 9.16.</td>
<td>2026-06-18</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12045" target=3D= "_blank" rel=3D"noopener">CVE-2026-12045</a></td>
</tr>
<td class=3D"vendor-product">pgadmin.org--pgAdmin 4</td>
<td>Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DEL= ETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqledi= tor/update_connection/<sgid>/<sid>/<did> -- were the only=
routes in the module missing the @pga_login_required decorator. Both reach=
a pickle.loads sink on session['gridData'][<trans_id>]['command_obj'=
]: the close endpoint via close_sqleditor_session(), and update_sqleditor_c= onnection via check_transaction_status(). In server mode these endpoints we=
re reachable without any authenticated pgAdmin session. The defect is a mis= sing-authentication-on-critical-function (CWE-306) wrapper around a deseria= lization-of-untrusted-data sink (CWE-502). Exploiting it for remote code ex= ecution requires the attacker to also forge a server-side session file whos=
e gridData entry contains a malicious pickle payload, which in turn require=
s both (a) knowledge of pgAdmin's Flask SECRET_KEY (no chain to leak it is = described here -- the attacker must already possess it) and (b) write acces=
s to pgAdmin's sessions/ directory on the host. Neither precondition is gra= nted by this defect on its own. When those preconditions are met from anoth=
er channel (misconfigured deployment, prior compromise, leaked configuratio= n), the missing auth gate is the final hop that turns an existing partial c= ompromise into unauthenticated code execution in the pgAdmin process -- and=
, by extension, on the host under whatever account runs pgAdmin. Fix is a o= ne-line @pga_login_required decorator on each of the two endpoints, matchin=
g the convention used by every other route in the module. The is_authentica= ted / MFA chain now runs before the trans_id is dereferenced, so an unauthe= nticated request is rejected before reaching the deserialization path. The = defect is server-mode only. In DESKTOP mode pgAdmin's before_request hook r= e-authenticates DESKTOP_USER on every request, so no endpoint can be exerci= sed in an unauthenticated state and no auth decorator (or its absence) is m= eaningful. The accompanying regression test mirrors the attacker's path -- = harvests an X-pgA-CSRFToken from GET /login and replays it against both end= points -- and self-skips outside server mode for that reason; it is wired i= nto the existing server-mode CI workflow alongside the data-isolation tests=
. This issue affects pgAdmin 4: from 6.9 before 9.16.</td>
<td>2026-06-18</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12046" target=3D= "_blank" rel=3D"noopener">CVE-2026-12046</a></td>
</tr>
<td class=3D"vendor-product">pgadmin.org--pgAdmin 4</td>
<td>Stored cross-site scripting in pgAdmin 4's error-rendering and plan-nod= e-rendering paths. Text returned by a PostgreSQL server (ErrorResponse mess= ages, including object names quoted back inside relation-does-not-exist err= ors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed = verbatim through html-react-parser at every user-facing sink - the notifier=
toasts, FormFooterMessage / FormInput help and error areas, FormNote, Moda= lProvider AlertContent and confirmDelete, ToolErrorView, the Explain visual= iser's NodeText panel, the SQL editor confirm dialogs, ConfirmSaveContent, = PreferencesHelper modal alerts, and SelectThemes helper text. A PostgreSQL = server an attacker controls - or any server returning attacker-influenced t= ext such as a table or column name a low-privilege database user can create=
- could inject arbitrary HTML (including <iframe>) into the pgAdmin = DOM the moment the victim's pgAdmin connected to that server or viewed an E= xplain plan that referenced the crafted object. The injected iframe's srcdo=
c could fetch attacker-served JavaScript and, by writing to parent.location=
, redirect the victim's top-level pgAdmin browser tab to an attacker-contro= lled URL. Because the injection originates from inside pgAdmin's own interf= ace, standard anti-clickjacking controls (X-Frame-Options, Content-Security= -Policy: frame-ancestors) do not mitigate it. A phishing page rendered insi=
de the legitimate pgAdmin window is indistinguishable from a genuine pgAdmi=
n dialog. Fix combines three complementary layers. (1) DOMPurify sanitisati=
on is wrapped around every html-react-parser call site reachable from notif= ier, alert, form-error, Explain, and SQL-editor flows. (2) A new plain-text=
rendering contract - SafeMessage / SafeHtmlMessage components plus Notifie= r.errorText / alertText / warningText / infoText / successText helpers - is=
introduced; around fifty callers across browser, tools, dashboard, debugge=
r, misc, llm, preferences, schema diff, and the SQL editor that previously = interpolated backend-derived strings are migrated to the plain-text variant=
s. (3) Backend HTML-escape is applied at the post-connection-SQL handler (e= xecute_post_connection_sql) via a new sanitize_external_text helper, so thi= rd-party JSON consumers (audit logs, API clients) never receive raw markup = either; the Explain plan-info renderer is also patched to _.escape Recheck = Cond and Exact Heap Blocks at construction (matching every sibling field), = giving defence in depth even before DOMPurify runs. This issue affects pgAd= min 4: from 6.0 before 9.16.</td>
<td>2026-06-18</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12048" target=3D= "_blank" rel=3D"noopener">CVE-2026-12048</a></td>
</tr>
<td class=3D"vendor-product">pgadmin.org--pgAdmin 4</td>
<td>SQL injection in pgAdmin 4 across every dialog template that renders ``= COMMENT ON ... IS '<description>'`` for a user-supplied description f= ield. The Jinja templates for Domains (and their constraints), Foreign Tabl= es, Languages, and Event Triggers, plus the Views OID-lookup query, interpo= lated the description directly inside a single-quoted SQL literal -- ``'{{ = data.description }}'`` -- instead of passing it through the ``qtLiteral`` e= scape filter. An authenticated pgAdmin user with permission to create or al= ter the affected object types could submit a description containing an apos= trophe, break out of the literal and chain arbitrary SQL. The injected SQL = runs under the PostgreSQL role the user is already authenticated as; for a = connected role with ``COPY ... TO/FROM PROGRAM`` (typically PostgreSQL supe= ruser), this chains to OS command execution on the PostgreSQL host. The def= ect does not cross a privilege boundary -- the user already has direct SQL = access to that role through pgAdmin's Query Tool -- so the attacker gains n=
o capability beyond what their database role already grants. The marginal i= mpact captures bypass of any application-layer Query Tool gating an operato=
r may have configured. The defect was originally reported against the Domai=
n Dialog ``description`` field; a code-wide audit identified sixteen sites =
of the same pattern across the templates listed above. The same review also=
surfaced ten related sinks in the pgstattuple/pgstatindex stats templates =
-- ``pgstattuple('{{schema}}.{{table}}')`` and the matching pgstatindex sha=
pe -- where ``qtIdent`` escapes embedded double quotes inside the identifie=
r but not apostrophes, so a user with CREATE privilege on a schema could pl= ant a table or index named ``foo'bar`` and a later stats viewer would rende=
r an unbalanced literal. Fix is layered: 1. Sites: replace every ``'{{ x.de= scription }}'`` with ``{{ x.description|qtLiteral(conn) }}`` (no surroundin=
g quotes -- the filter wraps the value in escaped quotes itself). Plumb ``c= onn=3Dself.conn`` through every ``render_template`` call that loads one of = these templates. Also corrects a ``{ % elif`` Jinja typo in the foreign-tab=
le schema diff (dead branch). Rewrite the ten pgstattuple/pgstatindex stats=
sites to address the relation via OID + ``::oid::regclass`` cast (e.g. ``p= gstattuple({{ tid }}::oid::regclass)``), eliminating the embedded literal-c= all form entirely so that bug-class can no longer recur there. 2. Driver ha= rdening: ``qtLiteral`` (in ``utils/driver/psycopg3/__init__.py``) used to s= ilently return the raw unescaped value when its ``conn`` argument was falsy=
. It now raises ``ValueError`` -- surfacing the entire bug class going forw= ard. The change immediately uncovered eight latent plumbing bugs (in ``sche= mas/__init__.py``, ``schemas/functions/__init__.py``, ``schemas/tables/util= s.py``, ``foreign_servers/__init__.py``, and seven sites in ``roles/__init_= _.py``) -- all fixed as part of this patch. The inner ``except`` block that=
swallowed adapter-level failures and returned the raw value is also remove=
d, so unadaptable inputs raise instead of leaking unescaped values. 3. Regr= ession tests: a per-template behavioural test renders each previously-vulne= rable template with an apostrophe-injection payload and asserts the escaped=
fragment is present and the vulnerable fragment absent; a lint test walks = every ``*.sql`` template flagging any ``'{{ ... }}'`` single-quote-wrapped = interpolation against an explicit allowlist; unit tests cover the new qtLit= eral fail-fast and inner-except raise paths. This issue affects pgAdmin 4: = from 1.0 before 9.16.</td>
<td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12044" target=3D= "_blank" rel=3D"noopener">CVE-2026-12044</a></td>
</tr>
<td class=3D"vendor-product">php-standard-library--php-standard-library</td=
<td>PHP Standard Library (PSL) is set of APIs covering async, collections, = networking, I/O, cryptography, terminal UI, etc. In versions 6.1.0, 6.1.1 a=
nd 6.2.0, the Psl\H2\ServerConnection does not validate that the total byte=
s received in DATA frames match the content-length header declared in the H= EADERS frame, allowing request smuggling. This is in violation of RFC 9113 = =C3=82=C2=A78.1.1. A malicious client is able to send more DATA bytes than = declared, smuggling additional content past application-level size limits a=
nd send fewer DATA bytes than declared and close the stream early, causing = applications that trust the declared length to behave incorrectly. The vuln= erability is only reachable for consumers using Psl\H2\ServerConnection dir= ectly to accept untrusted client traffic. Consumers of documented high-leve=
l PSL APIs are not affected. This issue has been fixed in versions 6.1.2 an=
d 6.2.1.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48979" target=3D= "_blank" rel=3D"noopener">CVE-2026-48979</a></td>
</tr>
<td class=3D"vendor-product">phpMyFAQ--phpMyFAQ</td>
<td>phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in=
editUser() and updateUserRights() endpoints that allow authenticated admin= istrators to escalate privileges. Non-SuperAdmin users with edit_user permi= ssion can set is_superadmin flag or grant arbitrary rights to escalate to S= uperAdmin access.</td>
<td>2026-06-21</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56396" target=3D= "_blank" rel=3D"noopener">CVE-2026-56396</a></td>
</tr>
<td class=3D"vendor-product">PickleScan--PickleScan</td>
<td>PickleScan before 0.0.33 fails to include the pty.spawn function in its=
unsafe globals list, allowing attackers to bypass security checks. Malicio=
us actors can craft pickle payloads using pty.spawn to achieve arbitrary co=
de execution when files are processed by PickleScan.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71322" target=3D= "_blank" rel=3D"noopener">CVE-2025-71322</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing a= ttackers to bypass the entire blocklist by resolving any dangerous function=
through indirect REDUCE calls. Remote attackers can invoke any blocked fun= ction such as os.system, builtins.exec, or subprocess.call to achieve remot=
e code execution.</td>
<td>2026-06-17</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3490" target=3D"= _blank" rel=3D"noopener">CVE-2026-3490</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.33 contains an incomplete deny-list that fails to=
block pydoc.locate and operator.methodcaller functions, allowing attackers=
to bypass security checks. Remote attackers can craft malicious pickle fil=
es using these unblocked functions to achieve arbitrary code execution when=
the pickle is deserialized.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71320" target=3D= "_blank" rel=3D"noopener">CVE-2025-71320</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.33 contains an arbitrary file writing vulnerabili=
ty that allows attackers to bypass the dangerous blocklist by using distuti= ls.file_util.write_file. Attackers can construct malicious pickle objects t=
o overwrite critical system files and achieve denial of service or remote c= ode execution.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71321" target=3D= "_blank" rel=3D"noopener">CVE-2025-71321</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.33 fails to block the ctypes module, allowing att= ackers to achieve remote code execution by invoking direct syscalls and acc= essing raw memory. Attackers can craft malicious pickle files using ctypes.= WinDLL to load kernel32.dll and execute arbitrary commands, bypassing sandb=
ox protections and gadget chain detection.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71323" target=3D= "_blank" rel=3D"noopener">CVE-2025-71323</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.27 contains a parsing logic error in the _list_gl= obals function when handling STACK_GLOBAL opcodes, failing to track argumen=
ts in the correct range and allowing malicious pickle files to bypass detec= tion. Attackers can craft pickle files with arguments at position zero to t= rigger unexpected exceptions and evade security scanning.</td> <td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71325" target=3D= "_blank" rel=3D"noopener">CVE-2025-71325</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 1.0.4 contains an incomplete blocklist for the profil=
e module that fails to block the module-level profile.run() function, allow= ing attackers to achieve arbitrary code execution via exec(). Attackers can=
craft malicious pickle files calling profile.run(statement) to execute arb= itrary Python code while picklescan reports zero security issues.</td> <td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53873" target=3D= "_blank" rel=3D"noopener">CVE-2026-53873</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 1.0.1 contains an unsafe deserialization vulnerabilit=
y allowing unauthenticated users to execute arbitrary code by hiding eval c= alls nested under callable objects via getattr. Attackers can embed malicio=
us code in pickle files that evades detection but executes when the pickle =
is loaded from untrusted sources.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53874" target=3D= "_blank" rel=3D"noopener">CVE-2026-53874</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.28 fails to detect malicious pickle files that in= voke torch.utils._config_module.load_config function within reduce methods.=
Attackers can craft pickle files embedding arbitrary code that evades dete= ction but executes during pickle.load, enabling remote code execution in su= pply chain attacks.</td>
<td>2026-06-21</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71348" target=3D= "_blank" rel=3D"noopener">CVE-2025-71348</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.30 fails to detect malicious pickle files using i= dlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers = can embed undetected code in pickle files that executes remote commands whe=
n loaded by victims.</td>
<td>2026-06-21</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71357" target=3D= "_blank" rel=3D"noopener">CVE-2025-71357</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.30 fails to detect cProfile.runctx function calls=
in pickle file reduce methods, allowing attackers to execute arbitrary cod=
e. Malicious pickle files bypass picklescan detection and execute remote co=
de when loaded via pickle.load().</td>
<td>2026-06-21</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71378" target=3D= "_blank" rel=3D"noopener">CVE-2025-71378</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.35 contains an unsafe pickle deserialization vuln= erability allowing unauthenticated attackers to read arbitrary server files=
by chaining io.FileIO and urllib.request.urlopen. Attackers can bypass RCE= -focused blocklists to exfiltrate sensitive data like /etc/passwd to extern=
al servers.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53872" target=3D= "_blank" rel=3D"noopener">CVE-2026-53872</a></td>
</tr>
<td class=3D"vendor-product">Pimcore GmbH--Pimcore CMS/DXP</td>
<td>Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability = that allows authenticated administrative attackers to execute arbitrary met= hods on PHP objects by exploiting empty checkMethodAllowed() and checkPrope= rtyAllowed() implementations in the custom Twig SecurityPolicy. Attackers c=
an supply malicious Twig templates through the DataObject ClassDefinition L= ayout\Text component to perform arbitrary file reads, execute arbitrary dat= abase queries, and potentially achieve remote code execution via PHP object=
gadget chains, with the pimcore_* function wildcard further broadening the=
bypass to all Pimcore Twig functions.</td>
<td>2026-06-17</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11407" target=3D= "_blank" rel=3D"noopener">CVE-2026-11407</a></td>
</tr>
<td class=3D"vendor-product">Pods Framework--Pods</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Pods <=3D 3.3.8 versio= ns.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54191" target=3D= "_blank" rel=3D"noopener">CVE-2026-54191</a></td>
</tr>
<td class=3D"vendor-product">pontedilana--php-weasyprint</td>
<td>PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an=
HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the=
shell command for WeasyPrint by passing the binary path through `escapeshe= llarg()` first and then checking the *quoted* result with `is_executable()`=
. On POSIX `escapeshellarg('/usr/local/bin/weasyprint')` returns `'/usr/loc= al/bin/weasyprint'` with the single-quote characters as part of the string,=
so `is_executable()` looks for a file whose actual name includes those quo= tes. That file never exists, the "safe" branch is dead code, and the raw `$= binary` string (set via the constructor or `setBinary()`) flows directly in=
to `Symfony\Component\Process\Process::fromShellCommandline()`. Any deploym= ent whose binary path is sourced from configuration, an environment variabl=
e, or a per-tenant setting reaches a shell-command-injection sink. The libr= ary is documented as a one-to-one substitute for KnpLabs/snappy and inherit=
ed the exact pre-fix codepath KnpLabs patched in GHSA-vpr4-p6fq-85jc. PhpWe= asyPrint version 2.5.1 contains a patch for the issue.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49260" target=3D= "_blank" rel=3D"noopener">CVE-2026-49260</a></td>
</tr>
<td class=3D"vendor-product">pontedilana--php-weasyprint</td>
<td>PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an=
HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded th=
e output filename against the `phar://` stream wrapper with a case-sensitiv=
e blacklist. PHP stream wrappers are case-insensitive, so `PHAR://`, `Phar:= //`, etc. bypass the check and reach `fileExists()` (`file_exists()`) in `p= repareOutput()`. On PHP 7 (which the library still supports - PHP 7.4+), th=
is triggers deserialization of a crafted PHAR archive's metadata, leading t=
o remote code execution. This is the patch-bypass of CVE-2023-28115. The sa=
me issue and fix were handled upstream in KnpLabs/snappy (GHSA-92rv-4j2h-8m= jj). PhpWeasyPrint version 2.6.0 contains a patch for the issue.</td> <td>2026-06-19</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49286" target=3D= "_blank" rel=3D"noopener">CVE-2026-49286</a></td>
</tr>
<td class=3D"vendor-product">Powerpackelements--PowerPack Pro for Elementor= </td>
<td>Unauthenticated Broken Authentication in PowerPack Pro for Elementor &l=
t; v2.13.0 versions.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42629" target=3D= "_blank" rel=3D"noopener">CVE-2026-42629</a></td>
</tr>
<td class=3D"vendor-product">PraisonAI--PraisonAI</td>
<td>PraisonAI before 4.5.128 contains an arbitrary shell command execution = vulnerability where the UI modules hardcode approval_mode to auto, overridi=
ng administrator configuration from PRAISON_APPROVAL_MODE environment varia= ble. Authenticated attackers can instruct the LLM agent to execute arbitrar=
y shell commands via subprocess.run with shell=3DTrue, bypassing the manual=
approval gate and insufficient command sanitization blocklists.</td> <td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56075" target=3D= "_blank" rel=3D"noopener">CVE-2026-56075</a></td>
</tr>
<td class=3D"vendor-product">PraisonAI--PraisonAI</td>
<td>PraisonAI before 1.5.128 contains a cross-origin agent execution vulner= ability in the AGUI endpoint that allows remote attackers to trigger arbitr= ary agent execution. The POST /agui endpoint lacks authentication and hardc= odes Access-Control-Allow-Origin: * headers, combined with Starlette's Cont= ent-Type-agnostic JSON parsing, enabling attackers to bypass CORS preflight=
checks via simple requests and exfiltrate sensitive agent responses includ= ing tool execution results and environment data.</td>
<td>2026-06-18</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56076" target=3D= "_blank" rel=3D"noopener">CVE-2026-56076</a></td>
</tr>
<td class=3D"vendor-product">PraisonAI--PraisonAI</td>
<td>PraisonAI before 1.5.115 contains a path traversal vulnerability in Mul= tiAgentMonitor that fails to sanitize agent IDs when building file paths. A= ttackers can include traversal sequences like ../ in agent IDs to read, wri= te, or overwrite arbitrary files, enabling sensitive disclosure, denial of = service, or code execution.</td>
<td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56078" target=3D= "_blank" rel=3D"noopener">CVE-2026-56078</a></td>
</tr>
<td class=3D"vendor-product">PremiumPress Limited.--WordPress Dating Theme<=
<td>Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating T= heme <=3D 11.2.0 versions.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22342" target=3D= "_blank" rel=3D"noopener">CVE-2026-22342</a></td>
</tr>
<td class=3D"vendor-product">PremiumPress Limited.--WordPress Dating Theme<=
<td>Unauthenticated Broken Access Control in WordPress Dating Theme <=3D=
11.2.0 versions.</td>
<td>2026-06-17</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22343" target=3D= "_blank" rel=3D"noopener">CVE-2026-22343</a></td>
</tr>
<td class=3D"vendor-product">premmerce--Premmerce Dev Tools</td>
<td>The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Co=
de Execution via missing authorization in versions up to and including 2.0.=
This is due to the 'generatePluginHandler' function lacking any authorizat= ion check before processing user-supplied POST data, combined with the 'cre= ateFromStub' function performing unsanitized string substitution of the 'pr= emmerce_plugin_namespace' parameter directly into PHP stub files written to=
the wp-content/plugins/ directory. An attacker can inject a semicolon foll= owed by arbitrary PHP code into the namespace parameter, causing the genera= ted plugin file to contain and execute that code when accessed via HTTP. Th=
is makes it possible for authenticated attackers with Subscriber-level acce=
ss and above to create arbitrary PHP files on the server and achieve remote=
code execution.</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6933" target=3D"= _blank" rel=3D"noopener">CVE-2026-6933</a></td>
</tr>
<td class=3D"vendor-product">PressLayouts--Alukas</td>
<td>Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.</td=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39445" target=3D= "_blank" rel=3D"noopener">CVE-2026-39445</a></td>
</tr>
<td class=3D"vendor-product">PressLayouts--EmallShop</td>
<td>Unauthenticated PHP Object Injection in EmallShop <=3D 2.4.21 versio= ns.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39443" target=3D= "_blank" rel=3D"noopener">CVE-2026-39443</a></td>
</tr>
<td class=3D"vendor-product">PressLayouts--Kapee</td>
<td>Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.</td> <td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39446" target=3D= "_blank" rel=3D"noopener">CVE-2026-39446</a></td>
</tr>
<td class=3D"vendor-product">PressLayouts--Kapee</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions= .</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41557" target=3D= "_blank" rel=3D"noopener">CVE-2026-41557</a></td>
</tr>
<td class=3D"vendor-product">PressLayouts--PressMart</td>
<td>Unauthenticated PHP Object Injection in PressMart <=3D 1.2.26 versio= ns.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39442" target=3D= "_blank" rel=3D"noopener">CVE-2026-39442</a></td>
</tr>
<td class=3D"vendor-product">Prince--Integrate Google Drive</td>
<td>Missing Authorization vulnerability in Prince Integrate Google Drive al= lows Exploiting Incorrectly Configured Access Control Security Levels. This=
issue affects Integrate Google Drive: from n/a through 1.3.8.</td> <td>2026-06-17</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-32949" target=3D= "_blank" rel=3D"noopener">CVE-2024-32949</a></td>
</tr>
<td class=3D"vendor-product">Projectopia--Projectopia</td>
<td>Custom role Insecure Direct Object References (IDOR) in Projectopia <= ;=3D 5.1.25.2 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59133" target=3D= "_blank" rel=3D"noopener">CVE-2025-59133</a></td>
</tr>
<td class=3D"vendor-product">Pulseextensions--Flip Wall</td>
<td>Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability=
that allows unauthenticated attackers to execute arbitrary SQL queries by = injecting malicious code through the wallid parameter. Attackers can send G=
ET requests to index.php with the option=3Dcom_flipwall&task=3Dclick&am= p;wallid parameter containing SQL injection payloads to extract sensitive d= atabase information.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20265" target=3D= "_blank" rel=3D"noopener">CVE-2017-20265</a></td>
</tr>
<td class=3D"vendor-product">Pulseextensions--Sponsor Wall</td>
<td>Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerabil= ity that allows unauthenticated attackers to execute arbitrary SQL queries =
by injecting malicious code through the wallid parameter. Attackers can sen=
d GET requests to index.php with the option=3Dcom_sponsorwall&task=3Dcl= ick&wallid parameter containing SQL injection payloads to extract sensi= tive database information including credentials and configuration data.</td=
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20264" target=3D= "_blank" rel=3D"noopener">CVE-2017-20264</a></td>
</tr>
<td class=3D"vendor-product">Qihoo--360 Total Security</td>
<td>A security flaw has been discovered in Qihoo 360 Total Security 6.0. Th=
is vulnerability affects the function RpcStringBindingComposeW of the compo= nent Nucleus Engine Monitoring Logic. Performing a manipulation of the argu= ment NetworkAddr results in protection mechanism failure. The attack requir=
es a local approach. The exploit has been released to the public and may be=
used for attacks. The vendor was contacted early about this disclosure but=
did not respond in any way.</td>
<td>2026-06-15</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12214" target=3D= "_blank" rel=3D"noopener">CVE-2026-12214</a></td>
</tr>
<td class=3D"vendor-product">QuantumCloud--ChatBot</td>
<td>Subscriber Broken Access Control in ChatBot <=3D 7.9.7 versions.</td=
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40788" target=3D= "_blank" rel=3D"noopener">CVE-2026-40788</a></td>
</tr>
<td class=3D"vendor-product">QuantumCloud--Conversational Forms for ChatBot= </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') vulnerability in QuantumCloud Conversational Forms for ChatBot allo=
ws Path Traversal. This issue affects Conversational Forms for ChatBot: fro=
m n/a through 1.1.8.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-32729" target=3D= "_blank" rel=3D"noopener">CVE-2024-32729</a></td>
</tr>
<td class=3D"vendor-product">QuantumCloud--WPBot Pro Wordpress Chatbot</td> <td>Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <=
=3D 13.6.5 versions.</td>
<td>2026-06-17</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60223" target=3D= "_blank" rel=3D"noopener">CVE-2025-60223</a></td>
</tr>
<td class=3D"vendor-product">quarkusio--quarkus</td>
<td>Quarkus is a Java framework for building cloud-native applications. Pri=
or to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20= .6.2, Quarkus HTTP path-based authorization policies can be bypassed using = encoded semicolons (%3B) to smuggle matrix parameters past the security lay= er, and using encoded slashes (%2F) or backslashes (%5C) to access protecte=
d static resources. This is a distinct issue from CVE-2026-39852, which add= ressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1,=
3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.</td> <td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50559" target=3D= "_blank" rel=3D"noopener">CVE-2026-50559</a></td>
</tr>
<td class=3D"vendor-product">Radiflow--iSAP Smart Collector</td>
<td>The device has a webserver that exposes a REST API authenticated with a=
token on the management network. By exploiting an OS command injection vul= nerability an authenticated attacker can send arbitrary commands to the dev= ice that are executed with administrative permissions by the underlying ope= rating system.</td>
<td>2026-06-16</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22313" target=3D= "_blank" rel=3D"noopener">CVE-2026-22313</a></td>
</tr>
<td class=3D"vendor-product">Radiflow--iSAP Smart Collector</td>
<td>The device has a webserver that exposes a REST API authenticated with a=
constant token. The unauthenticated API can be used by an attacker to get = access to system settings, modify the configuration and execute some comman=
ds (e.g. system reboot).</td>
<td>2026-06-16</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22312" target=3D= "_blank" rel=3D"noopener">CVE-2026-22312</a></td>
</tr>
<td class=3D"vendor-product">rainafarai--Notification for Telegram</td> <td>Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram=
<=3D 3.5 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40732" target=3D= "_blank" rel=3D"noopener">CVE-2026-40732</a></td>
</tr>
<td class=3D"vendor-product">Raindropsinfotech--Twitch Tv</td>
<td>Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability=
that allows unauthenticated attackers to execute arbitrary SQL queries by = injecting malicious code through the username and id parameters. Attackers = can send GET requests to index.php with option=3Dcom_twitchtv and view para= meters containing SQL injection payloads to extract sensitive database info= rmation including credentials and configuration data.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20270" target=3D= "_blank" rel=3D"noopener">CVE-2017-20270</a></td>
</tr>
<td class=3D"vendor-product">Real--RealTimes Desktop Service</td>
<td>RealTimes Desktop Service 18.1.4 contains an unquoted service path vuln= erability in the rpdsvc.exe binary that allows local attackers to escalate = privileges. Attackers can place malicious executables in unquoted path dire= ctories to execute arbitrary code with LocalSystem privileges during servic=
e startup or system reboot.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37251" target=3D= "_blank" rel=3D"noopener">CVE-2020-37251</a></td>
</tr>
<td class=3D"vendor-product">Really Simple Plugins--Really Simple SSL</td> <td>Unauthenticated Broken Authentication in Really Simple SSL <=3D 9.5.=
10 versions.</td>
<td>2026-06-15</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48970" target=3D= "_blank" rel=3D"noopener">CVE-2026-48970</a></td>
</tr>
<td class=3D"vendor-product">RealMag777--InPost Gallery</td> <td>Unauthenticated SQL Injection in InPost Gallery <=3D 2.1.4.6 version= s.</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39574" target=3D= "_blank" rel=3D"noopener">CVE-2026-39574</a></td>
</tr>
<td class=3D"vendor-product">Realtek--Realtek Audio Service</td>
<td>Realtek Audio Service 1.0.0.55 contains an unquoted service path vulner= ability in RtkAudioService64.exe that allows local attackers to escalate pr= ivileges by injecting malicious code. Attackers can place executable files =
in the unquoted service path directory to execute arbitrary code with Local= System privileges during service startup or system reboot.</td> <td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37252" target=3D= "_blank" rel=3D"noopener">CVE-2020-37252</a></td>
</tr>
<td class=3D"vendor-product">Realtek--Realtek High Definition Audio Driver<=
<td>Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted se= rvice path vulnerability that allows local attackers to escalate privileges=
by placing a malicious executable in the service path. Attackers can inser=
t an executable file in the unquoted path and restart the service to execut=
e code with LocalSystem privileges.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20085" target=3D= "_blank" rel=3D"noopener">CVE-2016-20085</a></td>
</tr>
<td class=3D"vendor-product">Realtyna--Realtyna Organic IDX plugin</td> <td>Unauthenticated SQL Injection in Realtyna Organic IDX plugin <=3D 5.= 1.0 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45439" target=3D= "_blank" rel=3D"noopener">CVE-2026-45439</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Ansible Automation Platform 2= </td>
<td>A command injection vulnerability was found in galaxy_ng. The do_git_ch= eckout() function in the legacy role import API (v1) interpolates unsanitiz=
ed git ref names (branch/tag names) into shell commands executed via subpro= cess.run() with shell=3DTrue. An authenticated user who controls a git repo= sitory can create a branch or tag with shell metacharacters in the name to = achieve remote code execution on the pulp worker. The vulnerable endpoint i=
s only reachable when GALAXY_ENABLE_LEGACY_ROLES is set to True, which is n=
ot the default configuration.</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12398" target=3D= "_blank" rel=3D"noopener">CVE-2026-12398</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in Pacemaker. An unauthenticated remote attacker can e= xploit an integer overflow vulnerability in the remote message decompressio=
n process. By sending a specially crafted compressed remote message before = authentication, an attacker can cause memory corruption, leading to a denia=
l of service (DoS) in the CIB remote listener. This can result in the affec= ted service crashing.</td>
<td>2026-06-16</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10649" target=3D= "_blank" rel=3D"noopener">CVE-2026-10649</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A heap buffer overflow vulnerability was found in GStreamer's librfb (R= FB/VNC client). The rectangle bounds check incorrectly validates area rathe=
r than individual dimensions, allowing a malicious VNC server to send a rec= tangle that extends beyond the framebuffer. A remote attacker could set up =
a malicious VNC server and trick a user into connecting, resulting in an ou= t-of-bounds heap write that could lead to code execution or a crash.</td> <td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52720" target=3D= "_blank" rel=3D"noopener">CVE-2026-52720</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in the cifs-utils package where the cifs.upcall helper=
fails to securely drop its root privileges before looking up user informat= ion inside a user-controlled environment. A local, low privileged attacker = can exploit this by using a crafted request_key payload to trick the root-o= wned helper into entering a custom environment (namespace) containing a mal= icious NSS module. This forces the system to load the attacker's controlled=
NSS Module and configuration, allowing them to execute arbitrary commands =
as the root user, elevating their privileges and fully compromising the sys= tem.</td>
<td>2026-06-18</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12505" target=3D= "_blank" rel=3D"noopener">CVE-2026-12505</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>An out-of-bounds read vulnerability was found in the VA JPEG decoder in=
GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value = from the bitstream without validating it against available data. A remote a= ttacker could trick a user into opening a specially crafted JPEG file, caus= ing downstream parsing to read beyond the provided input buffer, leading to=
a crash or potential information disclosure.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52719" target=3D= "_blank" rel=3D"noopener">CVE-2026-52719</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A signed integer overflow vulnerability was found in GStreamer's VMnc d= ecoder. A crafted VMnc stream with large cursor dimensions can overflow sig= ned integer payload-size arithmetic, bypassing a length check and leading t=
o out-of-bounds reads. A remote attacker could trick a user into opening a = specially crafted VMnc file, potentially causing a crash or information dis= closure.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52722" target=3D= "_blank" rel=3D"noopener">CVE-2026-52722</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugi= ns-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (= media properties) chunks to configure audio streams. For audio stream heade=
r versions 4 and 5, the parser reads fields such as codec type, packet size=
, sample rate, channel count, and extra codec data length from fixed offset=
s within the chunk without first checking that the chunk contains enough da= ta. If a malicious file provides an MDPR chunk that is too small to contain=
a complete audio stream header, the parser reads beyond the end of the buf= fer. This can cause the application to crash. In some cases, bytes read pas=
t the buffer boundary may be incorporated into stream metadata, which could=
result in limited information disclosure.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53703" target=3D= "_blank" rel=3D"noopener">CVE-2026-53703</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ug=
ly package. When processing a RealMedia file containing a specially crafted=
FILEINFO metadata section, the demuxer parses variable-name and variable-v= alue pairs using re_skip_pascal_string() without validating that offsets re= main within the mapped buffer. Additionally, the element count controlling = the parsing loop is read from attacker-controlled data without validation, = which can cause an infinite loop. A crafted RealMedia file can cause the ap= plication to crash, hang, or potentially read limited adjacent memory conte= nts.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53704" target=3D= "_blank" rel=3D"noopener">CVE-2026-53704</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-go= od. When processing a specially crafted WavPack file, an integer overflow i=
n the buffer size calculation (4 * block_samples * channels) in gst_wavpack= _dec_handle_frame() causes a very small heap allocation. The WavPack librar=
y then writes decoded audio samples far beyond the allocated buffer, result= ing in heap memory corruption. This affects both 32-bit and 64-bit systems = since the arithmetic is performed in 32-bit integers before promotion to th=
e allocation size type. A remote attacker could use this flaw to crash an a= pplication or potentially execute arbitrary code by convincing a user to op=
en a malicious WavPack audio file.</td>
<td>2026-06-15</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53705" target=3D= "_blank" rel=3D"noopener">CVE-2026-53705</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A heap buffer overflow vulnerability was found in libaom, the reference=
AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processin=
g (LAP) mode causes the first-pass stats ring buffer wrap-around guard to b=
e bypassed when g_lag_in_frames is set to 1 or higher. This results in a 23= 2-byte out-of-bounds write on every encoded frame after the second, corrupt= ing adjacent heap objects. An attacker who can influence encoder configurat= ion in a transcoding service or WebRTC session could exploit this to cause =
a denial of service (process crash) or potentially achieve code execution.<=
<td>2026-06-19</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56208" target=3D= "_blank" rel=3D"noopener">CVE-2026-56208</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>An arbitrary address write vulnerability was found in libaom, the refer= ence AV1 codec implementation. A missing bounds check in the SVC (Scalable = Video Coding) layer ID control function allows an attacker to inject an arb= itrary pointer into the cyclic refresh map field via crafted image pixel va= lues. The encoder then writes approximately 1,200 bytes at the attacker-con= trolled address. This is fully deterministic and does not require a separat=
e information leak. An attacker who can supply frames to a network-facing l= ibaom encoder with SVC enabled could exploit this for denial of service or = potential code execution.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56209" target=3D= "_blank" rel=3D"noopener">CVE-2026-56209</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A heap-buffer-overflow read vulnerability was found in libaom, the refe= rence AV1 codec implementation. A missing bounds check in the SVC (Scalable=
Video Coding) layer ID control function allows setting a spatial_layer_id = exceeding the configured number of layers. This causes an out-of-bounds hea=
p read of approximately 40,728 bytes when computing a layer context array i= ndex. An attacker who can influence SVC encoder parameters in a network-fac= ing service could exploit this for information disclosure (heap content lea=
k) or denial of service (segmentation fault from hitting unmapped memory).<=
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56210" target=3D= "_blank" rel=3D"noopener">CVE-2026-56210</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A remote code execution vulnerability was found in libaom, the referenc=
e AV1 codec implementation. Insufficient bounds validation in the AV1 encod= er's SVC (Scalable Video Coding) layer ID control allows an attacker to sup= ply crafted video frame pixels that overlap with internal encoder layer con= text structures. In fork-based video processing services, an attacker can u=
se this to hijack the cyclic refresh map pointer, brute-force the process b= ase address via a crash oracle, and redirect control flow to achieve arbitr= ary command execution. Exploitation requires the target service to use liba=
om with SVC encoding enabled and accept attacker-supplied video frames.</td=
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56211" target=3D= "_blank" rel=3D"noopener">CVE-2026-56211</a></td>
</tr>
<td class=3D"vendor-product">Redhat--QEMU</td>
<td>A flaw was found in QEMU. When reading input audio in the virtio-snd de= vice input callback, the `virtio_snd_pcm_in_cb` function did not check whet= her the iov could fit the data buffer, potentially leading to a heap out-of= -bounds write. This issue exists due to an incomplete fix for CVE-2024-7730= .</td>
<td>2026-06-19</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3195" target=3D"= _blank" rel=3D"noopener">CVE-2026-3195</a></td>
</tr>
<td class=3D"vendor-product">RelyWP--Coupon Affiliates</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <=3D=
7.5.3 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40770" target=3D= "_blank" rel=3D"noopener">CVE-2026-40770</a></td>
</tr>
<td class=3D"vendor-product">RelyWP--Coupon Affiliates</td>
<td>Subscriber Sensitive Data Exposure in Coupon Affiliates <=3D 7.8.1 v= ersions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49068" target=3D= "_blank" rel=3D"noopener">CVE-2026-49068</a></td>
</tr>
<td class=3D"vendor-product">ReviewX--ReviewX</td>
<td>Unauthenticated Broken Authentication in ReviewX <=3D 2.3.6 versions= .</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40781" target=3D= "_blank" rel=3D"noopener">CVE-2026-40781</a></td>
</tr>
<td class=3D"vendor-product">Ritlabs--TinyWeb Server</td>
<td>A security vulnerability has been detected in Ritlabs TinyWeb Server up=
to 1.94 on Win32. This impacts an unknown function in the library libeay32= .dll.html of the component Header Handler. The manipulation of the argument=
Authorization leads to stack-based buffer overflow. The attack can be init= iated remotely. The exploit has been disclosed publicly and may be used. Th=
e vendor was contacted early about this disclosure but did not respond in a=
ny way.</td>
<td>2026-06-15</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12200" target=3D= "_blank" rel=3D"noopener">CVE-2026-12200</a></td>
</tr>
<td class=3D"vendor-product">Royal Elementor Addons--Royal Elementor Addons=
Pro</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pr=
o < 1.7.1041 versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40720" target=3D= "_blank" rel=3D"noopener">CVE-2026-40720</a></td>
</tr>
<td class=3D"vendor-product">Royal Plugins--Royal MCP</td>
<td>Unauthenticated Broken Access Control in Royal MCP <=3D 1.4.2 versio= ns.</td>
<td>2026-06-15</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40775" target=3D= "_blank" rel=3D"noopener">CVE-2026-40775</a></td>
</tr>
<td class=3D"vendor-product">Ruben Garcia--AutomatorWP</td>
<td>Subscriber Broken Authentication in AutomatorWP <=3D 5.6.7 versions.= </td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40785" target=3D= "_blank" rel=3D"noopener">CVE-2026-40785</a></td>
</tr>
<td class=3D"vendor-product">Ruben Garcia--AutomatorWP</td>
<td>Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <=3D 5.6.7=
versions.</td>
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42650" target=3D= "_blank" rel=3D"noopener">CVE-2026-42650</a></td>
</tr>
<td class=3D"vendor-product">Ruben Garcia--AutomatorWP</td>
<td>Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <=3D 5.7.2=
versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42775" target=3D= "_blank" rel=3D"noopener">CVE-2026-42775</a></td>
</tr>
<td class=3D"vendor-product">Ruben Garcia--GamiPress</td>
<td>Subscriber SQL Injection in GamiPress <=3D 7.8.7 versions.</td> <td>2026-06-15</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48874" target=3D= "_blank" rel=3D"noopener">CVE-2026-48874</a></td>
</tr>
<td class=3D"vendor-product">rxi--microtar</td>
<td>A stack-based buffer overflow exists in the raw_to_header() function in=
src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte nam=
e and linkname fields of a TAR header with strcpy() without guaranteeing nu=
ll termination of the source. The POSIX ustar format permits these fixed-wi= dth fields to be fully populated with non-null bytes, so a crafted archive = whose linkname field (followed by the trailing padding of the 512-byte raw = header) contains no null terminator causes strcpy() to read past the end of=
the 512-byte raw header stack buffer and to write past the destination hea= der buffer. A remote attacker who supplies a crafted TAR archive that the v= ictim opens or parses (via mtar_open(), mtar_read_header(), or mtar_find())=
can cause an out-of-bounds read and a stack buffer overflow, resulting in = denial of service (crash) and potentially arbitrary code execution. Confirm=
ed with AddressSanitizer: stack-buffer-overflow READ of size 356 in raw_to_= header at src/microtar.c:112.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55738" target=3D= "_blank" rel=3D"noopener">CVE-2026-55738</a></td>
</tr>
<td class=3D"vendor-product">rxi--microtar</td>
<td>An integer overflow in the mtar_next() function in src/microtar.c in rx=
i microtar 0.1.0 allows a remote attacker to cause a denial of service (unc= ontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_= next() computes the offset to the next record as round_up(h.size, 512) + si= zeof(mtar_raw_header_t) using 32-bit arithmetic. When the header size field=
is a multiple of 512 in the range 0xFFFFFC01-0xFFFFFE00 (e.g. 0xFFFFFE00),=
the addition wraps to 0, so mtar_next() seeks to the current record positi=
on instead of advancing. As a result, mtar_find() and any loop that iterate=
s entries with mtar_next() repeat indefinitely over the same record, hangin=
g the process at 100% CPU with no recovery.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54417" target=3D= "_blank" rel=3D"noopener">CVE-2026-54417</a></td>
</tr>
<td class=3D"vendor-product">SaasProject--Booking Package</td> <td>Unauthenticated Broken Access Control in Booking Package <=3D 1.7.06=
versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40774" target=3D= "_blank" rel=3D"noopener">CVE-2026-40774</a></td>
</tr>
<td class=3D"vendor-product">Satinder Singh--Contact Form Extender for Divi=
Save Entries, File Upload & Country Code Field</td>
<td>Unauthenticated Arbitrary File Deletion in Contact Form Extender for Di=
vi &#8211; Save Entries, File Upload &amp; Country Code Field <=
=3D 1.0.6 versions.</td>
<td>2026-06-15</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40769" target=3D= "_blank" rel=3D"noopener">CVE-2026-40769</a></td>
</tr>
<td class=3D"vendor-product">sbouey--Falang multilanguage</td>
<td>Subscriber Privilege Escalation in Falang multilanguage <=3D 1.4.2 v= ersions.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54805" target=3D= "_blank" rel=3D"noopener">CVE-2026-54805</a></td>
</tr>
<td class=3D"vendor-product">Schiocco--Support Board</td>
<td>Unauthenticated Privilege Escalation in Support Board < 3.8.9 versio= ns.</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27395" target=3D= "_blank" rel=3D"noopener">CVE-2026-27395</a></td>
</tr>
<td class=3D"vendor-product">Select-Themes--Getaway</td>
<td>Unauthenticated Local File Inclusion in Getaway < 1.8 versions.</td> <td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39547" target=3D= "_blank" rel=3D"noopener">CVE-2026-39547</a></td>
</tr>
<td class=3D"vendor-product">Select-Themes--Hiroshi</td>
<td>Unauthenticated PHP Object Injection in Hiroshi <=3D 1.5.1 versions.= </td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39560" target=3D= "_blank" rel=3D"noopener">CVE-2026-39560</a></td>
</tr>
<td class=3D"vendor-product">Select-Themes--Manufaktur Solutions</td> <td>Unauthenticated PHP Object Injection in Manufaktur Solutions <=3D 1.= 1.1 versions.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40752" target=3D= "_blank" rel=3D"noopener">CVE-2026-40752</a></td>
</tr>
<td class=3D"vendor-product">Select-Themes--Micdrop</td>
<td>Unauthenticated PHP Object Injection in Micdrop <=3D 1.3.1 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39580" target=3D= "_blank" rel=3D"noopener">CVE-2026-39580</a></td>
</tr>
<td class=3D"vendor-product">Select-Themes--Mildhill</td>
<td>Unauthenticated PHP Object Injection in Mildhill <=3D 1.5 versions.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39573" target=3D= "_blank" rel=3D"noopener">CVE-2026-39573</a></td>
</tr>
<td class=3D"vendor-product">Select-Themes--Sant</td>
<td>Unauthenticated PHP Object Injection in Sant=C3=83=C2=A9 <=3D 1.5.1 = versions.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39567" target=3D= "_blank" rel=3D"noopener">CVE-2026-39567</a></td>
</tr>
<td class=3D"vendor-product">Select-Themes--Zermatt</td>
<td>Unauthenticated PHP Object Injection in Zermatt <=3D 1.6.1 versions.= </td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39545" target=3D= "_blank" rel=3D"noopener">CVE-2026-39545</a></td>
</tr>
<td class=3D"vendor-product">sentriz--gonic</td>
<td>gonic is a music streaming server / free-software subsonic server API i= mplementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpda= tePlaylist` allows any authenticated Subsonic user (including non-admin) to=
write playlist M3U content to an attacker-controlled absolute filesystem p= ath on the gonic host, and to create intermediate directories with `0o777` = permissions. The bug is independent of CVE-2026-49338 and CVE-2026-49339. I=
t is an unreachable guard clause combined with no path containment in `Stor= e.Write`. Version 0.21.0 patches the issue.</td>
<td>2026-06-19</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49340" target=3D= "_blank" rel=3D"noopener">CVE-2026-49340</a></td>
</tr>
<td class=3D"vendor-product">sentriz--gonic</td>
<td>gonic is a music streaming server / free-software subsonic server API i= mplementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/d= eletePlaylist.view` and `/rest/getPlaylist.view` perform no per-resource au= thorization. Once authenticated as any user (admin or not), an attacker can=
delete any playlist owned by any other user (including admin) by passing i=
ts `id` and read the full contents (name, comment, song list) of any other = user's **private** (non-public) playlist by passing its `id`. The Subsonic = playlist `id` is `base64url("<userID>/<filename>.m3u")`. Becaus=
e filenames are user-supplied or time-derived and the `userID` is a small i= nteger, IDs are guessable and frequently exposed (e.g. a previously-public = playlist that was later made private still has the same ID). This breaks th=
e multi-user trust boundary of gonic: a low-privileged user can wipe an adm= inistrator's curated playlists, and a user can exfiltrate any private playl= ist they obtain an ID for. The issue was fixed in commit `6dd71e6a3c966867e= f8c900d359a7df75789f410`, which is part of version 0.21.0.</td> <td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49338" target=3D= "_blank" rel=3D"noopener">CVE-2026-49338</a></td>
</tr>
<td class=3D"vendor-product">sentriz--gonic</td>
<td>gonic is a music streaming server / free-software subsonic server API i= mplementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a= 7df75789f410` added an ownership check based on `playlist.UserID`. However,=
`playlist.UserID` is derived from the first path segment of the attacker-c= ontrolled playlist ID, with no path containment on the resolved file path. = Any authenticated Subsonic user can therefore bypass the ownership check an=
d read any other user's playlist, delete any other user's playlist, and pro=
be arbitrary file paths on the host for existence/readability. This is a by= pass of the boundary the `6dd71e6` fix is trying to enforce; it is closely = related to the original GONIC-1 IDOR but uses a different primitive (path t= raversal in the `id` parameter rather than direct cross-user access). Commi=
t 0824bed88f6bbc490ba28bf09d28e5dfeb07b445 in version 0.21.0 fixes the issu= e.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49339" target=3D= "_blank" rel=3D"noopener">CVE-2026-49339</a></td>
</tr>
<td class=3D"vendor-product">SEO Squirrly--SEO Plugin by Squirrly SEO</td> <td>Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= ;=3D 12.4.16 versions.</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52714" target=3D= "_blank" rel=3D"noopener">CVE-2026-52714</a></td>
</tr>
<td class=3D"vendor-product">ServerCo--getssl</td>
<td>In ServerCo getssl version 2.49 and prior, the ACME challenge token ret= urned to the client was not strictly validated against RFC 8555 before bein=
g used in challenge-file handling, allowing a maliciously crafted token to = influence local path/filename usage during validation. An attacker who can = supply ACME challenge responses to getssl (for example, a malicious or comp= romised CA endpoint, or an on-path adversary able to tamper with that respo= nse path) could exploit this to achieve unauthorized file write/path traver= sal effects, usually with elevated privileges, ultimately allowing for remo=
te command injection. This issue appears related in spirit to CVE-2023-3819=
8, and is an instance of CWE-73, "External control of file name or path." O= ther ACME shell script handlers may be affected by similar issues.</td> <td>2026-06-16</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10303" target=3D= "_blank" rel=3D"noopener">CVE-2026-10303</a></td>
</tr>
<td class=3D"vendor-product">SeventhQueen--SweetDate Core</td> <td>Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5=
versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69140" target=3D= "_blank" rel=3D"noopener">CVE-2025-69140</a></td>
</tr>
<td class=3D"vendor-product">Shipster--Baggage Freight Shipping Australia</=
<td>WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an u= nrestricted file upload vulnerability that allows unauthenticated attackers=
to upload arbitrary files by exploiting the upload-package.php endpoint. A= ttackers can submit POST requests with malicious file extensions to the upl= oad handler, which moves files without validation to the plugin upload dire= ctory, enabling remote code execution.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25436" target=3D= "_blank" rel=3D"noopener">CVE-2018-25436</a></td>
</tr>
<td class=3D"vendor-product">ShopXO--ShopXO</td>
<td>A vulnerability was determined in ShopXO up to 6.7.1. This vulnerabilit=
y affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIn= tegral of the file app/api/controller/Crontab.php of the component Schedule=
d Task Endpoint. Executing a manipulation can lead to authorization bypass.=
The attack can be executed remotely. The exploit has been publicly disclos=
ed and may be utilized. The vendor was contacted early about this disclosur=
e but did not respond in any way.</td>
<td>2026-06-15</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12204" target=3D= "_blank" rel=3D"noopener">CVE-2026-12204</a></td>
</tr>
<td class=3D"vendor-product">ShortPixel--ShortPixel Image Optimizer</td> <td>Author PHP Object Injection in ShortPixel Image Optimizer <=3D 6.4.3=
versions.</td>
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39471" target=3D= "_blank" rel=3D"noopener">CVE-2026-39471</a></td>
</tr>
<td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
<td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Versions prior to 0.6.6=
2 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's si= gnup page. The application improperly trusts a URL parameter (`next`), whic=
h is passed to `router.push`. An attacker can craft a malicious link that, = when opened by an authenticated user, performs a client-side redirect and e= xecutes arbitrary JavaScript in the context of their browser. This could le=
ad to credential theft, internal network pivoting, and unauthorized actions=
performed on behalf of the victim. Version 0.6.62 patches the issue.</td> <td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55237" target=3D= "_blank" rel=3D"noopener">CVE-2026-55237</a></td>
</tr>
<td class=3D"vendor-product">Simbunch--SIMGenealogy</td>
<td>Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerab= ility that allows unauthenticated attackers to manipulate database queries =
by injecting SQL code through the type parameter. Attackers can send GET re= quests to index.php with the option=3Dcom_simgenealogy, view=3Dlatest param= eters and inject malicious SQL in the type parameter to extract sensitive d= atabase information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20276" target=3D= "_blank" rel=3D"noopener">CVE-2017-20276</a></td>
</tr>
<td class=3D"vendor-product">SiYuan--SiYuan</td>
<td>SiYuan before v3.6.1 fails to sanitize package metadata and README cont= ent in the Bazaar marketplace, allowing malicious package authors to inject=
arbitrary HTML and JavaScript. Attackers can achieve remote code execution=
on any user browsing the Bazaar by embedding XSS payloads in package displ= ayName, description, or README fields, exploiting Electron's nodeIntegratio=
n setting to execute OS commands.</td>
<td>2026-06-21</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56395" target=3D= "_blank" rel=3D"noopener">CVE-2026-56395</a></td>
</tr>
<td class=3D"vendor-product">SiYuan--SiYuan</td>
<td>SiYuan before v3.6.1 fails to sanitize package metadata and README cont= ent in the Bazaar marketplace, allowing malicious package authors to inject=
arbitrary HTML and JavaScript. Attackers can achieve remote code execution=
on any user browsing the Bazaar by embedding XSS payloads in package displ= ayName, description, or README fields, exploiting Electron's nodeIntegratio=
n setting to execute OS commands.</td>
<td>2026-06-21</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56397" target=3D= "_blank" rel=3D"noopener">CVE-2026-56397</a></td>
</tr>
<td class=3D"vendor-product">SlicedInvoices--Sliced Invoices</td>
<td>WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection=
vulnerability that allows authenticated attackers to manipulate database q= ueries by injecting SQL code through the 'post' parameter. Attackers can se=
nd requests to the admin.php endpoint with action=3Dduplicate_quote_invoice=
and malicious 'post' values to extract sensitive database information or m= odify data.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25746" target=3D= "_blank" rel=3D"noopener">CVE-2019-25746</a></td>
</tr>
<td class=3D"vendor-product">Sneeit--MagOne</td>
<td>Unauthenticated Cross Site Scripting (XSS) in MagOne <=3D 9.0 versio= ns.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39548" target=3D= "_blank" rel=3D"noopener">CVE-2026-39548</a></td>
</tr>
<td class=3D"vendor-product">Soft-Php--jCart for OpenCart</td>
<td>Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vuln= erability that allows unauthenticated attackers to manipulate database quer= ies by injecting SQL code through the product_id parameter. Attackers can s= end GET requests to index.php with the option=3Dcom_jcart&route=3Dprodu= ct/product parameters and malicious product_id values to extract sensitive = database information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20282" target=3D= "_blank" rel=3D"noopener">CVE-2017-20282</a></td>
</tr>
<td class=3D"vendor-product">SONAAR MUSIC--Sonaar</td>
<td>Subscriber Privilege Escalation in Sonaar <=3D 4.27.4 versions.</td> <td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59563" target=3D= "_blank" rel=3D"noopener">CVE-2025-59563</a></td>
</tr>
<td class=3D"vendor-product">SONAAR MUSIC--Sonaar</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Sonaar <=3D 4.27.4 ver= sions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59560" target=3D= "_blank" rel=3D"noopener">CVE-2025-59560</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--CET Automated Grading System w= ith AI Predictive Analytics</td>
<td>A security vulnerability has been detected in SourceCodester CET Automa= ted Grading System with AI Predictive Analytics 1.0. Affected is an unknown=
function of the file /index.php of the component Student Self-Registration=
Endpoint. The manipulation leads to improper access controls. Remote explo= itation of the attack is possible.</td>
<td>2026-06-17</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12529" target=3D= "_blank" rel=3D"noopener">CVE-2026-12529</a></td>
</tr>
<td class=3D"vendor-product">SpeakOut!--SpeakOut! Email Petitions</td> <td>Unauthenticated SQL Injection in SpeakOut! Email Petitions <=3D 4.6.=
5 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39530" target=3D= "_blank" rel=3D"noopener">CVE-2026-39530</a></td>
</tr>
<td class=3D"vendor-product">Splunk--Splunk AI Toolkit</td>
<td>In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin"=
Splunk role could execute arbitrary OS commands on the host running the Sp= lunk Enterprise instance. The vulnerability is possible because of an unsaf=
e shell execution pattern in the btool configuration helper, which construc=
ts OS command strings from dynamic parameters without disabling shell inter= pretation.</td>
<td>2026-06-17</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20266" target=3D= "_blank" rel=3D"noopener">CVE-2026-20266</a></td>
</tr>
<td class=3D"vendor-product">Spring--Spring AI</td>
<td>In Spring AI Vector Stores, special characters could be used to force t=
he execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire=
VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-op= ensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0=
through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).</td> <td>2026-06-15</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47835" target=3D= "_blank" rel=3D"noopener">CVE-2026-47835</a></td>
</tr>
<td class=3D"vendor-product">Spring--Spring Cloud Gateway</td>
<td>Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded = headers from untrusted proxies in certain configuration scenarios. This aff= ects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring=
Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13).=
Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.= 3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).</td>
<td>2026-06-15</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47825" target=3D= "_blank" rel=3D"noopener">CVE-2026-47825</a></td>
</tr>
<td class=3D"vendor-product">Spring--Spring Cloud Sleuth</td>
<td>In Spring Cloud Sleuth, it is possible for a user to provide specially = crafted calls that may cause a denial-of-service (DoS) condition. The appli= cation is vulnerable when it uses a vulnerable version of org.springframewo= rk.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation =
is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.1= 3.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41708" target=3D= "_blank" rel=3D"noopener">CVE-2026-41708</a></td>
</tr>
<td class=3D"vendor-product">startreedata--mcp-pinot</td>
<td>mcp-pinot is a Python-based Model Context Protocol (MCP) server for int= eracting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults=
to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication=
enabled. All MCP tools, including SQL query execution, schema creation, an=
d table-config mutation, are reachable by any network-adjacent caller. The = server proxies these calls using server-side Pinot credentials, producing a=
confused-deputy condition that yields full read/write access to the config= ured Pinot cluster. This issue has been fixed in version 3.1.0</td> <td>2026-06-18</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49257" target=3D= "_blank" rel=3D"noopener">CVE-2026-49257</a></td>
</tr>
<td class=3D"vendor-product">statamic--cms</td>
<td>Statamic is a Laravel and Git powered content management system (CMS). = Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It = addressed the issue in the query builder, but the same protection was not a= pplied to in-memory collection sorting. Manipulating sort parameters could = result in the loss of content and assets. This requires a front-end templat=
e that passes request input into a tag's sort parameter. It is not exploita= ble by default - a template would need to be explicitly set up to sort by a=
visitor-controlled value. This has been fixed in 5.73.23 and 6.20.0.</td> <td>2026-06-19</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49287" target=3D= "_blank" rel=3D"noopener">CVE-2026-49287</a></td>
</tr>
<td class=3D"vendor-product">SteeltoeOSS--Steeltoe.Discovery.Eureka</td> <td>Steeltoe is an open source project that provides a collection of librar= ies that helps users build cloud-native applications. In Steeltoe.Discovery= .Eureka prior to versions 4.2.0 and 3.4.0, `DataCenterInfo.FromJson` throws=
`ArgumentException` for any `name` value other than `"MyOwn"` or `"Amazon"=
`, despite the Java Eureka specification defining a third valid value: `"Ne= tflix"`. The exception propagates through the entire registry deserializati=
on chain and is swallowed by the periodic cache refresh task, leaving the l= ocal service registry permanently empty or stale. Versions 4.2.0 and 3.4.0 = patch the issue. If an immediate upgrade is not possible, remove any regist= rations using unsupported `DataCenterInfo.name` values from the registry. I=
n mixed Java/Spring and Steeltoe environments, audit for the `Netflix` data=
center type before deploying Steeltoe Eureka clients.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50196" target=3D= "_blank" rel=3D"noopener">CVE-2026-50196</a></td>
</tr>
<td class=3D"vendor-product">SteeltoeOSS--Steeltoe.Management.Endpoint</td> <td>Steeltoe is an open source project that provides a collection of librar= ies that helps users build cloud-native applications. When Steeltoe managem= ent endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to list=
en on an alternate port (`Management:Endpoints:Port` is configured), the mi= ddleware responsible for restricting access to the endpoints uses the `Host=
` HTTP header rather than the actual network socket port. Versions 3.4.0 an=
d 4.2.0 patch the issue. If an immediate upgrade to a patched version is no=
t possible, add explicit ASP.NET Core authorization (`RequireAuthorization`=
) to all sensitive actuator endpoints as a defense-in-depth measure indepen= dent of port isolation and/or configure the reverse proxy or load balancer =
to enforce the `Host` header value and prevent clients from setting an arbi= trary port.</td>
<td>2026-06-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50194" target=3D= "_blank" rel=3D"noopener">CVE-2026-50194</a></td>
</tr>
<td class=3D"vendor-product">SteeltoeOSS--Steeltoe.Management.Endpoint</td> <td>Steeltoe is an open source project that provides a collection of librar= ies that helps users build cloud-native applications. In Steeltoe.Managemen= t.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prio=
r to version 3.4.0, the `Sanitizer` component in the Environment actuator r= edacts configuration values by matching the configuration key name against =
a suffix list. The default list (`password`, `secret`, `key`, `token`, `.*c= redentials.*`, `vcap_services`) does not cover the standard .NET pattern `C= onnectionStrings:<name>` or Steeltoe Connectors' `Steeltoe:Client:<= ;type>:Default:ConnectionString`. There is no value-based scrubbing, so = full connection string values including embedded `Password=3D` and `user:pa= ss@host` segments are returned verbatim in `/actuator/env` responses. Steel= toe.Management.Endpoint 4.2.0 and Steeltoe.Management.EndpointCore 3.4.0 pa= tch the issue. If an immediate upgrade is not possible: On the standard pat=
h, remove `env` from the actuator exposure list; add `.*connectionstring.*`=
to `KeysToSanitize` as a defense-in-depth measure for both paths; and/or r= equire authorization on actuator endpoints.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50200" target=3D= "_blank" rel=3D"noopener">CVE-2026-50200</a></td>
</tr>
<td class=3D"vendor-product">Stiofan--Events Calendar for GeoDirectory</td> <td>Contributor PHP Object Injection in Events Calendar for GeoDirectory &l= t;=3D 2.3.25 versions.</td>
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39532" target=3D= "_blank" rel=3D"noopener">CVE-2026-39532</a></td>
</tr>
<td class=3D"vendor-product">Stiofan--GetPaid</td>
<td>Insertion of Sensitive Information Into Sent Data vulnerability in Stio= fan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects Get= Paid: from n/a through 2.8.49.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49064" target=3D= "_blank" rel=3D"noopener">CVE-2026-49064</a></td>
</tr>
<td class=3D"vendor-product">strukturag--libde265</td>
<td>libde265 is an open source implementation of the h.265 video codec. Pri=
or to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds = array write in `decoder_context::process_reference_picture_set()` (`libde26= 5/decctx.cc:1376`). The root cause is a missing aggregate bound check on pr= edicted short-term reference picture set entries. Individual list sizes are=
validated, but the combined count after predicted RPS construction can exc= eed the 16-entry `PocStFoll` array, writing at index 16. Version 1.0.20 pat= ches the issue.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49295" target=3D= "_blank" rel=3D"noopener">CVE-2026-49295</a></td>
</tr>
<td class=3D"vendor-product">strukturag--libde265</td>
<td>libde265 is an open source implementation of the h.265 video codec. Pri=
or to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions an=
d 16-bit bit depth causes a signed integer overflow in `de265_image_get_buf= fer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation s= ize to a small value (~1 KB), but the subsequent `fill_image()` call comput=
es the real size using `size_t`, writing ~4 GB into the undersized heap buf= fer. Version 1.1.0 patches the issue.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49346" target=3D= "_blank" rel=3D"noopener">CVE-2026-49346</a></td>
</tr>
<td class=3D"vendor-product">Studio Keren Aga LTD.--Unlimited Elements for = Elementor (Premium)</td>
<td>Contributor Arbitrary File Upload in Unlimited Elements for Elementor (= Premium) <=3D 2.0.6 versions.</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27041" target=3D= "_blank" rel=3D"noopener">CVE-2026-27041</a></td>
</tr>
<td class=3D"vendor-product">StylemixThemes--MasterStudy LMS</td> <td>Subscriber SQL Injection in MasterStudy LMS <=3D 3.7.25 versions.</t=
<td>2026-06-15</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40766" target=3D= "_blank" rel=3D"noopener">CVE-2026-40766</a></td>
</tr>
<td class=3D"vendor-product">StylemixThemes--Motors</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injec= tion. This issue affects Motors: from n/a through 1.4.109.</td> <td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54812" target=3D= "_blank" rel=3D"noopener">CVE-2026-54812</a></td>
</tr>
<td class=3D"vendor-product">StylemixThemes--Motors</td>
<td>Improper Control of Filename for Include/Require Statement in PHP Progr=
am ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors all= ows PHP Local File Inclusion. This issue affects Motors: from n/a through 1= .4.109.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54814" target=3D= "_blank" rel=3D"noopener">CVE-2026-54814</a></td>
</tr>
<td class=3D"vendor-product">sunnyadn--js-toml</td>
<td>js-toml is a TOML parser for JavaScript, fully compliant with the TOML = 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / = binary integer literals via a hand-written `parseBigInt` loop that multipli=
es a `BigInt` accumulator by the radix once per input digit. Each iteration=
performs a `BigInt * BigInt` operation on an accumulator that grows linear=
ly with the number of digits already consumed, so the whole loop is O(n=C3= =82=C2=B2) in the literal length. The lexer regex places no upper bound on = the literal length, so a single TOML document containing one ~500 kB hex li= teral pins one CPU core for ~40 seconds on a modern laptop (Apple M-series,=
Node v22). Memory amplification is bounded but CPU amplification is severe=
and grows quadratically: doubling the literal length quadruples the work. =
A caller that invokes `load()` on attacker-controlled TOML (configuration u= pload endpoints, CI/CD systems ingesting third-party `*.toml`, IDE plugins,=
build tools) is exposed to a single-request CPU exhaustion DoS. Version 1.= 1.1 fixes the issue.</td>
<td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49293" target=3D= "_blank" rel=3D"noopener">CVE-2026-49293</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Harvester</td>
<td>An attacker with network-level access between the SUSE Virtualization a=
nd Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the = TLS handshake and abuse it to bypass TLS as a security control.</td> <td>2026-06-16</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71261" target=3D= "_blank" rel=3D"noopener">CVE-2025-71261</a></td>
</tr>
<td class=3D"vendor-product">SUSE--wicked</td>
<td>Passing of unsanitized strings from DHCP replies into the wicked dhcp c= lient before wicked 0.6.79 could be used by attackers operating a malicious=
DHCP server to execute code on the local machine.</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44932" target=3D= "_blank" rel=3D"noopener">CVE-2026-44932</a></td>
</tr>
<td class=3D"vendor-product">Syed Balkhi--PushEngage Web Push Notifications=
, eCommerce Automation & Chat Widget</td>
<td>Subscriber Sensitive Data Exposure in PushEngage - Web Push Notificatio= ns, eCommerce Automation &amp; Chat Widget <=3D 4.2.3 versions.</td> <td>2026-06-17</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52698" target=3D= "_blank" rel=3D"noopener">CVE-2026-52698</a></td>
</tr>
<td class=3D"vendor-product">Sync-in--server</td>
<td>Sync-in Server is a secure, open-source platform for file storage, shar= ing, collaboration, and syncing. Prior to version 2.3.0, the private IP blo= cklist regex used in the URL download feature does not match IPv4-mapped IP=
v6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypass=
ed on dual-stack systems. Version 2.3.0 fixes the issue.</td> <td>2026-06-16</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47684" target=3D= "_blank" rel=3D"noopener">CVE-2026-47684</a></td>
</tr>
<td class=3D"vendor-product">sysown--proxysql</td>
<td>ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In = versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROX=
Y UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 fram=
e as a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 spe= cification says that when the protocol token is `UNKNOWN`, the receiver MUS=
T ignore any address fields that follow it, because the proxy has declared =
it cannot determine the client identity. ProxySQL parses those address fiel=
ds anyway via `sscanf` and writes the spoofed source address into the sessi= on's `addr.addr` field. From there it flows directly into the query-rule ma= tcher, where the `client_addr` predicate decides routing and ACL. When `mys= ql-proxy_protocol_networks =3D '*'` (the default), any TCP peer can send a = PP1 frame and choose any source IP claim. With that, any `mysql_query_rules=
` row pinned to a `client_addr` value is forgeable: the attacker writes the=
address they want to match into the PP1 line, and ProxySQL routes their qu= ery as if it came from that address. In practice this is a routing and ACL = bypass. Real deployments use `client_addr` for read-write splitting (intern=
al apps go to the primary, public traffic to read replicas), per-app schema=
pinning, and query-filter rules (DDL allowed only from admin CIDR, public = queries blocked from dangerous patterns). An attacker that can reach the fr= ontend port can forge their way into any of those routes. Version 3.0.9 pat= ches this issue.</td>
<td>2026-06-19</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48772" target=3D= "_blank" rel=3D"noopener">CVE-2026-48772</a></td>
</tr>
<td class=3D"vendor-product">sysown--proxysql</td>
<td>ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Ver= sions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption=
vulnerability in the MySQL and PostgreSQL protocol first-read paths. A rem= ote unauthenticated client can declare an oversized first packet length, an=
d ProxySQL passes that attacker-controlled length directly to `recv()` whil=
e writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue.<=
<td>2026-06-19</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48773" target=3D= "_blank" rel=3D"noopener">CVE-2026-48773</a></td>
</tr>
<td class=3D"vendor-product">sysown--proxysql</td>
<td>ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In = versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool = violates its documented read-only contract for MySQL targets. The tool vali= dates only the full input string with a substring blacklist and first-keywo=
rd allowlist, but then executes the entire SQL string on a backend connecti=
on created with `CLIENT_MULTI_STATEMENTS`. As a result, a caller can submit=
a read-only first statement followed by a side-effecting second statement,=
such as `SELECT 1; RENAME TABLE ...`. The validator accepts the payload be= cause it starts with `SELECT` and because side-effecting MySQL statements s= uch as `RENAME TABLE`, `SET`, `RESET`, `LOCK TABLES`, and `KILL` are not re= jected by the blacklist. In a live MCP runtime test, the `/mcp/query` endpo= int accepted a `run_sql_readonly` request. The MCP response reported succes=
s for the first `SELECT`, and direct backend verification showed that the t= able had actually been renamed. This violates the endpoint's read-only secu= rity contract and lets an MCP caller perform backend writes or administrati=
ve SQL, limited by the configured MCP target account's database privileges.=
Version 3.0.9 contains a fix. Other operator mitigations include: keeping = MCP disabled unless required; setting a non-empty `mcp-query_endpoint_auth`=
token before exposing `/mcp/query`; restricting MCP listener network expos= ure; configuring MCP backend target credentials as database-level read-only=
users; and adding temporary MCP query rules to block obvious multi-stateme=
nt patterns.</td>
<td>2026-06-19</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48774" target=3D= "_blank" rel=3D"noopener">CVE-2026-48774</a></td>
</tr>
<td class=3D"vendor-product">szTheory--relyra</td>
<td>Relyra is a strict-by-default SAML 2.0 Service Provider library for Eli= xir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures bec= ause SignatureValue was not cryptographically verified before the library r= eturned a successful authentication result. The XMLDSig trust boundary was = incomplete as :public_key.verify over the exclusive-C14N canonicalized Sign= edInfo was not performed against the configured IdP certificate's public ke=
y, DigestValue was not recomputed over the canonicalized referenced element=
, and canonicalize/2 remained an unused passthrough in the signature-verifi= cation path. The result was a structure-only acceptance path where document=
shape and trust-source rejection could succeed without proving the signatu=
re bytes. A forged SignatureValue carrying an attacker-controlled NameID co= uld be accepted as {:ok}. This issue has been fixed in version 1.2.0.</td> <td>2026-06-18</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49454" target=3D= "_blank" rel=3D"noopener">CVE-2026-49454</a></td>
</tr>
<td class=3D"vendor-product">Takashi Kitajima--MW WP Form</td> <td>Unauthenticated Cross Site Scripting (XSS) in MW WP Form <=3D 5.1.3 = versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48871" target=3D= "_blank" rel=3D"noopener">CVE-2026-48871</a></td>
</tr>
<td class=3D"vendor-product">Tammersoft--Shared Files</td>
<td>Unauthenticated Path Traversal in Shared Files <=3D 1.7.64 versions.= </td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49112" target=3D= "_blank" rel=3D"noopener">CVE-2026-49112</a></td>
</tr>
<td class=3D"vendor-product">Taskbuilder--Taskbuilder</td>
<td>Subscriber SQL Injection in Taskbuilder <=3D 5.0.7 versions.</td> <td>2026-06-15</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52697" target=3D= "_blank" rel=3D"noopener">CVE-2026-52697</a></td>
</tr>
<td class=3D"vendor-product">Techspawn--MultiLoca</td>
<td>Subscriber Privilege Escalation in MultiLoca <=3D 4.2.15 versions.</=
<td>2026-06-17</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39546" target=3D= "_blank" rel=3D"noopener">CVE-2026-39546</a></td>
</tr>
<td class=3D"vendor-product">Terrywcarter--KissGallery</td>
<td>Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerabi= lity that allows unauthenticated attackers to inject SQL commands through t=
he component URL path. Attackers can supply malicious SQL code in the kissg= allery endpoint to execute arbitrary database queries and extract sensitive=
information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20269" target=3D= "_blank" rel=3D"noopener">CVE-2017-20269</a></td>
</tr>
<td class=3D"vendor-product">The Browser Company of New York`--Arc Search</=
<td>Address bar spoofing in Arc Search for Android allows a remote attacker=
to display a trusted domain in the address bar while rendering attacker-co= ntrolled content, enabling phishing.</td>
<td>2026-06-16</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12348" target=3D= "_blank" rel=3D"noopener">CVE-2026-12348</a></td>
</tr>
<td class=3D"vendor-product">themagnifico52--Charity Zone</td>
<td>Subscriber Arbitrary File Upload in Charity Zone <=3D 1.1.1 versions= .</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40749" target=3D= "_blank" rel=3D"noopener">CVE-2026-40749</a></td>
</tr>
<td class=3D"vendor-product">themagnifico52--Ecommerce Zone</td>
<td>Subscriber Arbitrary File Upload in Ecommerce Zone <=3D 0.9.7 versio= ns.</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40747" target=3D= "_blank" rel=3D"noopener">CVE-2026-40747</a></td>
</tr>
<td class=3D"vendor-product">themagnifico52--Kids Gift Shop</td>
<td>Subscriber Arbitrary File Upload in Kids Gift Shop <=3D 0.5.4 versio= ns.</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40748" target=3D= "_blank" rel=3D"noopener">CVE-2026-40748</a></td>
</tr>
<td class=3D"vendor-product">themagnifico52--Kids Online Store</td> <td>Unrestricted Upload of File with Dangerous Type vulnerability in themag= nifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This = issue affects Kids Online Store: from n/a through 0.8.9.</td> <td>2026-06-16</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40750" target=3D= "_blank" rel=3D"noopener">CVE-2026-40750</a></td>
</tr>
<td class=3D"vendor-product">themagnifico52--Restaurant Zone</td> <td>Subscriber Arbitrary File Upload in Restaurant Zone <=3D 0.7.8 versi= ons.</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40746" target=3D= "_blank" rel=3D"noopener">CVE-2026-40746</a></td>
</tr>
<td class=3D"vendor-product">Theme passion--Support Ticket Management Syste= m</td>
<td>Unauthenticated Privilege Escalation in Support Ticket Management Syste=
m <=3D 1.9 versions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69179" target=3D= "_blank" rel=3D"noopener">CVE-2025-69179</a></td>
</tr>
<td class=3D"vendor-product">THEMECO--Cornerstone</td>
<td>Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.= </td>
<td>2026-06-16</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49113" target=3D= "_blank" rel=3D"noopener">CVE-2026-49113</a></td>
</tr>
<td class=3D"vendor-product">THEMECO--Cornerstone</td>
<td>Subscriber SQL Injection in Cornerstone < 7.8.8 versions.</td> <td>2026-06-17</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54185" target=3D= "_blank" rel=3D"noopener">CVE-2026-54185</a></td>
</tr>
<td class=3D"vendor-product">ThemeFusion--Avada</td>
<td>Contributor PHP Object Injection in Avada <=3D 3.15.3 versions.</td> <td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12256" target=3D= "_blank" rel=3D"noopener">CVE-2026-12256</a></td>
</tr>
<td class=3D"vendor-product">themefusion--Avada (Fusion) Builder</td>
<td>The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitr= ary file deletion due to insufficient file path validation in the maybe_del= ete_files function in all versions up to, and including, 3.15.3. This makes=
it possible for unauthenticated attackers to delete arbitrary files on the=
server, which can easily lead to remote code execution when the right file=
is deleted (such as wp-config.php). The attack requires a published Avada = form configured to save entries to the database; an unauthenticated attacke=
r submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submi= t_ajax handler while also controlling the fusion_privacy_expiration_interva=
l and privacy_expiration_action fields to force an immediate 'delete' clean= up, causing the planted entry to be automatically processed by the Fusion_F= orm_DB_Privacy shutdown-hook routine without any administrator interaction.= </td>
<td>2026-06-19</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8713" target=3D"= _blank" rel=3D"noopener">CVE-2026-8713</a></td>
</tr>
<td class=3D"vendor-product">ThemeFusion--Fusion Builder</td>
<td>Contributor PHP Object Injection in Fusion Builder <=3D 3.15.4 versi= ons.</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54194" target=3D= "_blank" rel=3D"noopener">CVE-2026-54194</a></td>
</tr>
<td class=3D"vendor-product">ThemeFusion--Fusion Builder</td>
<td>Contributor Arbitrary File Deletion in Fusion Builder <=3D 3.15.4 ve= rsions.</td>
<td>2026-06-17</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54193" target=3D= "_blank" rel=3D"noopener">CVE-2026-54193</a></td>
</tr>
<td class=3D"vendor-product">ThemeGoods--Avante</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 version= s.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-68524" target=3D= "_blank" rel=3D"noopener">CVE-2025-68524</a></td>
</tr>
<td class=3D"vendor-product">ThemeGoods--Grand Car Rental</td> <td>Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <=3D = 3.7 versions.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69151" target=3D= "_blank" rel=3D"noopener">CVE-2025-69151</a></td>
</tr>
<td class=3D"vendor-product">ThemeGrill--Masteriyo - LMS</td>
<td>Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - = LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n=
/a through 2.2.0.</td>
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49111" target=3D= "_blank" rel=3D"noopener">CVE-2026-49111</a></td>
</tr>
<td class=3D"vendor-product">ThemeGrill--Masteriyo - LMS</td> <td>Unauthenticated Broken Access Control in Masteriyo - LMS <=3D 2.1.5 = versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39524" target=3D= "_blank" rel=3D"noopener">CVE-2026-39524</a></td>
</tr>
<td class=3D"vendor-product">ThemeGrill--Registration Form for WooCommerce<=
<td>Unauthenticated Privilege Escalation in Registration Form for WooCommer=
ce <=3D 1.0.9 versions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54807" target=3D= "_blank" rel=3D"noopener">CVE-2026-54807</a></td>
</tr>
<td class=3D"vendor-product">ThemeGrill--User Registration</td> <td>Unauthenticated Broken Access Control in User Registration <=3D 5.1.=
2 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25425" target=3D= "_blank" rel=3D"noopener">CVE-2026-25425</a></td>
</tr>
<td class=3D"vendor-product">ThemeGrill--User Registration Stripe</td> <td>Unauthenticated Broken Access Control in User Registration Stripe <=
=3D 1.3.14 versions.</td>
<td>2026-06-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40726" target=3D= "_blank" rel=3D"noopener">CVE-2026-40726</a></td>
</tr>
<td class=3D"vendor-product">ThemeGrill--User Registration Stripe</td> <td>Unauthenticated Broken Access Control in User Registration Stripe <=
=3D 1.3.12 versions.</td>
<td>2026-06-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49081" target=3D= "_blank" rel=3D"noopener">CVE-2026-49081</a></td>
</tr>
<td class=3D"vendor-product">Themeisle--Redirection for Contact Form 7</td> <td>Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact F= orm 7 <=3D 3.2.8 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23970" target=3D= "_blank" rel=3D"noopener">CVE-2026-23970</a></td>
</tr>
<td class=3D"vendor-product">Themeisle--Social Slider Feed</td> <td>Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <=
=3D 2.3.2 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39507" target=3D= "_blank" rel=3D"noopener">CVE-2026-39507</a></td>
</tr>
<td class=3D"vendor-product">THEMELOGI--Roneous</td>
<td>Unauthenticated Local File Inclusion in Roneous <=3D 2.1.5 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69177" target=3D= "_blank" rel=3D"noopener">CVE-2025-69177</a></td>
</tr>
<td class=3D"vendor-product">THEMELOGI--Wanium</td>
<td>Unauthenticated Local File Inclusion in Wanium <=3D 1.9.8 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69136" target=3D= "_blank" rel=3D"noopener">CVE-2025-69136</a></td>
</tr>
<td class=3D"vendor-product">ThemeMove--Atomlab</td>
<td>Unauthenticated Local File Inclusion in Atomlab <=3D 2.4.5 versions.= </td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39590" target=3D= "_blank" rel=3D"noopener">CVE-2026-39590</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX Group--Elementra</td>
<td>Unauthenticated PHP Object Injection in Elementra <=3D 1.0.9 version= s.</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39529" target=3D= "_blank" rel=3D"noopener">CVE-2026-39529</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX Group--Geya</td>
<td>Unauthenticated Local File Inclusion in Geya <=3D 1.15 versions.</td=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-58924" target=3D= "_blank" rel=3D"noopener">CVE-2025-58924</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX Group--Learnify</td>
<td>Unauthenticated Local File Inclusion in Learnify <=3D 1.15.0 version= s.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60085" target=3D= "_blank" rel=3D"noopener">CVE-2025-60085</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Abelle</td>
<td>Unauthenticated Local File Inclusion in Abelle <=3D 1.22 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69142" target=3D= "_blank" rel=3D"noopener">CVE-2025-69142</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--AirSupply</td>
<td>Unauthenticated Local File Inclusion in AirSupply <=3D 2.0.0 version= s.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69110" target=3D= "_blank" rel=3D"noopener">CVE-2025-69110</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--AutoParts</td>
<td>Unauthenticated Local File Inclusion in AutoParts <=3D 1.5.8 version= s.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22331" target=3D= "_blank" rel=3D"noopener">CVE-2026-22331</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Choreo</td>
<td>Unauthenticated Local File Inclusion in Choreo <=3D 1.6 versions.</t=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69165" target=3D= "_blank" rel=3D"noopener">CVE-2025-69165</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--CopyPress</td>
<td>Unauthenticated Local File Inclusion in CopyPress <=3D 1.4.5 version= s.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69118" target=3D= "_blank" rel=3D"noopener">CVE-2025-69118</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Corbesier</td>
<td>Unauthenticated Local File Inclusion in Corbesier <=3D 1.15.0 versio= ns.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69119" target=3D= "_blank" rel=3D"noopener">CVE-2025-69119</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Dazzle</td>
<td>Unauthenticated Local File Inclusion in Dazzle <=3D 1.0.0 versions.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69120" target=3D= "_blank" rel=3D"noopener">CVE-2025-69120</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Deliciosa</td>
<td>Unauthenticated Local File Inclusion in Deliciosa <=3D 1.10.0 versio= ns.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69121" target=3D= "_blank" rel=3D"noopener">CVE-2025-69121</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Dom</td>
<td>Unauthenticated Local File Inclusion in Dom <=3D 1.24 versions.</td> <td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69146" target=3D= "_blank" rel=3D"noopener">CVE-2025-69146</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--EcoBlue</td>
<td>Unauthenticated Local File Inclusion in EcoBlue <=3D 1.15 versions.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22338" target=3D= "_blank" rel=3D"noopener">CVE-2026-22338</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Eros</td>
<td>Unauthenticated Local File Inclusion in Eros <=3D 1.3 versions.</td> <td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69167" target=3D= "_blank" rel=3D"noopener">CVE-2025-69167</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Especio</td>
<td>Unauthenticated Local File Inclusion in Especio <=3D 1.0 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69124" target=3D= "_blank" rel=3D"noopener">CVE-2025-69124</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Etude</td>
<td>Unauthenticated Local File Inclusion in Etude <=3D 1.6 versions.</td=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69174" target=3D= "_blank" rel=3D"noopener">CVE-2025-69174</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Eventicity</td>
<td>Unauthenticated Local File Inclusion in Eventicity <=3D 1.5 versions= .</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69170" target=3D= "_blank" rel=3D"noopener">CVE-2025-69170</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Food Drop</td>
<td>Unauthenticated Local File Inclusion in Food Drop <=3D 1.3 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69125" target=3D= "_blank" rel=3D"noopener">CVE-2025-69125</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Fortius</td>
<td>Unauthenticated Local File Inclusion in Fortius <=3D 2.3.0 versions.= </td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69126" target=3D= "_blank" rel=3D"noopener">CVE-2025-69126</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Gamic</td>
<td>Unauthenticated Local File Inclusion in Gamic <=3D 1.15 versions.</t=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69157" target=3D= "_blank" rel=3D"noopener">CVE-2025-69157</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Gat</td>
<td>Unauthenticated Local File Inclusion in Gat <=3D 1.16 versions.</td> <td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69145" target=3D= "_blank" rel=3D"noopener">CVE-2025-69145</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Gita</td>
<td>Unauthenticated Local File Inclusion in Gita <=3D 1.11 versions.</td=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69160" target=3D= "_blank" rel=3D"noopener">CVE-2025-69160</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Granola</td>
<td>Unauthenticated Local File Inclusion in Granola <=3D 1.13 versions.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69158" target=3D= "_blank" rel=3D"noopener">CVE-2025-69158</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Grecko</td>
<td>Unauthenticated Local File Inclusion in Grecko <=3D 5.17 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69162" target=3D= "_blank" rel=3D"noopener">CVE-2025-69162</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Gunslinger</td>
<td>Unauthenticated Local File Inclusion in Gunslinger <=3D 1.7 versions= .</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69166" target=3D= "_blank" rel=3D"noopener">CVE-2025-69166</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--HomeRoofer</td>
<td>Unauthenticated Local File Inclusion in HomeRoofer <=3D 2.11.0 versi= ons.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-58954" target=3D= "_blank" rel=3D"noopener">CVE-2025-58954</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Hot Coffee</td>
<td>Unauthenticated PHP Object Injection in Hot Coffee <=3D 1.7 versions= .</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69108" target=3D= "_blank" rel=3D"noopener">CVE-2025-69108</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Imba</td>
<td>Unauthenticated Local File Inclusion in Imba <=3D 1.5.0 versions.</t=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69106" target=3D= "_blank" rel=3D"noopener">CVE-2025-69106</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Ingenioso</td>
<td>Unauthenticated Local File Inclusion in Ingenioso <=3D 1.14.0 versio= ns.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69117" target=3D= "_blank" rel=3D"noopener">CVE-2025-69117</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Iona</td>
<td>Unauthenticated Local File Inclusion in Iona <=3D 1.0.8 versions.</t=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69116" target=3D= "_blank" rel=3D"noopener">CVE-2025-69116</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--ITactics</td>
<td>Unauthenticated Local File Inclusion in ITactics <=3D 1.0 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69176" target=3D= "_blank" rel=3D"noopener">CVE-2025-69176</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Joly</td>
<td>Unauthenticated Local File Inclusion in Joly <=3D 1.22.0 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-58953" target=3D= "_blank" rel=3D"noopener">CVE-2025-58953</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Kelly Young</td>
<td>Unauthenticated Local File Inclusion in Kelly Young <=3D 1.1.0 versi= ons.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69141" target=3D= "_blank" rel=3D"noopener">CVE-2025-69141</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Line Agency</td>
<td>Unauthenticated Local File Inclusion in Line Agency <=3D 1.3.1 versi= ons.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69175" target=3D= "_blank" rel=3D"noopener">CVE-2025-69175</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--LuxMed | Medicine & Healthcare D= octor WordPress Theme</td>
<td>Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthc= are Doctor WordPress Theme <=3D 1.2.2 versions.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69115" target=3D= "_blank" rel=3D"noopener">CVE-2025-69115</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--MaxiNet</td>
<td>Unauthenticated Local File Inclusion in MaxiNet <=3D 1.2.10 versions= .</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69114" target=3D= "_blank" rel=3D"noopener">CVE-2025-69114</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Medeus</td>
<td>Unauthenticated Local File Inclusion in Medeus <=3D 1.14 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69150" target=3D= "_blank" rel=3D"noopener">CVE-2025-69150</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Mission</td>
<td>Unauthenticated Local File Inclusion in Mission <=3D 1.22 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69143" target=3D= "_blank" rel=3D"noopener">CVE-2025-69143</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Modernee</td>
<td>Unauthenticated Local File Inclusion in Modernee <=3D 1.6.0 versions= .</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69105" target=3D= "_blank" rel=3D"noopener">CVE-2025-69105</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Neuronet</td>
<td>Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-58952" target=3D= "_blank" rel=3D"noopener">CVE-2025-58952</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Nexio</td>
<td>Unauthenticated Local File Inclusion in Nexio <=3D 1.10.0 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69113" target=3D= "_blank" rel=3D"noopener">CVE-2025-69113</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Orpheus</td>
<td>Unauthenticated Local File Inclusion in Orpheus <=3D 1.3 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69171" target=3D= "_blank" rel=3D"noopener">CVE-2025-69171</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Planty</td>
<td>Unauthenticated Local File Inclusion in Planty <=3D 1.14.0 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69112" target=3D= "_blank" rel=3D"noopener">CVE-2025-69112</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Plumbing</td>
<td>Unauthenticated PHP Object Injection in Plumbing <=3D 1.6 versions.<=
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69127" target=3D= "_blank" rel=3D"noopener">CVE-2025-69127</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Preservation</td>
<td>Unauthenticated Local File Inclusion in Preservation <=3D 1.10 versi= ons.</td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69144" target=3D= "_blank" rel=3D"noopener">CVE-2025-69144</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Printo</td>
<td>Unauthenticated Local File Inclusion in Printo <=3D 1.11 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69159" target=3D= "_blank" rel=3D"noopener">CVE-2025-69159</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Putter</td>
<td>Unauthenticated Local File Inclusion in Putter <=3D 1.17 versions.</=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69147" target=3D= "_blank" rel=3D"noopener">CVE-2025-69147</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Quirky</td>
<td>Unauthenticated Local File Inclusion in Quirky <=3D 1.23 versions.</=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69148" target=3D= "_blank" rel=3D"noopener">CVE-2025-69148</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Raider Spirit</td>
<td>Unauthenticated Local File Inclusion in Raider Spirit <=3D 1.1.2 ver= sions.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69109" target=3D= "_blank" rel=3D"noopener">CVE-2025-69109</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Reisen</td>
<td>Unauthenticated PHP Object Injection in Reisen <=3D 1.4.1 versions.<=
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69111" target=3D= "_blank" rel=3D"noopener">CVE-2025-69111</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Resurs</td>
<td>Unauthenticated Local File Inclusion in Resurs <=3D 1.3 versions.</t=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69172" target=3D= "_blank" rel=3D"noopener">CVE-2025-69172</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Rosaleen</td>
<td>Unauthenticated Local File Inclusion in Rosaleen <=3D 2.8 versions.<=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69107" target=3D= "_blank" rel=3D"noopener">CVE-2025-69107</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--SeaFood Company</td>
<td>Unauthenticated PHP Object Injection in SeaFood Company <=3D 1.4 ver= sions.</td>
<td>2026-06-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69122" target=3D= "_blank" rel=3D"noopener">CVE-2025-69122</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Skyward</td>
<td>Unauthenticated Local File Inclusion in Skyward <=3D 1.10 versions.<=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69164" target=3D= "_blank" rel=3D"noopener">CVE-2025-69164</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Snow Club</td>
<td>Unauthenticated Local File Inclusion in Snow Club <=3D 1.1 versions.= </td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69123" target=3D= "_blank" rel=3D"noopener">CVE-2025-69123</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Snowy</td>
<td>Unauthenticated Local File Inclusion in Snowy <=3D 1.13 versions.</t=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69161" target=3D= "_blank" rel=3D"noopener">CVE-2025-69161</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Spike</td>
<td>Unauthenticated Local File Inclusion in Spike <=3D 1.2 versions.</td=
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69168" target=3D= "_blank" rel=3D"noopener">CVE-2025-69168</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--ThemeREX Addons</td>
<td>Unauthenticated PHP Object Injection in ThemeREX Addons <=3D 2.36.1.=
1 versions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60205" target=3D= "_blank" rel=3D"noopener">CVE-2025-60205</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Tipsy</td>
<td>Unauthenticated Local File Inclusion in Tipsy <=3D 1.1 versions.</td=
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69173" target=3D= "_blank" rel=3D"noopener">CVE-2025-69173</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--Top Dog</td>
<td>Unauthenticated Local File Inclusion in Top Dog <=3D 1.0.5 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69149" target=3D= "_blank" rel=3D"noopener">CVE-2025-69149</a></td>
</tr>
<td class=3D"vendor-product">ThemeREX--WineShop</td>
<td>Unauthenticated Local File Inclusion in WineShop <=3D 3.17 versions.= </td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69163" target=3D= "_blank" rel=3D"noopener">CVE-2025-69163</a></td>
</tr>
<td class=3D"vendor-product">themetechmount--TrueBooker</td> <td>Unauthenticated Broken Access Control in TrueBooker <=3D 1.1.9 versi= ons.</td>
<td>2026-06-15</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48881" target=3D= "_blank" rel=3D"noopener">CVE-2026-48881</a></td>
</tr>
<td class=3D"vendor-product">Themeton--Lagom</td>
<td>Deserialization of Untrusted Data vulnerability in Themeton Lagom allow=
s Object Injection. This issue affects Lagom: from n/a through 2.0.</td> <td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60229" target=3D= "_blank" rel=3D"noopener">CVE-2025-60229</a></td>
</tr>
<td class=3D"vendor-product">Themeton--The Barber Shop</td>
<td>Deserialization of Untrusted Data vulnerability in Themeton The Barber = Shop allows Object Injection. This issue affects The Barber Shop: from n/a = through 1.9.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60230" target=3D= "_blank" rel=3D"noopener">CVE-2025-60230</a></td>
</tr>
<td class=3D"vendor-product">Themeum--Right Way</td>
<td>Unauthenticated Local File Inclusion in Right Way <=3D 4.0 versions.= </td>
<td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22330" target=3D= "_blank" rel=3D"noopener">CVE-2026-22330</a></td>
</tr>
<td class=3D"vendor-product">Themeum--Skillate</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Skillate <=3D 1.2.10 v= ersions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22329" target=3D= "_blank" rel=3D"noopener">CVE-2026-22329</a></td>
</tr>
<td class=3D"vendor-product">Themeum--Tutor LMS Pro</td>
<td>Unauthenticated SQL Injection in Tutor LMS Pro <=3D 3.9.6 versions.<=
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22332" target=3D= "_blank" rel=3D"noopener">CVE-2026-22332</a></td>
</tr>
<td class=3D"vendor-product">Themify--Themify Folo</td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in Themify Folo allows Reflected XSS. This issu=
e affects Themify Folo: from n/a through 1.9.6.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-31013" target=3D= "_blank" rel=3D"noopener">CVE-2025-31013</a></td>
</tr>
<td class=3D"vendor-product">Themovation--Entrepreneur - Booking for Small = Businesses WordPress Theme</td>
<td>Subscriber PHP Object Injection in Entrepreneur - Booking for Small Bus= inesses WordPress Theme <=3D 3.1.3 versions.</td>
<td>2026-06-17</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69130" target=3D= "_blank" rel=3D"noopener">CVE-2025-69130</a></td>
</tr>
<td class=3D"vendor-product">Thrive Themes--Thrive Apprentice</td> <td>Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.=
2 versions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49107" target=3D= "_blank" rel=3D"noopener">CVE-2026-49107</a></td>
</tr>
<td class=3D"vendor-product">tinyhumansai--OpenHuman</td>
<td>The shell tool command allowlist in the SecurityPolicy of OpenHuman des= ktop agent through 0.54.0 (default Supervised security policy) can be bypas= sed to execute arbitrary OS commands with the privileges of the desktop use=
r. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe(=
) blocks the find flags -exec and -ok but not the functionally identical -e= xecdir and -okdir, which also execute an arbitrary command for each matched=
file; and (2) skip_env_assignments() strips leading inline KEY=3Dvalue env= ironment-variable assignments before allowlist validation, so a command suc=
h as GIT_EXTERNAL_DIFF=3D<cmd> git diff is validated as the allowed g=
it diff but, when executed via the shell, runs <cmd> through git's en= vironment-driven hooks (for example GIT_EXTERNAL_DIFF or GIT_SSH_COMMAND). = Because the sandbox is the primary trust boundary between untrusted LLM-pro= cessed content and the host operating system, an attacker can achieve remot=
e code execution via indirect prompt injection: a malicious document, email=
, calendar event, or web page ingested by the agent instructs it to run a b= enign-looking allowlisted command, resulting in arbitrary command execution=
, data exfiltration, arbitrary file read/write, and lateral movement on the=
user's machine. The issue was fixed in commit 60050aa09a870f53ed7e4cd40ed4= 1fd2860329e7 (first released in 0.54.22-staging; first stable release 0.56.= 0), which blocks -execdir/-okdir for find.</td>
<td>2026-06-17</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55743" target=3D= "_blank" rel=3D"noopener">CVE-2026-55743</a></td>
</tr>
<td class=3D"vendor-product">tinyproxy--tinyproxy</td>
<td>Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile c= onflicting Content-Length and Transfer-Encoding: chunked headers, forwardin=
g both verbatim to the backend while using Content-Length to determine how = many request body bytes to consume. Remote attackers can desynchronize the = proxy and backend parser state, allowing injection of arbitrary HTTP reques=
ts to the backend to enable cache poisoning, access control bypass, and req= uest hijacking.</td>
<td>2026-06-17</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54387" target=3D= "_blank" rel=3D"noopener">CVE-2026-54387</a></td>
</tr>
<td class=3D"vendor-product">tinyproxy--tinyproxy</td>
<td>Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requ= ests containing multiple Content-Length headers with differing values, forw= arding all duplicate headers to the backend while using the first value to = determine how many request body bytes to consume. Remote attackers can desy= nchronize the proxy and backend parser state, allowing injection of arbitra=
ry HTTP requests to the backend to enable cache poisoning, access control b= ypass, and request hijacking.</td>
<td>2026-06-17</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54388" target=3D= "_blank" rel=3D"noopener">CVE-2026-54388</a></td>
</tr>
<td class=3D"vendor-product">tinyproxy--tinyproxy</td>
<td>Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly va= lidate the Host header during stathost detection, allowing unauthenticated = attackers to access the stats page by injecting a matching Host header or b= ypass detection via port manipulation. Remote attackers can trigger unautho= rized access to internal proxy statistics or misroute requests as transpare=
nt proxy connections to circumvent access controls.</td>
<td>2026-06-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55202" target=3D= "_blank" rel=3D"noopener">CVE-2026-55202</a></td>
</tr>
<td class=3D"vendor-product">Tips and Tricks HQ--WP eMember</td> <td>Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.</td> <td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54811" target=3D= "_blank" rel=3D"noopener">CVE-2026-54811</a></td>
</tr>
<td class=3D"vendor-product">TMS--Amelia</td>
<td>Subscriber Privilege Escalation in Amelia <=3D 2.3 versions.</td> <td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48889" target=3D= "_blank" rel=3D"noopener">CVE-2026-48889</a></td>
</tr>
<td class=3D"vendor-product">TMS--Amelia</td>
<td>Unauthenticated Sensitive Data Exposure in Amelia <=3D 2.2 versions.= </td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40789" target=3D= "_blank" rel=3D"noopener">CVE-2026-40789</a></td>
</tr>
<td class=3D"vendor-product">TMS--wpDataTables</td>
<td>Unauthenticated SQL Injection in wpDataTables <=3D 7.3.6 versions.</=
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49080" target=3D= "_blank" rel=3D"noopener">CVE-2026-49080</a></td>
</tr>
<td class=3D"vendor-product">tnomi--Attendance Manager</td>
<td>Subscriber SQL Injection in Attendance Manager <=3D 0.6.2 versions.<=
<td>2026-06-16</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52712" target=3D= "_blank" rel=3D"noopener">CVE-2026-52712</a></td>
</tr>
<td class=3D"vendor-product">Tomdever--wpForo Forum</td>
<td>Unauthenticated SQL Injection in wpForo Forum <=3D 3.0.4 versions.</=
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40798" target=3D= "_blank" rel=3D"noopener">CVE-2026-40798</a></td>
</tr>
<td class=3D"vendor-product">Tomdever--wpForo Forum</td>
<td>Unauthenticated Broken Authentication in wpForo Forum <=3D 3.1.0 ver= sions.</td>
<td>2026-06-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49767" target=3D= "_blank" rel=3D"noopener">CVE-2026-49767</a></td>
</tr>
<td class=3D"vendor-product">Tomdever--wpForo Forum</td>
<td>Unauthenticated PHP Object Injection in wpForo Forum <=3D 3.1.0 vers= ions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49769" target=3D= "_blank" rel=3D"noopener">CVE-2026-49769</a></td>
</tr>
<td class=3D"vendor-product">Tomdever--wpForo Forum</td>
<td>Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versio= ns.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40767" target=3D= "_blank" rel=3D"noopener">CVE-2026-40767</a></td>
</tr>
<td class=3D"vendor-product">traccar--traccar-client</td>
<td>Traccar Client is a GPS tracking mobile app for sending location update=
s to private servers using the open-source Traccar platform. In versions 9.= 7.19 and below, a single crafted deep link can silently hijack all GPS trac= king parameters and redirect telemetry to an attacker-controlled server. Th=
e app registers a custom org.traccar.client://config deep-link scheme that = silently writes attacker-supplied parameters (server URL, device ID, accura= cy, distance, and interval) into the app's persistent configuration with no=
confirmation, notification, or visual indication. A single crafted link de= livered via SMS, email, a webpage, or any installed app can therefore recon= figure the app the moment the victim taps it, with no special permissions r= equired. As a result, an attacker can covertly redirect all of the victim's=
GPS telemetry to their own server at maximum precision and frequency, and = the change persists across restarts. This gives the attacker continuous, re= al-time tracking of the victim's location. This issue has been fixed in ver= sion 9.7.20.</td>
<td>2026-06-16</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48745" target=3D= "_blank" rel=3D"noopener">CVE-2026-48745</a></td>
</tr>
<td class=3D"vendor-product">truelockmc--streambert</td>
<td>Streambert is a cross-platform Electron Desktop App to stream and downl= oad any video media. In versions 2.4.0 and prior, a high-severity Zip Slip = vulnerability was identified in Streambert's subtitle extraction logic. The=
application does not sanitize archive entry filenames during extraction, a= llowing a malicious archive to perform path traversal and write arbitrary f= iles to the host filesystem. The subtitle extraction process downloads a ZI=
P archive and extracts its entries. The destination file path is constructe=
d by concatenating the raw archive entry name (extracted.name) directly to = the temporary directory path. If a malicious ZIP archive containing directo=
ry traversal sequences is processed, it escapes the temporary directory bou= ndaries. The application then writes the extracted payload anywhere on the = host filesystem subject to the application's current write permissions. Thi=
s issue has been fixed in version 2.5.0.</td>
<td>2026-06-16</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48055" target=3D= "_blank" rel=3D"noopener">CVE-2026-48055</a></td>
</tr>
<td class=3D"vendor-product">TURCK--TBEN-LL-SE-M2</td>
<td>Due to the improper neutralization of special elements used in a name p= arameter a low privileged remote attacker can exploit a command injection v= ulnerability in the Managed Ethernet Switch, resulting in full system compr= omise.</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5416" target=3D"= _blank" rel=3D"noopener">CVE-2026-5416</a></td>
</tr>
<td class=3D"vendor-product">tychesoftwares--Order Delivery Date for WooCom= merce</td>
<td>Unauthenticated SQL Injection in Order Delivery Date for WooCommerce &l= t;=3D 4.5.1 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42386" target=3D= "_blank" rel=3D"noopener">CVE-2026-42386</a></td>
</tr>
<td class=3D"vendor-product">Ultimatebeaver--Ultimate Addons for Beaver Bui= lder</td>
<td>WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authen= tication bypass vulnerability that allows attackers to gain unauthorized ac= cess by exploiting the social media login form functionality. Attackers can=
submit a POST request to the admin-ajax.php endpoint with the uabb-lf-goog= le-submit action, a valid administrator email address, and a valid nonce to=
obtain session cookies and authenticate as that user.</td>
<td>2026-06-20</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25763" target=3D= "_blank" rel=3D"noopener">CVE-2019-25763</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: The undici WebSocket client enforces maxPayloadSize on the cumu= lative byte count of fragments in a message but does not enforce a limit on=
the number of fragments. A malicious WebSocket server can stream many smal=
l or empty continuation frames that each pass per-frame and cumulative-size=
validation, collectively causing unbounded memory growth in the client pro= cess. The result is memory exhaustion and a denial of service. Affected app= lications are those using the undici WebSocket client (new WebSocket(...)) =
or the WebSocketStream API that can be induced to connect to an attacker-co= ntrolled or compromised WebSocket endpoint. All releases starting at undici=
6.17.0 are affected. Patches:=C2=A0Upgrade to undici >=3D 6.26.0, >=
=3D 7.28.0, or >=3D 8.5.0.=C2=A0Workarounds: No workaround is available.=
The fix must be applied through an upgrade.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12151" target=3D= "_blank" rel=3D"noopener">CVE-2026-12151</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: When using Socks5ProxyAgent, undici reuses a single connection = pool across different origins without verifying that the pool's origin matc= hes the requested origin. All requests are dispatched through the pool conn= ected to the first origin, regardless of the intended destination. This cau= ses cross-origin request routing: credentials and request data intended for=
origin B are sent to origin A, responses from the wrong origin are trusted=
, and HTTPS requests may be silently downgraded to HTTP. Impacted users are=
applications that use Socks5ProxyAgent (directly or via setGlobalDispatche=
r) and make requests to more than one origin. This was introduced in undici=
7.23.0 via PR #4385 and affects all versions through 8.1.0. Patches: Upgra=
de to undici v7.26.0 or v8.2.0. Workarounds: Use a separate Socks5ProxyAgen=
t instance per origin, or avoid using Socks5ProxyAgent with multiple origin= s.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6734" target=3D"= _blank" rel=3D"noopener">CVE-2026-6734</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: The undici WebSocket client enforces maxPayloadSize per-frame b=
ut does not enforce the cumulative size of fragmented uncompressed messages=
. A malicious WebSocket server can stream many small fragments that each pa=
ss per-frame validation but collectively exceed the configured limit, causi=
ng unbounded memory growth in the client process. The result is memory exha= ustion and a denial of service. Affected applications are those using the u= ndici WebSocket client (new WebSocket(...)) that can be induced to connect =
to an attacker-controlled or compromised WebSocket endpoint. This is a regr= ession specific to undici 8.1.0. The 6.25.0 line shipped the equivalent cum= ulative check from the start and is unaffected. The 7.x line never had the = maxPayloadSize feature and is also unaffected. Patches: Upgrade to undici &= gt;=3D 8.5.0. Workarounds: No workaround is available. The fix must be appl= ied through an upgrade.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9675" target=3D"= _blank" rel=3D"noopener">CVE-2026-9675</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: undici's ProxyAgent silently drops the requestTls option when c= onfigured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS=
connection through the SOCKS5 tunnel falls back to Node's default trust st= ore, ignoring user-configured ca, cert, key, rejectUnauthorized, and server= name settings. Applications that pin to an internal or corporate CA via req= uestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA=
bundle as the trust anchor instead. Any cert signed by any publicly-truste=
d CA for the target hostname is accepted, breaking the intended pin and ena= bling MITM read and tamper of the HTTPS exchange. Affected applications are=
those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOC= KS5 AND rely on requestTls for TLS scope restriction. The bug was introduce=
d in undici 7.23.0 when SOCKS5 support was added. Patches: Upgrade to undic=
i v7.28.0 or v8.5.0. Workarounds: No workaround is available within the SOC= KS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an u= pgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAg= ent instead, where requestTls is honored correctly.</td>
<td>2026-06-17</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9697" target=3D"= _blank" rel=3D"noopener">CVE-2026-9697</a></td>
</tr>
<td class=3D"vendor-product">Utillz--Brikk</td>
<td>Subscriber Arbitrary Content Deletion in Brikk <=3D 3.0.0 versions.<=
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69103" target=3D= "_blank" rel=3D"noopener">CVE-2025-69103</a></td>
</tr>
<td class=3D"vendor-product">VamTam--Auto Repair</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Auto Repair <=3D 22.6 = versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22328" target=3D= "_blank" rel=3D"noopener">CVE-2026-22328</a></td>
</tr>
<td class=3D"vendor-product">vanyukov--Offload, AI & Optimize with Clou= dflare Images</td>
<td>The Offload, AI & Optimize with Cloudflare Images plugin for WordPr= ess is vulnerable to Remote Code Execution in all versions up to, and inclu= ding, 1.10.2 via the 'account-id' parameter parameter. This is due to insuf= ficient privilege enforcement on the cf_images_do_setup AJAX handler, which=
requires only the upload_files capability (Author+) rather than manage_opt= ions before writing to wp-config.php, combined with the absence of single-q= uote escaping - sanitize_text_field() does not strip single quotes, and fil= ter_input(INPUT_POST) bypasses wp_magic_quotes() slashing - allowing a sing=
le quote in the account-id or api-key parameter to break out of the single-= quoted PHP string literal in the write_config() define() statement. This ma= kes it possible for authenticated attackers, with author-level access and a= bove, to execute code on the server. This is possible because the 'cf-image= s-nonce' nonce required by the AJAX handler is exposed to all Author-level = and above users on wp-admin/upload.php via the CFImages JavaScript object, = meaning any upload-capable user can satisfy the nonce check and reach the v= ulnerable wp-config.php write path.</td>
<td>2026-06-18</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9860" target=3D"= _blank" rel=3D"noopener">CVE-2026-9860</a></td>
</tr>
<td class=3D"vendor-product">Vembu--Vembu StoreGrid</td>
<td>Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in = the RemoteBackup and RemoteBackup_webServer services that allows local atta= ckers to escalate privileges. Attackers can place a malicious executable in=
the unquoted path and restart the service to execute code with LocalSystem=
privileges.</td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20086" target=3D= "_blank" rel=3D"noopener">CVE-2016-20086</a></td>
</tr>
<td class=3D"vendor-product">VeronaLabs--Slimstat Analytics</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind S=
QL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.1= 1.</td>
<td>2026-06-17</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54818" target=3D= "_blank" rel=3D"noopener">CVE-2026-54818</a></td>
</tr>
<td class=3D"vendor-product">VideoWhisper.com--Broadcast Live Video</td> <td>Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3=
versions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27053" target=3D= "_blank" rel=3D"noopener">CVE-2026-27053</a></td>
</tr>
<td class=3D"vendor-product">VideoWhisper.com--Paid Videochat Turnkey Site<=
<td>Unauthenticated Deserialization of untrusted data in Paid Videochat Tur= nkey Site <=3D 7.3.23 versions.</td>
<td>2026-06-15</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27333" target=3D= "_blank" rel=3D"noopener">CVE-2026-27333</a></td>
</tr>
<td class=3D"vendor-product">VillaTheme--GIFT4U</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection=
. This issue affects GIFT4U: from n/a through 1.0.10.</td>
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54809" target=3D= "_blank" rel=3D"noopener">CVE-2026-54809</a></td>
</tr>
<td class=3D"vendor-product">vLLM--vLLM</td>
<td>vLLM versions >=3D 0.10.2 and < 0.13.0 are missing sparse tensor = validation in multimodal embeddings processing. Because PyTorch disables sp= arse tensor invariant checks by default, an attacker can submit crafted emb= edding requests with malformed (negative or out-of-bounds) tensor indices, = when the prompt-embeds feature is enabled, to trigger crashes or resource e= xhaustion (denial of service), with potential for out-of-bounds/write-what-= where memory corruption. This continues CVE-2025-62164, whose prior fix onl=
y disabled the feature by default rather than addressing the root cause.</t=
<td>2026-06-20</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56340" target=3D= "_blank" rel=3D"noopener">CVE-2026-56340</a></td>
</tr>
<td class=3D"vendor-product">Wasiliy Strecker--Contest Gallery</td> <td>Unauthenticated SQL Injection in Contest Gallery <=3D 28.1.6 version= s.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40771" target=3D= "_blank" rel=3D"noopener">CVE-2026-40771</a></td>
</tr>
<td class=3D"vendor-product">WC Lovers.--WooCommerce Frontend Manager Ultim= ate</td>
<td>Subscriber SQL Injection in WooCommerce Frontend Manager - Ultimate <=
; 6.7.7 versions.</td>
<td>2026-06-17</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22335" target=3D= "_blank" rel=3D"noopener">CVE-2026-22335</a></td>
</tr>
<td class=3D"vendor-product">WC Product Table--WooCommerce Product Table Li= te</td>
<td>Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table=
Lite <=3D 4.6.3 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34902" target=3D= "_blank" rel=3D"noopener">CVE-2026-34902</a></td>
</tr>
<td class=3D"vendor-product">WcMultishipping Mondial Relay & Chronopost=
for Wooommerce--WCMultiShipping</td>
<td>Subscriber SQL Injection in WCMultiShipping <=3D 3.0.2 versions.</td=
<td>2026-06-15</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52700" target=3D= "_blank" rel=3D"noopener">CVE-2026-52700</a></td>
</tr>
<td class=3D"vendor-product">Wdmtech--vAccount</td>
<td>Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerabilit=
y that allows unauthenticated attackers to execute arbitrary SQL queries by=
injecting malicious code through the vid parameter. Attackers can send GET=
requests to the vaccount-dashboard/expense endpoint with crafted SQL paylo= ads in the vid parameter to extract sensitive database information includin=
g version and database names.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25756" target=3D= "_blank" rel=3D"noopener">CVE-2019-25756</a></td>
</tr>
<td class=3D"vendor-product">Wdmtech--vBizz</td>
<td>Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vuln= erability that allows authenticated attackers to upload arbitrary PHP files=
by submitting malicious files through the profile_pic parameter. Attackers=
can upload PHP files via POST requests to the employee view endpoint and e= xecute them from the uploads directory to achieve remote code execution.</t=
<td>2026-06-19</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25758" target=3D= "_blank" rel=3D"noopener">CVE-2019-25758</a></td>
</tr>
<td class=3D"vendor-product">Wdmtech--vBizz</td>
<td>Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability t= hat allows authenticated attackers to execute arbitrary SQL queries by inje= cting malicious code through the payid parameter. Attackers can submit POST=
requests to the employee management interface with crafted payid array val= ues containing SQL commands to extract sensitive database information inclu= ding version and database names.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25759" target=3D= "_blank" rel=3D"noopener">CVE-2019-25759</a></td>
</tr>
<td class=3D"vendor-product">Wdmtech--VMap</td>
<td>Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability th=
at allows unauthenticated attackers to execute arbitrary SQL queries by inj= ecting malicious code into the latlngbound parameter. Attackers can send GE=
T requests to index.php with the option=3Dcom_vmap&task=3Dloadmarker pa= rameters containing SQL injection payloads to manipulate database queries a=
nd extract sensitive information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25753" target=3D= "_blank" rel=3D"noopener">CVE-2019-25753</a></td>
</tr>
<td class=3D"vendor-product">Wdmtech--vRestaurant</td>
<td>Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerabil= ity that allows unauthenticated attackers to execute arbitrary SQL queries =
by injecting malicious code through the keysearch parameter. Attackers can = send POST requests to the menu-listing-layout endpoint with crafted SQL pay= loads in the keysearch parameter to extract database table names and sensit= ive information from the database.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25754" target=3D= "_blank" rel=3D"noopener">CVE-2019-25754</a></td>
</tr>
<td class=3D"vendor-product">Wdmtech--vReview</td>
<td>Joomla Component vReview 1.9.11 contains an SQL injection vulnerability=
that allows unauthenticated attackers to execute arbitrary SQL queries by = injecting malicious code through the cmId parameter. Attackers can send POS=
T requests to the editReview task endpoint with URL-encoded SQL UNION state= ments in the cmId parameter to extract database information including usern= ames, passwords, and database versions.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25755" target=3D= "_blank" rel=3D"noopener">CVE-2019-25755</a></td>
</tr>
<td class=3D"vendor-product">Wdmtech--vWishlist</td>
<td>Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that all= ows authenticated attackers to execute arbitrary SQL queries by injecting m= alicious code through the vproductid and userid parameters. Attackers can s= end POST requests to the component with crafted SQL payloads in these param= eters to extract sensitive database information including version and datab= ase names.</td>
<td>2026-06-19</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25757" target=3D= "_blank" rel=3D"noopener">CVE-2019-25757</a></td>
</tr>
<td class=3D"vendor-product">Web Guy--Stop Spammers</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <=3D 202= 6.3 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48876" target=3D= "_blank" rel=3D"noopener">CVE-2026-48876</a></td>
</tr>
<td class=3D"vendor-product">WebAppick--CTX Feed</td>
<td>Shop manager PHP Object Injection in CTX Feed <=3D 6.6.26 versions.<=
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39434" target=3D= "_blank" rel=3D"noopener">CVE-2026-39434</a></td>
</tr>
<td class=3D"vendor-product">WebGeniusLab--Integrio Core</td> <td>Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versio= ns.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34894" target=3D= "_blank" rel=3D"noopener">CVE-2026-34894</a></td>
</tr>
<td class=3D"vendor-product">WebGeniusLab--Softlab Core</td> <td>Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versio= ns.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34895" target=3D= "_blank" rel=3D"noopener">CVE-2026-34895</a></td>
</tr>
<td class=3D"vendor-product">WebGeniusLab--Thegov Core</td>
<td>Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 version= s.</td>
<td>2026-06-16</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34893" target=3D= "_blank" rel=3D"noopener">CVE-2026-34893</a></td>
</tr>
<td class=3D"vendor-product">Webilia Inc.--Listdom</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Inject= ion. This issue affects Listdom: from n/a through 5.4.0.</td> <td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54819" target=3D= "_blank" rel=3D"noopener">CVE-2026-54819</a></td>
</tr>
<td class=3D"vendor-product">Webilia Inc.--Listdom</td>
<td>Unauthenticated Privilege Escalation in Listdom <=3D 5.5.0 versions.= </td>
<td>2026-06-15</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49063" target=3D= "_blank" rel=3D"noopener">CVE-2026-49063</a></td>
</tr>
<td class=3D"vendor-product">Webkul--Ajax Quiz</td>
<td>Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability=
that allows unauthenticated attackers to execute arbitrary SQL queries by = injecting malicious code through the cid parameter. Attackers can send GET = requests to index.php with the option=3Dcom_ajaxquiz and view=3Dajaxquiz pa= rameters to extract sensitive database information including table names an=
d column structures.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20262" target=3D= "_blank" rel=3D"noopener">CVE-2017-20262</a></td>
</tr>
<td class=3D"vendor-product">Webmin--Webmin</td>
<td>The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers t=
o impersonate any user with a configured SSL client certificate by sending =
a forged HTTP header. A remote attacker can spoof certificate DNs and authe= nticate as any user. Fixed in 2.641.</td>
<td>2026-06-18</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56020" target=3D= "_blank" rel=3D"noopener">CVE-2026-56020</a></td>
</tr>
<td class=3D"vendor-product">Weborange--Bargain Product VM3</td>
<td>Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vul= nerability that allows unauthenticated attackers to execute arbitrary SQL q= ueries by injecting malicious code through the product_id parameter. Attack= ers can supply crafted SQL statements in GET requests to the brainy and ali=
ce views to extract sensitive database information.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20261" target=3D= "_blank" rel=3D"noopener">CVE-2017-20261</a></td>
</tr>
<td class=3D"vendor-product">Weborange--Price Alert</td>
<td>Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerabi= lity that allows unauthenticated attackers to execute arbitrary SQL queries=
by injecting malicious code through the product_id parameter. Attackers ca=
n send requests to the subscribeajax view with crafted SQL payloads in the = product_id parameter to extract sensitive database information including cr= edentials and configuration data.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20260" target=3D= "_blank" rel=3D"noopener">CVE-2017-20260</a></td>
</tr>
<td class=3D"vendor-product">websockets--ws</td>
<td>ws is an open source WebSocket client and server for Node.js. All versi= ons from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, fro=
m 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory = exhaustion DoS vulnerability. A peer can send a high volume of exceptionall=
y small fragments and data chunks, with modest network traffic, to force th=
e remote peer into allocating and holding structural wrappers that consume = far more memory than the default documented message-size limit, leading to = process termination due to OOM. This issue has been fixed in versions 5.2.5=
, 6.2.4, 7.5.11, and 8.21.0.</td>
<td>2026-06-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48779" target=3D= "_blank" rel=3D"noopener">CVE-2026-48779</a></td>
</tr>
<td class=3D"vendor-product">WebToffee--WooCommerce PDF Invoices, Packing S= lips, Delivery Notes and Shipping Labels</td>
<td>Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Pa= cking Slips, Delivery Notes and Shipping Labels <=3D 4.9.4 versions.</td=
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49056" target=3D= "_blank" rel=3D"noopener">CVE-2026-49056</a></td>
</tr>
<td class=3D"vendor-product">Weird-Solutions--TFTP Broadband</td>
<td>TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerabili=
ty in the tftpt.exe service binary that allows local attackers to execute a= rbitrary code with system privileges. Attackers can place a malicious execu= table in the Program Files directory path that will be executed during serv= ice startup or system reboot with LocalSystem privileges.</td> <td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37250" target=3D= "_blank" rel=3D"noopener">CVE-2020-37250</a></td>
</tr>
<td class=3D"vendor-product">Winstep--Winstep</td>
<td>Winstep 18.06.0096 contains an unquoted service path vulnerability in t=
he Winstep Xtreme Service that allows local attackers to escalate privilege=
s. Attackers can place malicious executables in the Program Files directory=
to be executed with LocalSystem privileges when the service starts.</td> <td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37253" target=3D= "_blank" rel=3D"noopener">CVE-2020-37253</a></td>
</tr>
<td class=3D"vendor-product">Wise--Wisecleaner</td>
<td>Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service = path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respe= ctively, allowing local users to execute arbitrary code with SYSTEM privile= ges. Attackers can insert malicious executables in the system root path tha=
t execute during service startup or system reboot with elevated privileges.= </td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20093" target=3D= "_blank" rel=3D"noopener">CVE-2016-20093</a></td>
</tr>
<td class=3D"vendor-product">WishList Products, LLC.--WishList Member X</td=
<td>Subscriber Arbitrary File Upload in WishList Member X <=3D 3.29.0 ve= rsions.</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25446" target=3D= "_blank" rel=3D"noopener">CVE-2026-25446</a></td>
</tr>
<td class=3D"vendor-product">Wombat Plugins--Advanced Product Fields (Produ=
ct Addons) for WooCommerce</td>
<td>Shop manager PHP Object Injection in Advanced Product Fields (Product A= ddons) for WooCommerce <=3D 1.6.19 versions.</td>
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39499" target=3D= "_blank" rel=3D"noopener">CVE-2026-39499</a></td>
</tr>
<td class=3D"vendor-product">Wondershare--PDFelement</td>
<td>Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerabil= ity due to an unquoted service path in the WsAppService Windows service. Lo= cal attackers can place a malicious executable in the service path and exec= ute code with LocalSystem privileges upon service restart or system reboot.= </td>
<td>2026-06-19</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37254" target=3D= "_blank" rel=3D"noopener">CVE-2020-37254</a></td>
</tr>
<td class=3D"vendor-product">WooCommerce--WooCommerce</td>
<td>WooCommerce 7.1.0 contains a remote code execution vulnerability that a= llows attackers to execute arbitrary PHP code by injecting shell commands t= hrough the product-type parameter. Attackers can send requests to the class= -wc-meta-box-product-images.php endpoint with unsanitized product-type valu=
es to write malicious PHP files to the web root.</td>
<td>2026-06-20</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-50972" target=3D= "_blank" rel=3D"noopener">CVE-2022-50972</a></td>
</tr>
<td class=3D"vendor-product">WP Chill--Modula Image Gallery</td>
<td>Author PHP Object Injection in Modula Image Gallery <=3D 2.14.18 ver= sions.</td>
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39481" target=3D= "_blank" rel=3D"noopener">CVE-2026-39481</a></td>
</tr>
<td class=3D"vendor-product">Wp Directory Kit--WP Directory Kit</td> <td>Unauthenticated Broken Access Control in WP Directory Kit <=3D 1.5.0=
versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39534" target=3D= "_blank" rel=3D"noopener">CVE-2026-39534</a></td>
</tr>
<td class=3D"vendor-product">WP E-Signature--Signature Add-On for WooCommer= ce</td>
<td>Unauthenticated Sensitive Data Exposure in Signature Add-On for WooComm= erce <=3D 2.0 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52694" target=3D= "_blank" rel=3D"noopener">CVE-2026-52694</a></td>
</tr>
<td class=3D"vendor-product">WP Engine--Faust.js</td>
<td>Authentication Bypass Using an Alternate Path or Channel vulnerability =
in WP Engine Faust.Js allows Password Recovery Exploitation. This issue aff= ects Faust.Js: from n/a through 1.8.7.</td>
<td>2026-06-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49062" target=3D= "_blank" rel=3D"noopener">CVE-2026-49062</a></td>
</tr>
<td class=3D"vendor-product">WP Overnight--WooCommerce PDF Invoices & P= acking Slips</td>
<td>Shop manager PHP Object Injection in WooCommerce PDF Invoices & Pac= king Slips < 5.9.0 versions.</td>
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39472" target=3D= "_blank" rel=3D"noopener">CVE-2026-39472</a></td>
</tr>
<td class=3D"vendor-product">WP Swings--Event Tickets Manager for WooCommer= ce</td>
<td>Unauthenticated Broken Access Control in Event Tickets Manager for WooC= ommerce <=3D 1.5.3 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34898" target=3D= "_blank" rel=3D"noopener">CVE-2026-34898</a></td>
</tr>
<td class=3D"vendor-product">WP Swings--Upsell Order Bump Offer for WooComm= erce</td>
<td>Unauthenticated Broken Authentication in Upsell Order Bump Offer for Wo= oCommerce <=3D 3.1.4 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49110" target=3D= "_blank" rel=3D"noopener">CVE-2026-49110</a></td>
</tr>
<td class=3D"vendor-product">WP Travel Engine--WP Travel Engine</td> <td>Unauthenticated PHP Object Injection in WP Travel Engine <=3D 6.7.12=
versions.</td>
<td>2026-06-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49770" target=3D= "_blank" rel=3D"noopener">CVE-2026-49770</a></td>
</tr>
<td class=3D"vendor-product">WP Travel Engine--WP Travel Engine</td> <td>Unauthenticated Other Vulnerability Type in WP Travel Engine <=3D 6.= 7.10 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49078" target=3D= "_blank" rel=3D"noopener">CVE-2026-49078</a></td>
</tr>
<td class=3D"vendor-product">WP Travel--WP Travel Gutenberg Blocks</td> <td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows = Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/=
a through 3.9.4.</td>
<td>2026-06-17</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54808" target=3D= "_blank" rel=3D"noopener">CVE-2026-54808</a></td>
</tr>
<td class=3D"vendor-product">WP User Manager--WP User Manager</td> <td>Subscriber Arbitrary File Deletion in WP User Manager <=3D 2.9.16 ve= rsions.</td>
<td>2026-06-15</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49766" target=3D= "_blank" rel=3D"noopener">CVE-2026-49766</a></td>
</tr>
<td class=3D"vendor-product">wp-buy--SEO Redirection</td>
<td>Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <=3D 9= .17 versions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52702" target=3D= "_blank" rel=3D"noopener">CVE-2026-52702</a></td>
</tr>
<td class=3D"vendor-product">wp.insider--Affiliates Manager</td> <td>Unauthenticated Sensitive Data Exposure in Affiliates Manager <=3D 2= .9.50 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52692" target=3D= "_blank" rel=3D"noopener">CVE-2026-52692</a></td>
</tr>
<td class=3D"vendor-product">wp.insider--Simple Membership</td> <td>Unauthenticated Broken Access Control in Simple Membership <=3D 4.7.=
1 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34886" target=3D= "_blank" rel=3D"noopener">CVE-2026-34886</a></td>
</tr>
<td class=3D"vendor-product">WPClever--WPC Product Bundles for WooCommerce<=
<td>Unauthenticated Broken Access Control in WPC Product Bundles for WooCom= merce <=3D 8.5.3 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48883" target=3D= "_blank" rel=3D"noopener">CVE-2026-48883</a></td>
</tr>
<td class=3D"vendor-product">WPClever--WPC Product Options for WooCommerce<=
<td>Unauthenticated Arbitrary File Download in WPC Product Options for WooC= ommerce <=3D 3.2.1 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49061" target=3D= "_blank" rel=3D"noopener">CVE-2026-49061</a></td>
</tr>
<td class=3D"vendor-product">WPDeveloper--EmbedPress</td>
<td>Unauthenticated Sensitive Data Exposure in EmbedPress <=3D 4.5.2 ver= sions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48872" target=3D= "_blank" rel=3D"noopener">CVE-2026-48872</a></td>
</tr>
<td class=3D"vendor-product">WPExperts--Post SMTP</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Post SMTP <=3D 3.6.2 v= ersions.</td>
<td>2026-06-15</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48838" target=3D= "_blank" rel=3D"noopener">CVE-2026-48838</a></td>
</tr>
<td class=3D"vendor-product">WPFactory--Min Max Step Quantity Limits Manage=
r for WooCommerce</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Lim= its Manager for WooCommerce <=3D 5.2.2 versions.</td>
<td>2026-06-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39437" target=3D= "_blank" rel=3D"noopener">CVE-2026-39437</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--WPFunnels Pro</td>
<td>Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <=3D 2.9=
.4 versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49778" target=3D= "_blank" rel=3D"noopener">CVE-2026-49778</a></td>
</tr>
<td class=3D"vendor-product">WPGraphQL--WPGraphQL</td>
<td>Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.</td> <td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40762" target=3D= "_blank" rel=3D"noopener">CVE-2026-40762</a></td>
</tr>
<td class=3D"vendor-product">WPLocker--PT Luxa Addons</td>
<td>Subscriber Arbitrary File Upload in PT Luxa Addons <=3D 1.2.2 versio= ns.</td>
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60218" target=3D= "_blank" rel=3D"noopener">CVE-2025-60218</a></td>
</tr>
<td class=3D"vendor-product">WPManageNinja--Best Payments Plugin for WP</td=
<td>Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= ;=3D 4.6.19 versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42655" target=3D= "_blank" rel=3D"noopener">CVE-2026-42655</a></td>
</tr>
<td class=3D"vendor-product">WPMet--MetForm Pro</td>
<td>Unauthenticated Broken Access Control in MetForm Pro <=3D 3.9.1 vers= ions.</td>
<td>2026-06-17</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24611" target=3D= "_blank" rel=3D"noopener">CVE-2026-24611</a></td>
</tr>
<td class=3D"vendor-product">wpmudev--Branda White Label & Branding, Fr=
ee Login Page Customizer</td>
<td>The Branda plugin for WordPress is vulnerable to privilege escalation v=
ia account takeover in all versions up to, and including, 3.4.29. This is d=
ue to the plugin not properly validating a user's identity prior to updatin=
g their password. This makes it possible for unauthenticated attackers to c= hange arbitrary user's passwords, including administrators, and leverage th=
at to gain access to their account.</td>
<td>2026-06-19</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11551" target=3D= "_blank" rel=3D"noopener">CVE-2026-11551</a></td>
</tr>
<td class=3D"vendor-product">WPos--Woocommerce Book Price</td>
<td>Subscriber Arbitrary File Download in Woocommerce Book Price <=3D 1.=
3 versions.</td>
<td>2026-06-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22334" target=3D= "_blank" rel=3D"noopener">CVE-2026-22334</a></td>
</tr>
<td class=3D"vendor-product">WPTasty--AWP Classifieds</td>
<td>Unauthenticated Broken Access Control in AWP Classifieds <=3D 4.4.4 = versions.</td>
<td>2026-06-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39533" target=3D= "_blank" rel=3D"noopener">CVE-2026-39533</a></td>
</tr>
<td class=3D"vendor-product">Wptimecapsule--Time Capsule Plugin</td> <td>WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass=
vulnerability that allows unauthenticated attackers to gain administrative=
access by sending a crafted POST request with the IWP_JSON_PREFIX header. = Attackers can exploit this flaw to obtain valid administrator session cooki=
es and access the WordPress dashboard without providing credentials.</td> <td>2026-06-20</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37255" target=3D= "_blank" rel=3D"noopener">CVE-2020-37255</a></td>
</tr>
<td class=3D"vendor-product">wpWax--Directorist Booking</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in wpWax Directorist Booking allows Blind SQL I= njection. This issue affects Directorist Booking: from n/a through 3.0.3.</=
<td>2026-06-16</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49073" target=3D= "_blank" rel=3D"noopener">CVE-2026-49073</a></td>
</tr>
<td class=3D"vendor-product">WPZOOM--WPZOOM Addons for Elementor</td> <td>Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Element=
or <=3D 1.3.4 versions.</td>
<td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39597" target=3D= "_blank" rel=3D"noopener">CVE-2026-39597</a></td>
</tr>
<td class=3D"vendor-product">XServer--CloudSecure WP Security</td> <td>Unauthenticated Broken Authentication in CloudSecure WP Security <=
=3D 1.4.7 versions.</td>
<td>2026-06-15</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42411" target=3D= "_blank" rel=3D"noopener">CVE-2026-42411</a></td>
</tr>
<td class=3D"vendor-product">xtemos--Hitek</td>
<td>Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.</td> <td>2026-06-17</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39582" target=3D= "_blank" rel=3D"noopener">CVE-2026-39582</a></td>
</tr>
<td class=3D"vendor-product">Yandex--Punto Switcher</td>
<td>Punto Switcher through 4.5.0.583 contains an unquoted search path eleme=
nt vulnerability that allows local attackers to execute arbitrary code by e= xploiting the application's call to WinExec without a fully qualified path = for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll. Attack= ers can place a malicious executable earlier in the search order to achieve=
arbitrary code execution in the context of the affected user.</td> <td>2026-06-18</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25865" target=3D= "_blank" rel=3D"noopener">CVE-2026-25865</a></td>
</tr>
<td class=3D"vendor-product">Yannick Lefebvre--Link Library</td> <td>Contributor Arbitrary File Deletion in Link Library <=3D 7.8.8 versi= ons.</td>
<td>2026-06-15</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40779" target=3D= "_blank" rel=3D"noopener">CVE-2026-40779</a></td>
</tr>
<td class=3D"vendor-product">Yealink--SIP-T46U</td>
<td>A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affec= ted element is the function StartReportInformation of the file /api/inner/b= eforewifitest of the component Web FastCGI Service. The manipulation of the=
argument port results in stack-based buffer overflow. Access to the local = network is required for this attack. The exploit is now public and may be u= sed. The vendor was contacted early about this disclosure but did not respo=
nd in any way.</td>
<td>2026-06-15</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12218" target=3D= "_blank" rel=3D"noopener">CVE-2026-12218</a></td>
</tr>
<td class=3D"vendor-product">Yealink--SIP-T46U</td>
<td>A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This a= ffects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/a= ccupgradebychunk of the component Firmware Chunk Upload handler. Such manip= ulation of the argument uid leads to stack-based buffer overflow. The attac=
k can only be initiated within the local network. The exploit has been disc= losed to the public and may be used. The vendor was contacted early about t= his disclosure but did not respond in any way.</td>
<td>2026-06-15</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12220" target=3D= "_blank" rel=3D"noopener">CVE-2026-12220</a></td>
</tr>
<td class=3D"vendor-product">Yealink--SIP-T46U</td>
<td>A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impact=
s the function sprintf of the file /api/upgrade/upgrade of the component Fi= rmware Chunk Upload Handler. Performing a manipulation of the argument uid/= start_offset results in stack-based buffer overflow. The attack needs to be=
approached within the local network. The exploit has been made public and = could be used. The vendor was contacted early about this disclosure but did=
not respond in any way.</td>
<td>2026-06-15</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12221" target=3D= "_blank" rel=3D"noopener">CVE-2026-12221</a></td>
</tr>
<td class=3D"vendor-product">Yealink--SIP-T46U</td>
<td>A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affect=
ed is the function mod_webd.BlueToothTest of the file /api/inner/bttest of = the component Web FastCGI Service. Executing a manipulation of the argument=
btMac/pin/reserved can lead to stack-based buffer overflow. The attack nee=
ds to be done within the local network. The exploit has been publicly discl= osed and may be utilized. The vendor was contacted early about this disclos= ure but did not respond in any way.</td>
<td>2026-06-15</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12222" target=3D= "_blank" rel=3D"noopener">CVE-2026-12222</a></td>
</tr>
<td class=3D"vendor-product">Yeeaddons--YayMail</td>
<td>Shop manager PHP Object Injection in YayMail <=3D 4.3.3 versions.</t=
<td>2026-06-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39498" target=3D= "_blank" rel=3D"noopener">CVE-2026-39498</a></td>
</tr>
<td class=3D"vendor-product">yeoman--environment</td>
<td>Yeoman Environment provides an API to discover, create, and run generat= ors, and to configure where and how a generator is resolved. Versions 2.9.0=
through 6.0.0 install missing local generator packages from caller-supplie=
d package names without user confirmation. In downstream consumers that pas=
s attacker-controlled project configuration into this path, this can result=
in arbitrary package installation and code execution during CLI bootstrap.=
The vulnerable method is installLocalGenerators(), which calls repository.= install() directly without prompting the user. This issue has been fixed in=
version 6.0.0.</td>
<td>2026-06-16</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42089" target=3D= "_blank" rel=3D"noopener">CVE-2026-42089</a></td>
</tr>
<td class=3D"vendor-product">yydevelopment--Advanced 301 and 302 Redirect</=
<td>Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <=3D = 1.6.9 versions.</td>
<td>2026-06-15</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49067" target=3D= "_blank" rel=3D"noopener">CVE-2026-49067</a></td>
</tr>
<td class=3D"vendor-product">Zcontent--Zap Calendar Lite</td>
<td>Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vul= nerability that allows unauthenticated attackers to execute arbitrary SQL q= ueries by injecting malicious code through the 'eid' parameter. Attackers c=
an send GET requests to the RSVP plugin endpoint with crafted SQL payloads =
to extract sensitive database information including database names and tabl=
e structures.</td>
<td>2026-06-19</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2017-20268" target=3D= "_blank" rel=3D"noopener">CVE-2017-20268</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role par= ser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds writ=
e. During Service Level Connection setup the HF sends AT+CIND=3D? and parse=
s the AG's +CIND: response in cind_handle(), which assigns a per-entry coun= ter index and calls cind_handle_values() for each list element. cind_handle= _values() then wrote hf-ind_table[index] =3D i without verifying that index=
is within the 20-element int8_t ind_table[] array of struct bt_hfp_hf. Bec= ause the parser places no cap on the number of +CIND: list entries, a remot=
e Attendant Gateway (a malicious, compromised, or spoofed peer the device c= onnects to over Bluetooth) can send a response with more than 20 recognized=
indicator entries and drive index arbitrarily large, writing a small attac= ker-positioned value past the array into adjacent struct fields (feature ma= sks, SDP/version state, the calls[] array, work/atomic bookkeeping) and pot= entially beyond the static connection pool slot. This yields memory corrupt= ion and at least denial of service of the Bluetooth host, triggered by a si= ngle malformed AT response with no user interaction. The sibling consumer a= g_indicator_handle_values() already performed the equivalent bounds check; = this commit adds the same index =3D ARRAY_SIZE(hf-ind_table) guard to close=
the gap. Affects builds with CONFIG_BT_HFP_HF enabled; introduced with the=
original HFP HF CIND parser (~v1.7) and present through v4.4.0.</td> <td>2026-06-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10641" target=3D= "_blank" rel=3D"noopener">CVE-2026-10641</a></td>
</tr>
<td class=3D"vendor-product">Zidithemes--Grip</td>
<td>Subscriber Arbitrary File Upload in Grip <=3D 1.0.9 versions.</td> <td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-52488" target=3D= "_blank" rel=3D"noopener">CVE-2024-52488</a></td>
</tr>
<td class=3D"vendor-product">Zozothemes--Restaurt</td>
<td>Subscriber Arbitrary File Upload in Restaurt <=3D 1.0.4 versions.</t=
<td>2026-06-17</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22327" target=3D= "_blank" rel=3D"noopener">CVE-2026-22327</a></td>
</tr>
<td class=3D"vendor-product">Zyxel--GS1900-48HPv2 firmware</td>
<td>A stack-based buffer overflow vulnerability in the CGI program of Zyxel=
GS1900-48HPv2 firmware versions through=C2=A02.90(ABTQ.1)C0 could allow a = LAN-based, unauthenticated attacker to exploit the flaw and potentially exe= cute OS commands via a crafted HTTP request.</td>
<td>2026-06-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7273" target=3D"= _blank" rel=3D"noopener">CVE-2026-7273</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"medium_v">
<h2 id=3D"medium_v_title">Medium Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Medium Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">10web--Form Maker by 10Web Mobile-Friendly Dra=
g & Drop Contact Form Builder</td>
<td>The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form = Builder plugin for WordPress is vulnerable to generic SQL Injection via the=
'groupids' parameter in all versions up to, and including, 1.15.43 due to = insufficient escaping on the user supplied parameter and lack of sufficient=
preparation on the existing SQL query. This makes it possible for authenti= cated attackers, with administrator-level access and above, to append addit= ional SQL queries into already existing queries that can be used to extract=
sensitive information from the database.</td>
<td>2026-06-18</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11776" target=3D= "_blank" rel=3D"noopener">CVE-2026-11776</a></td>
</tr>
<td class=3D"vendor-product">10web--Form Maker by 10Web Mobile-Friendly Dra=
g & Drop Contact Form Builder</td>
<td>The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form = Builder plugin for WordPress is vulnerable to generic SQL Injection via the=
'name' parameter in all versions up to, and including, 1.15.43 due to insu= fficient escaping on the user supplied parameter and lack of sufficient pre= paration on the existing SQL query. This makes it possible for authenticate=
d attackers, with administrator-level access, to append additional SQL quer= ies into already existing queries that can be used to extract sensitive inf= ormation from the database.</td>
<td>2026-06-18</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11777" target=3D= "_blank" rel=3D"noopener">CVE-2026-11777</a></td>
</tr>
<td class=3D"vendor-product">2download--2Download Connector for 2DL Hosted = Checkout</td>
<td>The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is=
vulnerable to unauthorized access in all versions up to, and including, 0.= 1.5. This is due to the plugin not properly verifying that a user is author= ized to perform an action. This makes it possible for unauthenticated attac= kers to view arbitrary customers' subscription data including subscription = status, product names, order IDs, purchase dates, and expiry dates.</td> <td>2026-06-19</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6798" target=3D"= _blank" rel=3D"noopener">CVE-2026-6798</a></td>
</tr>
<td class=3D"vendor-product">abtest--Abtest</td>
<td>WordPress Plugin Abtest contains a local file inclusion vulnerability t= hat allows unauthenticated attackers to include arbitrary files by manipula= ting the action parameter. Attackers can send GET requests to abtest_admin.= php with malicious action values to include files from the admin directory = and execute arbitrary code.</td>
<td>2026-06-15</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20082" target=3D= "_blank" rel=3D"noopener">CVE-2016-20082</a></td>
</tr>
<td class=3D"vendor-product">AcademySoftwareFoundation--openexr</td> <td>OpenEXR is the reference implementation and specification for the EXR i= mage format, widely used in the motion picture industry. In versions 3.4.0 = through 3.4.11, an integer overflow in ht_undo_impl() in src/lib/OpenEXRCor= e/internal_ht.cpp leads to a heap-buffer overflow when decoding a crafted H= TJ2K-compressed EXR file. decode->channels[i].width (int32_t) is multipl= ied by bytes_per_element in 32-bit signed arithmetic. With large widths (e.= g., >=3D 536870912 for FLOAT data), this overflows, producing a corrupte=
d offset that is later used for pointer arithmetic and can cause a heap out= -of-bounds write. The same unchecked multiplication pattern appears in two = other HTJ2K paths (bytes-per-line accumulation and pixel-line pointer advan= cement). As with related CVE-2026-34378 through CVE-2026-34589 fixes in oth=
er codecs, validating only after the multiplication is too late because the=
value may already be overflowed. This issue has been fixed in version 3.4.= 12.</td>
<td>2026-06-18</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44663" target=3D= "_blank" rel=3D"noopener">CVE-2026-44663</a></td>
</tr>
<td class=3D"vendor-product">activepieces--activepieces</td>
<td>A vulnerability was detected in activepieces up to 0.83.0. This vulnera= bility affects the function handleUrlFile in the library packages/server/en= gine/src/lib/variables/processors/file.ts of the component File URL Handler=
. The manipulation results in server-side request forgery. The attack can b=
e executed remotely. The exploit is now public and may be used. The vendor = was contacted early about this disclosure but did not respond in any way.</=
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12813" target=3D= "_blank" rel=3D"noopener">CVE-2026-12813</a></td>
</tr>
<td class=3D"vendor-product">adamsilverstein--User Admin Simplifier</td> <td>The User Admin Simplifier plugin for WordPress is vulnerable to Cross-S= ite Request Forgery in all versions up to, and including, 3.0.0. This is du=
e to missing or incorrect nonce validation on the useradminsimplifier_optio= ns_page function. This makes it possible for unauthenticated attackers to r= eset and permanently delete any user's stored menu and admin-bar configurat= ion via a forged request that triggers uas_save_admin_options() and overwri= tes the useradminsimplifier_options database entry via a forged request gra= nted they can trick a site administrator into performing an action such as = clicking on a link.</td>
<td>2026-06-19</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11775" target=3D= "_blank" rel=3D"noopener">CVE-2026-11775</a></td>
</tr>
<td class=3D"vendor-product">addonspress--Advanced Import</td>
<td>The Advanced Import plugin for WordPress is vulnerable to Server-Side R= equest Forgery in all versions up to, and including, 1.4.6. This is due to = the plugin using wp_remote_get() to fetch a user-supplied URL without valid= ating that the URL does not point to internal or private network resources =
in the demo_download_and_unzip() function. The 'demo_file' parameter from $= _POST is passed through sanitize_text_field() (which only handles XSS-relat=
ed sanitization) and then directly into wp_remote_get() when 'demo_file_typ=
e' is set to 'url'. Notably, the plugin uses wp_safe_remote_get() in other = locations (theme template libraries) which would provide SSRF protection, b=
ut fails to use it in this critical AJAX handler. This makes it possible fo=
r authenticated attackers, with Author-level access and above (upload_files=
capability), to make web requests to arbitrary locations originating from = the web application, which can be used to query and view data from internal=
services, including cloud instance metadata endpoints.</td> <td>2026-06-19</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4328" target=3D"= _blank" rel=3D"noopener">CVE-2026-4328</a></td>
</tr>
<td class=3D"vendor-product">Adobe--DNG SDK</td>
<td>DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bound=
s read vulnerability that could lead to disclosure of sensitive memory. An = attacker could leverage this vulnerability to disclose sensitive informatio=
n. Exploitation of this issue requires user interaction in that a victim mu=
st open a malicious file.</td>
<td>2026-06-16</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47927" target=3D= "_blank" rel=3D"noopener">CVE-2026-47927</a></td>
</tr>
<td class=3D"vendor-product">Adobe--DNG SDK</td>
<td>DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bound=
s read vulnerability that could lead to disclosure of sensitive memory. An = attacker could leverage this vulnerability to disclose sensitive informatio=
n. Exploitation of this issue requires user interaction in that a victim mu=
st open a malicious file.</td>
<td>2026-06-16</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47934" target=3D= "_blank" rel=3D"noopener">CVE-2026-47934</a></td>
</tr>
<td class=3D"vendor-product">Adobe--DNG SDK</td>
<td>DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bound=
s read vulnerability that could lead to disclosure of sensitive memory. An = attacker could leverage this vulnerability to disclose sensitive informatio=
n. Exploitation of this issue requires user interaction in that a victim mu=
st open a malicious file.</td>
<td>2026-06-16</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47963" target=3D= "_blank" rel=3D"noopener">CVE-2026-47963</a></td>
</tr>
<td class=3D"vendor-product">Ahmad--JS Help Desk</td>
<td>Unauthenticated Broken Access Control in JS Help Desk <=3D 3.0.9 ver= sions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48887" target=3D= "_blank" rel=3D"noopener">CVE-2026-48887</a></td>
</tr>
<td class=3D"vendor-product">Ahmad--WP Job Portal</td>
<td>Subscriber Cross Site Scripting (XSS) in WP Job Portal <=3D 2.5.2 ve= rsions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48880" target=3D= "_blank" rel=3D"noopener">CVE-2026-48880</a></td>
</tr>
<td class=3D"vendor-product">algolplus--Advanced Order Export For WooCommer= ce</td>
<td>The Advanced Order Export For WooCommerce plugin for WordPress is vulne= rable to generic SQL Injection via the 'sort_direction' parameter in all ve= rsions up to, and including, 4.0.10 due to insufficient escaping on the use=
r supplied parameter and lack of sufficient preparation on the existing SQL=
query. This makes it possible for authenticated attackers, with shop manag= er-level access and above, to append additional SQL queries into already ex= isting queries that can be used to extract sensitive information from the d= atabase. The endpoint requires a valid woe_nonce and Shop Manager-level cap= abilities (view_woocommerce_reports or export_woocommerce_orders), and wp_m= agic_quotes protection is stripped via stripslashes_deep() before processin=
g, allowing quote and backslash characters to survive intact into the SQL c= ontext.</td>
<td>2026-06-18</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11360" target=3D= "_blank" rel=3D"noopener">CVE-2026-11360</a></td>
</tr>
<td class=3D"vendor-product">ali2woo--AliNext</td>
<td>Missing Authorization vulnerability in ali2woo AliNext allows Exploitin=
g Incorrectly Configured Access Control Security Levels. This issue affects=
AliNext: from n/a through 3.3.5.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-37210" target=3D= "_blank" rel=3D"noopener">CVE-2024-37210</a></td>
</tr>
<td class=3D"vendor-product">Amit Mittal--Shipment Tracker for Woocommerce<=
<td>Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommer=
ce <=3D 1.5.3.2 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39540" target=3D= "_blank" rel=3D"noopener">CVE-2026-39540</a></td>
</tr>
<td class=3D"vendor-product">Andy Moyle--Emergency Password Reset</td> <td>Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency=
Password Reset allows Cross Site Request Forgery. This issue affects Emerg= ency Password Reset: from n/a through 8.0.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-35648" target=3D= "_blank" rel=3D"noopener">CVE-2024-35648</a></td>
</tr>
<td class=3D"vendor-product">Apollo Pharmacy--Blood Glucose Monitoring Syst=
em (Model No. APG-01 BT)</td>
<td>An attacker within BLE communication range can passively intercept wire= less traffic and obtain sensitive health-related information, including glu= cose measurement values.</td>
<td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50034" target=3D= "_blank" rel=3D"noopener">CVE-2026-50034</a></td>
</tr>
<td class=3D"vendor-product">Apollo Pharmacy--Blood Glucose Monitoring Syst=
em (Model No. APG-01 BT)</td>
<td>An attacker within BLE communication range can monopolize the device's = only available BLE connection slot, preventing legitimate users or applicat= ions from establishing a connection.</td>
<td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52866" target=3D= "_blank" rel=3D"noopener">CVE-2026-52866</a></td>
</tr>
<td class=3D"vendor-product">artbees--JupiterX Core</td>
<td>Subscriber Cross Site Scripting (XSS) in JupiterX Core <=3D 4.14.1 v= ersions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39491" target=3D= "_blank" rel=3D"noopener">CVE-2026-39491</a></td>
</tr>
<td class=3D"vendor-product">authlib--joserfc</td>
<td>joserfc is a Python library that provides an implementation of several = JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 thro= ugh 1.6.5, joserfc accepts oversized RFC7797 b64=3Dfalse JWS payloads witho=
ut applying JWSRegistry.max_payload_length, which can lead to resource exha= ustion. The normal JWS compact and flattened JSON paths reject payloads abo=
ve the configured payload-size limit with ExceededSizeError. The RFC7797 un= encoded payload paths do not make the same check. A valid b64=3Dfalse compa=
ct or flattened JSON JWS can therefore deserialize successfully with a payl= oad larger than JWSRegistry.max_payload_length. Applications that accept lo= wer-trust JWS values and rely on joserfc to reject oversized token content = during verification have a moderate availability risk. This issue has been = fixed in version 1.6.7.</td>
<td>2026-06-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48990" target=3D= "_blank" rel=3D"noopener">CVE-2026-48990</a></td>
</tr>
<td class=3D"vendor-product">Autodesk--Revit</td>
<td>A maliciously crafted RFA file, when converted to FormIt via "Convert R=
FA to FormIt" in Autodesk Revit, can force a NULL Pointer Dereference vulne= rability. Successful exploitation may cause the application to crash, leadi=
ng to a denial-of-service condition.</td>
<td>2026-06-17</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1288" target=3D"= _blank" rel=3D"noopener">CVE-2026-1288</a></td>
</tr>
<td class=3D"vendor-product">AVideo--AVideo</td>
<td>AVideo through version 27.0 contains a server-side request forgery vuln= erability in plugin/Live/test.php that allows authenticated administrators =
to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeUR= L() validation and accepts requests to private IP ranges and cloud metadata=
endpoints. Attackers can exploit this by crafting requests to internal ser= vices, cloud metadata endpoints like 169.254.169.254, and localhost to retr= ieve sensitive information including IAM credentials, internal service resp= onses, and network configuration details.</td>
<td>2026-06-20</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56342" target=3D= "_blank" rel=3D"noopener">CVE-2026-56342</a></td>
</tr>
<td class=3D"vendor-product">AVideo--AVideo</td>
<td>AVideo through version 25.0 contains an authentication bypass vulnerabi= lity in the decryptMessage.json.php endpoint that allows unauthenticated us= ers to decrypt PGP messages. Remote attackers can submit private keys, ciph= ertext, and passphrases to perform server-side decryption without credentia= ls, exposing key material to logs and enabling resource exhaustion attacks.= </td>
<td>2026-06-20</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56346" target=3D= "_blank" rel=3D"noopener">CVE-2026-56346</a></td>
</tr>
<td class=3D"vendor-product">Avirtum--iPages Flipbook</td>
<td>Missing Authorization vulnerability in Avirtum iPages Flipbook allows E= xploiting Incorrectly Configured Access Control Security Levels. This issue=
affects iPages Flipbook: from n/a through 1.5.1.</td>
<td>2026-06-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-33909" target=3D= "_blank" rel=3D"noopener">CVE-2024-33909</a></td>
</tr>
<td class=3D"vendor-product">Awesomemotive--Envira Photo Gallery</td> <td>Unauthenticated Broken Access Control in Envira Photo Gallery <=3D 1= .12.5 versions.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54190" target=3D= "_blank" rel=3D"noopener">CVE-2026-54190</a></td>
</tr>
<td class=3D"vendor-product">AWS--Kiro IDE</td>
<td>Incorrect default permissions in Kiro IDE on macOS and Linux before ver= sion 0.11.133 could expose the authentication token cache file to other loc=
al users or processes via world-readable permissions (0644) instead of owne= r-restricted permissions (0600). To remediate this issue, users should upgr= ade to Kiro IDE version 0.11.133 or later. After upgrading and restarting t=
he application, the cache file permissions are automatically updated on the=
next token refresh. Users operating in a multi-user environment can invali= date existing tokens by reauthenticating.</td>
<td>2026-06-15</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11931" target=3D= "_blank" rel=3D"noopener">CVE-2026-11931</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A security flaw has been discovered in BerriAI litellm up to 1.82.2. Th=
is impacts the function authenticate_user of the file litellm/proxy/auth/lo= gin_utils.py of the component PROXY_ADMIN database API Key Generator. Perfo= rming a manipulation results in session expiration. The attack may be initi= ated remotely. The exploit has been released to the public and may be used = for attacks. The vendor was contacted early about this disclosure.</td> <td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12772" target=3D= "_blank" rel=3D"noopener">CVE-2026-12772</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A security vulnerability has been detected in BerriAI litellm up to 1.8= 2.2. Affected by this vulnerability is the function _execute_with_mcp_clien=
t of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of t=
he component MCP Server Connection Testing. The manipulation leads to serve= r-side request forgery. Remote exploitation of the attack is possible. The = exploit has been disclosed publicly and may be used. The vendor was contact=
ed early about this disclosure.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12774" target=3D= "_blank" rel=3D"noopener">CVE-2026-12774</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A vulnerability was identified in BerriAI litellm up to 1.82.2. This im= pacts the function get_redirect_response_from_openid of the file litellm/pr= oxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow=
. The manipulation leads to session expiration. The attack is possible to b=
e carried out remotely. The exploit is publicly available and might be used=
. The vendor was contacted early about this disclosure.</td> <td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12796" target=3D= "_blank" rel=3D"noopener">CVE-2026-12796</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A security flaw has been discovered in BerriAI litellm up to 1.82.5. Af= fected is the function async_pre_call_hook of the file enterprise/enterpris= e_hooks/banned_keywords.py of the component Completions Interface. The mani= pulation of the argument prompt results in incorrect authorization. The att= ack may be performed from remote. The exploit has been released to the publ=
ic and may be used for attacks. The vendor was contacted early about this d= isclosure.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12797" target=3D= "_blank" rel=3D"noopener">CVE-2026-12797</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A weakness has been identified in BerriAI litellm up to 1.82.2. Affecte=
d by this vulnerability is the function load_openapi_spec_async of the file=
litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the = component MCP OpenAPI Spec Loader. This manipulation of the argument spec_p= ath causes server-side request forgery. It is possible to initiate the atta=
ck remotely. The exploit has been made available to the public and could be=
used for attacks. The vendor was contacted early about this disclosure.</t=
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12798" target=3D= "_blank" rel=3D"noopener">CVE-2026-12798</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A vulnerability was determined in BerriAI litellm up to 1.63.1. The imp= acted element is an unknown function of the file litellm/proxy/management_e= ndpoints/key_management_endpoints.py of the component Admin Key Handler. Th=
is manipulation causes improper authorization. The attack can be initiated = remotely. The exploit has been publicly disclosed and may be utilized. Patc=
h name: 23781. It is recommended to apply a patch to fix this issue. The ve= ndor was contacted early about this disclosure.</td>
<td>2026-06-21</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12770" target=3D= "_blank" rel=3D"noopener">CVE-2026-12770</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A vulnerability was identified in BerriAI litellm up to 1.82.2. This af= fects an unknown function of the file litellm/proxy/auth/user_api_key_auth.=
py of the component M2M JWT Handler. Such manipulation leads to improper au= thorization. The attack can be launched remotely. A high complexity level i=
s associated with this attack. The exploitability is reported as difficult.=
The exploit is publicly available and might be used. The vendor was contac= ted early about this disclosure.</td>
<td>2026-06-21</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12771" target=3D= "_blank" rel=3D"noopener">CVE-2026-12771</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>A security vulnerability has been detected in BerriAI litellm up to 1.8= 2.2. Affected by this issue is the function ui_view_users of the file litel= lm/proxy/management_endpoints/internal_user_endpoints.py of the component I= ncomplete Fix CVE-2025-0628. Such manipulation leads to improper authorizat= ion. It is possible to launch the attack remotely. The exploit has been dis= closed publicly and may be used. The vendor was contacted early about this = disclosure.</td>
<td>2026-06-21</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12799" target=3D= "_blank" rel=3D"noopener">CVE-2026-12799</a></td>
</tr>
<td class=3D"vendor-product">Bitnami--bitnami/mariadb-galera</td>
<td>Bitnami MariaDB Galera container images and Helm chart are affected by =
a hardcoded default credential vulnerability in the Galera replication heal= th-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWOR=
D environment variables defaulted to monitor and monitor respectively. This=
user is granted REPLICATION CLIENT privileges from any host ('%'). The Bit= nami Helm chart for MariaDB Galera did not expose parameters to configure t= his user's credentials, resulting in all chart deployments using this publi= cly known credential by default. Affected versions - Container image: 10.6.=
x prior to 10.6.27-photon-5-r0; 10.11.x prior to 10.11.17-photon-5-r1; 11.4=
.x prior to 11.4.12-photon-5-r0; 11.8.x prior to 11.8.7-photon-5-r1; 12.3.x=
prior to 12.3.2-photon-5-r0 / 12.3.2-debian-12-r0. Helm chart: prior to 18= .3.0.</td>
<td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47847" target=3D= "_blank" rel=3D"noopener">CVE-2026-47847</a></td>
</tr>
<td class=3D"vendor-product">bitpressadmin--Bit integrations Form Integrati= on, Webhook, Spreadsheets, CRM, LMS & Email Automation</td>
<td>The Bit integrations - Form Integration, Webhook, Spreadsheets, CRM, LM=
S & Email Automation plugin for WordPress is vulnerable to Server-Side = Request Forgery in all versions up to, and including, 2.8.7 via the upload_= attachment. This makes it possible for unauthenticated attackers to make we=
b requests to arbitrary locations originating from the web application and = can be used to query and modify information from internal services. Exploit= ation requires a form integration to be configured with a field mapped to a=
WooCommerce product image, product gallery, downloadable files, or Google = Contacts attachment field, which is a default use case for these integratio= ns.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11989" target=3D= "_blank" rel=3D"noopener">CVE-2026-11989</a></td>
</tr>
<td class=3D"vendor-product">Black Lantern Security--BBOT</td>
<td>The postman_download module uses the workspace name field from the Post= man API to construct the local directory path without sanitization. If a ma= licious workspace has a name containing path traversal characters, pathlib = resolves the path outside the intended output directory, allowing an attack=
er to write arbitrary files to the user's system.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12568" target=3D= "_blank" rel=3D"noopener">CVE-2026-12568</a></td>
</tr>
<td class=3D"vendor-product">Black Lantern Security--BBOT</td>
<td>The unarchive internal module's archive extraction commands perform no = code-level validation on extracted file paths, relying entirely on the beha= vior of external tools (e.g. GNU tar) which varies by platform. While CVE-2= 025-10284 addressed git-specific RCE vectors, the underlying archive extrac= tion path traversal was never fixed. On systems with GNU tar < 1.34 (Ubu= ntu 20.04, Debian Buster, CentOS 7, many Docker base images), a malicious a= rchive can write files outside the intended extraction directory.</td> <td>2026-06-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12565" target=3D= "_blank" rel=3D"noopener">CVE-2026-12565</a></td>
</tr>
<td class=3D"vendor-product">blubrry--PowerPress Podcasting plugin by Blubr= ry</td>
<td>The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vul= nerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in al=
l versions up to, and including, 11.16.8 due to insufficient input sanitiza= tion and output escaping. This makes it possible for authenticated attacker=
s, with author-level access and above, to inject arbitrary web scripts in p= ages that will execute whenever a user accesses an injected page. The embed=
value is stored via update_post_meta() rather than through WordPress core'=
s post content pipeline, meaning kses-on-save filtering is never applied - = even for Author-role users who would otherwise lack unfiltered_html - makin=
g this path unprotected by WordPress's standard role-based XSS mitigations.= </td>
<td>2026-06-18</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12098" target=3D= "_blank" rel=3D"noopener">CVE-2026-12098</a></td>
</tr>
<td class=3D"vendor-product">BoldGrid--W3 Total Cache</td>
<td>Author Broken Access Control in W3 Total Cache <=3D 2.9.1 versions.<=
<td>2026-06-17</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39595" target=3D= "_blank" rel=3D"noopener">CVE-2026-39595</a></td>
</tr>
<td class=3D"vendor-product">Booking Activities Team--Booking Activities</t=
<td>Unauthenticated Broken Access Control in Booking Activities <=3D 1.1= 6.48.1 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39525" target=3D= "_blank" rel=3D"noopener">CVE-2026-39525</a></td>
</tr>
<td class=3D"vendor-product">Bootstrapped Ventures--Visual Link Preview</td=
<td>Subscriber Sensitive Data Exposure in Visual Link Preview <=3D 2.4.1=
versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48878" target=3D= "_blank" rel=3D"noopener">CVE-2026-48878</a></td>
</tr>
<td class=3D"vendor-product">bplugins--Services Section Block Showcase Serv= ice Details in Grid or Columns</td>
<td>The Services Section Block - Showcase Service Details in Grid or Column=
s plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'li= nk' Block Attribute in all versions up to, and including, 1.4.4 due to insu= fficient input sanitization and output escaping. This makes it possible for=
authenticated attackers, with contributor-level access and above, to injec=
t arbitrary web scripts in pages that will execute whenever a user accesses=
an injected page. The payload persists inside HTML comments in post_conten=
t, bypassing wp_kses_post sanitization at save time, and executes via both = the primary service link anchor and a secondary title-wrapped anchor when t=
he linkIn option is set to 'title'.</td>
<td>2026-06-18</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11402" target=3D= "_blank" rel=3D"noopener">CVE-2026-11402</a></td>
</tr>
<td class=3D"vendor-product">Brandfolder--Brandfolder</td>
<td>WordPress Brandfolder plugin version 3.0 and earlier contains a local f= ile inclusion vulnerability in callback.php that allows unauthenticated att= ackers to include arbitrary files by manipulating the wp_abspath parameter.=
Attackers can supply path traversal sequences or remote URLs through the w= p_abspath parameter to read sensitive files like wp-config.php or execute r= emote code.</td>
<td>2026-06-15</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20080" target=3D= "_blank" rel=3D"noopener">CVE-2016-20080</a></td>
</tr>
<td class=3D"vendor-product">Bricks--Bricks Builder</td>
<td>Subscriber Broken Access Control in Bricks Builder <=3D 2.1.4 versio= ns.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40723" target=3D= "_blank" rel=3D"noopener">CVE-2026-40723</a></td>
</tr>
<td class=3D"vendor-product">Bricksable--Bricksable for Bricks Builder</td> <td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in Bricksable for Bricks Builder allows Stored = XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6= .83.</td>
<td>2026-06-18</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56009" target=3D= "_blank" rel=3D"noopener">CVE-2026-56009</a></td>
</tr>
<td class=3D"vendor-product">bunny.net--bunny.net</td>
<td>Subscriber Broken Access Control in bunny.net <=3D 2.3.6 versions.</=
<td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-68049" target=3D= "_blank" rel=3D"noopener">CVE-2025-68049</a></td>
</tr>
<td class=3D"vendor-product">Canon Inc.--EOS Network Setting Tool for Windo= ws</td>
<td>Improper validation of SSH host keys in Canon EOS Network Setting Tool = Version 1.5.0 or earlier</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9258" target=3D"= _blank" rel=3D"noopener">CVE-2026-9258</a></td>
</tr>
<td class=3D"vendor-product">Canon Inc.--EOS Network Setting Tool for Windo= ws</td>
<td>Improper validation of server certificates in Canon EOS Network Setting=
Tool Version 1.5.0 or earlier</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9259" target=3D"= _blank" rel=3D"noopener">CVE-2026-9259</a></td>
</tr>
<td class=3D"vendor-product">Canon Inc.--EOS Network Setting Tool for Windo= ws</td>
<td>Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool = Version 1.5.0 or earlier</td>
<td>2026-06-15</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9260" target=3D"= _blank" rel=3D"noopener">CVE-2026-9260</a></td>
</tr>
<td class=3D"vendor-product">Canon Inc.--EOS Network Setting Tool for Windo= ws</td>
<td>Use of weak SSH cryptographic algorithms in Canon EOS Network Setting T= ool Version 1.5.0 or earlier</td>
<td>2026-06-15</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9261" target=3D"= _blank" rel=3D"noopener">CVE-2026-9261</a></td>
</tr>
<td class=3D"vendor-product">Canon Inc.--EOS Network Setting Tool for Windo= ws</td>
<td>Use of a non-secure protocol as the default FTP configuration in Canon = EOS Network Setting Tool Version 1.5.0 or earlier</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9262" target=3D"= _blank" rel=3D"noopener">CVE-2026-9262</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Cap-go capgo before 12.128.2 contains an authorization bypass in severa=
l Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, ge= t_total_metrics) that are granted to the anon role without enforcing org me= mbership or permission checks. An unauthenticated attacker using only the p= ublic Supabase API key (sb_publishable_*) can query arbitrary org_id values=
to disclose cross-tenant usage telemetry (MAU, bandwidth, installs, gets),=
enumerate app IDs for a target org, and determine org existence via an ora= cle (valid org returns metrics, invalid returns []).</td>
<td>2026-06-20</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56235" target=3D= "_blank" rel=3D"noopener">CVE-2026-56235</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Cap-go before 12.128.2 contains an information disclosure vulnerability=
in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated=
attackers to enumerate valid builder job IDs through observable response d= iscrepancies. Attackers can probe the endpoint without authentication to di= stinguish valid job IDs from invalid ones and generate sustained unauthenti= cated traffic for resource consumption.</td>
<td>2026-06-21</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56316" target=3D= "_blank" rel=3D"noopener">CVE-2026-56316</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Capgo before 12.128.2 contains a flaw in the Enforce Password Policy fe= ature: after a Super Admin enables the policy and successfully changes thei=
r password to a compliant one, the backend does not update the password-com= pliance state. As a result, the backend continues to treat the account as n= on-compliant and repeatedly forces password-reset prompts, permanently lock= ing the Super Admin out of organization access (organization lockout / deni=
al of service) despite valid authentication.</td>
<td>2026-06-19</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56080" target=3D= "_blank" rel=3D"noopener">CVE-2026-56080</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Cap-go before 12.128.12 contains a broken cursor pagination vulnerabili=
ty in the /private/devices endpoint on the Cloudflare/workerd path that all= ows authenticated attackers to cause duplicate-page loops and make later ro=
ws unreachable. Attackers with app.read_devices access can exploit non-adva= ncing cursor filters to trigger infinite pagination loops, prevent dataset = traversal, and cause repeated processing in device-management workflows.</t=
<td>2026-06-20</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56307" target=3D= "_blank" rel=3D"noopener">CVE-2026-56307</a></td>
</tr>
<td class=3D"vendor-product">capacitor-native-biometric--capacitor-native-b= iometric</td>
<td>capacitor-native-biometric before 12.128.2 contains an authentication b= ypass vulnerability where the onAuthenticationSucceeded() method fails to v= alidate CryptoObject parameters. Attackers can hook the onAuthenticationSuc= ceeded() function using dynamic instrumentation to bypass biometric authent= ication without valid credentials.</td>
<td>2026-06-20</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56294" target=3D= "_blank" rel=3D"noopener">CVE-2026-56294</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a cross-tenant authorization bypass vuln= erability in PostgREST endpoints that allows org-scoped read API keys to ac= cess other tenants' webhook secrets and delivery logs. Attackers can query = the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing se= crets and delivery payloads, enabling forged webhook events against victim = organizations.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56079" target=3D= "_blank" rel=3D"noopener">CVE-2026-56079</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authorization bypass vulnerability in=
the /build/status and /build/logs endpoints that allows attackers to acces=
s build jobs belonging to different applications by supplying a mismatched = app_id and job_id combination. Limited API keys restricted to a single app = can retrieve build status and logs from other apps by providing an authoriz=
ed app_id while using a job_id from an unauthorized app, exposing sensitive=
build information including logs, metadata, and potentially credentials.</=
<td>2026-06-21</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56229" target=3D= "_blank" rel=3D"noopener">CVE-2026-56229</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a broken row level security policy in th=
e org_users table that allows authenticated users to elevate privileges fro=
m admin to super_admin. Attackers can exploit the insufficient RLS enforcem= ent to gain unauthorized super_admin access and compromise system security.= </td>
<td>2026-06-21</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56251" target=3D= "_blank" rel=3D"noopener">CVE-2026-56251</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authorization bypass vulnerability in=
webhook management endpoints that allows non-expiring API keys to bypass t=
he require_apikey_expiration organization policy. The checkWebhookPermissio=
n function fails to call apikeyHasOrgRightWithPolicy, enabling attackers wi=
th legacy non-expiring keys to list, create, and delete webhooks despite ex= plicit organizational policy requiring key expiration.</td>
<td>2026-06-20</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56295" target=3D= "_blank" rel=3D"noopener">CVE-2026-56295</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authorization bypass vulnerability in=
the public.upsert_version_meta SECURITY DEFINER function exposed via Postg= REST RPC, allowing unauthenticated attackers to insert arbitrary rows into = version_meta for any app_id. Attackers can exploit this by calling the RPC = endpoint with a public anon key to poison storage metrics, causing persiste=
nt false data in dashboards and triggering incorrect alerts across victim a= pplications.</td>
<td>2026-06-20</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56213" target=3D= "_blank" rel=3D"noopener">CVE-2026-56213</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 fails to strip EXIF metadata including GPS geoloc= ation data from uploaded images, allowing information disclosure. Attackers=
can download uploaded images and extract precise latitude and longitude co= ordinates revealing user physical location at capture time.</td> <td>2026-06-20</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56218" target=3D= "_blank" rel=3D"noopener">CVE-2026-56218</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a server-side request forgery vulnerabil= ity in webhook URL validation that allows loopback and internal addresses. = Organization admins can configure webhooks pointing to localhost or 127.0.0= .1, and when triggered, the backend performs outbound requests to these add= resses with error responses disclosed to users.</td>
<td>2026-06-20</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56227" target=3D= "_blank" rel=3D"noopener">CVE-2026-56227</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an information disclosure vulnerability =
in the unauthenticated /replication endpoint that exposes internal PostgreS=
QL replication telemetry including slot names and WAL LSN positions. Attack= ers can access this endpoint without authentication to retrieve sensitive i= nfrastructure details such as replication slot names, confirmed_flush_lsn, = restart_lsn values, and database error messages for reconnaissance purposes= .</td>
<td>2026-06-20</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56282" target=3D= "_blank" rel=3D"noopener">CVE-2026-56282</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authentication bypass vulnerability i=
n the /build/upload/:jobId/* endpoint that allows unauthenticated attackers=
to trigger consistent 500 errors. Remote attackers can send OPTIONS reques=
ts to bypass authentication middleware and invoke tusProxy logic with inval=
id credentials, enabling trivial request flooding and denial of service.</t=
<td>2026-06-21</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56299" target=3D= "_blank" rel=3D"noopener">CVE-2026-56299</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 fails to enforce a maximum value on the minimum p= assword length field in its password policy configuration. An authenticated=
organization administrator can set an extremely large numeric value (e.g.,=
billions of characters) as the minimum password length, making compliance = impossible for all organization members. Once the policy is enabled, users = (including administrators) are unable to change their passwords or access t=
he organization, resulting in an organization-wide account lockout and appl= ication-level denial of service.</td>
<td>2026-06-20</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56228" target=3D= "_blank" rel=3D"noopener">CVE-2026-56228</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an information disclosure vulnerability =
in the GET /statistics/app/:app_id endpoint that allows app-limited API key=
s to distinguish existing sibling app IDs through differential error respon= ses. Attackers can enumerate real app IDs outside their allowed scope by ob= serving 500 PGRST116 errors for inaccessible apps versus 401 errors for non= existent apps, breaking tenant isolation.</td>
<td>2026-06-20</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56319" target=3D= "_blank" rel=3D"noopener">CVE-2026-56319</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an open redirect vulnerability in the co= nfirm-signup endpoint that allows attackers to redirect users to arbitrary = external websites. The confirmation_url parameter is not validated, enablin=
g attackers to craft malicious links for phishing and credential harvesting=
attacks.</td>
<td>2026-06-20</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56332" target=3D= "_blank" rel=3D"noopener">CVE-2026-56332</a></td>
</tr>
<td class=3D"vendor-product">capgo--cli</td>
<td>Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabili= ties in login and build credentials operations that follow symlinks without=
validation. Attackers can create malicious symlinks in repositories to ove= rwrite arbitrary files or expose credentials with world-readable permission=
s when developers run the CLI.</td>
<td>2026-06-21</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56236" target=3D= "_blank" rel=3D"noopener">CVE-2026-56236</a></td>
</tr>
<td class=3D"vendor-product">carrierwaveuploader--carrierwave</td> <td>CarrierWave is a framework to upload files from Ruby applications. In v= ersions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to = escape regex metacharacters in string entries, causing the denylist to sile= ntly not match the content types it is intended to block. In lib/carrierwav= e/uploader/content_type_denylist.rb:57, denylist entries are interpolated d= irectly into a regex without Regexp.quote or anchoring, so an entry such as=
image/svg+xml becomes the pattern /image\/svg+xml/, in which + is treated =
as a quantifier rather than a literal character and therefore never matches=
the real MIME type image/svg+xml. This is inconsistent with the allowlist = implementation, which correctly applies both Regexp.quote and a \A anchor. = Other content types containing regex metacharacters, such as application/xh= tml+xml, are affected as well. As a result, any application that relies on = content_type_denylist to block image/svg+xml, most commonly to prevent stor=
ed XSS, is silently unprotected. An attacker can upload an SVG file contain= ing arbitrary JavaScript; if the application serves that SVG inline from it=
s own origin, the script executes in the victim's browser, resulting in sto= red XSS. This issue has been fixed in versions 2.2.7 and 3.1.3.</td> <td>2026-06-16</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44587" target=3D= "_blank" rel=3D"noopener">CVE-2026-44587</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Catalyst SD-WAN Manager</td>
<td>A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerl=
y SD-WAN vManage, could allow an authenticated, remote attacker to create a=
file or overwrite any file on the filesystem of an affected system. This v= ulnerability exists because the affected software does not properly validat=
e user-supplied input during a file upload process. An attacker could explo=
it this vulnerability by sending a crafted HTTP request to an affected API = endpoint of the affected system. A successful exploit could allow the attac= ker to create or overwrite any file on the underlying operating system. Thi=
s file could later be used to elevate to root. To exploit this vulnerabilit=
y, the attacker must have valid credentials with at least a lower-privilege=
d, single-task user account.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20262" target=3D= "_blank" rel=3D"noopener">CVE-2026-20262</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Crosswork Network Change Automati= on</td>
<td>A vulnerability in the web-based management interface of Cisco Crosswor=
k Network Controller could allow an&nbsp;authenticated, remote attacker=
to execute arbitrary commands on an affected device. This vulnerability is=
due to insufficient input validation in the configuration&nbsp;templat=
e engine of the web-based management interface. An attacker could exploit t= his vulnerability by sending a crafted request to the affected device. A su= ccessful exploit could allow the attacker to execute arbitrary commands on = the underlying operating system in limited areas of the file system. This v= ulnerability affects only areas of the operating system for which the templ= ate user has write permissions.&nbsp; To exploit this vulnerability, th=
e attacker must have valid template user credentials with write permissions=
. Template users with read permissions cannot exploit this vulnerability.&a= mp;nbsp;</td>
<td>2026-06-17</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20220" target=3D= "_blank" rel=3D"noopener">CVE-2026-20220</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Umbrella Insights Virtual Applian= ce</td>
<td>A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance = could allow an authenticated, local attacker to elevate privileges on an af= fected device. This vulnerability is due to insufficient validation of user= -supplied commands. An attacker with vmadmin privileges could exploit this = vulnerability by using certain commands at the CLI. A successful exploit co= uld allow the attacker to elevate privileges to root.</td>
<td>2026-06-17</td>
<td>6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20246" target=3D= "_blank" rel=3D"noopener">CVE-2026-20246</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Webex App</td>
<td>A vulnerability in the browser-based version of Cisco Webex App could h= ave allowed an unauthenticated, remote attacker to redirect users to a mali= cious webpage. Cisco has addressed this vulnerability in the Cisco Webex Ap=
p, and no customer action is needed. This vulnerability existed due to impr= oper input validation of URL parameters in an HTTP request. Prior to this v= ulnerability being addressed, an attacker could have exploited this vulnera= bility by persuading a user to click a crafted URL. A successful exploit co= uld have allowed the attacker to redirect a user to a malicious website.</t=
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20178" target=3D= "_blank" rel=3D"noopener">CVE-2026-20178</a></td>
</tr>
<td class=3D"vendor-product">Client Portal Ltd.--Client Portal (Pro)</td> <td>CP Client Arbitrary File Download in Client Portal (Pro) <=3D 5.6.2 = versions.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40724" target=3D= "_blank" rel=3D"noopener">CVE-2026-40724</a></td>
</tr>
<td class=3D"vendor-product">Cloud Foundry Foundation--bpm-release</td> <td>setupBpmLogs follows symlink for bpm.log open and chown - container-to-= host privilege escalation via /etc/shadow. A compromised process inside a b=
pm container can cause root to chown an arbitrary host file to vcap and app= end bpm JSON log lines to it. The chown alone lets the attacker take owners= hip of /etc/shadow and read every password hash on the host via the read-on=
ly /etc bind mount. This is a container-to-host confidentiality break affec= ting every bpm-managed job. Affected versions: bpm-release, all versions pr= ior to v1.4.30.</td>
<td>2026-06-18</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47833" target=3D= "_blank" rel=3D"noopener">CVE-2026-47833</a></td>
</tr>
<td class=3D"vendor-product">Cloudflare--Quiche</td>
<td>Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in t=
he connection ID iterator FFI functions. The "quiche_connection_id_iter_nex=
t" and "quiche_conn_retired_scid_next" functions would return a pointer to =
a "ConnectionId" to the applications via function arguments, but the owned = "ConnectionId" would be dropped at the end of those functions' scope. Only = applications using those FFI functions are affected. The FFI API is disable=
d by default by a build-time feature flag. Impact If unpatched, an applicat= ion calling the affected FFI functions will dereference freed memory. The m= ost likely outcome is undefined behavior leading to a process crash (denial=
of service). Depending on allocator state, the read may also return adjace=
nt heap contents, resulting in limited information disclosure or incorrect = connection identifier handling. Mitigation Users are requested to upgrade t=
o quiche 0.29.2 which is the earliest version containing the fix for this i= ssue.</td>
<td>2026-06-19</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11941" target=3D= "_blank" rel=3D"noopener">CVE-2026-11941</a></td>
</tr>
<td class=3D"vendor-product">codepeople--Appointment Booking Calendar</td> <td>The Appointment Booking Calendar plugin for WordPress is vulnerable to = Sensitive Information Exposure in versions up to, and including, 1.4.01. Th=
is is due to insufficient authorization and missing per-calendar ownership = checks in the cpabc_appointments_calendar_load2() function, which is reacha= ble via the cpabc_calendar_load2=3D1 query parameter in wp-admin and only c= hecks is_admin() && current_user_can('edit_posts'), a capability av= ailable to Contributor-level users and above. This makes it possible for au= thenticated attackers with Contributor-level access and above to supply an = arbitrary calendar ID via the id parameter and extract customer booking inf= ormation, including email addresses, names, phone numbers, booking times, a=
nd comments, from any calendar managed by the plugin.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12111" target=3D= "_blank" rel=3D"noopener">CVE-2026-12111</a></td>
</tr>
<td class=3D"vendor-product">Comfast--CF-WR631AX V3</td>
<td>A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issu=
e affects the function system of the file /cgi-bin/mbox-config?section=3Dpi= ng_config of the component API Endpoint. This manipulation of the argument = destination causes os command injection. The attack is possible to be carri=
ed out remotely. The exploit has been published and may be used. The vendor=
was contacted early about this disclosure but did not respond in any way.<=
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12814" target=3D= "_blank" rel=3D"noopener">CVE-2026-12814</a></td>
</tr>
<td class=3D"vendor-product">contrid--Slideshow Gallery LITE</td>
<td>The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored=
Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versi= ons up to, and including, 1.8.5. This is due to insufficient input sanitiza= tion and output escaping on user-supplied attributes. This makes it possibl=
e for authenticated attackers, with Contributor-level access and above, to = inject arbitrary web scripts in pages that will execute whenever a user acc= esses an injected page.</td>
<td>2026-06-18</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2021" target=3D"= _blank" rel=3D"noopener">CVE-2026-2021</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is=
an unknown function of the component Image Name Handler. Such manipulation=
leads to os command injection. The attack may be performed from remote. Th=
e vendor was contacted early about this disclosure but did not respond in a=
ny way. The changelog for 4.1.2 mentions "[i]mproved image, branch, proxy, = and deployment input validation".</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12815" target=3D= "_blank" rel=3D"noopener">CVE-2026-12815</a></td>
</tr>
<td class=3D"vendor-product">Cotonti--Cotonti</td>
<td>Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-S= ite Request Forgery in the Personal File Storage (PFS) module. In modules/p= fs/inc/pfs.editfolder.php, the folder update action ('a=3Dupdate') updates = folder metadata (title, description, public/gallery flags) without calling = cot_check_xg() to validate the anti-CSRF token. A remote attacker who lures=
an authenticated user into visiting a malicious page can force the browser=
to submit a forged request that modifies the victim's folder metadata, inc= luding making a private folder public.</td>
<td>2026-06-18</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55745" target=3D= "_blank" rel=3D"noopener">CVE-2026-55745</a></td>
</tr>
<td class=3D"vendor-product">coturn--coturn</td>
<td>Coturn is a free open source implementation of TURN and STUN Server. Ve= rsions prior to 4.11.0 contain a stored cross-site scripting (XSS) vulnerab= ility in the web-admin HTTPS interface. An attacker who can create a TURN a= llocation with a crafted USERNAME value can inject HTML/JavaScript that exe= cutes when an authenticated web-admin user views the TURN session list. In = configurations using anonymous TURN access (--no-auth), this may be exploit= able without TURN credentials. In authenticated deployments, exploitation r= equires valid TURN credentials or control over a provisioned username. This=
issue has been fixed in version 4.11.0.</td>
<td>2026-06-18</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43915" target=3D= "_blank" rel=3D"noopener">CVE-2026-43915</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulne= rability in the assets/icon endpoint where the extension parameter is not v= alidated before file existence checks. Attackers can bypass extension valid= ation by passing traversal sequences that resolve to existing SVG files, al= lowing local file read access.</td>
<td>2026-06-21</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56394" target=3D= "_blank" rel=3D"noopener">CVE-2026-56394</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting=
vulnerability in the User Permissions page where user group names are rend= ered without proper HTML escaping. Attackers with admin access can inject a= rbitrary JavaScript via the user group name field that executes when other = users view or edit permissions.</td>
<td>2026-06-21</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56381" target=3D= "_blank" rel=3D"noopener">CVE-2026-56381</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS contains a stored cross-site scripting (XSS) vulnerability in=
the editableTable.twig component when using the 'Row Heading' column type.=
The application fails to sanitize input within row heading default values,=
allowing an attacker with an administrator account (with allowAdminChanges=
enabled) to inject arbitrary JavaScript that executes when another user vi= ews a page containing the affected table field. Affected versions are >=
=3D 4.5.0-beta.1 through 4.16.18 and >=3D 5.0.0-RC1 through 5.8.22; fixe=
d in 4.16.19 and 5.8.23.</td>
<td>2026-06-21</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56383" target=3D= "_blank" rel=3D"noopener">CVE-2026-56383</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS contains a missing authorization vulnerability in the assets/= preview-thumb endpoint. A Control Panel user without permission to view a t= arget private asset can call the endpoint with an attacker-controlled asset=
Id and receive preview HTML containing a signed fallback transform preview = link for that private asset, because no asset-view permission check is perf= ormed before preview generation. This affects versions >=3D 4.0.0-RC1, &= lt;=3D 4.17.7 and >=3D 5.0.0-RC1, <=3D 5.9.13, and is fixed in 4.17.8=
and 5.9.14.</td>
<td>2026-06-21</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56384" target=3D= "_blank" rel=3D"noopener">CVE-2026-56384</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions >=3D 5.0.0-RC1, <=3D 5.9.13 and >=3D 4.0.0-= RC1, <=3D 4.17.7 contain an authorization bypass in the assets/preview-f= ile endpoint. The action does not enforce per-asset view authorization befo=
re returning preview content, allowing an authenticated low-privileged user=
to supply a controlled assetId for an asset they are not permitted to view=
and still receive preview response data (previewHtml), including a private=
preview image route containing the target private assetId. Fixed in 5.9.14=
and 4.17.8.</td>
<td>2026-06-21</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56385" target=3D= "_blank" rel=3D"noopener">CVE-2026-56385</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS 4.x (>=3D 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>=3D = 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting = vulnerabilities where settings names and field option labels are rendered w= ithout sanitization (e.g., via the checkbox.twig template, which used {{ la= bel|raw }}). An authenticated administrator (with allowAdminChanges enabled=
) can inject malicious payloads into section names, volume names, user grou=
p names, global set names, generated field names, checkbox/radio option lab= els, and custom source labels, causing arbitrary JavaScript to execute in o= ther users' control-panel sessions. Fixed in 4.17.0-beta.1 and 5.9.0-beta.1= .</td>
<td>2026-06-21</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56393" target=3D= "_blank" rel=3D"noopener">CVE-2026-56393</a></td>
</tr>
<td class=3D"vendor-product">creativethemeshq--Blocksy Companion</td>
<td>The Blocksy Companion plugin for WordPress is vulnerable to Stored Cros= s-Site Scripting via admin settings in all versions up to, and including, 2= .1.45 due to insufficient input sanitization and output escaping. This make=
s it possible for authenticated attackers, with editor-level permissions an=
d above, to inject arbitrary web scripts in pages that will execute wheneve=
r a user accesses an injected page. This only affects multi-site installati= ons and installations where unfiltered_html has been disabled.</td> <td>2026-06-19</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12430" target=3D= "_blank" rel=3D"noopener">CVE-2026-12430</a></td>
</tr>
<td class=3D"vendor-product">creavi--Creavi Appointment Booking Calendar</t=
<td>The Appointment Booking Calendar plugin for WordPress is vulnerable to = Stored Cross-Site Scripting via custom booking field labels in all versions=
up to, and including, 1.4.4 due to insufficient input sanitization and out= put escaping. This makes it possible for authenticated attackers, with Auth= or-level access and above, to inject arbitrary web scripts in pages that wi=
ll execute whenever a user accesses an injected page.</td>
<td>2026-06-19</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1856" target=3D"= _blank" rel=3D"noopener">CVE-2026-1856</a></td>
</tr>
<td class=3D"vendor-product">deepakkite--Secure Client Portal and Private F= ile Sharing Plugin User Private Files</td>
<td>The File Sharing & Download Manager - User Private Files plugin for=
WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' = parameter in all versions up to, and including, 2.1.6 due to insufficient i= nput sanitization and output escaping. This makes it possible for authentic= ated attackers, with subscriber-level access and above, to inject arbitrary=
web scripts in pages that will execute whenever a user accesses an injecte=
d page.</td>
<td>2026-06-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10093" target=3D= "_blank" rel=3D"noopener">CVE-2026-10093</a></td>
</tr>
<td class=3D"vendor-product">Dell--Peripheral Manager</td>
<td>Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontroll=
ed search path element vulnerability. An attacker could potentially exploit=
this vulnerability through preloading malicious dll., leading to arbitrary=
code execution.</td>
<td>2026-06-16</td>
<td>6.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-22447" target=3D= "_blank" rel=3D"noopener">CVE-2024-22447</a></td>
</tr>
<td class=3D"vendor-product">Dell--Peripheral Manager</td>
<td>Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncon= trolled search path element vulnerability. An attacker could potentially ex= ploit this vulnerability through preloading malicious executable, leading t=
o arbitrary code execution.</td>
<td>2026-06-16</td>
<td>6.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-22451" target=3D= "_blank" rel=3D"noopener">CVE-2024-22451</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper A= ccess Control vulnerability. A low privileged attacker with adjacent networ=
k access could potentially exploit this vulnerability, leading to Elevation=
of privileges and Unauthorized access.</td>
<td>2026-06-17</td>
<td>5.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35067" target=3D= "_blank" rel=3D"noopener">CVE-2026-35067</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper N= eutralization of Special Elements used in an SQL Command ('SQL Injection') = vulnerability. A low privileged attacker with adjacent network access could=
potentially exploit this vulnerability, leading to Script injection.</td> <td>2026-06-17</td>
<td>5.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35069" target=3D= "_blank" rel=3D"noopener">CVE-2026-35069</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper A= ccess Control vulnerability. A low privileged attacker with remote access c= ould potentially exploit this vulnerability, leading to denial of service.<=
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35162" target=3D= "_blank" rel=3D"noopener">CVE-2026-35162</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) 4.6.0.1, contain(s) an Use of a Brok=
en or Risky Cryptographic Algorithm vulnerability. An unauthenticated attac= ker with remote access could potentially exploit this vulnerability, leadin=
g to Information disclosure and Information tampering.</td>
<td>2026-06-17</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40641" target=3D= "_blank" rel=3D"noopener">CVE-2026-40641</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex Manager</td>
<td>Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper = certificate validation vulnerability. A remote unauthenticated attacker cou=
ld potentially exploit this vulnerability leading to man-in-the-middle atta=
ck in tandem with DNS cache poisoning.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-47477" target=3D= "_blank" rel=3D"noopener">CVE-2024-47477</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex rack</td>
<td>Dell PowerFlex rack, version(s) RCM 3.7/3.7, contain(s) a Host Header I= njection vulnerability. An unauthenticated attacker with remote access coul=
d potentially exploit this vulnerability to trigger redirections.</td> <td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-32748" target=3D= "_blank" rel=3D"noopener">CVE-2025-32748</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore</td>
<td>PowerStore contains a Stored Cross-Site Scripting Vulnerability in the = PowerStore Manager. A remote authenticated low-privileged malicious actor c= ould potentially exploit this vulnerability, it could lead to script execut= ion in the client browser.</td>
<td>2026-06-16</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-30476" target=3D= "_blank" rel=3D"noopener">CVE-2024-30476</a></td>
</tr>
<td class=3D"vendor-product">dijitul--Fancy Testimonials</td>
<td>The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cro= ss-Site Scripting via the 'author' shortcode attribute in the 'testimonial'=
shortcode in all versions up to, and including, 1.0 due to insufficient in= put sanitization and output escaping. This makes it possible for authentica= ted attackers, with Contributor-level access and above, to inject arbitrary=
web scripts in pages that will execute whenever a user accesses an injecte=
d page.</td>
<td>2026-06-18</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8039" target=3D"= _blank" rel=3D"noopener">CVE-2026-8039</a></td>
</tr>
<td class=3D"vendor-product">Discuz!--Discuz! X5.0</td>
<td>Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypa=
ss vulnerability that allows unauthenticated remote attackers to defeat cha= llenge controls by exploiting limited complexity and predictable character = sets in generated CAPTCHA images. Attackers can train a custom optical char= acter recognition model against collected CAPTCHA samples to reliably predi=
ct challenge text, bypassing protections on login, registration, and other = functionality from automated abuse.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49953" target=3D= "_blank" rel=3D"noopener">CVE-2026-49953</a></td>
</tr>
<td class=3D"vendor-product">dokaninc--Dokan: AI Powered WooCommerce Multiv= endor Marketplace Solution Build Your Own Amazon, eBay, Etsy</td>
<td>The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution - Bu= ild Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insec= ure Direct Object Reference in all versions up to, and including, 5.0.3 via=
the change_order_status, add_order_note, delete_order_note, add_shipping_t= racking_info, grant_access_to_download, and revoke_access_to_download AJAX = handlers due to missing ownership validation on a user-controlled order ID = key. This makes it possible for authenticated attackers, with custom vendor= -level access and above, to modify the status of arbitrary orders, add atta= cker-controlled notes to any order (including customer-facing notes that tr= igger WooCommerce notification emails to buyers), delete any order note or = WordPress comment by ID regardless of ownership, inject fake shipping track= ing information on any order, and grant or revoke downloadable-product perm= issions on any order in the marketplace. Critically, nonce validity is not =
a barrier to exploitation: each of these AJAX handlers generates and embeds=
its nonce on the authenticated vendor's own dashboard order pages (e.g., /= dashboard/orders/?order_id=3DOWN_ORDER_ID), which the attacker legitimately=
controls. The attacker harvests a valid nonce from their own order detail = page and replays it against a victim order ID - the nonce only proves the r= equest originates from a logged-in session, not that the order belongs to t= hat vendor. This directly rebuts the prior rejection reasoning that 'users = cannot generate valid nonces on command': vendor users can and do generate = valid nonces on demand simply by loading their own dashboard pages. Source-= code analysis confirmed the vulnerable code path is present and unpatched t= hrough version 5.0.1.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10023" target=3D= "_blank" rel=3D"noopener">CVE-2026-10023</a></td>
</tr>
<td class=3D"vendor-product">dwbooster--Booking Calendar Contact Form</td> <td>WordPress Booking Calendar Contact Form 1.0.23 contains privilege escal= ation and stored cross-site scripting vulnerabilities that allow authentica= ted users to modify plugin options and inject malicious scripts by failing =
to verify user privileges and sanitize input parameters. Attackers with sub= scriber-level accounts can inject XSS payloads through parameters like pric=
e, name, calendar_language, and email_confirmation_to_user via admin-ajax.p=
hp and admin.php endpoints to execute arbitrary JavaScript in administrator=
browsers.</td>
<td>2026-06-15</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20070" target=3D= "_blank" rel=3D"noopener">CVE-2016-20070</a></td>
</tr>
<td class=3D"vendor-product">dwbooster--CP Polls</td>
<td>WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerab= ility that allows attackers to perform unauthorized actions on behalf of au= thenticated users. Attackers can craft malicious HTML pages that execute un= wanted poll operations when administrators visit the page while logged in.<=
<td>2026-06-15</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20067" target=3D= "_blank" rel=3D"noopener">CVE-2016-20067</a></td>
</tr>
<td class=3D"vendor-product">Edimax--BR-6478AC V2</td>
<td>A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the=
function setWAN of the file /goform/setWAN of the component POST Request H= andler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserN= ame results in command injection. It is possible to launch the attack remot= ely. The exploit has been made public and could be used. The vendor was con= tacted early about this disclosure but did not respond in any way.</td> <td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12807" target=3D= "_blank" rel=3D"noopener">CVE-2026-12807</a></td>
</tr>
<td class=3D"vendor-product">Edimax--BR-6478AC V2</td>
<td>A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impact=
s the function stainfo of the file /goform/stainfo of the component POST Re= quest Handler. This manipulation of the argument interface causes command i= njection. The attack can be initiated remotely. The exploit has been public=
ly disclosed and may be utilized. The vendor was contacted early about this=
disclosure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12808" target=3D= "_blank" rel=3D"noopener">CVE-2026-12808</a></td>
</tr>
<td class=3D"vendor-product">Edimax--BR-6478AC V2</td>
<td>A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is=
the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of th=
e component POST Request Handler. Such manipulation of the argument newpass=
leads to command injection. The attack can be launched remotely. The explo=
it is publicly available and might be used. The vendor was contacted early = about this disclosure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12809" target=3D= "_blank" rel=3D"noopener">CVE-2026-12809</a></td>
</tr>
<td class=3D"vendor-product">Edimax--BR-6478AC V2</td>
<td>A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affect=
ed by this vulnerability is the function mp of the file /goform/mp of the c= omponent POST Request Handler. Performing a manipulation of the argument co= mmand results in command injection. The attack may be initiated remotely. T=
he exploit has been released to the public and may be used for attacks. The=
vendor was contacted early about this disclosure but did not respond in an=
y way.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12810" target=3D= "_blank" rel=3D"noopener">CVE-2026-12810</a></td>
</tr>
<td class=3D"vendor-product">eemitch--Simple File List</td>
<td>The Simple File List plugin for WordPress is vulnerable to unauthorized=
file operations due to a missing authorization check on the 'frontmanage' = shortcode attribute in all versions up to, and including, 6.3.7. This makes=
it possible for authenticated attackers, with contributor-level access and=
above, to perform arbitrary file operations including deletion, move, fold=
er creation, and download. An attacker can create a draft post containing t=
he 'eeSFL' shortcode, render it via the post preview endpoint to harvest th=
e nonce needed to authorize the operations, and then submit file operation = requests that bypass the intended authorization checks in includes/ee-list-= ops-bar-process.php.</td>
<td>2026-06-20</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12119" target=3D= "_blank" rel=3D"noopener">CVE-2026-12119</a></td>
</tr>
<td class=3D"vendor-product">eLightUp--Meta Box WordPress Custom Fields Fra= mework</td>
<td>Contributor Arbitrary File Deletion in Meta Box - WordPress Custom Fiel=
ds Framework <=3D 5.11.1 versions.</td>
<td>2026-06-15</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39468" target=3D= "_blank" rel=3D"noopener">CVE-2026-39468</a></td>
</tr>
<td class=3D"vendor-product">equalizedigital--Equalize Digital Accessibilit=
y Checker WCAG, ADA, EAA and Section 508 compliance</td>
<td>The Equalize Digital Accessibility Checker - WCAG, ADA, EAA and Section=
508 compliance plugin for WordPress is vulnerable to authorization bypass =
in all versions up to, and including, 1.42.1. This is due to the plugin not=
properly verifying that a user is authorized to perform an action. This ma= kes it possible for authenticated attackers, with author-level access and a= bove, to dismiss, ignore, or restore accessibility audit issue records belo= nging to posts they are not permitted to edit by supplying an issue from th= eir own post as an authorization token to affect matching issues across the=
entire site. An Author-level user can exploit this by passing largeBatch= =3Dtrue on a dismiss-issue request referencing one of their own post's issu= es, causing the handler to bulk-modify all site-wide accessibility issues s= haring the same 'object' value - including those belonging to administrator= -owned posts.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9199" target=3D"= _blank" rel=3D"noopener">CVE-2026-9199</a></td>
</tr>
<td class=3D"vendor-product">eventkoi--Event Koi Lite Events Calendar, Even=
t Management, RSVP, and Tickets</td>
<td>The Event Koi Lite - Events Calendar, Event Management, RSVP, and Ticke=
ts plugin for WordPress is vulnerable to Sensitive Information Exposure in = all versions up to, and including, 1.3.13.1 via the get_events. This makes =
it possible for unauthenticated attackers to extract sensitive data includi=
ng virtual meeting URLs, physical location data, latitude/longitude coordin= ates, Google Maps links, and RSVP configuration belonging to draft, pending=
, and private events that are otherwise inaccessible via public URLs.</td> <td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10029" target=3D= "_blank" rel=3D"noopener">CVE-2026-10029</a></td>
</tr>
<td class=3D"vendor-product">Extend Themes--Skyline WP</td>
<td>Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skylin=
e WP allows Cross Site Request Forgery. This issue affects Skyline WP: from=
n/a through 1.0.10.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-34810" target=3D= "_blank" rel=3D"noopener">CVE-2024-34810</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Gateway Fabric</td>
<td>When NGINX Gateway Fabric is configured using GRPCRoutes, an authentica= ted, remote attacker with permission to create or modify GRPCRoute resource=
s can cause the NGINX Gateway Fabric control plane to terminate by sending = undisclosed GRPCRoute configurations containing backendRef filters. Note: S= oftware versions which have reached End of Technical Support (EoTS) are not=
evaluated.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32682" target=3D= "_blank" rel=3D"noopener">CVE-2026-32682</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Open Source</td>
<td>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_c= harset_module=C2=A0module. When content is served or proxied through a loca= tion block with both source_charset=C2=A0utf-8; and a charset=C2=A0directiv=
e (for example, charset koi8-r;) configured, remote, unauthenticated attack= ers can send requests (in conjunction with conditions beyond their control)=
to cause a heap buffer over-read in the NGINX worker process, leading to l= imited disclosure of memory or a restart. Note: Software versions which hav=
e reached End of Technical Support (EoTS) are not evaluated.</td> <td>2026-06-17</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48142" target=3D= "_blank" rel=3D"noopener">CVE-2026-48142</a></td>
</tr>
<td class=3D"vendor-product">fduflyer--DroneAware-Node-Releases</td> <td>DroneAware is a drone detection platform. The centralized DroneAware se= rver backing droneaware.io was vulnerable to an account pre-hijacking attac=
k in which an attacker could register an account using a victim's email add= ress with an attacker-controlled password before the victim completed accou=
nt activation. When the legitimate owner later activated the account, eithe=
r by clicking the email verification link or by logging in via Google SSO, = the attacker-set password became fully valid, enabling silent and persisten=
t account takeover without any notification to the victim. The vulnerabilit=
y was fixed server-side on 2025-05-20; no user action is required. Node bin= aries and self-hosted detection nodes are not affected. There are no workar= ounds; the fix was deployed server-side and no client-side mitigation is ap= plicable.</td>
<td>2026-06-17</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48117" target=3D= "_blank" rel=3D"noopener">CVE-2026-48117</a></td>
</tr>
<td class=3D"vendor-product">fireplugins--FireBox Popups Increase Sales and=
Grow Your Email List</td>
<td>The FireBox Popups - Increase Sales and Grow Your Email List plugin for=
WordPress is vulnerable to Sensitive Information Exposure in all versions =
up to, and including, 3.1.7 via the 'form_id' parameter. This makes it poss= ible for unauthenticated attackers to extract download a full CSV export of=
all form submissions - including any personally identifiable information s= ubmitted by users - for any arbitrary form_id.</td>
<td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12120" target=3D= "_blank" rel=3D"noopener">CVE-2026-12120</a></td>
</tr>
<td class=3D"vendor-product">Flowise--Flowise</td>
<td>Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerabilit=
y caused by insufficient input filtering in chat messages and custom agent = functions. An attacker can inject malicious JavaScript by sending an iframe=
payload (e.g., <iframe src=3D"javascript:alert(document.cookie)">) i=
n a chat box, or by having a custom agent function return an XSS payload fr=
om an external website. The injected script executes in the victim's browse=
r, enabling theft of cookies and session data.</td>
<td>2026-06-20</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71331" target=3D= "_blank" rel=3D"noopener">CVE-2025-71331</a></td>
</tr>
<td class=3D"vendor-product">FlowiseAI--Flowise</td>
<td>A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The im= pacted element is an unknown function of the file packages/components/nodes= /documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a = manipulation can lead to path traversal. It is possible to launch the attac=
k remotely. The vendor was contacted early about this disclosure but did no=
t respond in any way.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12821" target=3D= "_blank" rel=3D"noopener">CVE-2026-12821</a></td>
</tr>
<td class=3D"vendor-product">FluxBuilder--MStore API</td>
<td>Authentication Bypass Using an Alternate Path or Channel vulnerability =
in FluxBuilder MStore API allows Password Recovery Exploitation. This issue=
affects MStore API: from n/a through 4.18.4.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54817" target=3D= "_blank" rel=3D"noopener">CVE-2026-54817</a></td>
</tr>
<td class=3D"vendor-product">FolioVision--FV Flowplayer Video Player</td> <td>Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player <=
; 7.5.51.7212 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49773" target=3D= "_blank" rel=3D"noopener">CVE-2026-49773</a></td>
</tr>
<td class=3D"vendor-product">geoserver--org.geoserver.web:gs-web-app</td> <td>GeoServer is an open source server that allows users to share and edit = geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses=
`ENTITY_RESOLUTION_ALLOWLIST` may allow attacker to perform unauthenticate=
d Server-Side Request Forgery (SSRF). This vulnerability requires that GeoS= erver is set up to use a proxy base URL and the `ENTITY_RESOLUTION_ALLOWLIS=
T` (default since 2.25.0). Versions 2.26.4 and 2.27.3 contain a fix. GeoSer= ver installations are only affected by this vulnerability if they use a pro=
xy base URL that does not contain a URL path or end with a slash. If the pr= oxy base URL does not contain a path, adding a slash to the end of the URL = will mitigate this vulnerability.</td>
<td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-58175" target=3D= "_blank" rel=3D"noopener">CVE-2025-58175</a></td>
</tr>
<td class=3D"vendor-product">gitroomhq--postiz-app</td>
<td>Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 = contained an unauthenticated endpoint that accepted a signed token and appl= ied subscription-enforcement side effects to the organization referenced in=
that token's claims, without verifying the token's intended purpose. The e= ndpoint, /public/modify-subscription, could not change the persisted subscr= iption tier, but it did execute enforcement-related side effects on the cal= ler's own organization, including adjusting team-member enablement state, d= isabling integrations exceeding the asserted plan's limits, and resetting t=
he scheduled-post cron when the asserted plan was the free tier. Impact is = limited to the attacker's own organization and cannot be redirected at othe=
r tenants through this endpoint. This issue has been fixed in version 2.21.= 8.</td>
<td>2026-06-16</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48783" target=3D= "_blank" rel=3D"noopener">CVE-2026-48783</a></td>
</tr>
<td class=3D"vendor-product">GNOME--Evolution Data Server</td>
<td>A flaw was found in evolution-data-server. Inconsistent comparison logi=
c in the addressbook file backend allows a Flatpak application with D-Bus a= ccess to craft a malicious URI containing directory traversal sequences. Th=
is URI is stored without proper validation during contact creation or modif= ication. Later, during contact deletion, the URI is processed with a less s= trict check, leading to the deletion of arbitrary files on the host filesys= tem. This could potentially include critical Flatpak override files.</td> <td>2026-06-16</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2604" target=3D"= _blank" rel=3D"noopener">CVE-2026-2604</a></td>
</tr>
<td class=3D"vendor-product">Government Accountability Office--Electronic P= rotest Docketing System (EPDS)</td>
<td>The U.S. Government Accountability Office (GAO) Electronic Protest Dock= eting System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electroni=
c Docketing System (EDS) expose sensitive account information through the '= update-profile/' API endpoint. A remote, unauthenticated attacker can submi=
t a request containing an arbitrary 'user_id' parameter and receive a JSON = response containing account-specific information, including the associated = email address.</td>
<td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54105" target=3D= "_blank" rel=3D"noopener">CVE-2026-54105</a></td>
</tr>
<td class=3D"vendor-product">Government Accountability Office--Electronic P= rotest Docketing System (EPDS)</td>
<td>The U.S. Government Accountability Office (GAO) Electronic Protest Dock= eting System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electroni=
c Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allo= wing a remote attacker with compromised administrator credentials to bypass=
network access controls and log in.</td>
<td>2026-06-18</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54106" target=3D= "_blank" rel=3D"noopener">CVE-2026-54106</a></td>
</tr>
<td class=3D"vendor-product">Grafana--Enterprise Traces (GET)</td>
<td>A TraceQL query in Grafana Tempo with a large exemplars hint value can = cause the Tempo instance to allocate an excessive amount of memory, resulti=
ng in an out-of-memory crash. This could allow an authenticated user to tri= gger a denial of service against the Tempo service.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27878" target=3D= "_blank" rel=3D"noopener">CVE-2026-27878</a></td>
</tr>
<td class=3D"vendor-product">Greg Winiarski--WPAdverts</td>
<td>Unauthenticated Broken Access Control in WPAdverts <=3D 2.3.0 versio= ns.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40782" target=3D= "_blank" rel=3D"noopener">CVE-2026-40782</a></td>
</tr>
<td class=3D"vendor-product">Grit42--Grit</td>
<td>A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue = affects the function Grit::Assays::DataTableEntity of the file modules/assa= ys/backend/app/models/grit/assays/data_table_entity.rb. The manipulation le= ads to sql injection. The attack is possible to be carried out remotely. Th=
e exploit is publicly available and might be used. The vendor was contacted=
early about this disclosure but did not respond in any way.</td> <td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12206" target=3D= "_blank" rel=3D"noopener">CVE-2026-12206</a></td>
</tr>
<td class=3D"vendor-product">Groundhogg--Groundhogg</td>
<td>Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.</td=
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40793" target=3D= "_blank" rel=3D"noopener">CVE-2026-40793</a></td>
</tr>
<td class=3D"vendor-product">Hackplayers--evil-winrm</td>
<td>Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traver= sal vulnerability in the download_dir() function that allows a rogue or com= promised remote Windows server to write files outside the intended download=
directory by returning filenames with traversal sequences from Get-ChildIt=
em command output that are passed unsanitized to File.join(). Attackers con= trolling the remote server can exploit this to overwrite sensitive client-s= ide files such as SSH authorized_keys or shell configuration files, achievi=
ng persistent access or privilege escalation on the client machine.</td> <td>2026-06-17</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55201" target=3D= "_blank" rel=3D"noopener">CVE-2026-55201</a></td>
</tr>
<td class=3D"vendor-product">harttle--liquidjs</td>
<td>LiquidJS is a Shopify/GitHub Pages compatible template engine written i=
n pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through=
a flaw in the strip_html filter logic. The strip_html filter is intended t=
o remove HTML tags from a string before rendering, and is widely used as an=
XSS sanitizer. The implementation uses a regex whose catch-all branch (<= ;.*?>) does not match line terminators, so any HTML tag containing a \n =
or \r character passes through unmodified. An attacker who can place a newl= ine inside a tag (e.g. <img\nsrc=3Dx\nonerror=3Dalert(1)>) bypasses s= anitization entirely, since browsers treat newlines as whitespace within a = tag and execute the resulting onerror/onload/etc. handler. Exploitation is = possible for applications that both render attacker-controlled strings via =
{{ x | strip_html }} to defend against HTML injection and do not separately=
HTML-escape that output (default behavior - outputEscape is unset by defau= lt). This issue has been fixed in version 10.26.0.</td>
<td>2026-06-17</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44644" target=3D= "_blank" rel=3D"noopener">CVE-2026-44644</a></td>
</tr>
<td class=3D"vendor-product">harttle--liquidjs</td>
<td>LiquidJS is a Shopify/GitHub Pages compatible template engine written i=
n pure JavaScript. In versions 10.25.7 and below, the renderLimit option ca=
n be fully bypassed by a {% for %} (or {% tablerow %}) tag whose body is em= pty. The renderLimit option is documented in docs/source/tutorials/dos.md a=
s the mechanism that "mitigates this by limiting the time consumed by each = render() call." The per-iteration time check is reached only when the body = contains at least one template node, so a template such as {%- for i in (1.= .N) -%}{%- endfor -%} iterates the full collection without ever consulting = renderLimit. With a configured renderLimit of 50 ms, a single parseAndRende= rSync call has been observed to consume 2.26 seconds (~45=C3=83=E2=80=94 ov=
er the limit) and scales linearly with N up to memoryLimit, allowing a low-= privileged template author to wedge an event-loop thread for an attacker-ch= osen duration. Deployments that rely on a finite renderLimit for DoS protec= tion (common in multi-tenant template-authoring environments) can still be = forced by a single crafted template to monopolize a Node.js event-loop work=
er for attacker-controlled time, potentially stalling in-flight requests, w= ith availability impact only. This issue has been fixed in version 10.26.0.= </td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44645" target=3D= "_blank" rel=3D"noopener">CVE-2026-44645</a></td>
</tr>
<td class=3D"vendor-product">harttle--liquidjs</td>
<td>LiquidJS is a Shopify/GitHub Pages compatible template engine written i=
n pure JavaScript. In versions 10.25.7 and below, Context.spawn() creates a=
child Context for the {% render %} tag but does not propagate the parent c= ontext's resolved ownPropertyOnly value, resulting in a silent bypass. The = new context re-derives ownPropertyOnly from opts.ownPropertyOnly (the insta= nce-level option), silently discarding any RenderOptions.ownPropertyOnly ov= erride that was supplied to parseAndRender(). As a result, a developer who = runs a Liquid instance with the backwards-compatible ownPropertyOnly:false = and then locks down an untrusted render with parseAndRender(..., { ownPrope= rtyOnly: true }) still leaks prototype-chain properties from inside any {% = render %} partial. This is a distinct exploit surface from the previously i= dentified array-filter variants (where, reject, group_by, find, find_index,=
has) - the underlying root cause in Context.spawn() is shared, but {% rend=
er %} is a separately reachable sink that needs no filter usage. This issue=
has been fixed in version 10.26.0.</td>
<td>2026-06-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44646" target=3D= "_blank" rel=3D"noopener">CVE-2026-44646</a></td>
</tr>
<td class=3D"vendor-product">hashgraph--guardian</td>
<td>Hashgraph Guardian through 3.5.0, fixed in commit ba8c566, contains a s= tored cross-site scripting vulnerability that allows authenticated users wi=
th the STANDARD_REGISTRY role to inject malicious scripts by submitting a c= rafted companyName value via the branding configuration API endpoint. Attac= kers can exploit the unsanitized innerHTML assignment in the branding servi=
ce to execute arbitrary JavaScript in the browser of every authenticated us=
er on every page load.</td>
<td>2026-06-18</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22674" target=3D= "_blank" rel=3D"noopener">CVE-2026-22674</a></td>
</tr>
<td class=3D"vendor-product">hcengineering--Huly Platform</td>
<td>A vulnerability has been found in hcengineering Huly Platform up to 0.7= .0. Affected is the function getMailboxSecret of the file server/account/sr= c/operations.ts of the component RPC Interface. The manipulation leads to i= mproper access controls. The attack may be initiated remotely. The exploit = has been disclosed to the public and may be used. The vendor was contacted = early about this disclosure but did not respond in any way.</td> <td>2026-06-15</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12212" target=3D= "_blank" rel=3D"noopener">CVE-2026-12212</a></td>
</tr>
<td class=3D"vendor-product">hcengineering--Huly Platform</td>
<td>A vulnerability was found in hcengineering Huly Platform up to 0.7.0. A= ffected by this vulnerability is the function getAccountInfo of the file se= rver/account/src/operations.ts of the component User Information Handler. T=
he manipulation results in improper authorization. The attack may be launch=
ed remotely. The exploit has been made public and could be used. The vendor=
was contacted early about this disclosure but did not respond in any way.<=
<td>2026-06-15</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12213" target=3D= "_blank" rel=3D"noopener">CVE-2026-12213</a></td>
</tr>
<td class=3D"vendor-product">HCL Software--ZIE</td>
<td>HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerabilit=
y, If the server is configured to execute code, then it may be possible to = obtain command execution on the server by uploading a file known as a web s= hell, which allows you to execute arbitrary code or operating system comman= ds. For this attack to be successful, the file needs to be uploaded inside = the Webroot, and the server must be configured to execute the code</td> <td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59872" target=3D= "_blank" rel=3D"noopener">CVE-2025-59872</a></td>
</tr>
<td class=3D"vendor-product">HCLSoftware--Verse for Android</td>
<td>The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for And= roid's rich text email composition fails to properly validate all HTML inpu=
t thereby allowing malicious content to be executed in certain situations.<=
<td>2026-06-19</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21768" target=3D= "_blank" rel=3D"noopener">CVE-2026-21768</a></td>
</tr>
<td class=3D"vendor-product">henrikmelin--More Fields</td>
<td>WordPress More Fields Plugin 2.1 contains a cross-site request forgery = vulnerability that allows attackers to perform unauthorized actions by disa= bling CSRF token validation. Attackers can craft malicious web pages that t= rick logged-in administrators into adding or deleting custom fields and box=
es on the Write/Edit page via POST and GET requests to the options-general.= php endpoint.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20083" target=3D= "_blank" rel=3D"noopener">CVE-2016-20083</a></td>
</tr>
<td class=3D"vendor-product">Henrique Dias--IMDb Profile Widget</td> <td>WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vul= nerability that allows unauthenticated attackers to read arbitrary files by=
manipulating the url parameter. Attackers can supply directory traversal s= equences in GET requests to pic.php to access sensitive files like wp-confi= g.php containing database credentials and configuration data.</td> <td>2026-06-15</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20078" target=3D= "_blank" rel=3D"noopener">CVE-2016-20078</a></td>
</tr>
<td class=3D"vendor-product">HKUDS--AI-Trader</td>
<td>A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657d= f8365c8544678a16e215. This affects an unknown part of the file /api/researc= h/agents.csv of the component Research Export. Performing a manipulation re= sults in information disclosure. Remote exploitation of the attack is possi= ble. The exploit has been made public and could be used. This product follo=
ws a rolling release approach for continuous delivery, so version details f=
or affected or updated releases are not provided. The patch is named 91a31a= ac1b0f4dbc6b8bef9f6eff0b7912e0bc65. Applying a patch is the recommended act= ion to fix this issue. The vendor confirms: "Research export endpoints now = require an authenticated agent with the research_exports capability".</td> <td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12203" target=3D= "_blank" rel=3D"noopener">CVE-2026-12203</a></td>
</tr>
<td class=3D"vendor-product">ILIAS--Learning Management System</td>
<td>A vulnerability was identified in ILIAS Learning Management System 11.0=
. This issue affects the function ilTrQuery::executeQueries of the file com= ponents/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learnin=
g Progress Tracking. Such manipulation of the argument troup_table_nav lead=
s to sql injection. It is possible to launch the attack remotely. The explo=
it is publicly available and might be used. The vendor was contacted early = about this disclosure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12789" target=3D= "_blank" rel=3D"noopener">CVE-2026-12789</a></td>
</tr>
<td class=3D"vendor-product">info@welcart--Welcart e-Commerce</td> <td>Unauthenticated Broken Access Control in Welcart e-Commerce <=3D 2.1= 1.28 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49775" target=3D= "_blank" rel=3D"noopener">CVE-2026-49775</a></td>
</tr>
<td class=3D"vendor-product">Inisev--Social Media & Share Icons</td>
<td>: Missing Authorization vulnerability in Inisev Social Media & Shar=
e Icons allows Exploiting Incorrectly Configured Access Control Security Le= vels. This issue affects Social Media & Share Icons: from n/a through 2= .8.6.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-31435" target=3D= "_blank" rel=3D"noopener">CVE-2024-31435</a></td>
</tr>
<td class=3D"vendor-product">IObit--Malware Fighter</td>
<td>A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected b=
y this vulnerability is an unknown functionality of the component DLL Handl= er. This manipulation causes permission issues. The attack requires local a= ccess. The exploit has been published and may be used. The vendor was conta= cted early about this disclosure but did not respond in any way.</td> <td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12201" target=3D= "_blank" rel=3D"noopener">CVE-2026-12201</a></td>
</tr>
<td class=3D"vendor-product">Iqonic Design--KiviCare</td>
<td>Subscriber Insecure Direct Object References (IDOR) in KiviCare <=3D=
4.2.1 versions.</td>
<td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40792" target=3D= "_blank" rel=3D"noopener">CVE-2026-40792</a></td>
</tr>
<td class=3D"vendor-product">j_3rk--Video Conferencing with Zoom</td>
<td>The Video Conferencing with Zoom plugin for WordPress is vulnerable to = authorization bypass in all versions up to, and including, 4.6.7. This is d=
ue to the plugin not properly verifying that a user is authorized to perfor=
m an action. This makes it possible for unauthenticated attackers to obtain=
the site's Zoom SDK API key and a freshly-signed JWT that can be used with=
the Zoom Web SDK to join any Zoom meeting associated with those credential=
s without a legitimate invitation.</td>
<td>2026-06-16</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6964" target=3D"= _blank" rel=3D"noopener">CVE-2026-6964</a></td>
</tr>
<td class=3D"vendor-product">jamie--Dharma Booking</td>
<td>WordPress Dharma Booking 2.28.3 and earlier contains a local file inclu= sion vulnerability that allows unauthenticated attackers to include arbitra=
ry files by manipulating the gateway parameter. Attackers can supply file p= aths with directory traversal sequences or null byte injection to the gatew=
ay parameter in proccess.php to read sensitive files like configuration and=
system files.</td>
<td>2026-06-15</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20079" target=3D= "_blank" rel=3D"noopener">CVE-2016-20079</a></td>
</tr>
<td class=3D"vendor-product">Jegstudio--Startupzy</td>
<td>Missing Authorization vulnerability in Jegstudio Startupzy startupzy al= lows Exploiting Incorrectly Configured Access Control Security Levels. This=
issue affects Startupzy: from n/a through 1.1.1.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-33685" target=3D= "_blank" rel=3D"noopener">CVE-2024-33685</a></td>
</tr>
<td class=3D"vendor-product">Jetmonsters--JetFormBuilder</td>
<td>Subscriber Privilege Escalation in JetFormBuilder <=3D 3.6.1 version= s.</td>
<td>2026-06-17</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54196" target=3D= "_blank" rel=3D"noopener">CVE-2026-54196</a></td>
</tr>
<td class=3D"vendor-product">jgwhite33--WP Google Review Slider</td> <td>Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider &= lt;=3D 18.0 versions.</td>
<td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39451" target=3D= "_blank" rel=3D"noopener">CVE-2026-39451</a></td>
</tr>
<td class=3D"vendor-product">Joomtech--Easy Shop</td>
<td>Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulne= rability that allows unauthenticated attackers to read arbitrary files by s= upplying base64-encoded file paths. Attackers can send GET requests to inde= x.php with the option parameter set to com_easyshop, task set to ajax.loadI= mage, and a base64-encoded file path in the file parameter to retrieve sens= itive files like configuration.php and system files.</td>
<td>2026-06-19</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2019-25760" target=3D= "_blank" rel=3D"noopener">CVE-2019-25760</a></td>
</tr>
<td class=3D"vendor-product">jsonata-js--jsonata</td>
<td>A weakness has been identified in jsonata-js jsonata up to 2.2.0. The a= ffected element is the function createFrame of the file src/jsonata.js of t=
he component Function Binding Frame System. This manipulation causes improp= erly controlled modification of object prototype attributes. It is possible=
to initiate the attack remotely. The exploit has been made available to th=
e public and could be used for attacks. The vendor was contacted early abou=
t this disclosure but did not respond in any way.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12208" target=3D= "_blank" rel=3D"noopener">CVE-2026-12208</a></td>
</tr>
<td class=3D"vendor-product">Jthemes--Genemy</td>
<td>Subscriber Broken Access Control in Genemy <=3D 1.6.6 versions.</td> <td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69137" target=3D= "_blank" rel=3D"noopener">CVE-2025-69137</a></td>
</tr>
<td class=3D"vendor-product">juice-shop--multi-juicer</td>
<td>MultiJuicer is used to run separate Juice Shop instances on a central k= ubernetes cluster without the need for local instances. In versions 8.0.0 t= hrough 10.0.0, the team join endpoint (POST /multi-juicer/api/teams/{team}/= join) accepted requests with any Content-Type, including text/plain. Becaus=
e that content type does not trigger a CORS preflight, an attacker could ho=
st a cross-site HTML form that auto-submits to the endpoint and forces a vi= ctim's browser to log in as the attacker's team. A successful, undetected a= ttacker can cause victims to unwittingly solve Juice Shop challenges under = the attacker's team identity. In a CTF context this lets the attacker infla=
te their team's score using other players' activity, and any sensitive data=
the victim enters into "their" Juice Shop ends up in the attacker's instan= ce. The vulnerability is exploitable without any prior authentication; the = victim only needs to visit a page the attacker controls while having networ=
k access to the MultiJuicer deployment. SameSite=3DStrict on the session co= okie does not mitigate this, because the attack plants a new cookie rather = than relying on an existing one. This issue was fixed in version 10.0.1.</t=
<td>2026-06-15</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48518" target=3D= "_blank" rel=3D"noopener">CVE-2026-48518</a></td>
</tr>
<td class=3D"vendor-product">KaymeePhotography--Photocart Link</td> <td>WordPress Plugin Photocart Link 1.6 contains a local file inclusion vul= nerability that allows unauthenticated attackers to read arbitrary files by=
exploiting insufficient input validation in decode.php. Attackers can supp=
ly base64-encoded file paths in the 'id' parameter to the decode.php endpoi=
nt to retrieve sensitive files like wp-config.php containing database crede= ntials and configuration data.</td>
<td>2026-06-15</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20077" target=3D= "_blank" rel=3D"noopener">CVE-2016-20077</a></td>
</tr>
<td class=3D"vendor-product">kestra-io--kestra</td>
<td>Kestra is an open-source, event-driven orchestration platform. Prior to=
versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writ=
es rendered file names directly under the task working directory. When a fl=
ow forwards untrusted execution or webhook data into an `inputFiles` file n= ame, a caller can use `../` path segments to create or overwrite files outs= ide that task working directory on the worker filesystem. Versions 1.3.19, = 1.2.19, 1.1.19, and 1.0.43 patch the issue.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48129" target=3D= "_blank" rel=3D"noopener">CVE-2026-48129</a></td>
</tr>
<td class=3D"vendor-product">King Addons--King Addons for Elementor</td> <td>Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= =3D 51.1.62 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48870" target=3D= "_blank" rel=3D"noopener">CVE-2026-48870</a></td>
</tr>
<td class=3D"vendor-product">Kludex--starlette</td>
<td>Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 an=
d below, when dispatching a request, HTTPEndpoint selects the handler by lo= wercasing the HTTP method and looking it up as an attribute with getattr, w= ithout restricting the lookup to a known set of HTTP verbs. When an HTTPEnd= point subclass is registered through Route(...) without an explicit methods= =3D argument, the route does not constrain the method and every method reac= hes the endpoint. If a non-standard HTTP method whose lowercased name match=
es an attribute on the endpoint subclass reaches the endpoint, that attribu=
te is invoked as if it were a request handler. An attacker can use this to = reach methods that were never meant to be HTTP handlers, such as internal h= elpers, without the authorization checks applied by the intended public han= dler. An application (including Starlette-based frameworks like FastAPI) is=
affected if it registers an HTTPEndpoint subclass via Route(...) without e= xplicitly setting methods=3D, and that subclass includes extra methods name=
d like non-standard HTTP verbs that take one request argument and return a = response. This issue has been fixed in version 1.1.0.</td>
<td>2026-06-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48817" target=3D= "_blank" rel=3D"noopener">CVE-2026-48817</a></td>
</tr>
<td class=3D"vendor-product">kortix-ai--suna</td>
<td>A weakness has been identified in kortix-ai suna up to 0.8.38. Affected=
by this issue is the function router.replace/router.push of the file apps/= frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a = manipulation of the argument returnURL can lead to cross site scripting. Th=
e attack may be launched remotely. The exploit has been made available to t=
he public and could be used for attacks. Upgrading to version 0.8.39 can re= solve this issue. This patch is called f5dec7aa0c1b8fa0125938f292c0f2430ca7= 5f6c. It is advisable to upgrade the affected component. The researcher exp= lains: "The issue was fixed in v0.8.39 without notifying the wider user bas=
e via a security disclosure."</td>
<td>2026-06-21</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12811" target=3D= "_blank" rel=3D"noopener">CVE-2026-12811</a></td>
</tr>
<td class=3D"vendor-product">langchain-ai--langchain-ai</td>
<td>LangGraph Python SDK is used to connect to running LangGraph API server=
s, manage assistants, threads and stream runs from Python applications. Ver= sions 0.3.14 and prior have unsafe URL path construction through unsanitize=
d caller-supplied identifier values used in HTTP request paths for resource=
operations. Without sanitization of those values, identifiers that contain=
characters with special meaning in URL paths could cause the resulting req= uest to address a different resource (and potentially a different resource = type) than the SDK method's call site indicates. In deployments where the S=
DK receives identifier values that originate from untrusted sources, this c= ould result in unintended access, modification, or deletion of resources be= yond the calling user's authorization scope. This issue is most consequenti=
al in deployments that forward end-user-supplied values directly into SDK i= dentifier parameters without first validating them against an expected form=
at (such as a UUID), and rely on URL-prefix-based authorization at an upstr= eam layer (reverse proxy, edge gateway, WAF), where the authorization decis= ion is made on the SDK call's intended path rather than on the final delive= red request path. The issue has been fixed in version 0.3.15.</td> <td>2026-06-16</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48776" target=3D= "_blank" rel=3D"noopener">CVE-2026-48776</a></td>
</tr>
<td class=3D"vendor-product">langchain-ai--langgraph</td>
<td>LangGraph SQLite Checkpoint is an implementation of LangGraph Checkpoin= tSaver that uses SQLite DB (both sync and async, via aiosqlite). In version=
s 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects fr=
om JSON checkpoint payloads. Under conditions where someone could modify ch= eckpoint bytes at rest in the backing store, the deserialization path could=
reconstruct objects beyond what the application expects, which could in tu=
rn result in code execution at checkpoint load time. This is a defense-in-d= epth issue. The affected behavior is reachable only when checkpoint bytes a=
t rest in the backing store can be modified by an unauthorized party. In mo=
st deployments that prerequisite already implies a serious incident; the ad= ditional concern is turning "checkpoint-store write access" into code execu= tion in the application runtime. This issue has been fixed in version 4.1.1= .</td>
<td>2026-06-16</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48775" target=3D= "_blank" rel=3D"noopener">CVE-2026-48775</a></td>
</tr>
<td class=3D"vendor-product">langflow-ai--langflow</td>
<td>A vulnerability was identified in langflow-ai langflow up to 1.9.3. Thi=
s affects an unknown function of the component Bundle URL Loader. The manip= ulation leads to code injection. The attack needs to be performed locally. = The vendor was contacted early about this disclosure but did not respond in=
any way.</td>
<td>2026-06-21</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12822" target=3D= "_blank" rel=3D"noopener">CVE-2026-12822</a></td>
</tr>
<td class=3D"vendor-product">leejet--stable-diffusion.cpp</td> <td>stable-diffusion.cpp is a pure C/C++ library for running diffusion mode=
l (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. V= ersions prior to master-584-0a7ae07 are vulnerable to an out-of-bounds read=
s error through PyTorch checkpoint pickle opcode parsing. The pickle .ckpt = parser in src/model.cpp did not consistently check that enough input remain=
ed before reading opcode arguments or advancing the parser buffer with a cr= afted or truncated .ckpt file. Throughout the pickle parser, opcode handler=
s advanced the parser position with expressions such as buffer +=3D N witho=
ut first checking that buffer + N <=3D buffer_end. A truncated file coul=
d therefore cause reads past the end of the metadata buffer. LibFuzzer foun=
d crashes in under one second using malformed checkpoint inputs. Any applic= ation using affected stable-diffusion.cpp releases to load untrusted .ckpt = model files could be vulnerable. The attack requires the victim or applicat= ion to load a .ckpt file from an untrusted source, such as a downloaded mod=
el from a model sharing site. This issue has been fixed in version master-5= 84-0a7ae07. If developers are unable to immediately update their applicatio= ns, they can work around this issue by ensuring they do not load .ckpt chec= kpoint files from untrusted sources. They should prefer trusted model sourc=
es and safer formats such as .safetensors where possible.</td> <td>2026-06-16</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47748" target=3D= "_blank" rel=3D"noopener">CVE-2026-47748</a></td>
</tr>
<td class=3D"vendor-product">leethompson--Lazy Content Slider Plugin</td> <td>WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request = forgery vulnerability that allows attackers to perform unauthorized actions=
by crafting malicious HTML forms. Attackers can trick authenticated admini= strators into submitting POST requests to the plugin settings page via lzcs= _admin.php to modify plugin configuration parameters like lzcs_color and lz= cs_count.</td>
<td>2026-06-15</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2016-20074" target=3D= "_blank" rel=3D"noopener">CVE-2016-20074</a></td>
</tr>
<td class=3D"vendor-product">legalweb--WP DSGVO Tools (GDPR)</td>
<td>The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authori= zation bypass in all versions up to, and including, 3.1.39. This is due to = the plugin not properly verifying that a user is authorized to perform an a= ction. This makes it possible for unauthenticated attackers to supply an ar= bitrary victim email address and trigger immediate SAR processing via the p= rocess_now and is_ajax parameters, receiving tokenized download links (zip_= link, pdf_link) in the HTTP response that expose the victim's personal data=
- including WordPress account details, comment author names, email address= es, IP addresses, and comment content - without any proof of ownership. The=
nonce used for the CSRF check is publicly rendered by the SAR shortcode fo=
rm and is shared across all anonymous visitors, meaning any unauthenticated=
attacker can trivially obtain a valid nonce and bypass this gate entirely.= </td>
<td>2026-06-19</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10034" target=3D= "_blank" rel=3D"noopener">CVE-2026-10034</a></td>
</tr>
<td class=3D"vendor-product">lemonldap-ng--lemonldap-ng</td>
<td>A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is =
an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Por= tal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing =
a manipulation of the argument url results in open redirect. The attack is = possible to be carried out remotely. The exploit is now public and may be u= sed. The vendor was contacted early about this disclosure but did not respo=
nd in any way.</td>
<td>2026-06-21</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12804" target=3D= "_blank" rel=3D"noopener">CVE-2026-12804</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>In libexpat before 2.8.2, there is a heap-based buffer overflow in doPr= olog in xmlparse.c because scaffold backing array reallocation is mishandle=
d when there is data-structure sharing across parsers.</td>
<td>2026-06-19</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56132" target=3D= "_blank" rel=3D"noopener">CVE-2026-56132</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 has an integer overflow in storeAtts.</td> <td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56403" target=3D= "_blank" rel=3D"noopener">CVE-2026-56403</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 has an integer overflow in addBinding.</td> <td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56404" target=3D= "_blank" rel=3D"noopener">CVE-2026-56404</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 has an integer overflow in getAttributeId.</td> <td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56405" target=3D= "_blank" rel=3D"noopener">CVE-2026-56405</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer becaus=
e it lacked a check that was present in XML_Parse.</td>
<td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56406" target=3D= "_blank" rel=3D"noopener">CVE-2026-56406</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 has an integer overflow in doProlog that is relat=
ed to storeEntityValue and entity textLen.</td>
<td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56407" target=3D= "_blank" rel=3D"noopener">CVE-2026-56407</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 has an integer overflow in copyString.</td> <td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56408" target=3D= "_blank" rel=3D"noopener">CVE-2026-56408</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>xmlwf in libexpat before 2.8.2 has an integer overflow for the output f= ilename when -d outputDir is used.</td>
<td>2026-06-21</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56409" target=3D= "_blank" rel=3D"noopener">CVE-2026-56409</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystem= Id.</td>
<td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56410" target=3D= "_blank" rel=3D"noopener">CVE-2026-56410</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDec=
l via NOTATION declarations.</td>
<td>2026-06-21</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56411" target=3D= "_blank" rel=3D"noopener">CVE-2026-56411</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 lacks handler call depth tracking for calls to XM= L_ResumeParser from within handlers in cases of a policy violation. Thus, a=
use-after-free can occur (similar to the CVE-2026-50219 situation).</td> <td>2026-06-19</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56131" target=3D= "_blank" rel=3D"noopener">CVE-2026-56131</a></td>
</tr>
<td class=3D"vendor-product">libexpat project--libexpat</td>
<td>libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSe= ction and thus lacks handler call depth tracking for various calls from wit= hin handlers in cases of a policy violation. Thus, a use-after-free can occ= ur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219= .</td>
<td>2026-06-21</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56412" target=3D= "_blank" rel=3D"noopener">CVE-2026-56412</a></td>
</tr>
<td class=3D"vendor-product">libssh2--libssh2</td>
<td>libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bou= nds heap read vulnerability in the sftp_symlink() function in src/sftp.c th=
at allows a malicious SSH server or man-in-the-middle attacker to disclose = heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME res= ponse. Attackers can supply a link_len value larger than the actual packet = data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, t= riggering a heap buffer over-read of up to target_len minus one bytes due t=
o the missing validation of available packet buffer size before the memcpy = operation.</td>
<td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15661" target=3D= "_blank" rel=3D"noopener">CVE-2025-15661</a></td>
</tr>
<td class=3D"vendor-product">libssh2--libssh2</td>
<td>libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authent= ication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in = src/packet.c that allows a malicious SSH server to cause a client CPU exhau= stion loop by sending a crafted extension count value. A malicious server c=
an set nr_extensions to 0xFFFFFFFF during key exchange, causing the client =
to spin in a tight CPU loop for over 60 seconds because return values from = _libssh2_get_string() are unchecked and the session timeout does not apply =
to CPU-bound loops.</td>
<td>2026-06-17</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55199" target=3D= "_blank" rel=3D"noopener">CVE-2026-55199</a></td>
</tr>
<td class=3D"vendor-product">Liquid Web / StellarWP--Event Tickets</td> <td>Unauthenticated Bypass Vulnerability in Event Tickets <=3D 5.27.5 ve= rsions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42662" target=3D= "_blank" rel=3D"noopener">CVE-2026-42662</a></td>
</tr>
<td class=3D"vendor-product">liseperu--Elizaibots</td>
<td>Contributor Cross Site Scripting (XSS) in Elizaibots <=3D 1.0.2 vers= ions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15659" target=3D= "_blank" rel=3D"noopener">CVE-2025-15659</a></td>
</tr>
<td class=3D"vendor-product">lsegal--yard</td>
<td>YARD is a documentation generation tool for the Ruby programming langua= ge. Prior to version 0.9.44, YARD's static cache lookup reads a request pat=
h before the router's path cleanup runs. When a server is configured with a=
document root, a traversal path such as `/../yard-cache-secret.html` is jo= ined against that root and can return a readable sibling `.html` file outsi=
de the intended static tree. Version 0.9.44 patches the issue.</td> <td>2026-06-19</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49342" target=3D= "_blank" rel=3D"noopener">CVE-2026-49342</a></td>
</tr>
<td class=3D"vendor-product">Mamunur Rashid--Classified Listing</td> <td>Unauthenticated Broken Access Control in Classified Listing <=3D 5.3=
.8 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42640" target=3D= "_blank" rel=3D"noopener">CVE-2026-42640</a></td>
</tr>
<td class=3D"vendor-product">Mamunur Rashid--Classified Listing</td> <td>Subscriber Broken Access Control in Classified Listing <=3D 5.3.9 ve= rsions.</td>
<td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42651" target=3D= "_blank" rel=3D"noopener">CVE-2026-42651</a></td>
</tr>
<td class=3D"vendor-product">marimo-team--marimo</td>
<td>marimo before 0.23.9 contains a reflected cross-site scripting vulnerab= ility in the notebook page that allows unauthenticated attackers to inject = arbitrary JavaScript by exploiting improper escaping of single quotes in th=
e file query parameter reflected into an inline JavaScript string literal. = Attackers can craft a malicious link with a payload beginning with __new__ =
to bypass the 404 check and inject JavaScript into the page, which executes=
without Content-Security-Policy restrictions in the origin of a victim's m= arimo server.</td>
<td>2026-06-17</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54386" target=3D= "_blank" rel=3D"noopener">CVE-2026-54386</a></td>
</tr>
<td class=3D"vendor-product">markdown-it--markdown-it</td>
<td>markdown-it is a Markdown parser. Versions 14.1.1 and below contain a d= enial-of-service vulnerability when typographer: true is enabled, due to qu= adratic (O(n^2)) processing in the smartquotes rule. The issue stems from r= epeatedly modifying strings with replaceAt(), which performs O(n) slicing a=
nd concatenation per quote character. This can cause excessive CPU consumpt= ion when parsing quote-heavy, user-supplied markdown and may let attackers = degrade or disrupt service availability. Although typographer is disabled b=
y default, many production apps enable it for smart typography, making the = issue relevant. This issue has been fixed in version 14.2.0.</td> <td>2026-06-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48988" target=3D= "_blank" rel=3D"noopener">CVE-2026-48988</a></td>
</tr>
<td class=3D"vendor-product">MarketingFire--Widget Options</td>
<td>Insertion of sensitive information into sent data vulnerability in Mark= etingFire Widget Options allows Retrieve Embedded Sensitive Data. This issu=
e affects Widget Options: from n/a through 4.0.1.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-35690" target=3D= "_blank" rel=3D"noopener">CVE-2024-35690</a></td>
</tr>
<td class=3D"vendor-product">Mattermost--Mattermost</td>
<td>Mattermost Desktop App versions <=3D6.1 5.5.13.0 fail to restrict th=
e allow list of domains to which NTLM credentials were forwarded to in the = Mattermost Desktop App which allows any user on a server without the image = proxy enabled to intercept other users credentials via embedding an image t= hat routes to an external web server. Mattermost Advisory ID: MMSA-2026-006= 51</td>
<td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6517" target=3D"= _blank" rel=3D"noopener">CVE-2026-6517</a></td>
</tr>
<td class=3D"vendor-product">Mattermost--Mattermost</td>
<td>Mattermost Desktop App versions <=3D6.1 5.5.13.0 fail to account for=
attempting to open extremely long URLs in the Mattermost Desktop App which=
allows a malicious server owner to crash the application via including a s= cript to call window.open on a very large URL. Mattermost Advisory ID: MMSA= -2026-00652</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8683" target=3D"= _blank" rel=3D"noopener">CVE-2026-8683</a></td>
</tr>
<td class=3D"vendor-product">mbis--Permalink Manager Lite</td>
<td>The Permalink Manager Lite plugin for WordPress is vulnerable to Stored=
Cross-Site Scripting via post titles in the admin URI Editor interface in = all versions up to, and including, 2.5.3.3 due to insufficient output escap= ing. This makes it possible for authenticated attackers, with Contributor-l= evel access and above, to inject arbitrary web scripts in the admin Permali=
nk Manager page that will execute whenever an administrator accesses the Pe= rmalink Manager page.</td>
<td>2026-06-17</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8494" target=3D"= _blank" rel=3D"noopener">CVE-2026-8494</a></td>
</tr>
<td class=3D"vendor-product">mcdope--pam_usb</td>
<td>pam_usb provides hardware authentication for Linux using removable medi=
a. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION,=
DISPLAY and TMUX allow environment variable injection into local-check log= ic. These environment variables influence whether a current session is loca=
l or remote, and a PAM module that runs in the context of setuid binaries (= sudo, su), getenv() returns attacker-controlled values whenever the process=
environment has been manipulated by a local user. This issue has been fixe=
d in version 0.9.2.</td>
<td>2026-06-18</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48980" target=3D= "_blank" rel=3D"noopener">CVE-2026-48980</a></td>
</tr>
<td class=3D"vendor-product">mcdope--pam_usb</td>
<td>pam_usb provides hardware authentication for Linux using ordinary remov= able media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with fl= ags=3D0 when loading the configuration file, allowing libxml2 to process ex= ternal entity references (XXE), potentially making outbound network connect= ions or local file reads at XML parse time from the context of the authenti= cating process. The vulnerability requires the configuration file to contai=
n crafted XML entity references. Since pam_usb.conf is root-owned, direct e= xploitation requires prior write access to the config, but the defence-in-d= epth impact is significant given that pam_usb.so runs in setuid contexts (s= udo, su). This issue has been fixed in version 0.9.2.</td>
<td>2026-06-18</td>
<td>6.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48981" target=3D= "_blank" rel=3D"noopener">CVE-2026-48981</a></td>
</tr>
<td class=3D"vendor-product">mcdope--pam_usb</td>
<td>pam_usb provides hardware authentication for Linux using ordinary remov= able media. In versions prior to 0.9.2, when updating a one-time pad file, =
a temporary file is created using open() without the O_EXCL flag. Without O= _EXCL, the create operation is not atomic: two concurrent processes racing =
to update the same pad may both succeed in opening the file, with the secon=
d write silently overwriting the first. The one-time pad is the core replay= -prevention mechanism of pam_usb. A successful race could result in the sto= red pad value diverging from what either process expected, potentially caus= ing authentication failures or, in a precisely timed attack, creating a win= dow for pad reuse. This issue has been fixed in version 0.9.2.</td> <td>2026-06-18</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48982" target=3D= "_blank" rel=3D"noopener">CVE-2026-48982</a></td>
</tr>
<td class=3D"vendor-product">mcdope--pam_usb</td>
<td>pam_usb provides hardware authentication for Linux using ordinary remov= able media. In versions prior to 0.9.2, a symlink race condition exists in = per-device and per-user pad directory creation. pam_usb uses a check-then-a=
ct pattern: it calls lstat() to test for existence and then calls mkdir() s= eparately to create the directory. A local attacker can win the race betwee=
n these calls by replacing the target path with a symlink to a directory th=
ey control. If successful, one-time pad files may be written to an attacker= -controlled location, potentially exposing future pad values before use or = disrupting authentication. This issue has been fixed in version 0.9.2.</td> <td>2026-06-18</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48983" target=3D= "_blank" rel=3D"noopener">CVE-2026-48983</a></td>
</tr>
<td class=3D"vendor-product">mcdope--pam_usb</td>
<td>pam_usb provides hardware authentication for Linux using ordinary remov= able media. In versions 0.9.1 and below, pusb_is_loginctl_local() can cause=
a NULL dereference crash when parsing loginctl output. The function calls = popen() and reads the result; if the Remote field is only a newline, fgets(=
) succeeds but strtok_r(buf, "\n", &saveptr) returns NULL. A subsequent=
strcmp(is_remote, "no") then dereferences NULL, causing undefined behavior=
(typically SIGSEGV) and crashing the PAM module. This can crash the authen= ticating process (e.g., sudo, login) and, depending on PAM stack configurat= ion, deny access for all users of the affected service. This issue has been=
fixed in version 0.9.2.</td>
<td>2026-06-18</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48985" target=3D= "_blank" rel=3D"noopener">CVE-2026-48985</a></td>
</tr>
<td class=3D"vendor-product">mcdope--pam_usb</td>
<td>pam_usb provides hardware authentication for Linux using ordinary remov= able media. In versions 0.9.1 and below, the xfree() memory release helper =
in calls free() without first zeroing the buffer contents, releasing heap-a= llocated buffers containing sensitive data - including one-time pad bytes r= ead from disk - without clearing, leaving the sensitive content in freed he=
ap memory until it happens to be overwritten by a subsequent allocation. On=
a system where a use-after-free condition exists, or where a heap inspecti=
on primitive becomes available, this could allow recovery of pad values or = other authentication material from freed memory regions. This is a defence-= in-depth requirement consistent with prior hardening work in this codebase = (GHSA-vx6f-rrqr-j87c applied explicit_bzero to some pad paths; this issue g= eneralises the pattern to the central deallocation helper).</td> <td>2026-06-18</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48984" target=3D= "_blank" rel=3D"noopener">CVE-2026-48984</a></td>
</tr>
<td class=3D"vendor-product">mcdope--pam_usb</td>
<td>pam_usb provides hardware authentication for Linux using removable medi=
a. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an i= nfinite loop DoS because it does not initialize *ppid on failure. In pusb_l= ocal_login(), the same variable is reused as input and output in a process-= tree while loop; if /proc/<pid>/stat cannot be read (for example, whe=
n an ancestor process exits during authentication), the PID is not updated = and the loop does not terminate. This hangs the authenticating process (suc=
h as sudo, sshd, or login) until it is forcibly terminated. This issue has = been fixed in version 0.9.2.</td>
<td>2026-06-18</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48986" target=3D= "_blank" rel=3D"noopener">CVE-2026-48986</a></td>
</tr>
<td class=3D"vendor-product">medkey-org--medkey</td>
<td>A security flaw has been discovered in medkey-org medkey up to fc09b7ba= 9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatient= ById of the file app\modules\medical\port\rest\controllers\PatientControlle= r.php of the component HTTP REST API. The manipulation of the argument ID r= esults in improper control of resource identifiers. The attack may be perfo= rmed from remote. The exploit has been released to the public and may be us=
ed for attacks. This product utilizes a rolling release system for continuo=
us delivery, and as such, version information for affected or updated relea= ses is not disclosed. The vendor was contacted early about this disclosure = but did not respond in any way.</td>
<td>2026-06-15</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12207" target=3D= "_blank" rel=3D"noopener">CVE-2026-12207</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--GitHub Copilot Chat</td> <td>Initialization of a resource with an insecure default in GitHub Copilot=
and Visual Studio Code allows an unauthorized attacker to disclose informa= tion over a network.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50519" target=3D= "_blank" rel=3D"noopener">CVE-2026-50519</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft 365 Copilot</td>
<td>Improper neutralization of special elements used in a command ('command=
injection') in Microsoft Copilot allows an unauthorized attacker to perfor=
m tampering over a network.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42895" target=3D= "_blank" rel=3D"noopener">CVE-2026-42895</a></td>
</tr>
<td class=3D"vendor-product">mohammadtanzilurrahman--Static Block</td>
<td>The Static Block plugin for WordPress is vulnerable to Insecure Direct = Object Reference in all versions up to, and including, 2.2. This is due to = the static_block_content() shortcode handler retrieving a post via get_post=
() using an attacker-supplied 'id' attribute and outputting its post_conten=
t without verifying the post's status (private, draft, pending) or the requ= esting user's capability to view it. This makes it possible for authenticat=
ed attackers, with contributor-level access and above, to read the contents=
of arbitrary posts, including private and draft static blocks (and any oth=
er post type) created by administrators, by embedding the [static_block_con= tent id=3D"X"] shortcode in their own content and previewing it.</td> <td>2026-06-16</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10780" target=3D= "_blank" rel=3D"noopener">CVE-2026-10780</a></td>
</tr>
<td class=3D"vendor-product">Mojoomla--School Management</td> <td>Unauthenticated Insecure Direct Object References (IDOR) in School Mana= gement <=3D 93.1.0 versions.</td>
<td>2026-06-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15657" target=3D= "_blank" rel=3D"noopener">CVE-2025-15657</a></td>
</tr>
<td class=3D"vendor-product">mojoomla--WPAMS</td>
<td>Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.</t=
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39433" target=3D= "_blank" rel=3D"noopener">CVE-2026-39433</a></td>
</tr>
<td class=3D"vendor-product">Montodel--House-Rental-Management</td>
<td>A flaw has been found in Montodel House-Rental-Management up to 9001001= 7b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file=
/index.php?page=3Dhouses. This manipulation of the argument ID causes sql = injection. The attack is possible to be carried out remotely. The exploit h=
as been published and may be used. This product adopts a rolling release st= rategy to maintain continuous delivery. Therefore, version details for affe= cted or updated releases cannot be specified. The vendor was contacted earl=
y about this disclosure but did not respond in any way.</td> <td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12776" target=3D= "_blank" rel=3D"noopener">CVE-2026-12776</a></td>
</tr>
<td class=3D"vendor-product">mra13 / Team Tips and Tricks HQ--Stripe Paymen= ts</td>
<td>Unauthenticated Bypass Vulnerability in Stripe Payments <=3D 2.0.98 = versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42752" target=3D= "_blank" rel=3D"noopener">CVE-2026-42752</a></td>
</tr>
<td class=3D"vendor-product">multer--multer</td>
<td>Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 a=
re vulnerable to a Denial of Service when using diskStorage. Aborted or mal= formed multipart uploads leave orphaned partial files on disk because the R= eadable.pipe() call does not propagate the stream destroy signal to the und= erlying fs.WriteStream. An attacker can exhaust disk space by triggering ma=
ny aborted uploads, with no application bug required. Patches: Users should=
upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both=
versions track in-flight write streams and clean them up on the abort path=
. Workarounds: None.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5038" target=3D"= _blank" rel=3D"noopener">CVE-2026-5038</a></td>
</tr>
<td class=3D"vendor-product">myCred--Bookify</td>
<td>Subscriber Broken Access Control in Bookify <=3D 1.1.1 versions.</td=
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-69332" target=3D= "_blank" rel=3D"noopener">CVE-2025-69332</a></td>
</tr>
<td class=3D"vendor-product">myCred--myCred</td>
<td>Subscriber Broken Access Control in myCred <=3D 3.0.3 versions.</td> <td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40794" target=3D= "_blank" rel=3D"noopener">CVE-2026-40794</a></td>
</tr>
<td class=3D"vendor-product">Nasir Ahmed--Advanced Form Integration</td> <td>Subscriber Broken Access Control in Advanced Form Integration <=3D 1= .126.12 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42659" target=3D= "_blank" rel=3D"noopener">CVE-2026-42659</a></td>
</tr>
<td class=3D"vendor-product">nesquena--hermes-webui</td>
<td>Hermes WebUI before 0.51.443 contains a broken access control vulnerabi= lity in the /api/session endpoint that allows authenticated users to disclo=
se cross-profile session transcripts. Attackers can bypass profile boundary=
checks by directly querying session IDs belonging to other profiles via GE=
T /api/session?session_id=3D<foreign_id>&messages=3D1 to retrieve=
unauthorized conversation transcripts and metadata.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55197" target=3D= "_blank" rel=3D"noopener">CVE-2026-55197</a></td>
</tr>
<td class=3D"vendor-product">nesquena--hermes-webui</td>
<td>Hermes WebUI before 0.51.443 contains an authorization bypass vulnerabi= lity in the session export endpoint that allows authenticated users to acce=
ss sessions from other profiles. The _handle_session_export handler in api/= routes.py fails to verify active-profile ownership before serializing sessi=
on data, enabling attackers to exfiltrate foreign session transcripts by gu= essing or knowing session identifiers.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55198" target=3D= "_blank" rel=3D"noopener">CVE-2026-55198</a></td>
</tr>
<td class=3D"vendor-product">nesquena--hermes-webui</td>
<td>Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerabili=
ty in the unauthenticated POST /api/onboarding/oauth/start endpoint that al= lows unbounded accumulation of in-memory flow state and daemon threads. Att= ackers can send repeated or concurrent requests to exhaust server memory an=
d thread resources, potentially triggering repeated outbound device-code re= quests to upstream OAuth providers.</td>
<td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55205" target=3D= "_blank" rel=3D"noopener">CVE-2026-55205</a></td>
</tr>
<td class=3D"vendor-product">NI--grpc-device</td>
<td>There is an unchecked enum cast vulnerability in NI grpc-device BeginSi= debandStream that may allow an attacker to trigger invalid enum states and = undefined behavior, potentially resulting in a denial of service. Successfu=
l exploitation requires an attacker to supply a specially crafted message c= ontaining an out-of-range value. This affects NI grpc-device 2.17.0 and pri=
or versions.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48140" target=3D= "_blank" rel=3D"noopener">CVE-2026-48140</a></td>
</tr>
<td class=3D"vendor-product">NI--grpc-device</td>
<td>There is a memory leak in NI grpc-device BeginSidebandStream that may r= esult in denial of service due to memory exhaustion.=C2=A0 This affects NI = grpc-device 2.17.0 and prior versions.</td>
<td>2026-06-19</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48141" target=3D= "_blank" rel=3D"noopener">CVE-2026-48141</a></td>
</tr>
<td class=3D"vendor-product">nilfs-dev--nilfs-utils</td>
<td>NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_val= id() function fails to validate s_log_block_size field in NILFS2 superblock=
before bit-shift operations. Attackers supplying crafted NILFS2 images tri= gger undefined behavior through oversized shifts or out-of-memory condition=
s, crashing tools like nilfs-tune and dumpseg.</td>
<td>2026-06-18</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55392" target=3D= "_blank" rel=3D"noopener">CVE-2026-55392</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>Hermes Agent before 0.16.0 creates response_store.db and webhook_subscr= iptions.json with world-readable permissions (mode 0o644), exposing convers= ation history and HMAC secrets to local users. Attackers with local filesys= tem access can read these files directly to obtain sensitive data including=
conversation history, tool payloads, prompts, and per-route HMAC secrets.<=
<td>2026-06-17</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53870" target=3D= "_blank" rel=3D"noopener">CVE-2026-53870</a></td>
</tr>
<td class=3D"vendor-product">OceanWP--Ocean Product Sharing</td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored = XSS. This issue affects Ocean Product Sharing: from n/a through 2.2.2.</td> <td>2026-06-18</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56007" target=3D= "_blank" rel=3D"noopener">CVE-2026-56007</a></td>
</tr>
<td class=3D"vendor-product">OFFIS--DCMTK</td>
<td>A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element =
is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Ex= ecuting a manipulation can lead to heap-based buffer overflow. The attack m=
ay be performed from remote. The exploit has been published and may be used=
. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best=
practice to apply a patch to resolve this issue. The vendor was contacted = early, responded in a very professional manner and quickly released a fixed=
version of the affected product.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12805" target=3D= "_blank" rel=3D"noopener">CVE-2026-12805</a></td>
</tr>
<td class=3D"vendor-product">ollybach--WPPizza</td>
<td>Subscriber Sensitive Data Exposure in WPPizza <=3D 3.19.9 versions.<=
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40796" target=3D= "_blank" rel=3D"noopener">CVE-2026-40796</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenBSD</td>
<td>sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allow=
s authentication bypass via certain zero values for lengths.</td> <td>2026-06-17</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55706" target=3D= "_blank" rel=3D"noopener">CVE-2026-55706</a></td>
</tr>
<td class=3D"vendor-product">openbsd--src</td>
<td>OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds re=
ad vulnerability in the mpls_do_error function within sys/netmpls/mpls_inpu= t.c that allows remote attackers to disclose kernel stack memory by sending=
crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.</td> <td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56099" target=3D= "_blank" rel=3D"noopener">CVE-2026-56099</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability=
in exported session HTML that preserves unsafe javascript: and data: links=
in generated content. Attackers can execute browser-side scripts if a trus= ted operator opens the exported file and activates a malicious link.</td> <td>2026-06-16</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53841" target=3D= "_blank" rel=3D"noopener">CVE-2026-53841</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.4.29 contains a session visibility check bypass vu= lnerability in shared memory search that allows authenticated callers to ac= cess memory entries without proper authorization. Attackers can skip sessio=
n visibility guards on the search path to retrieve memory entries that shou=
ld not be visible to their session.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53844" target=3D= "_blank" rel=3D"noopener">CVE-2026-53844</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.4.25 contains a privilege escalation vulnerability=
in internal and webchat command authentication that allows senders to inhe= rit wildcard ownerAllowFrom state across channel boundaries. Attackers can = exploit this by sending commands on affected internal or webchat paths to e= xecute owner-style command behavior outside intended channel scope, potenti= ally bypassing access controls.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53854" target=3D= "_blank" rel=3D"noopener">CVE-2026-53854</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.26 contains a hostname validation vulnerability = allowing attackers to bypass blocklist comparisons using trailing-dot notat= ion in model or workspace-derived URLs. Attackers can exploit inconsistent = hostname checks to reach destinations that operators intended to block thro= ugh hostname policies.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53859" target=3D= "_blank" rel=3D"noopener">CVE-2026-53859</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in = the macOS Swift exec feature that misses combined POSIX inline-command flag=
s. Attackers can execute shell content outside the intended allowlist check=
by using combined flag forms, potentially allowing unauthorized command ex= ecution depending on operator configuration.</td>
<td>2026-06-16</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53861" target=3D= "_blank" rel=3D"noopener">CVE-2026-53861</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.6 contains a privilege escalation vulnerability =
in the Active Memory write scope that allows Gateway operators with operato= r.write access to modify global configuration without requiring operator.ad= min privileges. Attackers with operator.write access can exploit insufficie=
nt scope validation to apply unauthorized configuration changes beyond the = intended write scope.</td>
<td>2026-06-16</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53847" target=3D= "_blank" rel=3D"noopener">CVE-2026-53847</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.4.25 contains a control scope enforcement bypass v= ulnerability in the focus command that allows authenticated callers to exec= ute the command without proper authorization checks. Attackers can trigger = the focus command to change focus state outside intended caller authority, = potentially enabling unauthorized operations depending on gateway configura= tion and input trust levels.</td>
<td>2026-06-16</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53850" target=3D= "_blank" rel=3D"noopener">CVE-2026-53850</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.12 contains a notification bypass vulnerability = allowing Slack reaction events to enter the agent pipeline despite disabled=
reaction notifications. Attackers can trigger unintended agent processing =
by sending reaction events when the feature is enabled, potentially leading=
to unauthorized processing of lower-trust input.</td>
<td>2026-06-16</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53851" target=3D= "_blank" rel=3D"noopener">CVE-2026-53851</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.4.25 contains a scope containment bypass vulnerabi= lity in device re-pairing that allows authenticated operators to restore br= oader scopes than intended by submitting empty-scope re-pairing requests. A= ttackers can exploit this by sending re-pairing requests with empty scope s= ets to skip containment guards and retain unauthorized device access.</td> <td>2026-06-16</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53852" target=3D= "_blank" rel=3D"noopener">CVE-2026-53852</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissio=
ns vulnerability in config recovery that restores OpenClaw.json with overly=
broad permissions. Local attackers on shared hosts can read sensitive conf= iguration data by exploiting the recovery path to access the restored confi=
g file.</td>
<td>2026-06-16</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53856" target=3D= "_blank" rel=3D"noopener">CVE-2026-53856</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.6 contains a hook bypass vulnerability where ski=
ll commands routed through the affected dispatch path skip before-tool-call=
hook coverage. Attackers can exploit this by sending skill commands throug=
h the vulnerable dispatch path to bypass hook-based auditing and policy enf= orcement mechanisms.</td>
<td>2026-06-16</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53845" target=3D= "_blank" rel=3D"noopener">CVE-2026-53845</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerabili=
ty allowing authenticated operators to execute wrapper-level side effects o= utside allowlisted command intent. Attackers can craft command requests tha=
t bypass allowlist validation by leveraging transparent command wrappers to=
perform unintended operations.</td>
<td>2026-06-16</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53848" target=3D= "_blank" rel=3D"noopener">CVE-2026-53848</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability =
in BlueBubbles that allows participants to match allowlist entries through = conversation metadata rather than stable sender identity. Attackers can inf= luence conversation-level identifiers to receive agent responses intended f=
or configured senders, potentially bypassing access controls.</td> <td>2026-06-16</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53860" target=3D= "_blank" rel=3D"noopener">CVE-2026-53860</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerabili=
ty allowing callers with pending token access to reuse tokens with broader = requested scopes. Attackers can replay bootstrap tokens before approval to = escalate pairing authority beyond intended scope limits.</td> <td>2026-06-16</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53862" target=3D= "_blank" rel=3D"noopener">CVE-2026-53862</a></td>
</tr>
<td class=3D"vendor-product">OpenStack--Horizon</td>
<td>OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file = downloading that may have a crafted project name with shell metacharacters.=
NOTE: some parties consider this a security hardening opportunity to addre=
ss certain types of user error, not a vulnerability.</td>
<td>2026-06-17</td>
<td>6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55748" target=3D= "_blank" rel=3D"noopener">CVE-2026-55748</a></td>
</tr>
<td class=3D"vendor-product">OpenStack--Nova</td>
<td>In OpenStack Nova before 33.0.2, the server create API does not strip c= ertain hint data. The resulting instance has no Placement allocation.</td> <td>2026-06-16</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46448" target=3D= "_blank" rel=3D"noopener">CVE-2026-46448</a></td>
</tr>
<td class=3D"vendor-product">OPMC--WooCommerce Anti-Fraud</td> <td>Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <=3D=
7.2.6 versions.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49072" target=3D= "_blank" rel=3D"noopener">CVE-2026-49072</a></td>
</tr>
<td class=3D"vendor-product">OPMC--WooCommerce Dropshipping</td> <td>Unauthenticated Broken Authentication in WooCommerce Dropshipping <=
=3D 5.2.4 versions.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49071" target=3D= "_blank" rel=3D"noopener">CVE-2026-49071</a></td>
</tr>
<td class=3D"vendor-product">optimole--Optimole Optimize Images | Convert W= ebP & AVIF | CDN & Lazy Load | Image Optimization</td>
<td>The Optimole - Optimize Images | Convert WebP & AVIF | CDN & La=
zy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Si=
te Request Forgery in all versions up to, and including, 4.2.6. This is due=
to missing or incorrect nonce validation on the replace_file function. Thi=
s makes it possible for unauthenticated attackers to overwrite existing med=
ia attachments with attacker-supplied file content by supplying a forged mu= ltipart POST request targeting any attachment the victim has edit_post capa= bility over via a forged request granted they can trick a site administrato=
r into performing an action such as clicking on a link. The forged request = requires a victim with at least Author-level privileges, as the handler enf= orces a current_user_can('edit_post', $id) check; tricking an Author-level =
or higher user into clicking a crafted link is sufficient to trigger the ov= erwrite against attachments that user can edit.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11784" target=3D= "_blank" rel=3D"noopener">CVE-2026-11784</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Identity Manager</td> <td>Vulnerability in the Identity Manager product of Oracle Fusion Middlewa=
re (component: End User Self Service). Supported versions that are affected=
are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows una= uthenticated attacker with network access via IIOP to compromise Identity M= anager. Successful attacks of this vulnerability can result in unauthorized=
update, insert or delete access to some of Identity Manager accessible dat=
a as well as unauthorized read access to a subset of Identity Manager acces= sible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts)=
. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</td> <td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46810" target=3D= "_blank" rel=3D"noopener">CVE-2026-46810</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL Shell</td> <td>Vulnerability in the MySQL Shell product of Oracle MySQL (component: Sh= ell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 a=
nd 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated att= acker with network access via multiple protocols to compromise MySQL Shell.=
Successful attacks require human interaction from a person other than the = attacker. Successful attacks of this vulnerability can result in unauthoriz=
ed access to critical data or complete access to all MySQL Shell accessible=
data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVS= S:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46869" target=3D= "_blank" rel=3D"noopener">CVE-2026-46869</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--MySQL Shell</td> <td>Vulnerability in the MySQL Shell product of Oracle MySQL (component: Sh= ell for VS Code). The supported version that is affected is 2026.2.0+9.6.1.=
Easily exploitable vulnerability allows low privileged attacker with netwo=
rk access via multiple protocols to compromise MySQL Shell. Successful atta= cks of this vulnerability can result in unauthorized access to critical dat=
a or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Scor=
e 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N= /S:U/C:H/I:N/A:N).</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46871" target=3D= "_blank" rel=3D"noopener">CVE-2026-46871</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Access Manager</td> <td>Vulnerability in the Oracle Access Manager product of Oracle Fusion Mid= dleware (component: Authentication Engine). Supported versions that are aff= ected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allow=
s unauthenticated attacker with network access via HTTP to compromise Oracl=
e Access Manager. Successful attacks of this vulnerability can result in un= authorized update, insert or delete access to some of Oracle Access Manager=
accessible data as well as unauthorized read access to a subset of Oracle = Access Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality an=
d Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:= L/A:N).</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35261" target=3D= "_blank" rel=3D"noopener">CVE-2026-35261</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Access Manager</td> <td>Vulnerability in the Oracle Access Manager product of Oracle Fusion Mid= dleware (component: Authentication Engine). Supported versions that are aff= ected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allow=
s unauthenticated attacker with network access via HTTP to compromise Oracl=
e Access Manager. Successful attacks require human interaction from a perso=
n other than the attacker and while the vulnerability is in Oracle Access M= anager, attacks may significantly impact additional products (scope change)=
. Successful attacks of this vulnerability can result in unauthorized updat=
e, insert or delete access to some of Oracle Access Manager accessible data=
as well as unauthorized read access to a subset of Oracle Access Manager a= ccessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impa= cts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</td> <td>2026-06-16</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46812" target=3D= "_blank" rel=3D"noopener">CVE-2026-46812</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Application Develop= ment Framework (ADF)</td>
<td>Vulnerability in the Oracle Application Development Framework (ADF) pro= duct of Oracle Fusion Middleware (component: Security Framework). Supported=
versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitab=
le vulnerability allows unauthenticated attacker with network access via HT=
TP to compromise Oracle Application Development Framework (ADF). Successful=
attacks require human interaction from a person other than the attacker an=
d while the vulnerability is in Oracle Application Development Framework (A= DF), attacks may significantly impact additional products (scope change). S= uccessful attacks of this vulnerability can result in unauthorized update, = insert or delete access to some of Oracle Application Development Framework=
(ADF) accessible data as well as unauthorized read access to a subset of O= racle Application Development Framework (ADF) accessible data. CVSS 3.1 Bas=
e Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1= /AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</td>
<td>2026-06-16</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46770" target=3D= "_blank" rel=3D"noopener">CVE-2026-46770</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Application Develop= ment Framework (ADF)</td>
<td>Vulnerability in the Oracle Application Development Framework (ADF) pro= duct of Oracle Fusion Middleware (component: Java Business Objects). Suppor= ted versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to = exploit vulnerability allows high privileged attacker with logon to the inf= rastructure where Oracle Application Development Framework (ADF) executes t=
o compromise Oracle Application Development Framework (ADF). Successful att= acks of this vulnerability can result in unauthorized access to critical da=
ta or complete access to all Oracle Application Development Framework (ADF)=
accessible data. CVSS 3.1 Base Score 4.1 (Confidentiality impacts). CVSS V= ector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).</td>
<td>2026-06-16</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46771" target=3D= "_blank" rel=3D"noopener">CVE-2026-46771</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle Application Develop= ment Framework (ADF)</td>
<td>Vulnerability in the Oracle Application Development Framework (ADF) pro= duct of Oracle Fusion Middleware (component: ADF Faces). Supported versions=
that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vuln= erability allows high privileged attacker with logon to the infrastructure = where Oracle Application Development Framework (ADF) executes to compromise=
Oracle Application Development Framework (ADF). Successful attacks of this=
vulnerability can result in unauthorized access to critical data or comple=
te access to all Oracle Application Development Framework (ADF) accessible = data as well as unauthorized update, insert or delete access to some of Ora= cle Application Development Framework (ADF) accessible data. CVSS 3.1 Base = Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/A= V:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N).</td>
<td>2026-06-16</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46772" target=3D= "_blank" rel=3D"noopener">CVE-2026-46772</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: VMSVGA device). The supported version that is affected is 7= .2.8. Easily exploitable vulnerability allows high privileged attacker with=
logon to the infrastructure where Oracle VM VirtualBox executes to comprom= ise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBo=
x, attacks may significantly impact additional products (scope change). Suc= cessful attacks of this vulnerability can result in unauthorized ability to=
cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Vi= rtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVS= S:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).</td>
<td>2026-06-16</td>
<td>6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46768" target=3D= "_blank" rel=3D"noopener">CVE-2026-46768</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: VMSVGA device). The supported version that is affected is 7= .2.8. Easily exploitable vulnerability allows high privileged attacker with=
logon to the infrastructure where Oracle VM VirtualBox executes to comprom= ise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBo=
x, attacks may significantly impact additional products (scope change). Suc= cessful attacks of this vulnerability can result in unauthorized creation, = deletion or modification access to critical data or all Oracle VM VirtualBo=
x accessible data. CVSS 3.1 Base Score 6.0 (Integrity impacts). CVSS Vector=
: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N).</td>
<td>2026-06-16</td>
<td>6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46825" target=3D= "_blank" rel=3D"noopener">CVE-2026-46825</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: VMSVGA device). The supported version that is affected is 7= .2.8. Easily exploitable vulnerability allows high privileged attacker with=
logon to the infrastructure where Oracle VM VirtualBox executes to comprom= ise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBo=
x, attacks may significantly impact additional products (scope change). Suc= cessful attacks of this vulnerability can result in unauthorized access to = critical data or complete access to all Oracle VM VirtualBox accessible dat=
a. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.= 1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).</td>
<td>2026-06-16</td>
<td>6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46877" target=3D= "_blank" rel=3D"noopener">CVE-2026-46877</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle WebCenter Content</=
<td>Vulnerability in the Oracle WebCenter Content product of Oracle Fusion = Middleware (component: Content Server). The supported version that is affec= ted is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated = attacker with network access via HTTP to compromise Oracle WebCenter Conten=
t. Successful attacks of this vulnerability can result in unauthorized read=
access to a subset of Oracle WebCenter Content accessible data. CVSS 3.1 B= ase Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/P= R:N/UI:N/S:U/C:L/I:N/A:N).</td>
<td>2026-06-16</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46790" target=3D= "_blank" rel=3D"noopener">CVE-2026-46790</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--PeopleSoft Enterprise CS C= ampus Community</td>
<td>Vulnerability in the PeopleSoft Enterprise CS Campus Community product =
of Oracle PeopleSoft (component: Integration and Interfaces). The supported=
version that is affected is 9.2.38. Easily exploitable vulnerability allow=
s high privileged attacker with network access via HTTPS to compromise Peop= leSoft Enterprise CS Campus Community. Successful attacks of this vulnerabi= lity can result in unauthorized creation, deletion or modification access t=
o critical data or all PeopleSoft Enterprise CS Campus Community accessible=
data as well as unauthorized access to critical data or complete access to=
all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Ba=
se Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.= 1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46979" target=3D= "_blank" rel=3D"noopener">CVE-2026-46979</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--WebLogic Server</td> <td>Vulnerability in the WebLogic Server product of Oracle Fusion Middlewar=
e (component: Console). Supported versions that are affected are 14.1.2.0.0=
and 15.1.1.0.0. Difficult to exploit vulnerability allows high privileged = attacker with network access via HTTP to compromise WebLogic Server. Succes= sful attacks of this vulnerability can result in takeover of WebLogic Serve=
r. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability imp= acts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</td> <td>2026-06-16</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35291" target=3D= "_blank" rel=3D"noopener">CVE-2026-35291</a></td>
</tr>
<td class=3D"vendor-product">pgadmin.org--pgAdmin 4</td>
<td>Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA = validate and register endpoints honoured the user-supplied 'next' query/for=
m parameter without confirming the target pointed back inside pgAdmin, so a=
n authenticated victim who clicked /mfa/validate?next=3D<external> --=
a link typically delivered by phishing -- would be sent to an attacker-con= trolled host directly out of the trusted auth flow. The defect is a trusted= -domain redirect, not a privilege bypass: the attacker gains no read/write = access to pgAdmin or the victim's database, but the redirect launders the a= ttacker's destination through pgAdmin's URL, which raises the success rate =
of credential-phishing follow-on against the victim. Fix introduces a same-= origin _is_safe_redirect_url helper and gates every MFA redirect that consu= mes user-supplied 'next' values through it. The helper allows only relative=
paths and absolute URLs whose scheme is http(s) and whose host matches the=
current request host; it rejects external hosts in absolute and protocol-r= elative form, non-http schemes (javascript:, data:, mailto:), userinfo tric=
ks (
http://localhost@attacker/), and backslash variants that some browsers = normalize to forward slashes. Unsafe targets fall back to the internal brow= ser index. A dedicated regression test exercises each accept/reject categor=
y and the original reporter PoC. This issue affects pgAdmin 4: from 6.0 bef= ore 9.16.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12049" target=3D= "_blank" rel=3D"noopener">CVE-2026-12049</a></td>
</tr>
<td class=3D"vendor-product">pgadmin.org--pgAdmin 4</td>
<td>SQL injection in pgAdmin 4's named restore point endpoint (POST /browse= r/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was in= terpolated directly into the SQL string with str.format() instead of being = passed as a bound parameter, allowing an authenticated pgAdmin user with a = connected PostgreSQL session to inject additional statements through that e= ndpoint. The injected SQL executes under the database role the user is alre= ady authenticated as. The defect does not cross a privilege boundary -- the=
user already has direct SQL access to that role through the Query Tool -- =
so the attacker gains no capability beyond what their database role already=
grants them. The marginal impact accounts for the fact that the injection = path is not the documented SQL-execution interface, so a deployment that ga= tes the Query Tool at the application layer could see SQL executed through =
a path it did not anticipate. Fix passes the restore point name as a bound = parameter and schema-qualifies the function call as pg_catalog.pg_create_re= store_point so a non-default search_path on the connection cannot redirect = the call to a shadow definition. A regression test asserts the value arrive=
s as a bound parameter and not spliced into the SQL string. This issue affe= cts pgAdmin 4: from 1.0 before 9.16.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12050" target=3D= "_blank" rel=3D"noopener">CVE-2026-12050</a></td>
</tr>
<td class=3D"vendor-product">phppoet--SysBasics Customize My Account for Wo= oCommerce Dashboard, Endpoints, Avatar & Menu Manager</td>
<td>The Customize My Account For Woocommerce plugin for WordPress is vulner= able to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortco=
de in versions up to, and including, 4.3.6. This is due to insufficient inp=
ut sanitization and output escaping on user supplied attributes (min_height=
, min_width, max_height, max_width) in the wcmamtx_get_avatar_default() fun= ction, which are concatenated unescaped into the get_avatar() extra_attr st= yle attribute. This makes it possible for authenticated attackers, with Con= tributor-level access and above, to inject arbitrary web scripts in pages t= hat will execute whenever a user accesses an injected page.</td> <td>2026-06-18</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12136" target=3D= "_blank" rel=3D"noopener">CVE-2026-12136</a></td>
</tr>
<td class=3D"vendor-product">phppoet--SysBasics Customize My Account for Wo= oCommerce Dashboard, Endpoints, Avatar & Menu Manager</td>
<td>The SysBasics Customize My Account for WooCommerce - Dashboard, Endpoin= ts, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflect=
ed Cross-Site Scripting via the 'tab' parameter in all versions up to, and = including, 4.3.6 due to insufficient input sanitization and output escaping=
. This makes it possible for unauthenticated attackers to inject arbitrary = web scripts in pages that execute if they can successfully trick a user int=
o performing an action such as clicking on a link. Because the vulnerable p= lugin_options_page() function is only rendered within the WordPress admin d= ashboard, successful exploitation requires the targeted victim to be logged=
in with Shop Manager-level access or higher.</td>
<td>2026-06-18</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12137" target=3D= "_blank" rel=3D"noopener">CVE-2026-12137</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 1.0.1 contains an unsafe pickle deserialization vulne= rability allowing unauthenticated attackers to create arbitrary zero-byte f= iles via logging.FileHandler class instantiation. Attackers can exploit thi=
s by crafting malicious pickle payloads to bypass RCE blocklists and create=
lock files or other filesystem artifacts, potentially causing denial of se= rvice or application disruption.</td>
<td>2026-06-20</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56304" target=3D= "_blank" rel=3D"noopener">CVE-2026-56304</a></td>
</tr>
<td class=3D"vendor-product">pontedilana--php-weasyprint</td>
<td>PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an=
HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` fetches th=
e content of option values server-side via `file_get_contents()` when the v= alue looks like a URL, without restricting the URL scheme. The `attachment`=
option of `Pdf` is the reachable sink: any value that passes `isOptionUrl(=
)` (`filter_var(..., FILTER_VALIDATE_URL)`) is downloaded by the PHP proces=
s and embedded into the generated PDF. Because `FILTER_VALIDATE_URL` accept=
s `http`, `https`, `ftp`, `file` and PHP stream wrappers such as `php://`, =
an attacker who can influence the `attachment` value reaches both a **Serve= r-Side Request Forgery** primitive (e.g. internal HTTP endpoints, cloud met= adata) and a local file disclosure primitive (`file://`, `php://filter/...`=
), with the fetched bytes exfiltrated as a PDF attachment. This is the same=
class of issue KnpLabs/snappy patched for its `xsl-style-sheet` option in = GHSA-c5fp-p67m-gq56. The library is documented as a one-to-one substitute f=
or KnpLabs/snappy and shares the same code shape. PhpWeasyPrint version 2.6=
.0 contains a patch for the issue.</td>
<td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49359" target=3D= "_blank" rel=3D"noopener">CVE-2026-49359</a></td>
</tr>
<td class=3D"vendor-product">PraisonAI--PraisonAI</td>
<td>PraisonAI before 1.5.115 contains an information disclosure vulnerabili=
ty in the MultiAgentLedger component that allows attackers to access sensit= ive data by registering agents with duplicate IDs. Attackers can exploit th=
e lack of agent ID uniqueness enforcement to share ledger instances and exp= ose system prompts and conversation history between agents.</td> <td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56077" target=3D= "_blank" rel=3D"noopener">CVE-2026-56077</a></td>
</tr>
<td class=3D"vendor-product">PraisonAI--PraisonAI</td>
<td>PraisonAI before 1.5.128 caches tool approval decisions by tool name on= ly, not by invocation arguments, allowing subsequent execute_command calls =
to bypass approval prompts. Attackers can exploit this by obtaining initial=
approval for a benign command, then silently exfiltrate API keys and crede= ntials via subsequent shell commands without user consent.</td> <td>2026-06-18</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56074" target=3D= "_blank" rel=3D"noopener">CVE-2026-56074</a></td>
</tr>
<td class=3D"vendor-product">pressprimer--PressPrimer Quiz AI Quiz Maker, E= xam Builder & LMS Assessment Plugin</td>
<td>The PressPrimer Quiz - AI Quiz Maker, Exam Builder & LMS Assessment=
Plugin plugin for WordPress is vulnerable to Insecure Direct Object Refere= nce in all versions up to, and including, 2.3.0 via the 'rule_id' parameter=
due to missing validation on a user controlled key. This makes it possible=
for authenticated attackers, with custom-level access and above, to modify=
or delete quiz rules belonging to other teachers, resulting in unauthorize=
d tampering of another user's quiz structure.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10623" target=3D= "_blank" rel=3D"noopener">CVE-2026-10623</a></td>
</tr>
<td class=3D"vendor-product">properfraction--ProfilePress</td>
<td>Subscriber Cross Site Scripting (XSS) in ProfilePress <=3D 4.16.13 v= ersions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41556" target=3D= "_blank" rel=3D"noopener">CVE-2026-41556</a></td>
</tr>
<td class=3D"vendor-product">purethemes--WorkScout-Core</td> <td>Unauthenticated Arbitrary File Deletion in WorkScout-Core <=3D 1.7.1=
1 versions.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52716" target=3D= "_blank" rel=3D"noopener">CVE-2026-52716</a></td>
</tr>
<td class=3D"vendor-product">pydantic--pydantic-ai</td>
<td>Pydantic AI is a Python agent framework for building applications and w= orkflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, a=
nd 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the = metadata IP in an IPv6 transition form that the previous fix, CVE-2026-4667=
8, did not decode, exposing cloud IAM short-term credentials. The previous = remediation decoded only IPv4-mapped IPv6, 6to4, and the NAT64 well-known p= refix, so the metadata guarantee did not hold for the remaining transition = forms: IPv4-compatible IPv6 (::a.b.c.d), the NAT64 RFC 8215 local-use prefi=
x (64:ff9b:1::/48), operator-chosen NAT64 prefixes, and ISATAP. The IPv6 wr= apper is then delivered to the underlying IPv4 metadata endpoint. This occu=
rs when an application using Pydantic AI opts a URL into force_download=3D'= allow-local' (which disables the default block on private/internal IPs) and=
runs on a network that actually routes the affected IPv6 transition forms:=
NAT64-configured networks (IPv6-only or dual-stack-with-NAT64 deployments,=
including some Kubernetes setups) for the NAT64 variants, or networks with=
an ISATAP tunnel for ISATAP. A standard dual-stack cloud VM or container d= oes not route these forms and is not affected in practice. The IPv4-compati= ble and Teredo variants are deprecated and addressed as defense-in-depth. T= his is an incomplete fix of GHSA-cqp8-fcvh-x7r3 / CVE-2026-46678 (itself a = follow-up to CVE-2026-25580). This issue has been fixed in version 2.0.0b3.= </td>
<td>2026-06-16</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48782" target=3D= "_blank" rel=3D"noopener">CVE-2026-48782</a></td>
</tr>
<td class=3D"vendor-product">Rain-Task Ltd.--WPBakery Page Builder</td> <td>Subscriber Broken Access Control in WPBakery Page Builder <=3D 8.7.2=
versions.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45436" target=3D= "_blank" rel=3D"noopener">CVE-2026-45436</a></td>
</tr>
<td class=3D"vendor-product">Rank Math SEO--Rank Math SEO</td>
<td>Subscriber Broken Access Control in Rank Math SEO <=3D 1.0.271 versi= ons.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34892" target=3D= "_blank" rel=3D"noopener">CVE-2026-34892</a></td>
</tr>
<td class=3D"vendor-product">Rara Themes--Metro Magazine</td>
<td>Missing Authorization vulnerability in Rara Themes Metro Magazine allow=
s Exploiting Incorrectly Configured Access Control Security Levels. This is= sue affects Metro Magazine: from n/a through 1.4.1.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40809" target=3D= "_blank" rel=3D"noopener">CVE-2026-40809</a></td>
</tr>
<td class=3D"vendor-product">Rara Themes--Metro Magazine</td>
<td>Missing Authorization vulnerability in Rara Themes Metro Magazine allow=
s Exploiting Incorrectly Configured Access Control Security Levels. This is= sue affects Metro Magazine: from n/a through 1.3.7.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-37496" target=3D= "_blank" rel=3D"noopener">CVE-2024-37496</a></td>
</tr>
<td class=3D"vendor-product">Really Simple Plugins B.V.--Really Simple SSL<=
<td>Subscriber Broken Access Control in Really Simple SSL <=3D 9.5.9 ver= sions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48969" target=3D= "_blank" rel=3D"noopener">CVE-2026-48969</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat AI Inference Server</td>
<td>A flaw was found in vLLM, an open-source library for large language mod=
el inference. This vulnerability arises from improper handling of image met= adata, specifically EXIF orientation and PNG transparency (tRNS) data, duri=
ng image processing. When images are converted to RGB, transparency informa= tion may be implicitly discarded or remapped, leading to unexpected renderi=
ng of transparent pixels and distortion of input content. This can result i=
n the model misinterpreting image content, potentially affecting the integr= ity of processed data.</td>
<td>2026-06-17</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12491" target=3D= "_blank" rel=3D"noopener">CVE-2026-12491</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Ansible Automation Platform 2= </td>
<td>A flaw was found in the AWX GitHub webhook integration. When processing=
GitHub pull_request webhooks, the controller stores the pull_request.statu= ses_url value from the webhook payload without validating that it points to=
a trusted GitHub API endpoint. If a job template is configured with a GitH=
ub Personal Access Token as its webhook credential, the controller later PO= STs that token to the stored callback URL when posting job status updates. =
An attacker who can submit a correctly signed forged webhook using the job = template's webhook_key can redirect the callback to an attacker-controlled = URL and exfiltrate the configured GitHub PAT.</td>
<td>2026-06-19</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12726" target=3D= "_blank" rel=3D"noopener">CVE-2026-12726</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Ansible Automation Platform 2= .7</td>
<td>A flaw was found in Ansible Lightspeed. This vulnerability, related to = insufficient session expiration, allows a remote attacker to maintain persi= stent access to the Ansible Lightspeed instance. If an attacker exfiltrates=
a valid OAuth (Open Authorization) access token before a user logs out, th=
ey can continue to authenticate and access sensitive data. This is because = the application fails to invalidate the token on the backend, leaving it va= lid until its natural expiration. This can lead to unauthorized read access=
to Ansible resources such as inventories, playbooks, and configuration dat= a.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44188" target=3D= "_blank" rel=3D"noopener">CVE-2026-44188</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Directory Server 11</td>
<td>A flaw was found in 389 Directory Server. During schema reload, the att= r_syntax_swap_ht() function unconditionally frees attribute syntax informat= ion nodes, bypassing the refcount-based deferred deletion used elsewhere in=
the attribute syntax subsystem. If an administrator triggers schema reload=
while concurrent LDAP query traffic is active, worker threads may access f= reed memory, resulting in use-after-free or double-free and a denial of ser= vice (server crash).</td>
<td>2026-06-18</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11791" target=3D= "_blank" rel=3D"noopener">CVE-2026-11791</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Directory Server 11</td>
<td>A flaw was found in 389 Directory Server in the __aclp__normalize_acltx= t() function of aclparse.c. A malformed ACI (Access Control Instruction) st= ring can trigger heap-buffer-overflow writes and reads during ACI parsing. = The function fails to validate that the ACI keyword has sufficient length a= fter whitespace stripping, leading to a 1-byte out-of-bounds write and subs= equent out-of-bounds reads. An authenticated user with write access to the = aci attribute could send a crafted ACI value to silently corrupt heap memor=
y in the directory server process.</td>
<td>2026-06-17</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12528" target=3D= "_blank" rel=3D"noopener">CVE-2026-12528</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function,=
used for changing the Security Officer PIN, can lead to a use-after-free v= ulnerability. This occurs when an attacker attempts to change the PIN with =
a NULL old PIN for a token that lacks a protected authentication path.</td> <td>2026-06-16</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42014" target=3D= "_blank" rel=3D"noopener">CVE-2026-42014</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A denial of service vulnerability was found in GStreamer's AV1 codec pa= rser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function = passes a byte count to a bit-reader API that expects a bit count, causing p= arser desynchronization. A remote attacker could trick a user into opening =
a specially crafted AV1 media file, triggering an assertion abort and causi=
ng the application to crash.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52718" target=3D= "_blank" rel=3D"noopener">CVE-2026-52718</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in GNOME localsearch (previously known as tracker-mine= rs) MP3 Extractor. When processing specially crafted MP3 files containing I= D3v2.4 tags, a missing bounds check in the `extract_performers_tags` functi=
on can lead to a heap buffer overflow. This vulnerability allows a remote a= ttacker to cause a Denial of Service (DoS) by triggering a read of unmapped=
memory. In some cases, it could also lead to information disclosure by rea= ding visible heap data.</td>
<td>2026-06-16</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1764" target=3D"= _blank" rel=3D"noopener">CVE-2026-1764</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in the `tracker-extract-mp3` component of GNOME locals= earch (previously known as tracker-miners). This vulnerability, a heap buff=
er overflow, occurs when processing specially crafted MP3 files. A remote a= ttacker could exploit this by providing a malicious MP3 file, leading to a = Denial of Service (DoS) where the application crashes. It may also potentia= lly expose sensitive information from the system's memory.</td> <td>2026-06-16</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1765" target=3D"= _blank" rel=3D"noopener">CVE-2026-1765</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in GNOME localsearch (previously known as tracker-mine= rs) MP3 Extractor, specifically within the tracker-extract-mp3 component. T= his heap buffer overflow vulnerability occurs when processing specially cra= fted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacke=
r could exploit this by providing a malicious MP3 file, leading to a denial=
of service (DoS), which causes an application crash, and potentially discl= osing sensitive information from the heap memory.</td>
<td>2026-06-16</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1766" target=3D"= _blank" rel=3D"noopener">CVE-2026-1766</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in the GNOME localsearch (previously known as tracker-= miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker co= uld exploit this heap buffer overflow vulnerability by providing a speciall=
y crafted MP3 file containing malformed ID3 tags. This incorrect length cal= culation during the parsing of performer tags can lead to a read beyond the=
allocated buffer, potentially causing a Denial of Service (DoS) due to a c= rash or enabling information disclosure.</td>
<td>2026-06-16</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1767" target=3D"= _blank" rel=3D"noopener">CVE-2026-1767</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in libXpm. A local user with low privileges could expl= oit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by = processing a specially crafted or very small XPM (X PixMap) image file. Thi=
s improper validation of file boundaries can cause an internal pointer to r= ead beyond the file's end, leading to application crashes and Denial of Ser= vice conditions.</td>
<td>2026-06-16</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4367" target=3D"= _blank" rel=3D"noopener">CVE-2026-4367</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td> <td>Multiple out-of-bounds read vulnerabilities were found in GStreamer's p= capparse element. Malformed PCAP records can trigger reads beyond buffer bo= undaries during IPv4/TCP header parsing. This element is primarily used in = debugging pipelines, limiting real-world exposure. A local attacker could t= rick a user into processing a specially crafted PCAP file, potentially lead= ing to a crash or information disclosure.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52721" target=3D= "_blank" rel=3D"noopener">CVE-2026-52721</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux AI (RHEL AI)=
3</td>
<td>A use-after-free vulnerability was found in FFmpeg's RASC video decoder=
. The decode_move() function initializes a read pointer into a decompressed=
buffer, but a subsequent reallocation of that same buffer during move-tabl=
e processing leaves the pointer dangling. An attacker could exploit this by=
providing a specially crafted AVI file containing a malicious RASC video s= tream. When a user opens or plays the file, the decoder reads from freed he=
ap memory, which could lead to a denial of service (crash).</td> <td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12706" target=3D= "_blank" rel=3D"noopener">CVE-2026-12706</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Hardened Images</td>
<td>A flaw was found in Katello's of Red Hat Satellite. A content upload fu= nctionality where insufficient authorization checks in the ContentUploadsCo= ntroller allowed users with the edit_products permission to query content i= nformation for repositories outside the products they were authorized to ma= nage. An authenticated attacker could exploit this issue to determine wheth=
er specific content exists within repositories that should otherwise be ina= ccessible. This issue does not allow unauthorized modification, import, or = publication of content.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12515" target=3D= "_blank" rel=3D"noopener">CVE-2026-12515</a></td>
</tr>
<td class=3D"vendor-product">RelyWP--Simple Cloudflare Turnstile</td> <td>Unauthenticated Broken Authentication in Simple Cloudflare Turnstile &l= t;=3D 1.38.0 versions.</td>
<td>2026-06-15</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40799" target=3D= "_blank" rel=3D"noopener">CVE-2026-40799</a></td>
</tr>
<td class=3D"vendor-product">rewish--WP Emmet</td>
<td>Administrator Cross Site Scripting (XSS) in WP Emmet <=3D 0.3.4 vers= ions.</td>
<td>2026-06-15</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15658" target=3D= "_blank" rel=3D"noopener">CVE-2025-15658</a></td>
</tr>
<td class=3D"vendor-product">rocklobsterinc--Bogo</td>
<td>The Bogo plugin for WordPress is vulnerable to Sensitive Information Ex= posure in all versions up to, and including, 3.9.1 via the bogo_rest_create= _post_translation. This makes it possible for authenticated attackers, with=
subscriber-level access and above, to extract the raw title, content, exce= rpt, and password of any private, draft, or password-protected post by trig= gering its duplication via the translation endpoint and reading the returne=
d title.raw, content.raw, and excerpt.raw fields of the duplicated post. Th=
is vulnerability is exploitable against posts written in a non-default loca= le, as authenticated subscribers can request a translation into the site's = default locale to pass the locale-only permission gate. While subscribers c=
an trigger the endpoint, this is only impactful at the Contributor-level as=
they can actually read the duplicated content.</td>
<td>2026-06-19</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9013" target=3D"= _blank" rel=3D"noopener">CVE-2026-9013</a></td>
</tr>
<td class=3D"vendor-product">rometheme--RTMKit</td>
<td>The RTMKit plugin for WordPress is vulnerable to Incorrect Authorizatio=
n in all versions up to, and including, 2.0.7 This is due to the get_submis= sion_content AJAX endpoint lacking a capability check to verify that a user=
has permission to access the requested form submission data. This makes it=
possible for authenticated attackers, with Contributor-level access and ab= ove, to view arbitrary form submissions from other users by iterating the e= ntries_id parameter.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5149" target=3D"= _blank" rel=3D"noopener">CVE-2026-5149</a></td>
</tr>
<td class=3D"vendor-product">rtCamp Inc.--rtMedia for WordPress, BuddyPress=
and bbPress</td>
<td>Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress a=
nd bbPress <=3D 4.7.9 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40773" target=3D= "_blank" rel=3D"noopener">CVE-2026-40773</a></td>
</tr>
<td class=3D"vendor-product">RubyLouvre--avalon</td>
<td>A security vulnerability has been detected in RubyLouvre avalon up to 2= .2.10. The impacted element is an unknown function of the file src/filters/= index.js of the component Template Filter Handler. Such manipulation leads =
to improperly controlled modification of object prototype attributes. It is=
possible to launch the attack remotely. The exploit has been disclosed pub= licly and may be used. The vendor was contacted early about this disclosure=
but did not respond in any way.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12209" target=3D= "_blank" rel=3D"noopener">CVE-2026-12209</a></td>
</tr>
<td class=3D"vendor-product">runtipi--runtipi</td>
<td>Runtipi is a personal homeserver orchestrator. In versions 4.9.1 throug=
h 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-= store repositories through an unauthenticated endpoint, which leads to arbi= trary file read through app-store logo symlinks. The path guard checks only=
the lexical path before Node reads the file, so a Git app store that conta= ins metadata/logo.jpg as a symbolic link can cause Runtipi to read and retu=
rn the symlink target. Because the endpoint is public and the symlink targe=
t may point outside the cloned repository, this can expose local files from=
the Runtipi container such as /data/.env, /data/state/seed, logs, or appli= cation files. This can disclose JWT secrets, service credentials, local con= figuration, and operational logs depending on the instance. The issue has b= een fixed in version 4.10.0.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47277" target=3D= "_blank" rel=3D"noopener">CVE-2026-47277</a></td>
</tr>
<td class=3D"vendor-product">Saad Iqbal--WP EasyPay</td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPa=
y allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/=
a through 4.4.0.</td>
<td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56024" target=3D= "_blank" rel=3D"noopener">CVE-2026-56024</a></td>
</tr>
<td class=3D"vendor-product">saadiqbal--Points Management System For Gamifi= cation, Ranks, Badges, and Loyalty Rewards Program myCred</td>
<td>The Points Management System For Gamification, Ranks, Badges, and Loyal=
ty Rewards Program - myCred plugin for WordPress is vulnerable to Stored Cr= oss-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, an=
d including, 3.1 due to insufficient input sanitization and output escaping=
. This makes it possible for authenticated attackers, with contributor-leve=
l access and above, to inject arbitrary web scripts in pages that will exec= ute whenever a user accesses an injected page.</td>
<td>2026-06-17</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8607" target=3D"= _blank" rel=3D"noopener">CVE-2026-8607</a></td>
</tr>
<td class=3D"vendor-product">sc Internet Vivoo--WpStream</td>
<td>Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.</td> <td>2026-06-15</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39527" target=3D= "_blank" rel=3D"noopener">CVE-2026-39527</a></td>
</tr>
<td class=3D"vendor-product">shaarli--Shaarli</td>
<td>Shaarli is a personal bookmarking service. Versions 0.16.1 and prior co= ntain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail=
Synchronizer feature. When an administrator runs the thumbnail update proc= ess, malicious bookmark titles are returned via an AJAX response and insert=
ed into the DOM using innerHTML without proper sanitization. The issue orig= inates from the interaction between the backend thumbnail update endpoint a=
nd the frontend JavaScript responsible for rendering update progress. On th=
e backend, the ThumbnailsController::ajaxUpdate method returns bookmark dat=
a formatted using the 'raw' formatter. This includes the unescaped bookmark=
title in the JSON response. On the client side, the script thumbnails-upda= te.js processes this AJAX response and dynamically updates the progress int= erface. Administrators using the thumbnail synchronization feature are affe= cted and exploitation could lead to session hijacking, privilege escalation=
, backdoor injection and full compromise. This issue has been fixed in vers= ion 0.16.2.</td>
<td>2026-06-17</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48821" target=3D= "_blank" rel=3D"noopener">CVE-2026-48821</a></td>
</tr>
<td class=3D"vendor-product">shaarli--Shaarli</td>
<td>Shaarli is a personal bookmarking service. Versions 0.16.1 and prior co= ntain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-= HTML conversion process used in the Bookmark Description field. An authenti= cated user can inject a malicious javascript: URI inside a Markdown link. T=
he vulnerability originates in the filterProtocols method within BookmarkMa= rkdownFormatter.php.This method attempts to sanitize Markdown links by filt= ering dangerous protocols (such as javascript:) before rendering. It uses t=
he following regular expression: (#]\((.*?)\)#is). This regex is designed t=
o detect inline Markdown links, but it fails to detect Markdown reference-s= tyle links because reference-style links are resolved by the Markdown parse=
r after preprocessing. The filterProtocols method never inspects the actual=
URL used in these references and as a result, an attacker can supply a jav= ascript: URI inside a reference definition. This issue has been fixed in ve= rsion 0.16.2.</td>
<td>2026-06-17</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48822" target=3D= "_blank" rel=3D"noopener">CVE-2026-48822</a></td>
</tr>
<td class=3D"vendor-product">shaarli--Shaarli</td>
<td>Shaarli is a personal bookmarking service. Versions 0.16.1 and prior co= ntain a stored Cross-Site Scripting (XSS) vulnerability in the tag filterin=
g functionality of Shaarli. An authenticated user can inject arbitrary Java= Script into the tags field when creating a bookmark (Shaare). The malicious=
payload is stored and later executed when users interact with the "Filter =
by tag" search feature on the homepage. User-supplied input in the tags fie=
ld is not properly sanitized or output-escaped before being rendered in the=
tag filtering interface. When a bookmark is created with a malicious paylo=
ad inside the tag field, the payload is stored in the database. Later, when=
a user searches using the "Filter by tag" functionality on the homepage, t=
he application renders matching tags dynamically. If the tag value contains=
HTML with JavaScript event handlers, it is injected into the DOM. This imp= acts anyone interacting with the "Filter by tag" search functionality, admi= nistrators and privileged users. This issue has been fixed in version 0.16.= 2.</td>
<td>2026-06-17</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48823" target=3D= "_blank" rel=3D"noopener">CVE-2026-48823</a></td>
</tr>
<td class=3D"vendor-product">Shareaholic--Shareaholic</td>
<td>Missing Authorization vulnerability in Shareaholic allows Exploiting In= correctly Configured Access Control Security Levels. This issue affects Sha= reaholic: from n/a through 9.7.11.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-24709" target=3D= "_blank" rel=3D"noopener">CVE-2024-24709</a></td>
</tr>
<td class=3D"vendor-product">slimphp--Slim</td>
<td>Slim is a PHP micro framework that enables users to write simple web ap= plications and APIs. In versions 4.4.0 through 4.15, if an application uses=
HttpException::setTitle() and/or setDescription() to include untrusted/req= uest-derived data in the error title or description (e.g. "No products foun=
d matching '{$query}'."), an attacker could inject arbitrary HTML/JavaScrip=
t that executes in the victim's browser when they encounter an HTML error p= age generated by Slim. The vulnerability is present even with displayErrorD= etails =3D false as the unescaped title and description are rendered on thi=
s error path. Built-in exceptions (HttpNotFoundException, HttpBadRequestExc= eption, etc.) ship plain-text defaults, so a vanilla Slim app with no user = code is not exploitable. Only applications that feed untrusted data into se= tTitle() and/or setDescription() are affected. The issue has been fixed in = 4.15.2. If developers are unable to immediately update their applications, = they can work around this issue by avoiding passing untrusted/request-deriv=
ed data into HttpException::setTitle() and setDescription() and using stati=
c, plain-text error copy instead. They should also register a custom error = renderer (an ErrorRendererInterface implementation, or a subclass of HtmlEr= rorRenderer that escapes the title and description) for the HTML media type= .</td>
<td>2026-06-15</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48157" target=3D= "_blank" rel=3D"noopener">CVE-2026-48157</a></td>
</tr>
<td class=3D"vendor-product">Splunk--Splunk AI Toolkit</td>
<td>In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that d= oes not hold the "admin" or "power" Splunk roles could cause the Splunk AI = Toolkit to make outbound requests over HTTP to a server that an attacker co= ntrols, which could allow for data exfiltration. The vulnerability exists b= ecause of an insecure default domain allowlist in the Splunk AI Toolkit, wh= ich does not restrict outbound AI agent requests to approved external domai= ns.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20265" target=3D= "_blank" rel=3D"noopener">CVE-2026-20265</a></td>
</tr>
<td class=3D"vendor-product">statamic--cms</td>
<td>Statamic is a Laravel and Git powered content management system (CMS). = Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view=
metadata and content for resources they don't have permission to view, inc= luding entries, assets, users, roles, groups, and other configured resource=
s. Depending on the resource, this could expose titles, custom field values=
, entry content, asset metadata, and the existence of users, roles, and gro= ups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0.<=
<td>2026-06-19</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49288" target=3D= "_blank" rel=3D"noopener">CVE-2026-49288</a></td>
</tr>
<td class=3D"vendor-product">SteeltoeOSS--Steeltoe.Configuration.Abstractio= ns</td>
<td>Steeltoe is an open source project that provides a collection of librar= ies that helps users build cloud-native applications. In Steeltoe.Configura= tion.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bin= dings from `VCAP_SERVICES` include TLS client credentials, the Connectors l= ibrary writes those credentials to temporary files in `Path.GetTempPath()` = using `File.CreateText`. On Linux, `File.CreateText` creates files with mod=
e `0644` (world-readable) under the process umask, and the files are never = deleted. The same key material is protected at mode `0400` in `/proc/<pi= d>/environ`. Steeltoe.Configuration.Abstractions version 4.2.0 patches t=
he issue. If an immediate upgrade is not possible, prevent other processes = from running in the container under a different UID with access to `/tmp`.<=
<td>2026-06-17</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50267" target=3D= "_blank" rel=3D"noopener">CVE-2026-50267</a></td>
</tr>
<td class=3D"vendor-product">SteeltoeOSS--Steeltoe.Management.Endpoint</td> <td>Steeltoe is an open source project that provides a collection of librar= ies that helps users build cloud-native applications. In Steeltoe.Managemen= t.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prio=
r to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPer= missions.Restricted`, which is mappeds to Cloud Foundry's `read_basic_data`=
permission (granted to Space Auditors and similar low-trust roles). Sensit= ive actuators including heap dump, environment, and thread dump do not rais=
e this to `EndpointPermissions.Full`, so CF's `read_sensitive_data` permiss= ion flag is not enforced for those endpoints. Spring Boot's equivalent Clou=
d Foundry integration gates these endpoints with `read_sensitive_data` by d= efault. Steeltoe.Management.Endpoint 4.2.0 and Steeltoe.Management.Endpoint= Core 3.4.0 patch the issue. If an immediate upgrade is not possible, explic= itly set `RequiredPermissions =3D EndpointPermissions.Full` in the options = for `HeapDumpEndpointOptions`, `EnvironmentEndpointOptions`, and `ThreadDum= pEndpointOptions`; and/or if heap dump, thread dump, or environment are not=
needed in production, register only the required actuators individually in= stead of using `AddAllActuators()`.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50201" target=3D= "_blank" rel=3D"noopener">CVE-2026-50201</a></td>
</tr>
<td class=3D"vendor-product">SteeltoeOSS--Steeltoe.Security.Authentication.= CloudFoundryBase</td>
<td>Steeltoe is an open source project that provides a collection of librar= ies that helps users build cloud-native applications. In Steeltoe.Security.= Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.A= uthentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authe= ntication.OpenIdConnect prior to version 4.2.0, the JWT signing key cache i=
n `TokenKeyResolver` uses `kid` as the sole cache key without namespacing b=
y authority. In applications with multiple `JwtBearer` schemes pointing to = different identity providers, a key fetched for one scheme can satisfy toke=
n validation for another. Additionally, cached keys have no expiration, so = rotated or revoked keys remain trusted until the application process restar= ts. Steeltoe.Security.Authentication.CloudFoundryBase version 3.4.0, Steelt= oe.Security.Authentication.JwtBearer version 4.2.0, and Steeltoe.Security.A= uthentication.OpenIdConnect version 4.2.0 patch the issue. If an immediate = upgrade is not possible: In multi-scheme deployments, configure only one `J= wtBearer` scheme per application when different identity providers are requ= ired; and/or restart the application process after an identity provider sig= ning key rotation to clear stale cached keys.</td>
<td>2026-06-17</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50202" target=3D= "_blank" rel=3D"noopener">CVE-2026-50202</a></td>
</tr>
<td class=3D"vendor-product">stellarwp--Kadence Blocks Page Builder Toolkit=
for Gutenberg Editor</td>
<td>The Kadence Blocks - Page Builder Toolkit for Gutenberg Editor plugin f=
or WordPress is vulnerable to Sensitive Information Exposure in all version=
s up to, and including, 3.7.5 via the editor_assets_variables. This makes i=
t possible for authenticated attackers, with contributor-level access and a= bove, to extract the site's connected Kadence account license key, license = owner email, api_key, api_email, and license domain from the browser consol=
e by inspecting window.kadence_blocks_params.proData. Exploitation requires=
only that an administrator has previously connected a valid Kadence licens=
e; the full credential bundle is then readable by any Contributor-level use=
r from the block editor client context without any server-side request mani= pulation.</td>
<td>2026-06-18</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11357" target=3D= "_blank" rel=3D"noopener">CVE-2026-11357</a></td>
</tr>
<td class=3D"vendor-product">strablengineering--STRABL A checkout solution<=
<td>The STRABL - A checkout solution plugin for WordPress is vulnerable to = Missing Authentication in all versions up to and including 4.5. The plugin = registers a REST API webhook endpoint at /wp-json/strabl/webhook/order with=
a permission_callback of __return_true, which allows all incoming requests=
without any authentication or authorization checks. No shared secret, sign= ature validation, HMAC verification, or token-based authentication is imple= mented. This makes it possible for unauthenticated attackers to create frau= dulent WooCommerce orders and mark them as completed by supplying paymentSt= atus=3Dpaid, manipulate existing order statuses by providing an externalOrd= erId, create new WordPress user accounts with the customer role, issue refu= nds on existing orders, cancel existing orders, and apply chargeback fees -=
all without making a legitimate payment or having any valid credentials.</=
<td>2026-06-19</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3640" target=3D"= _blank" rel=3D"noopener">CVE-2026-3640</a></td>
</tr>
<td class=3D"vendor-product">strukturag--libde265</td>
<td>libde265 is an open source implementation of the h.265 video codec. Pri=
or to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder= _context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice head= ers to a finished picture object that has no active image unit, resulting i=
n attacker-controlled unbounded heap growth. The retained headers are never=
freed until the picture is released, which may not happen during continuou=
s streaming. Version 1.0.20 patches the issue.</td>
<td>2026-06-19</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49337" target=3D= "_blank" rel=3D"noopener">CVE-2026-49337</a></td>
</tr>
<td class=3D"vendor-product">strukturag--libheif</td>
<td>libheif is a HEIF and AVIF file format decoder and encoder. Prior to ve= rsion 1.22.1, the uncompressed HEIF decoder validates explicit icef compres= sed-unit offsets using unit_offset + unit_size. Because the addition can wr= ap, a crafted HEIF file can pass the range check and then construct a vecto=
r from iterators outside the compressed item buffer, producing an out-of-bo= unds heap read and crash. Version 1.22.1 patches the issue.</td> <td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49271" target=3D= "_blank" rel=3D"noopener">CVE-2026-49271</a></td>
</tr>
<td class=3D"vendor-product">StylemixThemes--MasterStudy LMS Pro</td> <td>Missing Authorization vulnerability in StylemixThemes MasterStudy LMS P=
ro allows Accessing Functionality Not Properly Constrained by ACLs. This is= sue affects MasterStudy LMS Pro: from n/a before 4.7.16.</td> <td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-64215" target=3D= "_blank" rel=3D"noopener">CVE-2025-64215</a></td>
</tr>
<td class=3D"vendor-product">StylemixThemes--Motors</td>
<td>Subscriber Broken Access Control in Motors < 1.4.107 versions.</td> <td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39515" target=3D= "_blank" rel=3D"noopener">CVE-2026-39515</a></td>
</tr>
<td class=3D"vendor-product">SUSE--libzypp</td>
<td>A path traversal in handling the "path" component of .repo files proces= sed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could=
be used by attackers to fill directories on the system outside of the zypp=
cache with content.</td>
<td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44942" target=3D= "_blank" rel=3D"noopener">CVE-2026-44942</a></td>
</tr>
<td class=3D"vendor-product">svaarala--duktape</td>
<td>A weakness has been identified in svaarala duktape up to 2.99.99. This = issue affects some unknown processing of the file duk_api_bytecode.c. Execu= ting a manipulation of the argument count_instr can lead to memory corrupti= on. The attack requires local access. The exploit has been made available t=
o the public and could be used for attacks. The vendor was contacted early = about this disclosure but did not respond in any way.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12216" target=3D= "_blank" rel=3D"noopener">CVE-2026-12216</a></td>
</tr>
<td class=3D"vendor-product">teamwsa--Woosa Marktplaats for WooCommerce</td=
<td>The Woosa - Marktplaats for WooCommerce plugin for WordPress is vulnera= ble to Arbitrary File Read via Path Traversal in versions up to and includi=
ng 2.0.4. This is due to insufficient path sanitization in the render_logs_= ui() function, which accepts a base64-encoded file name from the 'log_file'=
GET parameter and concatenates it directly with the plugin's log directory=
path without validating that the resolved path remains within the intended=
directory. This makes it possible for authenticated attackers, with Admini= strator-level access, to read the contents of arbitrary files on the server=
, including wp-config.</td>
<td>2026-06-19</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7547" target=3D"= _blank" rel=3D"noopener">CVE-2026-7547</a></td>
</tr>
<td class=3D"vendor-product">techlabpro1--Classified Listing AI-Powered Cla= ssified ads & Business Directory</td>
<td>The Classified Listing - Classified ads & Business Directory plugin=
for WordPress is vulnerable to Missing Authorization in all versions up to=
, and including, 5.4.2. This is due to a missing capability/ownership check=
on the gallery_image_update_as_feature AJAX handler (action: rtcl_fb_galle= ry_image_update_as_feature), which accepts a user-supplied listing ID and a= ttachment ID and sets the featured image of a listing while only validating=
a nonce that is exposed to any logged-in user on the frontend listing-subm= ission form. This makes it possible for authenticated attackers, with Subsc= riber-level access and above, to change the featured image of arbitrary lis= tings they do not own.</td>
<td>2026-06-19</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10779" target=3D= "_blank" rel=3D"noopener">CVE-2026-10779</a></td>
</tr>
<td class=3D"vendor-product">Themefic--Ultra Addons for WPForms</td> <td>Subscriber Broken Access Control in Ultra Addons for WPForms <=3D 1.= 0.11 versions.</td>
<td>2026-06-15</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39594" target=3D= "_blank" rel=3D"noopener">CVE-2026-39594</a></td>
</tr>
<td class=3D"vendor-product">ThemeGrill--Masteriyo - LMS</td> <td>Unauthenticated Broken Authentication in Masteriyo - LMS <=3D 2.1.8 = versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42743" target=3D= "_blank" rel=3D"noopener">CVE-2026-42743</a></td>
</tr>
<td class=3D"vendor-product">themeisle--Orbit Fox: Duplicate Page, Menu Ico= ns, SVG Support, Cookie Notice, Custom Fonts & More</td>
<td>The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, = Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-= Site Scripting via admin settings in all versions up to, and including, 3.0=
.6 due to insufficient input sanitization and output escaping. This makes i=
t possible for authenticated attackers, with administrator-level permission=
s and above, to inject arbitrary web scripts in pages that will execute whe= never a user accesses an injected page. This only affects multi-site instal= lations and installations where unfiltered_html has been disabled.</td> <td>2026-06-18</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11358" target=3D= "_blank" rel=3D"noopener">CVE-2026-11358</a></td>
</tr>
<td class=3D"vendor-product">Themeisle--WP Full Stripe Free</td>
<td>Subscriber Broken Authentication in WP Full Stripe Free <=3D 8.4.1 v= ersions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42378" target=3D= "_blank" rel=3D"noopener">CVE-2026-42378</a></td>
</tr>
<td class=3D"vendor-product">Themeum--Tutor LMS</td>
<td>Unauthenticated Broken Access Control in Tutor LMS <=3D 3.9.7 versio= ns.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40743" target=3D= "_blank" rel=3D"noopener">CVE-2026-40743</a></td>
</tr>
<td class=3D"vendor-product">themeum--Tutor LMS eLearning and online course=
solution</td>
<td>The Tutor LMS - eLearning and online course solution plugin for WordPre=
ss is vulnerable to generic SQL Injection via the 'data' parameter in all v= ersions up to, and including, 3.9.11 due to insufficient escaping on the us=
er supplied parameter and lack of sufficient preparation on the existing SQ=
L query. This makes it possible for authenticated attackers, with administr= ator-level access and above, to append additional SQL queries into already = existing queries that can be used to extract sensitive information from the=
database.</td>
<td>2026-06-18</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10736" target=3D= "_blank" rel=3D"noopener">CVE-2026-10736</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4=
have Missing Authorization in the API CategoryController. CVE-2026-24421 a= ddressed this in the BackupController by adding: $this->userHasPermissio= n(PermissionType::BACKUP). The same fix was not applied to 4 other write en= dpoints in the public API. All 4 only call $this->hasValidToken() - whic=
h checks a shared API key header, rather than the individual user's role pe= rmissions. The following APIs are affected: POST /api/v4.0/category (Catego= ryController::create), POST /api/v4.0/faq (FaqController::create), PUT /api= /v4.0/faq (FaqController::update), and POST /api/v4.0/question (QuestionCon= troller::create). This issue has been fixed in version 4.1.4.</td> <td>2026-06-18</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49205" target=3D= "_blank" rel=3D"noopener">CVE-2026-49205</a></td>
</tr>
<td class=3D"vendor-product">TMS--Amelia</td>
<td>Subscriber Broken Access Control in Amelia <=3D 2.2 versions.</td> <td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40795" target=3D= "_blank" rel=3D"noopener">CVE-2026-40795</a></td>
</tr>
<td class=3D"vendor-product">ts-deepmerge--ts-deepmerge</td>
<td>Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Unc= aught Exception due to the improper handling of built-in Object.prototype m= ethods (such as toString, valueOf). When user-controlled input contains the=
se keys with non-function values, the resulting merged object becomes broke=
n - any string context operation throws a TypeError, crashing the applicati= on.</td>
<td>2026-06-19</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12644" target=3D= "_blank" rel=3D"noopener">CVE-2026-12644</a></td>
</tr>
<td class=3D"vendor-product">typemill--typemill</td>
<td>Typemill before 2.24.0 contains a path traversal vulnerability that all= ows authenticated attackers with Author-level privileges to read arbitrary = files outside the content directory by supplying traversal sequences in the=
path query parameter passed to Storage::getFile() with an empty folder arg= ument. Attackers can bypass traversal-prevention controls in Storage::getFo= lderPath() to access sensitive files.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49133" target=3D= "_blank" rel=3D"noopener">CVE-2026-49133</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: Undici's cache interceptor incorrectly classifies some response=
s as cacheable when the upstream Cache-Control header uses whitespace-padde=
d qualified private or no-cache field names such as private=3D" authorizati= on" or no-cache=3D"\tauthorization". The parser preserves the surrounding w= hitespace, so later comparisons against the literal authorization field nam=
e fail and the response is stored. In shared-cache mode, this allows a resp= onse containing one user's authenticated data to be served from cache to a = subsequent caller, including an unauthenticated caller, when both requests = resolve to the same cache key. Affected applications are those that explici= tly enable the cache interceptor (interceptors.cache()) in shared mode, for= ward Authorization headers upstream, and receive cacheable responses with n= on-canonical qualified private or no-cache directives. Patches: Upgrade to = undici v7.28.0 or v8.5.0. Workarounds: If upgrade is not immediately possib= le, disable shared-cache mode for traffic that includes Authorization heade= rs, avoid caching responses to authenticated requests, or add Vary: Authori= zation upstream.</td>
<td>2026-06-17</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9678" target=3D"= _blank" rel=3D"noopener">CVE-2026-9678</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: undici's cookie parser in parseSetCookie percent-decodes cookie=
values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, an=
d %3D into their literal byte equivalents. RFC 6265 =C3=82=C2=A75.4 does no=
t specify any decoding and browsers do not decode either. Applications that=
parse a Set-Cookie header and then forward the parsed value into a respons=
e header (proxies, middleware, SSR frameworks) become vulnerable to HTTP re= sponse header injection: an attacker-controlled upstream can inject arbitra=
ry Set-Cookie, Location, or Cache-Control headers into the application's do= wnstream response, enabling session fixation, open redirect, or cache poiso= ning. Affected applications are those that use undici's cookie parsing (par= seSetCookie, parseCookie, getSetCookies) and forward the parsed cookie valu=
e into a response header. This was introduced in undici 7.0.0 via PR #3789.=
Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: If upg= rade is not immediately possible, do not forward values returned by parseSe= tCookie/parseCookie/getSetCookies directly into response headers; sanitize = the value first to strip or reject CR, LF, NUL, ;, and =3D bytes.</td> <td>2026-06-17</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9679" target=3D"= _blank" rel=3D"noopener">CVE-2026-9679</a></td>
</tr>
<td class=3D"vendor-product">universal-tool-calling-protocol--python-utcp</=
<td>A vulnerability was detected in universal-tool-calling-protocol python-= utcp 1.1.0. This affects an unknown function of the component utcp-gql/utcp= -websocket. Performing a manipulation results in server-side request forger=
y. The attack can be initiated remotely. The exploit is now public and may =
be used. The vendor was contacted early about this disclosure but did not r= espond in any way.</td>
<td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12210" target=3D= "_blank" rel=3D"noopener">CVE-2026-12210</a></td>
</tr>
<td class=3D"vendor-product">valhalla--valhalla</td>
<td>Valhalla is an open source routing engine and accompanying libraries fo=
r use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to r= eflected cross-site scripting (XSS) due to improper neutralization of input=
in the JSONP callback parameter. When a request specifies a JSONP callback=
, the value is reflected directly into the HTTP response body with Content-= Type: application/javascript, without any validation, output encoding, or a= llowlist filtering. An attacker can craft a URL containing arbitrary JavaSc= ript in the callback parameter; if a victim is induced to load that URL via=
a <script src=3D"..."> tag, the injected script executes in the cont= ext of the serving origin, potentially leading to session token theft, cred= ential disclosure, or actions performed on behalf of the victim. This issue=
was not fixed at time of publication.</td>
<td>2026-06-15</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49294" target=3D= "_blank" rel=3D"noopener">CVE-2026-49294</a></td>
</tr>
<td class=3D"vendor-product">VeronaLabs--Slimstat Analytics</td> <td>Unauthenticated Deserialization of untrusted data in Slimstat Analytics=
< 5.4.0 versions.</td>
<td>2026-06-17</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27410" target=3D= "_blank" rel=3D"noopener">CVE-2026-27410</a></td>
</tr>
<td class=3D"vendor-product">VeronaLabs--WP SMS</td>
<td>Subscriber Sensitive Data Exposure in WP SMS <=3D 7.2.1 versions.</t=
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40790" target=3D= "_blank" rel=3D"noopener">CVE-2026-40790</a></td>
</tr>
<td class=3D"vendor-product">virtio-snd device--virtio-snd device</td>
<td>An integer overflow vulnerability was found in the virtio-snd device vi=
a PCM_INFO requests from the guest. A malicious guest can provide out-of-bo= unds stream counts, potentially leading to unbounded memory allocation on t=
he host and a denial of service condition.</td>
<td>2026-06-19</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3196" target=3D"= _blank" rel=3D"noopener">CVE-2026-3196</a></td>
</tr>
<td class=3D"vendor-product">vllm--vllm</td>
<td>vLLM versions >=3D 0.6.3 and < 0.9.0 contain multiple regular exp= ression denial of service (ReDoS) vulnerabilities. Several regex patterns -=
in vllm/lora/utils.py, the phi4mini tool parser, and the OpenAI-compatible=
serving chat endpoint - are susceptible to catastrophic backtracking. An a= ttacker submitting crafted input with nested or repeated structures can tri= gger severe CPU consumption and performance degradation, resulting in denia=
l of service.</td>
<td>2026-06-20</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71379" target=3D= "_blank" rel=3D"noopener">CVE-2025-71379</a></td>
</tr>
<td class=3D"vendor-product">vynnus--PopAd</td>
<td>Administrator Server Side Request Forgery (SSRF) in PopAd <=3D 1.0.4=
versions.</td>
<td>2026-06-15</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-60175" target=3D= "_blank" rel=3D"noopener">CVE-2025-60175</a></td>
</tr>
<td class=3D"vendor-product">Wasiliy Strecker--Contest Gallery</td> <td>Subscriber Cross Site Scripting (XSS) in Contest Gallery <=3D 28.1.6=
versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42656" target=3D= "_blank" rel=3D"noopener">CVE-2026-42656</a></td>
</tr>
<td class=3D"vendor-product">Wasiliy Strecker--Contest Gallery</td> <td>Unauthenticated Other Vulnerability Type in Contest Gallery <=3D 28.= 1.7 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42657" target=3D= "_blank" rel=3D"noopener">CVE-2026-42657</a></td>
</tr>
<td class=3D"vendor-product">Wasiliy Strecker--Contest Gallery</td> <td>Subscriber Sensitive Data Exposure in Contest Gallery <=3D 28.1.7 ve= rsions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42660" target=3D= "_blank" rel=3D"noopener">CVE-2026-42660</a></td>
</tr>
<td class=3D"vendor-product">watchful--XCloner</td>
<td>Subscriber Sensitive Data Exposure in XCloner <=3D 4.8.6 versions.</=
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48965" target=3D= "_blank" rel=3D"noopener">CVE-2026-48965</a></td>
</tr>
<td class=3D"vendor-product">Webful Creations--RepairBuddy</td>
<td>Subscriber Broken Access Control in RepairBuddy <=3D 4.1132 versions= .</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39584" target=3D= "_blank" rel=3D"noopener">CVE-2026-39584</a></td>
</tr>
<td class=3D"vendor-product">Webmin--Webmin</td>
<td>Webmin allows unauthenticated attackers to read the contents of any fil=
e ending in .conf within module directories, due to a bypassable regex patt= ern.</td>
<td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56021" target=3D= "_blank" rel=3D"noopener">CVE-2026-56021</a></td>
</tr>
<td class=3D"vendor-product">Webmin--Webmin</td>
<td>Webmin accepts basic authentication without session cookies when an att= acker provides the 'User-Agent: webmin' header, allowing bypass of addition=
al MFA requirements. Fixed in 2.641.</td>
<td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56022" target=3D= "_blank" rel=3D"noopener">CVE-2026-56022</a></td>
</tr>
<td class=3D"vendor-product">webpack-dev-server--webpack-dev-server</td> <td>Impact: When a user-configured proxy on webpack-dev-server has a broad = context (e.g. /) and ws: true, it also intercepts the dev server's own HMR = WebSocket and forwards it to the proxy target. This leaks the browser's coo= kies and Origin header to the backend, bypasses the dev server's Host/Origi=
n validation, and corrupts the HMR socket (both HMR and the proxy end up wr= iting to the same socket). Patches: Fixed in webpack-dev-server@5.2.5. Work= arounds: Scope user-defined proxy context to specific paths instead of /, o=
r omit ws: true from the proxy entry when WebSocket forwarding is not requi= red.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9595" target=3D"= _blank" rel=3D"noopener">CVE-2026-9595</a></td>
</tr>
<td class=3D"vendor-product">WishList Member--WishList Member X</td> <td>Subscriber Broken Access Control in WishList Member X <=3D 3.29.0 ve= rsions.</td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24575" target=3D= "_blank" rel=3D"noopener">CVE-2026-24575</a></td>
</tr>
<td class=3D"vendor-product">woocommerce--WooCommerce Stripe Payment Gatewa= y</td>
<td>The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerab=
le to unauthorized modification of data due to a missing capability check o=
n the `ajax_pay_for_order()` function in all versions up to, and including,=
10.7.0 This is due to a missing order ownership or order_key verification = when processing payment for an order via the `wc_stripe_pay_for_order` WC-A= JAX endpoint. The function only validates a nonce (which is publicly availa= ble on any WooCommerce page where Express Checkout is enabled), but does no=
t verify that the requesting user owns the target order and is allowed to m= odify it. This makes it possible for unauthenticated attackers to force any=
pending order into a failed status by providing a fake payment method, cau= sing a payment exception that updates the order status to "failed" via sequ= ential order ID enumeration.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2381" target=3D"= _blank" rel=3D"noopener">CVE-2026-2381</a></td>
</tr>
<td class=3D"vendor-product">WP Chill--Download Monitor</td>
<td>Author Arbitrary File Download in Download Monitor <=3D 5.1.9 versio= ns.</td>
<td>2026-06-15</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39489" target=3D= "_blank" rel=3D"noopener">CVE-2026-39489</a></td>
</tr>
<td class=3D"vendor-product">WP Chill--Modula Image Gallery</td>
<td>Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <=3D 2= .14.23 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42688" target=3D= "_blank" rel=3D"noopener">CVE-2026-42688</a></td>
</tr>
<td class=3D"vendor-product">WP Engine--WP Migrate Lite</td> <td>Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite &l= t;=3D 2.7.8 versions.</td>
<td>2026-06-15</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49043" target=3D= "_blank" rel=3D"noopener">CVE-2026-49043</a></td>
</tr>
<td class=3D"vendor-product">wp.insider--Simple Membership</td> <td>Unauthenticated Cross Site Scripting (XSS) in Simple Membership <=3D=
4.7.2 versions.</td>
<td>2026-06-15</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42663" target=3D= "_blank" rel=3D"noopener">CVE-2026-42663</a></td>
</tr>
<td class=3D"vendor-product">wpcalc--Counter Box Add Countdowns, Timers &am=
p; Dynamic Counters to WordPress</td>
<td>The Counter Box - Add Countdowns, Timers & Dynamic Counters to Word= Press plugin for WordPress is vulnerable to PHP Object Injection in all ver= sions up to, and including, 2.0.13 via deserialization of untrusted input .=
This makes it possible for authenticated attackers, with administrator-lev=
el access and above, to inject a PHP Object. No known POP chain is present =
in the vulnerable software, which means this vulnerability has no impact un= less another plugin or theme containing a POP chain is installed on the sit=
e. If a POP chain is present via an additional plugin or theme installed on=
the target system, it may allow the attacker to perform actions like delet=
e arbitrary files, retrieve sensitive data, or execute code depending on th=
e POP chain present. Deserialization is triggered automatically upon the po= st-import redirect that renders the list table, and again when any item is = opened for editing, requiring no additional navigation beyond the import ac= tion itself.</td>
<td>2026-06-17</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12115" target=3D= "_blank" rel=3D"noopener">CVE-2026-12115</a></td>
</tr>
<td class=3D"vendor-product">WPDeveloper--Essential Addons for Elementor</t=
<td>Unauthenticated Broken Access Control in Essential Addons for Elementor=
< 6.6.0 versions.</td>
<td>2026-06-15</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25440" target=3D= "_blank" rel=3D"noopener">CVE-2026-25440</a></td>
</tr>
<td class=3D"vendor-product">wpdevteam--BetterDocs AI Documentation, Knowle= dge Base, Docs, Wikis, FAQ with Chatbot</td>
<td>The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor &= amp; Block Editor plugin for WordPress is vulnerable to Stored Cross-Site S= cripting via the blockId attribute of the betterdocs/category-slate-layout = Gutenberg block in versions up to, and including, 4.5.3. This is due to ins= ufficient input sanitization and output escaping in the CategorySlateLayout= ::render() method, which echoes the blockId block attribute directly into a=
n HTML class attribute without esc_attr(). This makes it possible for authe= nticated attackers, with contributor-level access and above, to inject arbi= trary web scripts in pages that will execute whenever a user accesses an in= jected page.</td>
<td>2026-06-19</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12157" target=3D= "_blank" rel=3D"noopener">CVE-2026-12157</a></td>
</tr>
<td class=3D"vendor-product">wpgmaps--WP Go Maps Google Map, OpenStreetMap,=
Leaflet Map</td>
<td>The WP Go Maps - Most Popular Map Plugin plugin for WordPress is vulner= able to authorization bypass in all versions up to, and including, 10.1.01.=
This is due to the plugin not properly verifying that a user is authorized=
to perform an action. This makes it possible for unauthenticated attackers=
to create arbitrary records in plugin database tables (maps, markers, circ= les, polygons, polylines, rectangles, and point labels) by supplying a WPGM= ZA-namespaced CRUD-backed class name via the phpClass parameter. The namesp= ace validation check (requiring the 'WPGMZA' prefix) does not prevent explo= itation because classes such as WPGMZA\Map and WPGMZA\Marker satisfy it whi=
le still triggering an INSERT into the corresponding plugin table before th=
e route rejects the request.</td>
<td>2026-06-19</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12238" target=3D= "_blank" rel=3D"noopener">CVE-2026-12238</a></td>
</tr>
<td class=3D"vendor-product">wpinsider-1--Simple Membership</td>
<td>The Simple Membership plugin for WordPress is vulnerable to authorizati=
on bypass in all versions up to, and including, 4.7.5. This is due to the p= lugin not properly verifying that a user is authorized to perform an action=
. This makes it possible for unauthenticated attackers to deactivate arbitr= ary member accounts by forging a charge.refunded webhook event containing a=
victim's subscription ID, setting the target member's account_state to 'in= active' and triggering cancellation hooks, transaction-record status change=
s, and cancellation notification emails. This vulnerability is exploitable = only on installations where no Stripe webhook signing secret has been confi= gured, which is the default out-of-the-box state; sites that have configure=
d the stripe-webhook-signing-secret option are routed to the properly verif= ied HMAC path and are not affected.</td>
<td>2026-06-18</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12093" target=3D= "_blank" rel=3D"noopener">CVE-2026-12093</a></td>
</tr>
<td class=3D"vendor-product">Wpmet--GetGenie</td>
<td>Unauthenticated Sensitive Data Exposure in GetGenie <=3D 4.4.1 versi= ons.</td>
<td>2026-06-16</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54197" target=3D= "_blank" rel=3D"noopener">CVE-2026-54197</a></td>
</tr>
<td class=3D"vendor-product">WPMet--MetForm Pro</td>
<td>Subscriber Broken Access Control in MetForm Pro <=3D 3.9.1 versions.= </td>
<td>2026-06-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24610" target=3D= "_blank" rel=3D"noopener">CVE-2026-24610</a></td>
</tr>
<td class=3D"vendor-product">wproyal--Royal Addons for Elementor Addons and=
Templates Kit for Elementor</td>
<td>The Royal Addons for Elementor - Addons and Templates Kit for Elementor=
plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.= 1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (intr= oduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling = back to is_readable() and fopen($source, 'r') on the attacker-controlled se= ttings.table_upload_csv.url value when it does not parse as an HTTP URL, wi=
th no allow-list, traversal block, or extension check. This makes it possib=
le for authenticated attackers, with Contributor-level access and above, to=
save a crafted wpr-data-table widget through Elementor's save_builder endp= oint and have the rendered preview return the line-by-line contents of any = file readable by the PHP process, including wp-config.php.</td> <td>2026-06-19</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8118" target=3D"= _blank" rel=3D"noopener">CVE-2026-8118</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo TopMenu plugin through version 26.0 contains a stored cross-site=
scripting vulnerability in menu item rendering due to missing output encod= ing of icon classes, URLs, and text labels. Attackers can inject malicious = JavaScript through unescaped menu item fields that execute for all site vis= itors, potentially stealing session cookies or performing unauthorized acti= ons.</td>
<td>2026-06-20</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56347" target=3D= "_blank" rel=3D"noopener">CVE-2026-56347</a></td>
</tr>
<td class=3D"vendor-product">XianYuLauncher--XianYuLauncher</td> <td>XianYuLauncher is a Minecraft Java Edition launcher. In versions prior =
to 1.5.5, sensitive authentication artifacts could be exposed during a user= -initiated login under certain local attack conditions. Affected versions r= elied on a fixed localhost redirect URI without PKCE or state validation. E= xploitation is most likely to occur when an attacker is able to observe, in= tercept, or otherwise interfere with the local authentication flow on the s= ame device. This issue has been fixed in version 1.5.5.</td> <td>2026-06-17</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48991" target=3D= "_blank" rel=3D"noopener">CVE-2026-48991</a></td>
</tr>
<td class=3D"vendor-product">Yealink--SIP-T46U</td>
<td>A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted el= ement is the function mod_diagnose.CommandShellByType of the file /api/diag= nosis/start of the component Web FastCGI Service. This manipulation of the = argument Time causes command injection. The attack can be initiated remotel=
y. The exploit has been published and may be used. The vendor was contacted=
early about this disclosure but did not respond in any way.</td> <td>2026-06-15</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12219" target=3D= "_blank" rel=3D"noopener">CVE-2026-12219</a></td>
</tr>
<td class=3D"vendor-product">Yealink--SIP-T46U</td>
<td>A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affect=
ed by this vulnerability is the function mod_webd.TFTPUploadIperf of the fi=
le /api/inner/tftpuploadiperf of the component Web FastCGI Service. The man= ipulation of the argument ip/port leads to command injection. The attack ne= eds to be initiated within the local network. The exploit is publicly avail= able and might be used. The vendor was contacted early about this disclosur=
e but did not respond in any way.</td>
<td>2026-06-15</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12223" target=3D= "_blank" rel=3D"noopener">CVE-2026-12223</a></td>
</tr>
<td class=3D"vendor-product">Yoast BV--Yoast SEO Premium</td>
<td>Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allow=
s Exploiting Incorrectly Configured Access Control Security Levels. This is= sue affects Yoast SEO Premium: from n/a through 26.6.</td>
<td>2026-06-17</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40722" target=3D= "_blank" rel=3D"noopener">CVE-2026-40722</a></td>
</tr>
<td class=3D"vendor-product">zealopensource--Abandoned Contact Form 7</td> <td>The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unau= thorized arbitrary post deletion in versions up to, and including, 2.2. Thi=
s is due to a missing capability check and missing nonce validation in the = action__remove_abandoned() function, which is registered to both the wp_aja= x_remove_abandoned and wp_ajax_nopriv_remove_abandoned hooks. The handler t= akes a user-supplied recover_id parameter from $_POST and passes it directl=
y to wp_delete_post() with the force-delete flag set to true, without verif= ying that the ID belongs to the plugin's own cf7af_data post type. This mak=
es it possible for unauthenticated attackers to permanently delete arbitrar=
y posts, pages, or other content on the affected site by sending a single a= dmin-ajax.</td>
<td>2026-06-16</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9187" target=3D"= _blank" rel=3D"noopener">CVE-2026-9187</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page= -table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_do= main_list, of active memory domains using a list node embedded inside the c= aller-owned struct k_mem_domain. When a domain is destroyed via k_mem_domai= n_deinit() - arch_mem_domain_deinit(), the page tables are torn down and do= main-arch.ptables is set to NULL, but the domain's node was not removed fro=
m xtensa_domain_list. The freed/deinitialized domain therefore remained lin= ked into the global list as a dangling pointer into caller-owned storage th=
at may then be freed or reused. Any subsequent arch_mem_map()/arch_mem_unma= p() operation (widely invoked by kernel memory-mapping and demand-paging co= de) traverses the stale node and dereferences domain-ptables: at minimum a = NULL pointer dereference causing a fatal MMU exception (denial of service),=
and if the k_mem_domain storage has been freed or reused, a use-after-free=
in which a stale/controlled ptables value is dereferenced and written thro= ugh during the page-table walk (l2_page_table_map writes l1_table[...] and = l2_table[...], and xtensa_mmu_compute_domain_regs writes into the domain st= ruct and the L1 table), yielding page-table memory corruption that can unde= rmine userspace isolation. The vulnerable path is reachable only from privi= leged kernel/supervisor code (k_mem_domain_deinit is not a syscall), not di= rectly from unprivileged user threads or remotely. Affected: Zephyr v4.4.0 = (the Xtensa memory-domain de-initialization feature was introduced in commi=
t 3032b58f52d and first shipped in v4.4.0); fixed on main by adding sys_sli= st_find_and_remove() in arch_mem_domain_deinit(). The Xtensa MPU path is un= affected.</td>
<td>2026-06-16</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10635" target=3D= "_blank" rel=3D"noopener">CVE-2026-10635</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td> <td>subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_p= kt_iface(pkt) after net_send_data(pkt) returned successfully. Per the netwo=
rk stack's ownership contract (include/zephyr/net/net_core.h, and the expli= cit warning in subsys/net/ip/net_core.c:453-460 'do not use pkt after that = call'), a successful send transfers ownership of the net_pkt and the L2 dri= ver frees it (e.g. ethernet_send() unrefs the packet on success, subsys/net= /l2/ethernet/ethernet.c:790), returning it to its k_mem_slab. The subsequen=
t net_pkt_iface(pkt) is therefore a read of a freed object; the recovered i= nterface pointer is then dereferenced and incremented by the per-interface = statistics path (net_stats.h UPDATE_STAT/SET_STAT) when CONFIG_NET_STATISTI= CS_PER_INTERFACE is enabled. If the freed slot is concurrently reallocated,=
pkt-iface may read back as NULL (NULL-pointer dereference / crash) or as a=
stale/garbage pointer (stray increment write / memory corruption). The pat=
h is reachable remotely on the local link without authentication: handle_ml= d_query() (registered for NET_ICMPV6_MLD_QUERY) responds to a valid MLDv2 G= eneral Query (unspecified multicast address, hop limit 1) by calling send_m= ld_report() - mld_send(). The result is a remotely triggerable denial of se= rvice of the networking stack, with a narrow possibility of memory corrupti= on. The fix caches the interface in a local before sending and no longer to= uches the packet after net_send_data(). The IPv4/IGMP sibling (igmp_send) a= lready used the corrected pattern.</td>
<td>2026-06-16</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10637" target=3D= "_blank" rel=3D"noopener">CVE-2026-10637</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td> <td>subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after=
that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_= request() and net_icmpv6_send_error(), the post-send statistics update call=
s net_pkt_iface(reply)/net_pkt_iface(pkt) on the just-sent packet. The send=
path (net_try_send_data - net_if_tx) unreferences and may free the packet = back to its memory slab before returning - synchronously in the RX thread w= hen no TX queue is configured (CONFIG_NET_TC_TX_COUNT =3D=3D 0), and asynch= ronously the driver/L2 may already have freed it otherwise. net_pkt_iface()=
therefore dereferences a freed (and possibly reused) net_pkt; with CONFIG_= NET_STATISTICS_PER_INTERFACE the stale iface pointer is further dereference=
d and written through (iface-stats.icmp.sent++), turning the use-after-free=
read into a write through an attacker-influenceable pointer. The core stac=
k already documents this hazard in net_core.c ("do not use pkt after that c= all") and caches iface before sending; the ICMPv6 callers did not. An unaut= henticated remote attacker triggers the flaw simply by sending an ICMPv6 Ec=
ho Request (ping) or an IPv6 packet that elicits an ICMPv6 error (unknown n= ext header, fragment reassembly timeout, destination unreachable), leading =
to denial of service via crash and potential memory corruption. Affected: Z= ephyr networking with CONFIG_NET_NATIVE_IPV6, roughly v4.2.0 through v4.4.0=
. The fix caches the interface pointer before sending and uses it for all s= tatistics updates; the sibling commit 86e21665d46 fixes the identical bug i=
n ICMPv4.</td>
<td>2026-06-16</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10638" target=3D= "_blank" rel=3D"noopener">CVE-2026-10638</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>Zephyr's native TCP stack iterates the global connection list in net_tc= p_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SA=
FE macro, which caches a pointer to the next list node. Prior to this fix t=
he function released tcp_lock while invoking the per-connection callback an=
d re-acquired it afterwards. During that window a concurrent tcp_conn_relea= se(), running on the dedicated TCP work-queue thread when a connection's re= ference count drops to zero (e.g. a remote peer closing or resetting the co= nnection), can remove and k_mem_slab_free() the cached next connection. Whe=
n the iterator advances it dereferences the freed (and possibly reallocated=
) slab memory - a use-after-free that can crash the system (denial of servi= ce) and, if the slot has been reused, cause the callback to operate on an a= ttacker-influenced object (potential information disclosure or further faul= t). net_tcp_foreach() is reached in production via the 'net conn' network s= hell command and via net_tcp_close_all_for_iface() on interface-down; the f= reeing side is driven by ordinary TCP traffic. The fix moves the connection= /context teardown in tcp_conn_release() inside the tcp_lock critical sectio=
n and keeps tcp_lock held across the callback in net_tcp_foreach(). The def= ect was introduced with the modern (TCP2) stack in 2020 and affects release=
s up to and including v4.4.0.</td>
<td>2026-06-15</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10634" target=3D= "_blank" rel=3D"noopener">CVE-2026-10634</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/n= et/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_sen= d_data(), and then, on success, calls net_stats_update_icmp_sent(net_pkt_if= ace(reply)). net_try_send_data() transfers ownership of reply to the TX pat=
h (net_if_try_queue_tx - net_if_tx - L2/driver send, or the asynchronous ne= t_if_tx_thread), which can unref it to refcount 0 and return the struct net= _pkt to its slab (net_pkt_unref - k_mem_slab_free) before the stats line ru= ns. net_core.c documents this exact contract ('the pkt might contain garbag=
e already ... do not use pkt after that call'). The post-send net_pkt_iface= (reply) therefore reads reply-iface out of a freed (and possibly already re= allocated) net_pkt, a use-after-free read; with CONFIG_NET_STATISTICS_PER_I= NTERFACE the stats macro additionally increments a counter through that val= ue, i.e. a dereference/write through a stale or recycled-slot pointer. The = path is reached unauthenticated by any remote host that pings the device (n= et_icmpv4_input - net_icmp_call_ipv4_handlers - icmpv4_handle_echo_request)=
and is gated on CONFIG_NET_STATISTICS_ICMP. Impact is a probabilistic read=
of recycled packet memory plus a possible wild-pointer write under a timin=
g race, leading most likely to corrupted interface statistics or a remotely=
triggerable crash (DoS). The defect was introduced in 2019 (v1.14) and is = present through v4.4.0. The companion change in net_icmpv4_send_error() is = not a use-after-free because it reads net_pkt_iface(orig), the caller-owned=
received packet, which stays alive across the send. The fix caches the int= erface pointer from the live received packet before sending and uses it for=
the post-send stats updates.</td>
<td>2026-06-16</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10639" target=3D= "_blank" rel=3D"noopener">CVE-2026-10639</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6= _send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-int= erface ICMP-sent statistics by calling net_pkt_iface(pkt) after net_send_da= ta(pkt) had already returned successfully. On the success path the network = stack owns and releases the packet's reference (the L2/driver send unrefs i=
t, e.g. ethernet_send - net_pkt_unref), so for a freshly allocated packet w= ith refcount 1 the net_pkt slab block can be freed before the statistics li=
ne runs (synchronously when no TX queue thread is configured, or via a conc= urrent TX thread otherwise). The subsequent net_pkt_iface(pkt) reads pkt-if= ace from the freed slab block, and with CONFIG_NET_STATISTICS_PER_INTERFACE=
enabled that loaded pointer is dereferenced to increment iface-stats.icmp.= sent, a use-after-free (CWE-416). If the slab block was reallocated in the = meantime the read/increment targets unrelated or attacker-influenced memory=
, yielding corrupted statistics, a fault/crash (denial of service), or pote= ntial limited memory corruption. The vulnerable Neighbor Advertisement path=
is reachable by any unauthenticated on-link node simply by sending ICMPv6 = Neighbor Solicitations to a Zephyr node with native IPv6 enabled (handle_ns= _input - net_ipv6_send_na). Affected from v3.3.0 through v4.4.0; the fix us=
es the already-available iface argument instead of touching the sent packet=
. Configurations without per-interface statistics dereference only a global=
counter and are not affected by the memory-safety aspect.</td> <td>2026-06-16</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10640" target=3D= "_blank" rel=3D"noopener">CVE-2026-10640</a></td>
</tr>
<td class=3D"vendor-product">zhilink ()--ADP Application Developer Platform= </td>
<td>A vulnerability was found in zhilink =C3=A6=E2=84=A2=C2=BA=C3=A4=C2=BA= =E2=80=99=C3=A8=C2=81=E2=80=9D(=C3=A6=C2=B7=C2=B1=C3=A5=C5=93=C2=B3)=C3=A7= =C2=A7=E2=80=98=C3=A6=C5=A0=E2=82=AC=C3=A6=C5=93=E2=80=B0=C3=A9=E2=84=A2=C2= =90=C3=A5=E2=80=A6=C2=AC=C3=A5=C2=8F=C2=B8 ADP Application Developer Platfo=
rm =C3=A5=C2=BA=E2=80=9D=C3=A7=E2=80=9D=C2=A8=C3=A5=C2=BC=E2=82=AC=C3=A5=C2= =8F=E2=80=98=C3=A8=E2=82=AC=E2=80=A6=C3=A5=C2=B9=C2=B3=C3=A5=C2=8F=C2=B0 1.= 0.0. This affects an unknown part of the component testConnection Endpoint.=
The manipulation of the argument jdbcUrl results in deserialization. The a= ttack may be performed from remote. The exploit has been made public and co= uld be used. The vendor was contacted early about this disclosure but did n=
ot respond in any way.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12787" target=3D= "_blank" rel=3D"noopener">CVE-2026-12787</a></td>
</tr>
<td class=3D"vendor-product">zhilink ()--ADP Application Developer Platform= </td>
<td>A vulnerability was determined in zhilink =C3=A6=E2=84=A2=C2=BA=C3=A4= =C2=BA=E2=80=99=C3=A8=C2=81=E2=80=9D(=C3=A6=C2=B7=C2=B1=C3=A5=C5=93=C2=B3)= =C3=A7=C2=A7=E2=80=98=C3=A6=C5=A0=E2=82=AC=C3=A6=C5=93=E2=80=B0=C3=A9=E2=84= =A2=C2=90=C3=A5=E2=80=A6=C2=AC=C3=A5=C2=8F=C2=B8 ADP Application Developer = Platform =C3=A5=C2=BA=E2=80=9D=C3=A7=E2=80=9D=C2=A8=C3=A5=C2=BC=E2=82=AC=C3= =A5=C2=8F=E2=80=98=C3=A8=E2=82=AC=E2=80=A6=C3=A5=C2=B9=C2=B3=C3=A5=C2=8F=C2= =B0 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/ba= se/barcodeDetail/import of the component XML Parser. This manipulation caus=
es xml external entity reference. It is possible to initiate the attack rem= otely. The exploit has been publicly disclosed and may be utilized. The ven= dor was contacted early about this disclosure but did not respond in any wa= y.</td>
<td>2026-06-21</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12788" target=3D= "_blank" rel=3D"noopener">CVE-2026-12788</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"low_v">
<h2 id=3D"low_v_title">Low Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Low Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">Black Lantern Security--BBOT</td>
<td>The docker_pull module uses the realm parameter from a Docker registry'=
s WWW-Authenticate response header as the authentication endpoint without v= alidation. An attacker in a man-in-the-middle position between bbot and a D= ocker registry could modify this header to redirect the authentication requ= est to an arbitrary endpoint, potentially leaking authentication tokens.</t=
<td>2026-06-17</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12566" target=3D= "_blank" rel=3D"noopener">CVE-2026-12566</a></td>
</tr>
<td class=3D"vendor-product">Black Lantern Security--BBOT</td>
<td>The github_workflows module constructs local directory paths from user-= controlled repository names without validating for symlinks. A local attack=
er sharing the scan directory can plant a symlink at the predictable output=
path, causing workflow data to be written to an attacker-chosen location.<=
<td>2026-06-17</td>
<td>2.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12567" target=3D= "_blank" rel=3D"noopener">CVE-2026-12567</a></td>
</tr>
<td class=3D"vendor-product">Browerbase--Browserbase</td>
<td>A security flaw has been discovered in Browserbase up to 20260526. This=
impacts an unknown function of the component Autobrowse Trace Artifact Han= dler. The manipulation results in incorrect default permissions. The attack=
requires a local approach. The exploit has been released to the public and=
may be used for attacks. The vendor was contacted early about this disclos= ure but did not respond in any way.</td>
<td>2026-06-21</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12823" target=3D= "_blank" rel=3D"noopener">CVE-2026-12823</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authentication logic flaw: a user wit=
h permission to manage team or organization security settings can enable ma= ndatory two-factor authentication for all team members without first enabli=
ng 2FA on their own account. The application fails to verify the initiator'=
s 2FA status before allowing the policy change, resulting in inconsistent s= ecurity enforcement, potential administrative misuse, and lockout risk for = team members.</td>
<td>2026-06-20</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56212" target=3D= "_blank" rel=3D"noopener">CVE-2026-56212</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matc= hing for app_id lookup in the preview subdomain resolver, allowing undersco=
re characters in app_id to act as SQL wildcards. Attackers can create apps = with app_ids differing by one character at underscore positions to cause un= intended pattern matches, breaking preview functionality for legitimate app=
s or causing app-id confusion.</td>
<td>2026-06-20</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56325" target=3D= "_blank" rel=3D"noopener">CVE-2026-56325</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an open redirect vulnerability in stripe= _portal and stripe_checkout endpoints that accept unvalidated callbackUrl, = successUrl, and cancelUrl parameters. Authenticated attackers can craft mal= icious billing URLs to redirect users to attacker-controlled domains for ph= ishing and credential harvesting.</td>
<td>2026-06-20</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56330" target=3D= "_blank" rel=3D"noopener">CVE-2026-56330</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex</td>
<td>Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper N= eutralization of Special Elements used in an SQL Command ('SQL Injection') = vulnerability. A low privileged attacker with adjacent network access could=
potentially exploit this vulnerability, leading to information disclosure.= </td>
<td>2026-06-17</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35068" target=3D= "_blank" rel=3D"noopener">CVE-2026-35068</a></td>
</tr>
<td class=3D"vendor-product">GNU--Savane</td>
<td>GNU Savannah Administration Savane through 3.17 uses untrusted data as = part of authorization.</td>
<td>2026-06-20</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56355" target=3D= "_blank" rel=3D"noopener">CVE-2026-56355</a></td>
</tr>
<td class=3D"vendor-product">HCL Software--iControl</td>
<td>HCL iControl was affected by Inadequate Session Timeout vulnerability. = The vulnerability involves a security risk where a web application fails to=
automatically terminate user sessions after a period of inactivity</td> <td>2026-06-17</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-62340" target=3D= "_blank" rel=3D"noopener">CVE-2025-62340</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an inte= ger overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in co= ders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Process= ing a crafted PSB file can lead to information disclosure or a crash.</td> <td>2026-06-21</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56367" target=3D= "_blank" rel=3D"noopener">CVE-2026-56367</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap = out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file = can trigger a one-byte heap out-of-bounds read during image decoding, resul= ting in denial of service and potential disclosure of an adjacent heap byte= .</td>
<td>2026-06-21</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56378" target=3D= "_blank" rel=3D"noopener">CVE-2026-56378</a></td>
</tr>
<td class=3D"vendor-product">Intelbras--iNVU 7016 FT</td>
<td>A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build=
2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/sy= slog/ of the component Web Interface. Executing a manipulation can lead to = path traversal. The attack can be launched remotely. The exploit has been p= ublished and may be used. It is recommended to upgrade the affected compone= nt. The vendor was contacted early, responded in a very professional manner=
and quickly released a fixed version of the affected product.</td> <td>2026-06-15</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12211" target=3D= "_blank" rel=3D"noopener">CVE-2026-12211</a></td>
</tr>
<td class=3D"vendor-product">Intelliants--Subrion CMS</td>
<td>A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. = Affected by this issue is some unknown functionality of the component Block=
s Endpoint. Such manipulation of the argument CSS class name leads to cross=
site scripting. The attack may be launched remotely. The exploit has been = disclosed to the public and may be used. The vendor was contacted early abo=
ut this disclosure but did not respond in any way.</td>
<td>2026-06-15</td>
<td>2.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12202" target=3D= "_blank" rel=3D"noopener">CVE-2026-12202</a></td>
</tr>
<td class=3D"vendor-product">NI--grpc-device</td>
<td>There is an incorrect conversion between numeric types vulnerability in=
NI grpc-device due to missing range checks in=C2=A0CodeGen.=C2=A0 This may=
silently discard high bits if a size value exceeded the target type's rang=
e. This affects NI grpc-device 2.17.0 and prior versions.</td> <td>2026-06-19</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9143" target=3D"= _blank" rel=3D"noopener">CVE-2026-9143</a></td>
</tr>
<td class=3D"vendor-product">OliveTin--OliveTin</td>
<td>OliveTin gives access to predefined shell commands from a web interface=
. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in = service/internal/api/api.go does not perform any authentication or authoriz= ation checks. Unlike all other data-returning API endpoints, it does not ca=
ll auth.UserFromApiCall or checkDashboardAccess. When AuthRequireGuestsToLo= gin is enabled (the security-conscious configuration), this endpoint remain=
s accessible to unauthenticated users and can be used as an oracle to enume= rate valid action binding IDs and their argument configurations. This issue=
has been fixed in version 3000.13.0.</td>
<td>2026-06-15</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48709" target=3D= "_blank" rel=3D"noopener">CVE-2026-48709</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: VMSVGA device). The supported version that is affected is 7= .2.8. Easily exploitable vulnerability allows high privileged attacker with=
logon to the infrastructure where Oracle VM VirtualBox executes to comprom= ise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBo=
x, attacks may significantly impact additional products (scope change). Suc= cessful attacks of this vulnerability can result in unauthorized read acces=
s to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score = 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S= :C/C:L/I:N/A:N).</td>
<td>2026-06-16</td>
<td>3.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46815" target=3D= "_blank" rel=3D"noopener">CVE-2026-46815</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: VMSVGA device). The supported version that is affected is 7= .2.8. Easily exploitable vulnerability allows high privileged attacker with=
logon to the infrastructure where Oracle VM VirtualBox executes to comprom= ise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBo=
x, attacks may significantly impact additional products (scope change). Suc= cessful attacks of this vulnerability can result in unauthorized read acces=
s to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score = 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S= :C/C:L/I:N/A:N).</td>
<td>2026-06-16</td>
<td>3.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46816" target=3D= "_blank" rel=3D"noopener">CVE-2026-46816</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: Core). The supported version that is affected is 7.2.8. Eas= ily exploitable vulnerability allows high privileged attacker with logon to=
the infrastructure where Oracle VM VirtualBox executes to compromise Oracl=
e VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attack=
s may significantly impact additional products (scope change). Successful a= ttacks of this vulnerability can result in unauthorized read access to a su= bset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Conf= identiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:= N/A:N).</td>
<td>2026-06-16</td>
<td>3.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46874" target=3D= "_blank" rel=3D"noopener">CVE-2026-46874</a></td>
</tr>
<td class=3D"vendor-product">Oracle Corporation--Oracle VM VirtualBox</td> <td>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualizat= ion (component: VMSVGA device). The supported version that is affected is 7= .2.8. Easily exploitable vulnerability allows high privileged attacker with=
logon to the infrastructure where Oracle VM VirtualBox executes to comprom= ise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBo=
x, attacks may significantly impact additional products (scope change). Suc= cessful attacks of this vulnerability can result in unauthorized read acces=
s to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score = 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S= :C/C:L/I:N/A:N).</td>
<td>2026-06-16</td>
<td>3.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46977" target=3D= "_blank" rel=3D"noopener">CVE-2026-46977</a></td>
</tr>
<td class=3D"vendor-product">pgadmin.org--pgAdmin 4</td>
<td>HTML injection in pgAdmin 4's cloud deployment module. The verify_crede= ntials, deploy, regions, and update-server endpoints under /rds/, /azure/, = /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Goog=
le SDK exception text - and the related file-resolution and database-commit=
exception text - into the JSON response body (the info and errormsg fields=
) without HTML-encoding. The Cloud Wizard frontend rendered these strings t= hrough html-react-parser, so an attacker-influenced exception message embed= ded structural HTML directly into the wizard's DOM. The reported entry poin=
t is /rds/verify_credentials/. An authenticated pgAdmin user submits a craf= ted access_key whose value contains an <iframe/src=3D...> payload; AW=
S STS rejects the credential with an IncompleteSignature exception whose te=
xt quotes the access_key verbatim; the pgAdmin backend forwards that text i= nto the JSON info field; the Cloud Wizard's FormFooterMessage parses it as = HTML. The browser fetches the iframe's src from an attacker-controlled host=
, and JavaScript executing inside the cross-origin iframe writes to parent.= location, redirecting the victim's pgAdmin tab. Because the injection rende=
rs inside pgAdmin's own interface, X-Frame-Options and Content-Security-Pol= icy frame-ancestors do not mitigate it. Baseline impact is self-targeted (t=
he same user who supplied the payload sees the injection); escalation again=
st other authenticated users requires an additional cross-site request-forg= ery primitive capable of submitting the malformed credential request with a=
valid X-pgA-CSRFToken in the victim's browser context. The same unsanitise= d-error-into-JSON pattern was present across multiple sibling endpoints - A= zure's check_cluster_name_availability, every Google endpoint that surfaces=
SDK errors (verification_ack, projects, regions, instance_types, database_= versions, the verify_credentials path-resolution branches), the central /de= ploy endpoint that bubbles str(e) from deploy_on_rds / deploy_on_azure / de= ploy_on_google, and update_cloud_server which surfaces the str(e) from a fa= iling db.session.commit - all of which are now covered. Fix HTML-escapes ev= ery external/SDK exception string at the endpoint sink via a new shared san= itize_external_text helper (HTML escape with control-character strip), prom= oted out of the psycopg3 driver into web/pgadmin/utils/text_sanitize.py. Th=
e Cloud Wizard frontend additionally renders its FormFooterMessage in plain= -text mode for backend-derived strings, so the value is never parsed as HTM=
L even if a future sink forgets the escape. This issue affects pgAdmin 4: f= rom 6.6 before 9.16.</td>
<td>2026-06-18</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12047" target=3D= "_blank" rel=3D"noopener">CVE-2026-12047</a></td>
</tr>
<td class=3D"vendor-product">pontedilana--php-weasyprint</td>
<td>PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an=
HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is=
a public array, and `removeTemporaryFiles()` - invoked from `__destruct()`=
and from a registered shutdown function - calls `unlink()` on every entry = without verifying that the path is contained within the temporary folder. A=
ny code holding a reference to a generator instance can push an arbitrary p= ath into the array and have it deleted on script shutdown. This mirrors the=
KnpLabs/snappy issue GHSA-87qc-37cw-84h4. PhpWeasyPrint version 2.6.0 cont= ains a patch for the issue.</td>
<td>2026-06-19</td>
<td>3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49358" target=3D= "_blank" rel=3D"noopener">CVE-2026-49358</a></td>
</tr>
<td class=3D"vendor-product">Radware--Cyber Controller</td>
<td>A security vulnerability has been detected in Radware Cyber Controller =
up to 10.11.0. This affects an unknown part of the component HTML Report Ge= neration. The manipulation leads to HTML injection. Remote exploitation of = the attack is possible. The exploit has been disclosed publicly and may be = used. The vendor was contacted early about this disclosure but did not resp= ond in any way.</td>
<td>2026-06-21</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12812" target=3D= "_blank" rel=3D"noopener">CVE-2026-12812</a></td>
</tr>
<td class=3D"vendor-product">Snes9X team--Snes9X</td>
<td>snes9x 1.63 allows an out-of-bounds write and denial of service via a c= rafted .ups file.</td>
<td>2026-06-17</td>
<td>2.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39199" target=3D= "_blank" rel=3D"noopener">CVE-2026-39199</a></td>
</tr>
<td class=3D"vendor-product">SteeltoeOSS--Steeltoe.Configuration.Encryption= </td>
<td>Steeltoe is an open source project that provides a collection of librar= ies that helps users build cloud-native applications. In Steeltoe.Configura= tion.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=3DO= AEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle tran= sformation string, the `OAEP` setting selects PKCS#1 v1.5, which is the sam=
e algorithm as the `DEFAULT` setting. Steeltoe.Configuration.Encryption ver= sion 4.2.0 patches the issue.</td>
<td>2026-06-17</td>
<td>1.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50268" target=3D= "_blank" rel=3D"noopener">CVE-2026-50268</a></td>
</tr>
<td class=3D"vendor-product">stiofansisland--UsersWP Front-end login form, = User Registration, User Profile & Members Directory plugin for WP</td> <td>The UsersWP - Front-end login form, User Registration, User Profile &am=
p; Members Directory plugin for WP plugin for WordPress is vulnerable to In= secure Direct Object Reference in all versions up to, and including, 1.2.63=
via the 'user_id' parameter due to missing validation on a user controlled=
key. This makes it possible for authenticated attackers, with editor-level=
access and above, to reset and permanently delete the avatar or banner ima=
ge of any arbitrary user, including administrators, by clearing their avata= r_thumb or banner_thumb metadata in the uwp_usermeta table.</td> <td>2026-06-18</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12102" target=3D= "_blank" rel=3D"noopener">CVE-2026-12102</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: When undici parses a Set-Cookie header, it accepts any SameSite=
attribute value that contains Strict, Lax, or None as a substring, rather = than the case-insensitive exact match specified by RFC 6265. Non-spec value=
s are silently mapped to one of the three standard tokens. For example, Sam= eSite=3DNoneOfYourBusiness is parsed as None (the most permissive setting),=
and SameSite=3DStrictLax is parsed as Lax (a downgrade from Strict). Affec= ted applications are those that consume Set-Cookie headers from server resp= onses (for example via undici's fetch or proxy code paths) and then forward=
or rely on the parsed sameSite attribute. A malicious or non-compliant ser= ver can coerce the consumer's view of a cookie's SameSite policy to a weake=
r value, silently degrading the SameSite enforcement the cookie is supposed=
to provide. This was introduced in undici 5.15.0 when the cookies feature = was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workaroun= ds: After parsing a Set-Cookie header, validate that the resulting sameSite=
attribute is one of 'Strict', 'Lax', or 'None' (exact, case-insensitive) b= efore forwarding or relying on it.</td>
<td>2026-06-17</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11525" target=3D= "_blank" rel=3D"noopener">CVE-2026-11525</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>Impact: Undici's HTTP/1.1 client is vulnerable to response queue poison= ing on reused keep-alive sockets. An attacker-controlled upstream server ca=
n inject an unsolicited HTTP/1.1 response onto an idle socket after a reque=
st completes. When the client dispatches the next request on that socket, i=
t associates the injected response with the new request, causing responses =
to be delivered to the wrong requests. This requires an attacker-controlled=
or compromised upstream HTTP/1.1 server and keep-alive connection reuse. P= atches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable = keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or=
Pool.</td>
<td>2026-06-17</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6733" target=3D"= _blank" rel=3D"noopener">CVE-2026-6733</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp=
.c read the network interface back out of the packet via net_pkt_iface(pkt)=
after the packet had been handed to net_send_data(). On the successful-sen=
d path the packet's last reference may already have been released by the L2=
driver or by the network stack's TX handling (synchronously in the default=
NET_TC_TX_COUNT=3D0 immediate-transmit configuration), returning the net_p=
kt slab block to its free list. The subsequent net_pkt_iface(pkt) dereferen= ces the freed packet, a use-after-free read; with CONFIG_NET_STATISTICS_PER= _INTERFACE the resulting dangling interface pointer is further dereferenced=
for a statistics-counter write. The IGMP send path is reachable without au= thentication from inbound IPv4 IGMP membership queries addressed to 224.0.0=
.1 (net_ipv4_igmp_input - send_igmp_report/send_igmp_v3_report - igmp_send)=
, as well as from local multicast join/leave/rejoin operations. Realistic i= mpact is undefined behavior and potential denial of service (sporadic crash=
or stats corruption); a controllable write requires the asynchronous TX pa=
th plus a concurrent slab reuse. The flaw was introduced with IGMPv2 suppor=
t and affects releases from v2.6.0 through v4.4.0. The fix caches the inter= face pointer before sending. Note the analogous IPv6 MLD path (mld_send in = subsys/net/ip/ipv6_mld.c) retains the same unfixed pattern.</td> <td>2026-06-16</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10636" target=3D= "_blank" rel=3D"noopener">CVE-2026-10636</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"snya_v">
<h2 id=3D"snya_v_title">Severity Not Yet Assigned</h2>
<table id=3D"table_severity_not_yet_assigned" class=3D"table no-tablesaw" s= tyle=3D"table-layout: fixed; width: 100%;" border=3D"1" summary=3D"Severity=
Not Yet Assigned">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">AcademySoftwareFoundation--openexr</td> <td>OpenEXR is the reference implementation and specification for the EXR i= mage format, widely used in the motion picture industry. In versions 3.4.0 = through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl=
() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The ht_undo= _imp function copies decoded pixels out of a per-line OpenJPH buffer using = the EXR channel's declared width as the iteration count. The codestream emb= edded in the EXR chunk can declare different (smaller) tile/line dimensions=
than the EXR header advertises, but ht_undo_impl() does not validate this =
- it pulls width 32-bit samples from cur_line->i32[] without checking th=
e OpenJPH line buffer's actual length. A crafted EXR file produces a 4-byte=
heap-buffer-overflow READ immediately after a buffer allocated by ojph::lo= cal::codestream::finalize_alloc(). The bug is reachable through the standar=
d scanline-decode entry point used by every consumer of exr_decoding_run/Im= f::checkOpenEXRFile, including thumbnailers, asset pipelines, and the exrch= eck utility - i.e. any application that opens untrusted EXR files. The resu=
lt is a deterministic crash (DoS) and potential adjacent-heap leak. This is= sue has been fixed in version 3.4.12.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45696" target=3D= "_blank" rel=3D"noopener">CVE-2026-45696</a></td>
</tr>
<td class=3D"vendor-product">ail-project--ail-framework</td>
<td>AIL framework contains a path traversal vulnerability in the /objects/i= tem/diff endpoint. The endpoint accepts item identifiers through the s1 and=
s2 query parameters and, prior to the fix, attempted to retrieve and compa=
re item contents without first verifying that both referenced items existed=
as valid AIL objects. An authenticated AIL user could craft malicious item=
identifiers containing path traversal sequences to cause the application t=
o read gzip-compressed files accessible to the AIL process. This could resu=
lt in unauthorized disclosure of local file contents, limited to files read= able by the application and compatible with the expected gzip-compressed it=
em format. The issue was fixed by validating that both requested items exis=
t before their contents are accessed.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56138" target=3D= "_blank" rel=3D"noopener">CVE-2026-56138</a></td>
</tr>
<td class=3D"vendor-product">Andrei Marcu--Andrei Marcu linx-server v2.3.8<=
<td>An issue in the uploadPostHandler component of Andrei Marcu linx-server=
v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted P= OST request.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50879" target=3D= "_blank" rel=3D"noopener">CVE-2026-50879</a></td>
</tr>
<td class=3D"vendor-product">Android--Android</td>
<td>In Contacts Provider, there is a possible way to access the contacts da= tabase due to SQL injection. This could lead to local information disclosur=
e with no additional execution privileges needed. User interaction is not n= eeded for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-28576" target=3D= "_blank" rel=3D"noopener">CVE-2026-28576</a></td>
</tr>
<td class=3D"vendor-product">anna-is-cute--paste v0.1.1</td>
<td>An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 al= lows attackers to cause a Denial of Service (DoS) via a crafted POST reques= t.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50882" target=3D= "_blank" rel=3D"noopener">CVE-2026-50882</a></td>
</tr>
<td class=3D"vendor-product">ANSSI--DFIR-ORC</td>
<td>Local privilege escalation by loading DLLs from a shared temporary dire= ctory in ANSSI's DFIR-ORC, versions 10.2.7 and prior. An attacker with prio=
r access to the system, can place a malicious DLL in C:\Windows\Temp and wa=
it for the application to be executed. Because DFIR-ORC is extracted and ex= ecuted from that location with administrative privileges, the malicious lib= rary can be loaded automatically, allowing the attacker to gain administrat=
or privileges on the affected machine.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11958" target=3D= "_blank" rel=3D"noopener">CVE-2026-11958</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow SFT=
P provider</td>
<td>A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / = `SFTPOperator(operation=3Dget)`) let a malicious or compromised remote SFTP=
server write files outside the configured local destination directory via = crafted directory-entry names. No Airflow account is required - the attack = surface is any deployment downloading directories from an untrusted SFTP se= rver. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50203" target=3D= "_blank" rel=3D"noopener">CVE-2026-50203</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Improper Input Validation vulnerability in Apache APISIX. The attacker = can take advantage of certain configuration in forward-auth plugin to spoof=
identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.= 16.0. Users are recommended to upgrade to version 3.17.0, which fixes the i= ssue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39998" target=3D= "_blank" rel=3D"noopener">CVE-2026-39998</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Authentication Bypass by Spoofing vulnerability in Apache APISIX. The a= ttacker can completely bypass authentication capitalising on certain config= urations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 th= rough v3.16.0. Users are recommended to upgrade to version v3.17.0, which f= ixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39999" target=3D= "_blank" rel=3D"noopener">CVE-2026-39999</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can=
take advantage of wolf-rbac plugin under default configuration to potentia= lly pollute logs with spoofed identity information and exploit IP based acc= ess control rules. This issue affects Apache APISIX: from 1.2.0 through 3.1= 6.0. Users are recommended to upgrade to version 3.17.0, which fixes the is= sue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44046" target=3D= "_blank" rel=3D"noopener">CVE-2026-44046</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Insufficient Verification of Data Authenticity vulnerability in Apache = APISIX. The openid-connect plugin under default configuration has an attack=
surface that allows the attacker to spoof identity headers allowing the at= tacker to get unauthorized access the protected resources. This issue affec=
ts Apache APISIX: from 2.3 through 3.16.0. Users are recommended to upgrade=
to version 3.17.0, which fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44087" target=3D= "_blank" rel=3D"noopener">CVE-2026-44087</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Ap= ache APISIX. The default configuration of cas-auth in Apache APISIX is vuln= erable to phishing and credential theft. This issue affects Apache APISIX: = from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17= .0, which fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44915" target=3D= "_blank" rel=3D"noopener">CVE-2026-44915</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Incorrect Authorization vulnerability in Apache APISIX. An attacker can=
capitalise on authz-casdoor plugin under default configuration to authenti= cate themselves with credentials from a different source. This issue affect=
s Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgra=
de to version 3.17.0, which fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47339" target=3D= "_blank" rel=3D"noopener">CVE-2026-47339</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Authentication Bypass by Capture-replay vulnerability in Apache APISIX.=
Attacker can benefit from certain configurations in hmac-auth to re-use a = token forever, bypassing expiry. This issue affects Apache APISIX: from 3.1= 1.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, whi=
ch fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47341" target=3D= "_blank" rel=3D"noopener">CVE-2026-47341</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Ap= ache APISIX. The attacker could manipulate some client headers to perform a=
n open-redirect, to potentially expose the session token. This issue affect=
s Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrad=
e to version 3.17.0, which fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48895" target=3D= "_blank" rel=3D"noopener">CVE-2026-48895</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Improper Validation of Integrity Check Value vulnerability in Apache AP= ISIX. The jwe-decrypt plugin under default configuration is vulnerable to a= uthentication bypass.=C2=A0 This issue affects Apache APISIX: from 3.8.0 th= rough 3.16.0. Users are recommended to upgrade to version 3.17.0, which fix=
es the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49230" target=3D= "_blank" rel=3D"noopener">CVE-2026-49230</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Authentication Bypass by Spoofing vulnerability in opa plugin. An attac= ker could relay spoofed identity headers to upstream capitalising on non-de= fault configuration in opa plugin. This could allow the attacker to assume = higher privileges on the upstream service. This issue affects Apache APISIX=
: from 3.5.0 through 3.16.0. Users are recommended to upgrade to version 3.= 17.0, which fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49231" target=3D= "_blank" rel=3D"noopener">CVE-2026-49231</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin = under default configurations. This defect allows a=C2=A0remote attacker tha=
t manages to send a victim to a webpage controlled by them can cause the vi= ctim's browser to become authenticated as a different identity. Actions the=
victim takes upstream are then attributed to attackers identity. This issu=
e affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended t=
o upgrade to version 3.17.0, which fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49871" target=3D= "_blank" rel=3D"noopener">CVE-2026-49871</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache APISIX</td> <td>Improper Authentication vulnerability in Apache APISIX. When the cas-au=
th plugin is used in a route, an attacker can possibly authenticate itself = with credentials from a different source. This issue affects Apache APISIX:=
from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.1= 7.0, which fixes the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49872" target=3D= "_blank" rel=3D"noopener">CVE-2026-49872</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache DolphinSche= duler</td>
<td>DataSource API Missing Authorization Check Leads to Arbitrary Data Sour=
ce Metadata Disclosure in Apache DolphinScheduler. This issue affects Apach=
e DolphinScheduler: before 3.4.2. Users are recommended to upgrade to versi=
on 3.4.2, which fixes the issue.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32966" target=3D= "_blank" rel=3D"noopener">CVE-2026-32966</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache DolphinSche= duler</td>
<td>Incorrect Authorization vulnerability of `/v2` experimental interface i=
n Apache DolphinScheduler. This issue affects Apache DolphinScheduler: befo=
re 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes th=
e issue.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32967" target=3D= "_blank" rel=3D"noopener">CVE-2026-32967</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache DolphinSche= duler</td>
<td>Incorrect Authorization vulnerability allows users with system login pr= ivileges to delete task definitions in unauthorized projects This issue aff= ects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended=
to upgrade to version 3.4.2, which fixes this issue.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41280" target=3D= "_blank" rel=3D"noopener">CVE-2026-41280</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache DolphinSche= duler</td>
<td>Incorrect Authorization vulnerability allows users to access workflow i= nstance information belonging to projects they do not have permission to ac= cess. This issue affects Apache DolphinScheduler versions prior to 3.4.2. U= sers are recommended to upgrade to version 3.4.2, which fixes this issue.</=
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42357" target=3D= "_blank" rel=3D"noopener">CVE-2026-42357</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache DolphinSche= duler</td>
<td>Allow authenticated users to access alert instances associated with ale=
rt groups they do not have permission to access. in Apache DolphinScheduler=
. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recom= mended to upgrade to version 3.4.2, which fixes the issue.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47340" target=3D= "_blank" rel=3D"noopener">CVE-2026-47340</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Shiro</td> <td>A remote attacker can inject LDAP special characters into the Distingui= shed Name (DN) construction in DefaultLdapRealm class. User-supplied userna=
me input is directly concatenated into the LDAP DN template without any esc= aping of RFC 2253 special characters. This allows an attacker to manipulate=
the DN structure used for LDAP bind authentication, potentially bypassing = authentication or impersonating other users. This issue affects all Apache = Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using=C2=A0DefaultLdap= Realm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes = the issue.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49268" target=3D= "_blank" rel=3D"noopener">CVE-2026-49268</a></td>
</tr>
<td class=3D"vendor-product">authelia--authelia</td>
<td>Authelia is an open-source authentication and authorization server prov= iding two-factor authentication and single sign-on (SSO) for applications v=
ia a web portal. In versions 4.38.0 through 4.39.19, when a user authentica= tes via Basic Auth (i.e via the `Authorization` header with the `Basic` sch= eme) on the authz verification endpoint, Authelia takes the username direct=
ly from the `Authorization` header and passes it as is to the regulation sy= stem for ban checking and attempt recording. LDAP treats usernames case ins= ensitively : `john`, `John`, and `JOHN` all bind as the same user. But the = regulation SQL queries treat the lookup of these values in certain scenario=
s as case sensitive. This allows each variation of a usernames case to have=
its own ban bucket. Upgrade to 4.39.20 to receive a patch. As a workaround=
, explicitly disable the basic auth mechanism.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47203" target=3D= "_blank" rel=3D"noopener">CVE-2026-47203</a></td>
</tr>
<td class=3D"vendor-product">authelia--authelia</td>
<td>Authelia is an open-source authentication and authorization server prov= iding two-factor authentication and single sign-on (SSO) for applications v=
ia a web portal. In versions 4.36.0 through 4.39.19, due to lack of canonic= alization of domains in very specific edge cases, an access control rule ma=
y be skipped when it should match a request. The specific conditions that c= ould lead to a security issue for vulnerability are: 1. The specific target=
resource of the attack must be using the forwarded authorization integrati= on; 2. The requested domain must have two additional segments compared to a=
session domain i.e. `a.b.example.com` is requested, but the session domain=
is `example.com`; 3. There access control rules must specify two separate = rules which both contain inexact domain matches such as `*.b.example.com` a=
nd `*.example.com` i.e. wildcards, username matches, group matches; 4. The = rules must be in order of most specific domain to least specific domain; 5.=
The second rule must be more permissive than the first rule; 6. The attack=
er must specifically request a URL for the more specific domain, with the s= econd part containing one or more capitalized letters i.e. `
https://a.B.exa= mple.com` and no other segment with capitalized letters; 7. The integration=
used must not be the Envoy ExtAuthz integration; and 8. The proxy must not=
canonicalize the requested host name in the relevant header before sending=
it to the relevant authorization endpoint. The kind of configuration used =
to produce this issue and result in a `bypass` rule being matched has long = been highly discouraged. Essentially hosts which should be bypassed entirel=
y should not be secured by having the proxy check them with the authorizati=
on handlers. Upgrade to 4.39.20 to receive a patch.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48794" target=3D= "_blank" rel=3D"noopener">CVE-2026-48794</a></td>
</tr>
<td class=3D"vendor-product">AzeoTech--DAQFactory</td>
<td>In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulner= ability can be exploited by an attacker using specially crafted .ctl files = which can result in code execution.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12390" target=3D= "_blank" rel=3D"noopener">CVE-2026-12390</a></td>
</tr>
<td class=3D"vendor-product">Ben Busby--whoogle-search v1.2.3</td>
<td>An information disclosure vulnerability in the configuration endpoint o=
f Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive info= rmation via a crafted GET request.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50870" target=3D= "_blank" rel=3D"noopener">CVE-2026-50870</a></td>
</tr>
<td class=3D"vendor-product">Benjamin Jonard Koillection--Benjamin Jonard K= oillection v1.8.0</td>
<td>An authenticated Server-Side Request Forgery (SSRF) in the custom scrap=
er subsystem component of Benjamin Jonard Koillection v1.8.0 allows attacke=
rs to scan internal resources via supplying a crafted URL.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50888" target=3D= "_blank" rel=3D"noopener">CVE-2026-50888</a></td>
</tr>
<td class=3D"vendor-product">Bernd Bestel--grocy v4.6.0</td>
<td>Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vul= nerability in the product-group parameter at /stockreports/spendings. This = vulnerability allows attackers to access sensitive database information via=
a crafted SQL statement.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50890" target=3D= "_blank" rel=3D"noopener">CVE-2026-50890</a></td>
</tr>
<td class=3D"vendor-product">BIAFRA--Dancer2::Plugin::Auth::OAuth</td> <td>Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a=
predictable nonce. The default nonce was generated using an MD5 hash of th=
e epoch time, which is predictable.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11832" target=3D= "_blank" rel=3D"noopener">CVE-2026-11832</a></td>
</tr>
<td class=3D"vendor-product">Bludit--Bludit CMS</td>
<td>Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via=
the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugi= n.php fails to perform authorization checks and lacks file extension valida= tion. An attacker with a valid API token can upload a malicious PHP script = and execute arbitrary code on the server.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38329" target=3D= "_blank" rel=3D"noopener">CVE-2026-38329</a></td>
</tr>
<td class=3D"vendor-product">Bludit--Bludit v3.19.0</td>
<td>An issue in the api/plugin.php component of Bludit v3.19.0 allows attac= kers to execute a directory traversal via supplying a crafted request.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50869" target=3D= "_blank" rel=3D"noopener">CVE-2026-50869</a></td>
</tr>
<td class=3D"vendor-product">Bonsai--Bonsai v6.0</td>
<td>Incorrect access control in the impworks Bonsai v6.0 allows authenticat=
ed attackers with Editor privileges to escalate privileges to Administrator=
and execute unauthorized account, password, and configuration changes.</td=
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50881" target=3D= "_blank" rel=3D"noopener">CVE-2026-50881</a></td>
</tr>
<td class=3D"vendor-product">Boyleep--Boyleep K11</td>
<td>An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physicall=
y proximate attacker to execute arbitrary code via the factory test feature= .</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36933" target=3D= "_blank" rel=3D"noopener">CVE-2026-36933</a></td>
</tr>
<td class=3D"vendor-product">byrongamatos--slopsmith</td>
<td>Slopsmith is a self-contained web application for browsing, playing, an=
d practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a pa= th-traversal vulnerability in Slopsmith's archive extractors allows an atta= cker to write arbitrary files outside the extraction directory by supplying=
a crafted PSARC or sloppak archive. With the default Docker configuration = (running as root) and the ability to drop a file into the plugin directory,=
this escalates to arbitrary remote code execution on the host. Three archi=
ve extractors concatenated archive-entry filenames directly onto the extrac= tion root without validation: `lib/psarc.py::unpack_psarc` - PSARC TOC file= names; `lib/patcher.py::unpack_psarc` - duplicate of the above in the patch=
er flow; `lib/sloppak.py::_unpack_zip` - bare `ZipFile.extractall()` with n=
o member filter. Each accepts entry names containing `..` segments, absolut=
e paths, or backslash separators. The Python `zipfile` module's default `ex= tractall()` is documented as not preventing traversal when callers don't su= pply a member-filter callback. Version 0.2.9-alpha.5 patches the issue. Unt=
il updated, do not open PSARC or sloppak archives from untrusted sources, a=
nd do not expose the Slopsmith instance to the public internet. Docker user=
s should also pull the latest image after the next slopsmith Docker image i=
s published.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49290" target=3D= "_blank" rel=3D"noopener">CVE-2026-49290</a></td>
</tr>
<td class=3D"vendor-product">cakephp--cakephp</td>
<td>CakePHP is a rapid development framework for PHP. In versions 4.5.11 an=
d earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, = and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that th=
e resolved element path is within the application/plugin view template path=
s. When element names are created with specifically crafted user-supplied d= ata this weakness can be leveraged to include other PHP files on the server=
. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11= .</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48820" target=3D= "_blank" rel=3D"noopener">CVE-2026-48820</a></td>
</tr>
<td class=3D"vendor-product">Canonical--Microceph</td>
<td>Canonical MicroCeph versions from the squid and tentacle track are vuln= erable to a path traversal issue in the remote-import API. Holders of a tru= sted cluster mTLS certificate (such as enrolled cluster members) or join to= ken can manipulate files in an imported remote cluster within the /var/snap= /microceph confinement. This would allow daemon disruption and pollution of=
the cluster state.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10720" target=3D= "_blank" rel=3D"noopener">CVE-2026-10720</a></td>
</tr>
<td class=3D"vendor-product">Citrix--Citrix Cloud</td>
<td>In Citrix Cloud through 2025-11-10, an account with read-only access ca=
n trigger the beginning of a workflow for write operations, e.g., the syste=
m will send a one-time password to an attacker-controlled email address whe=
n the attacker attempts to reset the password of a user account.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-66391" target=3D= "_blank" rel=3D"noopener">CVE-2025-66391</a></td>
</tr>
<td class=3D"vendor-product">cursor--cursor</td>
<td>Cursor is a code editor built for programming with AI. In versions prio=
r to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook = commands from .claude/settings.local.json without dedicated user approval. =
A malicious workspace or agent-created file could configure hooks that run = local commands in the user's context when an agent turn ends. This could al= low sandbox escape, persistence across turns, local data access, or follow-=
on compromise. This issue has been fixed in version 3.0.0.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48124" target=3D= "_blank" rel=3D"noopener">CVE-2026-48124</a></td>
</tr>
<td class=3D"vendor-product">CursorTouch--Windows-MCP</td>
<td>Windows-MCP is an open-source project that integrates AI agents with Wi= ndows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP contr=
ol plane without authentication while enabling wildcard CORS (allow_origins= =3D*, allow_methods=3D*, allow_headers=3D*). Because the same server also e= xposed a PowerShell tool that executes caller-controlled commands as the Wi= ndows user running Windows-MCP, attackers could reach the control plane fro=
m arbitrary origins or non-browser clients and achieve arbitrary PowerShell=
execution. This issue was fixed in version 0.7.5.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48989" target=3D= "_blank" rel=3D"noopener">CVE-2026-48989</a></td>
</tr>
<td class=3D"vendor-product">Datadog, Inc--Vector v.0.54.0</td>
<td>Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection v= ulnerability in the set_uri_query parameter in the KeyPartitioner::partitio=
n function. This vulnerability allows attackers to access sensitive databas=
e information via crafted SQL statements.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39196" target=3D= "_blank" rel=3D"noopener">CVE-2026-39196</a></td>
</tr>
<td class=3D"vendor-product">Datadog, Inc--Vector v.0.54.0</td>
<td>An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v= 0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted re= quest or payload.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39197" target=3D= "_blank" rel=3D"noopener">CVE-2026-39197</a></td>
</tr>
<td class=3D"vendor-product">Deck9--Deck9 Input v2.0.1</td>
<td>Incorrect access control in the /{form}/webhooks/{webhook} endpoint of = Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or = delete another tenant's webhook via a crafted request.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50875" target=3D= "_blank" rel=3D"noopener">CVE-2026-50875</a></td>
</tr>
<td class=3D"vendor-product">Deck9--Deck9 Intput v2.0.1</td>
<td>A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows=
attackers to execute arbitrary web scripts or HTML via a crafted payload.<=
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50876" target=3D= "_blank" rel=3D"noopener">CVE-2026-50876</a></td>
</tr>
<td class=3D"vendor-product">Devolutions--Devolutions Server</td>
<td>Improper access control in PAM account discovery results in Devolutions=
Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve accoun=
t discovery scan results.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11890" target=3D= "_blank" rel=3D"noopener">CVE-2026-11890</a></td>
</tr>
<td class=3D"vendor-product">Devolutions--Devolutions Server</td>
<td>Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allow=
s an authenticated user to access attachments via folder duplication with i= nherited permissions.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12105" target=3D= "_blank" rel=3D"noopener">CVE-2026-12105</a></td>
</tr>
<td class=3D"vendor-product">Devolutions--Devolutions Server</td>
<td>Improper access control in the social login connection endpoint in Devo= lutions Server 2026.2.5 allows an authenticated vault member to enumerate s= ocial login entry metadata to which they are not authorized via a crafted A=
PI request.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12117" target=3D= "_blank" rel=3D"noopener">CVE-2026-12117</a></td>
</tr>
<td class=3D"vendor-product">Devolutions--Remote Desktop Manager</td> <td>Improper input validation in the SSH Elevate Shell feature in Devolutio=
ns Remote Desktop Manager 2026.2.7 allows an authenticated user with permis= sion to create or modify a shared SSH entry to execute arbitrary commands o=
n a remote SSH host using stored elevation credentials via a crafted altern= ate username and user interaction with the Elevate Shell action.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12161" target=3D= "_blank" rel=3D"noopener">CVE-2026-12161</a></td>
</tr>
<td class=3D"vendor-product">Devolutions--Remote Desktop Manager</td> <td>Improper host validation in the social login autofill feature in Devolu= tions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored=
social login credentials via a crafted web entry pointing to a provider lo= okalike domain.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12162" target=3D= "_blank" rel=3D"noopener">CVE-2026-12162</a></td>
</tr>
<td class=3D"vendor-product">Devolutions--UniGetUI</td>
<td>Use of an incorrectly resolved name or reference in the pinget backend =
in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community cata= log contributor to cause an installed application to be correlated to an un= related, attacker-controlled catalog package and to execute an attacker-con= trolled installer via a crafted catalog package whose normalized name is co= ntained as a substring within the installed application name when a user ap= plies the proposed update.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10696" target=3D= "_blank" rel=3D"noopener">CVE-2026-10696</a></td>
</tr>
<td class=3D"vendor-product">Docker--Docker Sandboxes</td>
<td>Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but doe=
s not apply it to DNS resolution: the per-network embedded DNS server forwa= rds any queried name to the host resolver whenever the network is internet-= connected, without consulting the policy. A workload inside a sandbox, whic=
h the threat model treats as untrusted, can therefore encode data into DNS = labels for an attacker-controlled domain and exfiltrate it through a DNS co= vert channel, bypassing the configured allowlist.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12039" target=3D= "_blank" rel=3D"noopener">CVE-2026-12039</a></td>
</tr>
<td class=3D"vendor-product">Docker--Docker Sandboxes</td>
<td>Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied on=
ly at network-creation time, and does not re-apply it to networks rebuilt f= rom disk when the Docker daemon restarts, so a restart-surviving sandbox fo= rwards ICMP to arbitrary hosts. A workload inside a sandbox, which the thre=
at model treats as untrusted, can therefore defeat the documented ICMP egre=
ss block to perform network reconnaissance and exfiltrate data over an ICMP=
covert channel, regardless of the configured allowlist.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12539" target=3D= "_blank" rel=3D"noopener">CVE-2026-12539</a></td>
</tr>
<td class=3D"vendor-product">dtwang--line-desktop-mcp</td>
<td>Line Desktop MCP is a project that, while unaffiliated with the officia=
l line-bot-mcp-server, allows users to directly operate the LINE Desktop ap= plication on Windows or Mac via MCP. `line-desktop-mcp` supports a `--http-= mode` Streamable HTTP transport for use with clients such as n8n. In this m= ode the server binds to `0.0.0.0` and exposes the MCP `/mcp` endpoint witho=
ut an MCP-layer authentication check. Prior to version 1.1.2, any network c= lient that can reach the port can initialize a session, list tools, and cal=
l tools that read LINE Desktop chat history or send LINE messages through t=
he already logged-in desktop application. Version 1.1.2 fixes the issue.</t=
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49357" target=3D= "_blank" rel=3D"noopener">CVE-2026-49357</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse 4diac</td>
<td>In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DEL= ETE connection command to the management interface can lead to a dangling p= ointer. This allows subsequent commands to access freed memory (use-after-f= ree).</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9158" target=3D"= _blank" rel=3D"noopener">CVE-2026-9158</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Theia</td>
<td>In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdow=
n image tags from AI responses, triggering HTTP requests to arbitrary exter= nal URLs without restriction. Combined with prompt injection in a malicious=
workspace, an attacker could induce the AI agent to construct image URLs e= ncoding sensitive information from the workspace or conversation context, e= xfiltrating it to attacker-controlled servers. The workspace trust enforcem= ent introduced in v1.71.0 mitigates the documented attack chain by disablin=
g AI features in untrusted workspaces.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22551" target=3D= "_blank" rel=3D"noopener">CVE-2026-22551</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Theia</td>
<td>In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed = workspace file and directory names as part of its prompt context without di= stinguishing them from system instructions. An attacker could craft a malic= ious repository with adversarial directory or file names that, when analyze=
d by the AI agent, would cause the agent to follow attacker-controlled inst= ructions (indirect prompt injection). Combined with other AI chat features = available in untrusted workspaces, this enabled attack chains leading to da=
ta exfiltration via Markdown image rendering or arbitrary command execution=
via task definitions.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44688" target=3D= "_blank" rel=3D"noopener">CVE-2026-44688</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Theia</td>
<td>In Eclipse Theia versions prior to 1.69.0, custom task definitions in w= orkspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be execut=
ed without requiring workspace trust. An attacker could craft a malicious r= epository that, when cloned and opened in Theia, leads to execution of arbi= trary commands with the user's privileges. In combination with AI chat feat= ures and a workspace .theia/settings.json that disabled tool confirmation, = this could be triggered automatically by sending a message in the AI chat.<=
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44691" target=3D= "_blank" rel=3D"noopener">CVE-2026-44691</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Theia</td>
<td>In Eclipse Theia versions prior to 1.71.0, files matching the pattern .= prompts/*.prompttemplate in a workspace were automatically loaded and could=
override or extend the AI agent's system prompts. An attacker could craft =
a malicious repository containing prompt template files that, when the work= space was opened in Theia, replaced the AI's system instructions with attac= ker-controlled content (indirect prompt injection). Combined with other AI = chat features available in untrusted workspaces, this enabled attack chains=
leading to data exfiltration via Markdown image rendering or arbitrary com= mand execution via task definitions.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46580" target=3D= "_blank" rel=3D"noopener">CVE-2026-46580</a></td>
</tr>
<td class=3D"vendor-product">elixir-grpc--grpc</td>
<td>Authorization Bypass Through User-Controlled Key vulnerability in elixi= r-grpc grpc allows authenticated attackers to access or modify resources be= longing to other users by smuggling a conflicting value for any path-bound = field via the query string or request body. In 'Elixir.GRPC.Server.Transcod= e':map_request/5 (lib/grpc/server/transcode.ex), all three clauses use Map.= merge/2 with path bindings as the first argument, giving them the lowest me= rge precedence. A request such as GET /users/me/profile?user_id=3Dvictim (o=
r a POST with {"user_id": "victim"} when body: "*") yields a decoded protob=
uf struct where the path-bound field carries the attacker-supplied value ra= ther than the router-extracted value. Any handler that uses the path-bound = field for authorization, multi-tenancy scoping, or ownership checks is sile= ntly bypassed. This issue affects grpc from 0.8.0 before 1.0.0.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48599" target=3D= "_blank" rel=3D"noopener">CVE-2026-48599</a></td>
</tr>
<td class=3D"vendor-product">elixir-grpc--grpc</td>
<td>Deserialization of Untrusted Data and Allocation of Resources Without L= imits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticat=
ed attackers to crash the BEAM node via atom table exhaustion and, when a d= ecoded term flows into a call site that invokes it, achieve remote code exe= cution on the server. 'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/= erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body wit= hout the :safe option, no size bound, and no type guard. Any unauthenticate=
d peer that sends a request with Content-Type: application/grpc+erlpack can=
send a crafted payload that mints arbitrary new atoms (which are never gar= bage-collected, exhausting the bounded atom table and crashing the VM) or t= hat encodes a fun term which, if applied anywhere downstream, executes atta= cker-controlled code inside the server process. This issue affects grpc fro=
m 0.4.0 before 1.0.0.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48853" target=3D= "_blank" rel=3D"noopener">CVE-2026-48853</a></td>
</tr>
<td class=3D"vendor-product">elixir-grpc--grpc</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in e= lixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memo=
ry and crash the server by streaming a large or slow-trickle unary request = body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_body/3 (lib/gr= pc/server/adapters/cowboy/handler.ex) accumulates every received chunk into=
a single growing binary with no size cap. Additionally, when the client om= its the grpc-timeout header, the per-chunk read timeout resolves to :infini= ty, allowing a slow-trickle client to keep the connection alive indefinitel=
y while memory grows. A single connection is sufficient to exhaust server m= emory and crash the node. This issue affects grpc from 0.3.1 before 1.0.0.<=
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48854" target=3D= "_blank" rel=3D"noopener">CVE-2026-48854</a></td>
</tr>
<td class=3D"vendor-product">elixir-grpc--grpc</td>
<td>Improper Handling of Highly Compressed Data (Data Amplification) vulner= ability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) al= lows a denial of service via a gzip decompression bomb. This vulnerability =
is associated with program files lib/grpc/compressor/gzip.ex, lib/grpc/mess= age.ex and program routines 'Elixir.GRPC.Compressor.Gzip':decompress/1, 'El= ixir.GRPC.Message':from_data/2. 'Elixir.GRPC.Compressor.Gzip':decompress/1 = calls :zlib.gunzip/1 directly on attacker-controlled bytes with no decompre= ssed-size limit, ratio check, or incremental decoding. Because this module =
is the registered gzip GRPC.Compressor implementation, it is invoked automa= tically whenever an incoming gRPC frame carries the grpc-encoding: gzip hea= der. :zlib.gunzip/1 allocates the entire decompressed result as a single bi= nary, so a small highly compressible payload (for example a few kilobytes o=
f zeros, which gzip compresses at roughly 1000:1) expands to multiple gigab= ytes inside a single call. The max_receive_message_length limit is enforced=
only against the already-decompressed message, so it provides no protectio=
n. An unauthenticated remote peer can send a single crafted frame to exhaus=
t the BEAM node's heap and trigger an out-of-memory kill. This issue affect=
s grpc: from 0.4.0 before 1.0.0.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53430" target=3D= "_blank" rel=3D"noopener">CVE-2026-53430</a></td>
</tr>
<td class=3D"vendor-product">Enhancesoft--osTicket</td>
<td>A session fixation vulnerability has been identified in osTicket v1.18.=
2. This security flaw allows an attacker to hijack a victim's account by ke= eping the initial session identifier (OSTSESSID) active after a successful = login. The issue lies in the fact that the application does not invalidate = the pre-authentication cookie or generate a new identifier for the authenti= cated context. As a result, if an attacker manages to set a known session i= dentifier in the victim's browser, they will be able to maintain unauthoris=
ed access to the account once the victim has authenticated.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9507" target=3D"= _blank" rel=3D"noopener">CVE-2026-9507</a></td>
</tr>
<td class=3D"vendor-product">Feuerhamster--MailForm v1.1.0</td>
<td>An issue in the attachment handling component of Feuerhamster MailForm = v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted re= quest.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50878" target=3D= "_blank" rel=3D"noopener">CVE-2026-50878</a></td>
</tr>
<td class=3D"vendor-product">Filestash--Filestash v0.4.0</td>
<td>Incorrect access control in the /admin/api/config component of Filestas=
h v0.4.0 allows attackers to escalate privileges via sending a crafted requ= est.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50891" target=3D= "_blank" rel=3D"noopener">CVE-2026-50891</a></td>
</tr>
<td class=3D"vendor-product">flatnotes--flatnotes v5.5.4</td>
<td>An arbitrary file upload vulnerability in the attachment handling compo= nent of flatnotes v5.5.4 allows attackers to execute arbitrary code via upl= oading a crafted HTML or SVG file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50873" target=3D= "_blank" rel=3D"noopener">CVE-2026-50873</a></td>
</tr>
<td class=3D"vendor-product">Flexera--FlexNet Manager Suite</td>
<td>A security vulnerability has been identified in FlexNet Manager Suite 2= 025 R1 that could allow an authenticated user with read-only access to acco= unt settings to escalate their privileges to Administrator level.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4026" target=3D"= _blank" rel=3D"noopener">CVE-2026-4026</a></td>
</tr>
<td class=3D"vendor-product">Flexera--FlexNet Manager Suite</td>
<td>A security vulnerability has been identified in FlexNet Manager Suite 2= 025 R1 and R2 that could allow unauthorized access to attachment files due =
to insufficient access control.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4027" target=3D"= _blank" rel=3D"noopener">CVE-2026-4027</a></td>
</tr>
<td class=3D"vendor-product">flipped-aurora--gin-vue-admin</td> <td>gin-vue-admin is an AI-assisted basic development platform. In version = 2.9.1, an authenticated attacker with access to the code-generation feature=
and MCP management interface can exploit this vulnerability by injecting a= ttacker-controlled Go source code through POST /autoCode/addFunc, and then = invoking POST /autoCode/mcpStart to trigger a rebuild and restart of the st= andalone MCP service. This allows arbitrary operating system commands to be=
executed on the server with the privileges of the application process. Suc= cessful exploitation may lead to remote code execution (RCE), modification =
of backend source code or runtime logic, deployment of persistent backdoors=
, access to or manipulation of application data and configuration, and furt= her impact on local resources running under the same service account or pri= vilege context. The risk is highest in deployments that retain the source t= ree, allow writes to source files, and support local build or startup of st= andalone MCP components. In environments using binary-only releases, read-o= nly filesystems, or with local build capabilities removed, the exploitabili=
ty of the full attack chain is significantly reduced. However, once the onl= ine code-generation capability and MCP-hosted startup workflow are enabled,=
the overall security impact may reach high to critical severity. As of tim=
e of publication, it is unknown if a patched version is available. As a wor= karound, enforce strict allowlist validation on path- and identifier-relate=
d fields such as `humpPackageName`, `packageName`, `FuncName`, and `Router`=
, and only permit safe identifier formats.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48787" target=3D= "_blank" rel=3D"noopener">CVE-2026-48787</a></td>
</tr>
<td class=3D"vendor-product">Flowise--Flowise</td>
<td>Flowise before 3.0.13 contains an information exposure vulnerability in=
the POST /api/v1/account/forgot-password endpoint that returns full user o= bjects including PII to unauthenticated attackers. An attacker can enumerat=
e valid email addresses and harvest sensitive user data including user IDs,=
names, account status, and timestamps by sending requests with known email=
addresses.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56267" target=3D= "_blank" rel=3D"noopener">CVE-2026-56267</a></td>
</tr>
<td class=3D"vendor-product">Flowise--Flowise</td>
<td>Flowise before 3.1.2 contains a mass assignment vulnerability in the PU=
T /api/v1/user endpoint that allows authenticated users to directly modify = the credential field without validation. Attackers can bypass password chan=
ge verification and session invalidation by supplying a crafted password ha= sh, establishing persistent account access after temporary session compromi= se.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56276" target=3D= "_blank" rel=3D"noopener">CVE-2026-56276</a></td>
</tr>
<td class=3D"vendor-product">fossar--selfoss v2.20</td>
<td>An issue in the loopback request handling component of fossar selfoss v= 2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sen= sitive information via supplying a crafted HTTP request.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50872" target=3D= "_blank" rel=3D"noopener">CVE-2026-50872</a></td>
</tr>
<td class=3D"vendor-product">FuseSource--jansi</td>
<td>A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" = wrapper due to a lack of size verification for the argument array before th=
e system call. This can lead to heap corruption and application crashes (Do= S). All versions are believed to be vulnerable.=C2=A0This project is unmain= tained at the time of CVE assignment.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8484" target=3D"= _blank" rel=3D"noopener">CVE-2026-8484</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In multiple functions of btm_sec.cc, there is a possible way for an att= acker to intercept SMS messages due to a logic error in the code. This coul=
d lead to remote information disclosure with no additional execution privil= eges needed. User interaction is needed for exploitation.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-48571" target=3D= "_blank" rel=3D"noopener">CVE-2025-48571</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In overrideConfig of CarrierConfigLoader.java, there is a possible way =
to bypass UID check due to a permissions bypass. This could lead to local e= scalation of privilege with no additional execution privileges needed. User=
interaction is not needed for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-48617" target=3D= "_blank" rel=3D"noopener">CVE-2025-48617</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In multiple locations, there is a possible 3rd party passkey entry pair= ing approval due to a missing permission check. This could lead to remote (= proximal/adjacent) escalation of privilege with no additional execution pri= vileges needed. User interaction is not needed for exploitation.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-48640" target=3D= "_blank" rel=3D"noopener">CVE-2025-48640</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In multiple locations there is a possible provisioning bypass due to im= proper input validation. This could lead to local escalation of privilege w= ith no additional execution privileges needed. User interaction is not need=
ed for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-48643" target=3D= "_blank" rel=3D"noopener">CVE-2025-48643</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In SettingsLib, there is a possible way to disable system components du=
e to a logic error in the code. This could lead to local escalation of priv= ilege with no additional execution privileges needed. User interaction is n=
ot needed for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0019" target=3D"= _blank" rel=3D"noopener">CVE-2026-0019</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Contacts Provider, there is a possible way to access an incoming cal= l's phone number and associated metadata due to a missing permission check.=
This could lead to local information disclosure with no additional executi=
on privileges needed. User interaction is not needed for exploitation.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0057" target=3D"= _blank" rel=3D"noopener">CVE-2026-0057</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In setAllowedCarriers of PhoneInterfaceManager.java, there is a possibl=
e way to disable carrier restrictions due to a logic error in the code. Thi=
s could lead to local escalation of privilege with no additional execution = privileges needed. User interaction is not needed for exploitation.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0063" target=3D"= _blank" rel=3D"noopener">CVE-2026-0063</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In multiple places, there is a possible persistent denial of service du=
e to resource exhaustion. This could lead to local denial of service with n=
o additional execution privileges needed. User interaction is not needed fo=
r exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0064" target=3D"= _blank" rel=3D"noopener">CVE-2026-0064</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In createSessionInternal of PackageInstallerService.java, there is a po= ssible method to remove a DPC app from a managed device without DO consent = due to desync from persistence. This could lead to local escalation of priv= ilege if a user can install a malicious app with no additional execution pr= ivileges needed. User interaction is needed for exploitation.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0068" target=3D"= _blank" rel=3D"noopener">CVE-2026-0068</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In SettingsLib, there is a possible missing permission check due to a l= ogic error in the code. This could lead to local escalation of privilege wi=
th no additional execution privileges needed. User interaction is not neede=
d for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0071" target=3D"= _blank" rel=3D"noopener">CVE-2026-0071</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In NFC, there is a possible way to spoof an NFC event due to a missing = permission check. This could lead to local escalation of privilege with no = additional execution privileges needed. User interaction is not needed for = exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0081" target=3D"= _blank" rel=3D"noopener">CVE-2026-0081</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In tryStartActivity of NfcDispatcher.java, there is a possible automati=
c special app access permission assignment due to an insecure default value=
. This could lead to local escalation of privilege with no additional execu= tion privileges needed. User interaction is not needed for exploitation.</t=
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0082" target=3D"= _blank" rel=3D"noopener">CVE-2026-0082</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Nfc::eventCallback() of Nfc.h, there is a possible use after free du=
e to a race condition. This could lead to local escalation of privilege wit=
h no additional execution privileges needed. User interaction is not needed=
for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0083" target=3D"= _blank" rel=3D"noopener">CVE-2026-0083</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Package Manager, there is a possible device lock controller bypass d=
ue to a missing permission check. This could lead to local escalation of pr= ivilege with no additional execution privileges needed. User interaction is=
not needed for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0092" target=3D"= _blank" rel=3D"noopener">CVE-2026-0092</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In multiple functions of vpu_ioctl.c, there is a possible use after fre=
e due to a race condition. This could lead to local escalation of privilege=
with no additional execution privileges needed. User interaction is not ne= eded for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0125" target=3D"= _blank" rel=3D"noopener">CVE-2026-0125</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In WC-Radio, there is a possible out of bounds write due to a missing b= ounds check. This could lead to remote code execution with no additional ex= ecution privileges needed. User interaction is not needed for exploitation.= </td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0126" target=3D"= _blank" rel=3D"noopener">CVE-2026-0126</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, the=
re is a possible out-of-bounds read due to memory corruption. This could le=
ad to remote denial of service causing a communication processor crash with=
no additional execution privileges needed. User interaction is not needed = for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0127" target=3D"= _blank" rel=3D"noopener">CVE-2026-0127</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds = read due to an integer overflow. This could lead to remote information disc= losure with no additional execution privileges needed. User interaction is = needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0128" target=3D"= _blank" rel=3D"noopener">CVE-2026-0128</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In RtcpByePacket::decodeByePacket, there is a possible due to a missing=
bounds check. This could lead to remote information disclosure with no add= itional execution privileges needed. User interaction is needed for exploit= ation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0129" target=3D"= _blank" rel=3D"noopener">CVE-2026-0129</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read d=
ue to a heap buffer overflow. This could lead to remote information disclos= ure with no additional execution privileges needed. User interaction is nee= ded for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0130" target=3D"= _blank" rel=3D"noopener">CVE-2026-0130</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In RtpPacket::decodePacket, there is a possible out of bounds access du=
e to an integer overflow. This could lead to local escalation of privilege = with no additional execution privileges needed. User interaction is needed = for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0131" target=3D"= _blank" rel=3D"noopener">CVE-2026-0131</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Modem, there is a possible out of bounds write due to a heap buffer = overflow. This could lead to remote code execution with no additional execu= tion privileges needed. User interaction is not needed for exploitation.</t=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0132" target=3D"= _blank" rel=3D"noopener">CVE-2026-0132</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign ma= licious Android Runtime bootclass artifacts due to a missing permission che= ck. This could lead to local escalation of privilege with no additional exe= cution privileges needed. User interaction is not needed for exploitation.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0133" target=3D"= _blank" rel=3D"noopener">CVE-2026-0133</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In PostWipeData of recovery_ui.cpp, there is a possible data persistenc=
e issue after a factory reset due to a logic error in the code. This could = lead to local information disclosure with no additional execution privilege=
s needed. User interaction is not needed for exploitation.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0134" target=3D"= _blank" rel=3D"noopener">CVE-2026-0134</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Modem, there is a possible out of bounds read due to a missing bound=
s check. This could lead to remote code execution with no additional execut= ion privileges needed. User interaction is not needed for exploitation.</td=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0135" target=3D"= _blank" rel=3D"noopener">CVE-2026-0135</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Modem, there is a possible out of bounds read due to a missing bound=
s check. This could lead to remote denial of service with no additional exe= cution privileges needed. User interaction is not needed for exploitation.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0136" target=3D"= _blank" rel=3D"noopener">CVE-2026-0136</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a = possible elevation of privilege due to a use after free. This could lead to=
local escalation of privilege with System execution privileges needed. Use=
r interaction is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0137" target=3D"= _blank" rel=3D"noopener">CVE-2026-0137</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of=
bounds write due to memory corruption. This could lead to local escalation=
of privilege with System execution privileges needed. User interaction is = not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0138" target=3D"= _blank" rel=3D"noopener">CVE-2026-0138</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Modem, there is a possible out of bounds write due to a missing boun=
ds check. This could lead to remote code execution with no additional execu= tion privileges needed. User interaction is not needed for exploitation.</t=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0139" target=3D"= _blank" rel=3D"noopener">CVE-2026-0139</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In RtpPacket::decodePacket, there is a possible out-of-bounds read due =
to an integer overflow. This could lead to remote information disclosure wi=
th no additional execution privileges needed. User interaction is needed fo=
r exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0140" target=3D"= _blank" rel=3D"noopener">CVE-2026-0140</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read d=
ue to a missing bounds check. This could lead to remote information disclos= ure with no additional execution privileges needed. User interaction is not=
needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0141" target=3D"= _blank" rel=3D"noopener">CVE-2026-0141</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds = read due to improper input validation. This could lead to local information=
disclosure with no additional execution privileges needed. User interactio=
n is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0142" target=3D"= _blank" rel=3D"noopener">CVE-2026-0142</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In lwis_device_external_event_emit of lwis_event.c, there is a possible=
memory corruption due to a use after free. This could lead to local escala= tion of privilege with System execution privileges needed. User interaction=
is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0143" target=3D"= _blank" rel=3D"noopener">CVE-2026-0143</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In writeAocCommand of AocAudioCodec.cpp, there is a possible memory saf= ety issue due to a missing bounds check. This could lead to remote denial o=
f service with no additional execution privileges needed. User interaction =
is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0144" target=3D"= _blank" rel=3D"noopener">CVE-2026-0144</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In keymint, there is a possible Permission Bypass due to a logic error =
in the code. This could lead to local information disclosure with no additi= onal execution privileges needed. User interaction is not needed for exploi= tation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0145" target=3D"= _blank" rel=3D"noopener">CVE-2026-0145</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a = possible out of bounds write due to a missing bounds check. This could lead=
to remote code execution with no additional execution privileges needed. U= ser interaction is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0146" target=3D"= _blank" rel=3D"noopener">CVE-2026-0146</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there=
is a possible out of bounds write due to a missing bounds check. This coul=
d lead to remote code execution with no additional execution privileges nee= ded. User interaction is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0147" target=3D"= _blank" rel=3D"noopener">CVE-2026-0147</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a pos= sible out of bounds write due to an integer overflow. This could lead to re= mote code execution with no additional execution privileges needed. User in= teraction is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0148" target=3D"= _blank" rel=3D"noopener">CVE-2026-0148</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to =
a heap buffer overflow. This could lead to remote code execution with no ad= ditional execution privileges needed. User interaction is not needed for ex= ploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0149" target=3D"= _blank" rel=3D"noopener">CVE-2026-0149</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In ExecuteGraph command handler of EdgeTPU firmware, there is a possibl=
e out of bounds write due to an integer overflow. This could lead to local = escalation of privilege with root privileges needed. User interaction is no=
t needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0150" target=3D"= _blank" rel=3D"noopener">CVE-2026-0150</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In IntfGraphCreate of intfgraph.c, there is a possible out of bounds wr= ite due to an integer overflow. This could lead to remote code execution wi=
th no additional execution privileges needed. User interaction is not neede=
d for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0151" target=3D"= _blank" rel=3D"noopener">CVE-2026-0151</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a = system call to system call to maliciously expand the VMA out of bounds due =
to a logic error in the code. This could lead to local escalation of privil= ege with no additional execution privileges needed. User interaction is not=
needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0152" target=3D"= _blank" rel=3D"noopener">CVE-2026-0152</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Write of msg_to_host_buffer.cc, there is a possible out of bounds wr= ite due to an incorrect bounds check. This could lead to local escalation o=
f privilege with no additional execution privileges needed. User interactio=
n is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0153" target=3D"= _blank" rel=3D"noopener">CVE-2026-0153</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Modem, there is a possible way to trigger a modem crash during a SIP=
REFER request due to memory corruption. This could lead to remote code exe= cution with no additional execution privileges needed. User interaction is = not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0154" target=3D"= _blank" rel=3D"noopener">CVE-2026-0154</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due =
to a missing bounds check. This could lead to remote information disclosure=
with no additional execution privileges needed. User interaction is not ne= eded for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0155" target=3D"= _blank" rel=3D"noopener">CVE-2026-0155</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memor=
y safety issue due to a missing null check. This could lead to remote denia=
l of service with no additional execution privileges needed. User interacti=
on is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0156" target=3D"= _blank" rel=3D"noopener">CVE-2026-0156</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a = missing bounds check. This could lead to remote information disclosure with=
no additional execution privileges needed. User interaction is not needed = for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0157" target=3D"= _blank" rel=3D"noopener">CVE-2026-0157</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Camera, there is a possible unauthorized way to access photos due to=
a missing permission check. This could lead to local information disclosur=
e with no additional execution privileges needed. User interaction is not n= eeded for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0158" target=3D"= _blank" rel=3D"noopener">CVE-2026-0158</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.c= pp, there is a possible out of bounds write due to a missing bounds check. = This could lead to remote code execution with no additional execution privi= leges needed. User interaction is not needed for exploitation.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0160" target=3D"= _blank" rel=3D"noopener">CVE-2026-0160</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In numberOfReportBlocks of RtpSession.cpp, there is a possible out of b= ounds write due to an integer overflow. This could lead to remote escalatio=
n of privilege with no additional execution privileges needed. User interac= tion is not needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0161" target=3D"= _blank" rel=3D"noopener">CVE-2026-0161</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corr= uption due to type confusion. This could lead to remote code execution with=
no additional execution privileges needed. User interaction is not needed = for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0162" target=3D"= _blank" rel=3D"noopener">CVE-2026-0162</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Modem, there is a possible out of bounds write due to a missing boun=
ds check. This could lead to remote code execution with no additional execu= tion privileges needed. User interaction is not needed for exploitation.</t=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0164" target=3D"= _blank" rel=3D"noopener">CVE-2026-0164</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In several functions of the RTCP packet decoder, there is a possible ou= t-of-bounds read due to a missing bounds check. This could lead to remote i= nformation disclosure with no additional execution privileges needed. User = interaction is needed for exploitation.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0165" target=3D"= _blank" rel=3D"noopener">CVE-2026-0165</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In AndroidManifest.xml, there is a possible persistent denial of servic=
e due to a missing permission check. This could lead to local denial of ser= vice with no additional execution privileges needed. User interaction is no=
t needed for exploitation.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-28573" target=3D= "_blank" rel=3D"noopener">CVE-2026-28573</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In PackageInstaller.Session#transfer of frameworks/base/services/core/j= ava/com/android/server/pm/PackageInstallerSession.java, there is a possible=
memory exhaustion attack due to a logic error in the code. This could lead=
to local denial of service with no additional execution privileges needed.=
User interaction is not needed for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-28575" target=3D= "_blank" rel=3D"noopener">CVE-2026-28575</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to re= trieve sensitive information due to a missing permission check. This could = lead to local information disclosure with no additional execution privilege=
s needed. User interaction is not needed for exploitation.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-28587" target=3D= "_blank" rel=3D"noopener">CVE-2026-28587</a></td>
</tr>
<td class=3D"vendor-product">Google--Android</td>
<td>In Telecomm, there is a possible way to initiate an unauthorized phone = call due to a permissions bypass. This could lead to local escalation of pr= ivilege with no additional execution privileges needed. User interaction is=
not needed for exploitation.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-28615" target=3D= "_blank" rel=3D"noopener">CVE-2026-28615</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in WebShare in Google Chrome on Windows prior to 149.0.7= 827.155 allowed a remote attacker who had compromised the renderer process =
to potentially perform a sandbox escape via a crafted HTML page. (Chromium = security severity: Critical)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12437" target=3D= "_blank" rel=3D"noopener">CVE-2026-12437</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in WebView in Google Chrome on Android pri=
or to 149.0.7827.155 allowed a remote attacker who had compromised the rend= erer process to potentially perform a sandbox escape via a crafted HTML pag=
e. (Chromium security severity: Critical)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12438" target=3D= "_blank" rel=3D"noopener">CVE-2026-12438</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Digital Credentials in Google Chrome prior to 149.0.7= 827.155 allowed a remote attacker to potentially exploit heap corruption vi=
a a crafted HTML page. (Chromium security severity: Critical)</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12439" target=3D= "_blank" rel=3D"noopener">CVE-2026-12439</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in DigitalCredentials in Google Chrome on Windows prior =
to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbo=
x escape via a crafted HTML page. (Chromium security severity: Critical)</t=
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12440" target=3D= "_blank" rel=3D"noopener">CVE-2026-12440</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in File Input in Google Chrome on Linux prior to 149.0.7= 827.155 allowed a remote attacker to potentially exploit heap corruption vi=
a a crafted HTML page. (Chromium security severity: Critical)</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12441" target=3D= "_blank" rel=3D"noopener">CVE-2026-12441</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Passwords in Google Chrome on Android prior to 149.0.= 7827.155 allowed a remote attacker to execute arbitrary code via a crafted = HTML page. (Chromium security severity: Critical)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12442" target=3D= "_blank" rel=3D"noopener">CVE-2026-12442</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Web Authentication in Google Chrome prior to 149.0.78= 27.155 allowed a remote attacker to execute arbitrary code via a crafted HT=
ML page. (Chromium security severity: Critical)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12443" target=3D= "_blank" rel=3D"noopener">CVE-2026-12443</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Out of bounds read in Chromoting in Google Chrome on Windows prior to 1= 49.0.7827.155 allowed a local attacker to obtain potentially sensitive info= rmation from process memory via a malicious file. (Chromium security severi= ty: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12444" target=3D= "_blank" rel=3D"noopener">CVE-2026-12444</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Extensions in Google Chrome prior to 149.0.7827.155 a= llowed an attacker who convinced a user to install a malicious extension to=
potentially exploit heap corruption via a crafted Chrome Extension. (Chrom= ium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12445" target=3D= "_blank" rel=3D"noopener">CVE-2026-12445</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Passwords in Google Chrome prior to 149= .0.7827.155 allowed a remote attacker to leak cross-origin data via a craft=
ed HTML page. (Chromium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12446" target=3D= "_blank" rel=3D"noopener">CVE-2026-12446</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155=
allowed a remote attacker to execute arbitrary code inside a sandbox via a=
crafted HTML page. (Chromium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12447" target=3D= "_blank" rel=3D"noopener">CVE-2026-12447</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in WebView in Google Chrome on Android pri=
or to 149.0.7827.155 allowed a remote attacker to perform privilege escalat= ion via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12448" target=3D= "_blank" rel=3D"noopener">CVE-2026-12448</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Chromoting in Google Chrome on Windows prior to 149.0= .7827.155 allowed a local attacker to perform OS-level privilege escalation=
via a malicious file. (Chromium security severity: High)</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12449" target=3D= "_blank" rel=3D"noopener">CVE-2026-12449</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Media in Google Chrome prior to 149.0.7= 827.155 allowed a remote attacker to obtain potentially sensitive informati=
on from process memory via a crafted HTML page. (Chromium security severity=
: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12450" target=3D= "_blank" rel=3D"noopener">CVE-2026-12450</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in DigitalCredentials in Google Chrome prior to 149.0.78= 27.155 allowed a remote attacker who had compromised the renderer process t=
o potentially perform a sandbox escape via a crafted HTML page. (Chromium s= ecurity severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12451" target=3D= "_blank" rel=3D"noopener">CVE-2026-12451</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Downloads in Google Chrome on Android prior to 149.0.= 7827.155 allowed a remote attacker to potentially exploit heap corruption v=
ia a crafted HTML page. (Chromium security severity: High)</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12452" target=3D= "_blank" rel=3D"noopener">CVE-2026-12452</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Insufficient validation of untrusted input in Input in Google Chrome pr= ior to 149.0.7827.155 allowed a remote attacker who had compromised the ren= derer process to bypass same origin policy via a crafted HTML page. (Chromi=
um security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12453" target=3D= "_blank" rel=3D"noopener">CVE-2026-12453</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 a= llowed a remote attacker who had compromised the renderer process to potent= ially perform a sandbox escape via a crafted HTML page. (Chromium security = severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12454" target=3D= "_blank" rel=3D"noopener">CVE-2026-12454</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 al= lowed a remote attacker who convinced a user to engage in specific UI gestu= res to potentially exploit heap corruption via a crafted HTML page. (Chromi=
um security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12455" target=3D= "_blank" rel=3D"noopener">CVE-2026-12455</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Extensions in Google Chrome prior to 14= 9.0.7827.155 allowed an attacker who convinced a user to install a maliciou=
s extension to bypass same origin policy via a crafted Chrome Extension. (C= hromium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12456" target=3D= "_blank" rel=3D"noopener">CVE-2026-12456</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Extensions in Google Chrome prior to 14= 9.0.7827.155 allowed a remote attacker who had compromised the renderer pro= cess to bypass site isolation via a crafted HTML page. (Chromium security s= everity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12457" target=3D= "_blank" rel=3D"noopener">CVE-2026-12457</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Passwords in Google Chrome prior to 149= .0.7827.155 allowed a remote attacker who convinced a user to engage in spe= cific UI gestures to leak cross-origin data via a crafted HTML page. (Chrom= ium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12458" target=3D= "_blank" rel=3D"noopener">CVE-2026-12458</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Serial in Google Chrome prior to 149.0.= 7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXS=
S) via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12459" target=3D= "_blank" rel=3D"noopener">CVE-2026-12459</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Insufficient policy enforcement in File System Access in Google Chrome = prior to 149.0.7827.155 allowed a remote attacker who had compromised the r= enderer process to bypass site isolation via a crafted PDF file. (Chromium = security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12460" target=3D= "_blank" rel=3D"noopener">CVE-2026-12460</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0= .7827.155 allowed a remote attacker to obtain potentially sensitive informa= tion from process memory via a crafted HTML page. (Chromium security severi= ty: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12461" target=3D= "_blank" rel=3D"noopener">CVE-2026-12461</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Media in Google Chrome prior to 149.0.7827.155 allowe=
d a remote attacker who had compromised the renderer process to execute arb= itrary code inside a sandbox via a crafted HTML page. (Chromium security se= verity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12462" target=3D= "_blank" rel=3D"noopener">CVE-2026-12462</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Views in Google Chrome on Linux prior t=
o 149.0.7827.155 allowed a remote attacker who had compromised the renderer=
process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page=
. (Chromium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12463" target=3D= "_blank" rel=3D"noopener">CVE-2026-12463</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Browser in Google Chrome prior to 149.0.7827.155 allo= wed a remote attacker who had compromised the renderer process to potential=
ly perform a sandbox escape via a crafted HTML page. (Chromium security sev= erity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12464" target=3D= "_blank" rel=3D"noopener">CVE-2026-12464</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.= 155 allowed a remote attacker who had compromised the renderer process to p= otentially perform a sandbox escape via a crafted HTML page. (Chromium secu= rity severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12465" target=3D= "_blank" rel=3D"noopener">CVE-2026-12465</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149= .0.7827.155 allowed a remote attacker to execute arbitrary code via a craft=
ed HTML page. (Chromium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12466" target=3D= "_blank" rel=3D"noopener">CVE-2026-12466</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Extensions in Google Chrome prior to 149.0.7827.155 a= llowed a remote attacker who had compromised the renderer process to potent= ially perform a sandbox escape via a crafted HTML page. (Chromium security = severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12467" target=3D= "_blank" rel=3D"noopener">CVE-2026-12467</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed=
a remote attacker who had compromised the renderer process to potentially = perform a sandbox escape via a crafted HTML page. (Chromium security severi= ty: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12468" target=3D= "_blank" rel=3D"noopener">CVE-2026-12468</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.782= 7.155 allowed a remote attacker to leak cross-origin data via a crafted HTM=
L page. (Chromium security severity: High)</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12469" target=3D= "_blank" rel=3D"noopener">CVE-2026-12469</a></td>
</tr>
<td class=3D"vendor-product">Google--MCP Toolbox for Databases (googleapis/= mcp-toolbox)</td>
<td>An authentication bypass vulnerability exists in the generic opaque tok=
en validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When ve= rifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (R=
FC 7662), the toolbox decodes the response into an introspectResp struct wh= ere the Active field is declared as a pointer to a boolean (*bool). The cod=
e only explicitly rejects a token if the response contains a populated acti=
ve field set to false (if introspectResp.Active !=3D nil && !*intro= spectResp.Active). If an introspection endpoint responds with a payload tha=
t completely omits the mandatory active key, the internal variable remains = nil, causing the conditional check to short-circuit. As a result, Toolbox a= ccepts authorization tokens missing the "active" field, granting access to = protected tools and underlying data sources.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11717" target=3D= "_blank" rel=3D"noopener">CVE-2026-11717</a></td>
</tr>
<td class=3D"vendor-product">Google--MCP Toolbox for Databases (googleapis/= mcp-toolbox)</td>
<td>An authentication bypass vulnerability exists in the generic opaque tok=
en validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When th=
e toolbox validates an opaque token via an OAuth 2.0 introspection endpoint=
(RFC 7662), it decodes the response into an introspectResp struct. However=
, the subsequent claim-checking logic (validateClaims) evaluates the issuer=
condition as if a.issuer !=3D "" && iss !=3D "". If the external O= Auth provider's introspection response omits the optional iss (issuer) fiel=
d completely, the variable iss defaults to an empty string. This causes the=
conditional block to evaluate to false and be skipped silently. Consequent= ly, the application accepts tokens issued by unauthorized or unintended thi= rd-party identity providers.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11718" target=3D= "_blank" rel=3D"noopener">CVE-2026-11718</a></td>
</tr>
<td class=3D"vendor-product">Google--MCP Toolbox for Databases (googleapis/= mcp-toolbox)</td>
<td>An authenticated authorization bypass vulnerability exists in MCP Toolb=
ox for Databases due to missing scope enforcement across older protocol han= dlers. While the 2025-11-25 protocol version handler correctly enforces per= -tool restrictions defined by scopesRequired, older supported protocol vers= ions (2025-06-18, 2025-03-26, and 2024-11-05) omit this check. An authentic= ated client with low-privilege tokens (e.g., read) can bypass the intended = per-tool scope restrictions and execute high-privilege tools (e.g., admin) = simply by specifying an older protocol version in the MCP-Protocol-Version = header, or by omitting the header entirely (which causes the server to defa= ult to the vulnerable 2024-11-05 handler).</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11719" target=3D= "_blank" rel=3D"noopener">CVE-2026-11719</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A NULL pointer dereference in the gf_isom_copy_sample_info function (is= omedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial=
of Service (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55641" target=3D= "_blank" rel=3D"noopener">CVE-2025-55641</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>GPAC MP4Box v2.4 was discovered to contain a floating point exception i=
n the avidmx_process function (isomedia/isom_write.c).</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55642" target=3D= "_blank" rel=3D"noopener">CVE-2025-55642</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A NULL pointer dereference in the TrackWriter handling component (filte= rs/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Se= rvice (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55643" target=3D= "_blank" rel=3D"noopener">CVE-2025-55643</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A heap use-after-free in the gf_node_get_tag function (scenegraph/base_= scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Ser= vice (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55644" target=3D= "_blank" rel=3D"noopener">CVE-2025-55644</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_s= ample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service = (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55645" target=3D= "_blank" rel=3D"noopener">CVE-2025-55645</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_= isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (= DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55647" target=3D= "_blank" rel=3D"noopener">CVE-2025-55647</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A heap buffer overflow in the gf_opus_parse_packet_header function (med= ia_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Deni=
al of Service (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55648" target=3D= "_blank" rel=3D"noopener">CVE-2025-55648</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A NULL pointer dereference in the gf_media_map_esd function (media_tool= s/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of S= ervice (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55649" target=3D= "_blank" rel=3D"noopener">CVE-2025-55649</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A heap use-after-free in the gf_node_get_tag function (scenegraph/base_= scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Ser= vice (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55650" target=3D= "_blank" rel=3D"noopener">CVE-2025-55650</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/= avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Servic=
e (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55652" target=3D= "_blank" rel=3D"noopener">CVE-2025-55652</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A stack overflow in the gf_opus_read_length function (media_tools/av_pa= rsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service = (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55660" target=3D= "_blank" rel=3D"noopener">CVE-2025-55660</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A heap buffer overflow in the Opus audio stream parser component of GPA=
C MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via suppl= ying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55661" target=3D= "_blank" rel=3D"noopener">CVE-2025-55661</a></td>
</tr>
<td class=3D"vendor-product">GPAC--MP4Box v.2.4</td>
<td>A segmentation violation in the Track_SetStreamDescriptor function (iso= media/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Se= rvice (DoS) via supplying a crafted MP4 file.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-55663" target=3D= "_blank" rel=3D"noopener">CVE-2025-55663</a></td>
</tr>
<td class=3D"vendor-product">Grav--grav-plugin-api</td>
<td>Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site sc= ripting (XSS) vulnerability in the Admin2 Pages API save flow.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11982" target=3D= "_blank" rel=3D"noopener">CVE-2026-11982</a></td>
</tr>
<td class=3D"vendor-product">gtsteffaniak--filebrowser</td>
<td>FileBrowser Quantum is a free, self-hosted, web-based file manager. Ver= sions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Pa=
th Traversal through the publicPatchHandler in backend/http/public.go which=
joins user-controlled fromPath and toPath body fields with the trusted d.s= hare.Path BEFORE the downstream sanitizer runs. Because filepath.Join colla= pses .. segments during the join, the sanitizer in resourcePatchHandler nev=
er sees the traversal and the move/copy/rename operates on a path outside t=
he shared directory. The same root-cause pattern was patched for the bulk D= ELETE endpoint as CVE-2026-44542 (GHSA-fwj3-42wh-8673), but the PATCH handl=
er with the identical pattern was not updated. A public share link with All= owModify=3Dtrue is sufficient to exploit this. Anyone holding such a link c=
an move, copy, or rename arbitrary files within the share owner's source ro= ot. This issue has been fixed in versions 1.3.3-stable and 1.4.2-beta.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48777" target=3D= "_blank" rel=3D"noopener">CVE-2026-48777</a></td>
</tr>
<td class=3D"vendor-product">HAYAJO--Mojolicious::Sessions::Storable</td> <td>Mojolicious::Sessions::Storable versions through 0.05 for Perl generate=
session ids insecurely. The default session id generator returns a SHA-1 h= ash seeded with the built-in rand function, the epoch time, the heap addres=
s of an anonymous hash, and the PID. These are predictable or low-entropy s= ources that are unsuitable for security purposes.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9692" target=3D"= _blank" rel=3D"noopener">CVE-2026-9692</a></td>
</tr>
<td class=3D"vendor-product">HP Inc.--HP One Agent Software</td>
<td>Potential security vulnerabilities have been identified in the HP One A= gent for certain HP PC products, which might allow for escalation of privil= ege and/or denial of service. HP is releasing software updates to mitigate = these potential vulnerabilities.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5064" target=3D"= _blank" rel=3D"noopener">CVE-2026-5064</a></td>
</tr>
<td class=3D"vendor-product">icagenda.com--iCagenda extension for Joomla</t=
<td>A vulnerability in the iCagenda extension for Joomla allows the upload =
of arbitrary files in the file attachment feature, ultimately resulting in = PHP code upload and execution.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48939" target=3D= "_blank" rel=3D"noopener">CVE-2026-48939</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td> <td>Software installed and run as a non-privileged user may conduct imprope=
r GPU system calls to cause an error path leading to UAF of GPU page tables=
. The vulnerability allows physical memory allocated for MMU page tables to=
be used after being freed. This was caused by an error path that would not=
cleanup properly before freeing the physical allocation.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34192" target=3D= "_blank" rel=3D"noopener">CVE-2026-34192</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td> <td>Software installed and run as a non-privileged user may conduct imprope=
r GPU system calls to cause mismanagement of resources creating a write use=
after free scenario. A shared resource (memory page) managed by a CPU thre=
ad of control (driver) and accessed by a GPU thread of control (Firmware) c=
an cause a write UAF when the CPU thread frees the resource before the GPU =
FW has finished accessing it.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41156" target=3D= "_blank" rel=3D"noopener">CVE-2026-41156</a></td>
</tr>
<td class=3D"vendor-product">InHand Networks--IR912</td>
<td>InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including = earlier versions) were discovered to contain a command injection vulnerabil= ity in the Python configuration function. This vulnerability allows remote = attackers to execute arbitrary commands as root via a crafted input.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38714" target=3D= "_blank" rel=3D"noopener">CVE-2026-38714</a></td>
</tr>
<td class=3D"vendor-product">InHand Networks--IR912</td>
<td>InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including = earlier versions) were discovered to contain a command injection vulnerabil= ity in the log viewing function. This vulnerability allows remote attackers=
to execute arbitrary commands as root via a crafted input.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38715" target=3D= "_blank" rel=3D"noopener">CVE-2026-38715</a></td>
</tr>
<td class=3D"vendor-product">InHand Networks--IR912</td>
<td>InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including = earlier versions) were discovered to contain a command injection vulnerabil= ity in the Python application export function. This vulnerability allows re= mote attackers to execute arbitrary commands as root via a crafted input.</=
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38716" target=3D= "_blank" rel=3D"noopener">CVE-2026-38716</a></td>
</tr>
<td class=3D"vendor-product">InHand Networks--IR912</td>
<td>InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including = earlier versions) were discovered to contain a command injection vulnerabil= ity in the file upload function. The vulnerability allows remote attackers =
to execute arbitrary commands as root via a crafted input.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38717" target=3D= "_blank" rel=3D"noopener">CVE-2026-38717</a></td>
</tr>
<td class=3D"vendor-product">InHand Networks--IR912</td>
<td>InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including = earlier versions) were discovered to contain a buffer overflow vulnerabilit=
y in the device registration function. This vulnerability could allow an at= tacker to cause a denial of service attack on the remote target device.</td=
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38718" target=3D= "_blank" rel=3D"noopener">CVE-2026-38718</a></td>
</tr>
<td class=3D"vendor-product">Iru, Inc--Kandi Agent</td>
<td>An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local a= ttacker to escalate privileges via a client validation gap to invoke restri= cted agent functionality.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39118" target=3D= "_blank" rel=3D"noopener">CVE-2026-39118</a></td>
</tr>
<td class=3D"vendor-product">JazzCore--python-pdfkit</td>
<td>In JazzCore python-pdfkit 1.0.0, the from_string method enables the exe= cution of JavaScript code within the context of the server application and = the exfiltration of local files.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-26240" target=3D= "_blank" rel=3D"noopener">CVE-2025-26240</a></td>
</tr>
<td class=3D"vendor-product">JimuReport--JimuReport</td>
<td>JimuReport versions 2.3.4 and below are vulnerable to remote code execu= tion due to improper handling of Aviator expressions. The /jmreport/execute= SelectApi endpoint passes user-supplied input directly to the Aviator expre= ssion engine without adequate validation allowing attackers to execute arbi= trary code.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36418" target=3D= "_blank" rel=3D"noopener">CVE-2026-36418</a></td>
</tr>
<td class=3D"vendor-product">JONASBN--Crypt::OpenSSL::PKCS12</td> <td>Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB=
read in print_attribute UTF8STRING path. print_attribute() copies a UTF8ST= RING ASN.1 attribute value into a heap buffer sized exactly to its declared=
length via strncpy, leaving no NUL terminator. Downstream callers run strl= en() on the result and pass the inflated length to newSVpvn(), copying atta= cker-influenced adjacent heap bytes into a Perl scalar.</td> <td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9265" target=3D"= _blank" rel=3D"noopener">CVE-2026-9265</a></td>
</tr>
<td class=3D"vendor-product">joomshaper.net--SP LMS extension for Joomla</t=
<td>SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlle=
d cookie data without validation, enabling an unauthenticated remote attack=
er to execute arbitrary code on the server.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48909" target=3D= "_blank" rel=3D"noopener">CVE-2026-48909</a></td>
</tr>
<td class=3D"vendor-product">joomshaper.net--SP Page Builder extension for = Joomla</td>
<td>A vulnerability in SP Page Builder for Joomla allows unauthenticated us= ers to upload arbitrary files, ultimately resulting in the upload and execu= tion of PHP code.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48908" target=3D= "_blank" rel=3D"noopener">CVE-2026-48908</a></td>
</tr>
<td class=3D"vendor-product">kan-ishka--linux Reminiscene v0.3.0</td>
<td>An OS command injection vulnerability in the media archiving and export=
pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers =
to execute arbitrary commands via supplying a crafted input.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50871" target=3D= "_blank" rel=3D"noopener">CVE-2026-50871</a></td>
</tr>
<td class=3D"vendor-product">kanishka--linux Reminiscence v0.3.0</td>
<td>An OS command injection vulnerability in the /manage/features/media com= ponent of kanishka-linux Reminiscence v0.3.0 allows attackers to execute ar= bitrary commands via supplying a crafted input.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50874" target=3D= "_blank" rel=3D"noopener">CVE-2026-50874</a></td>
</tr>
<td class=3D"vendor-product">l3montree-dev--devguard</td>
<td>DevGuard provides vulnerability management for the full software supply=
chain. Prior to 1.4.2, on a DevGuard API instance with one or more public = assets, any authenticated user - including users from a different organizat= ion with no membership or role in the affected org/project - can create, up= date, reapply, and delete VEX rules on those public assets. The same flaw a= ffects the other vulnerability-triage write endpoints exposed under a publi=
c asset, including VEX rule create / update / reapply / delete; dependency-= vuln event creation (accept / reject / mitigate decisions), batch event cre= ation, vuln sync, and mitigation; license risk creation; external reference=
writes; and/or artifact creation and license refresh. The attacker needs a=
valid account on the instance, but no membership in the victim organizatio=
n, project, or asset is required. Version `v1.4.2`contains a patch. As a wo= rkaround, make affected assets non-public. In the asset settings, switch vi= sibility from public to private. This removes the public-read exemption in = the access-control middleware and restores correct authorization on all wri=
te endpoints for that asset. Downstream consumers that previously relied on=
the public `vex.json` / `sbom.json` endpoints will need to be granted expl= icit access or must receive an exported file version until the patched rele= ase is deployed.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48089" target=3D= "_blank" rel=3D"noopener">CVE-2026-48089</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= /sched: fix pedit partial COW leading to page cache corruption tcf_pedit_ac= t() computes the COW range for skb_ensure_writable() once before the key lo=
op using tcfp_off_max_hint, but the hint does not account for the runtime h= eader offset added by typed keys. This can leave part of the write region u= n-COW'd. Fix by moving skb_ensure_writable() inside the per-key loop where = the actual write offset is known, and add overflow checking on the offset a= rithmetic. For negative offsets (e.g. Ethernet header edits at ingress), us=
e skb_cow() to COW the headroom instead. Guard offset_valid() against INT_M= IN, where negation is undefined.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46331" target=3D= "_blank" rel=3D"noopener">CVE-2026-46331</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: RDM=
A: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_AC= CESS changes from RO to RW then the umem has to be re-evaluated to ensure i=
t is properly pinned as RW. Since the umem is hidden inside each driver's m=
r struct add a ib_umem_check_rereg() function that each driver has to call = before processing IB_MR_REREG_ACCESS. mlx4 has to retain its duplicate ib_a= ccess_writable check because it implements IB_MR_REREG_ACCESS | IB_MR_REREG= _TRANS by changing both items in place sequentially while the MR is live, s=
o it will continue to not support this combination.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52908" target=3D= "_blank" rel=3D"noopener">CVE-2026-52908</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ip6= _vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus=
reported that vti6_init_net() does not set the netns_immutable flag on the=
per-netns fallback tunnel device (ip6_vti0). Other similar tunnel drivers = (like ip6_tunnel, sit, ip6_gre, and ip_tunnel) correctly set this flag duri=
ng their fallback device initialization to prevent them from being moved to=
another network namespace.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52909" target=3D= "_blank" rel=3D"noopener">CVE-2026-52909</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: bpf=
: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the = splat below with a repro. [0] The repro sets up a UDP reuseport group with =
a cBPF prog and replaces it with a new one while another thread is sending =
a UDP packet to the group. The reuseport prog is freed by sk_reuseport_prog= _free(). bpf_prog_put() is called for "e"BPF prog to destruct through multi= ple stages while cBPF prog is freed immediately by bpf_release_orig_filter(=
) and bpf_prog_free(). If a reuseport prog is detached from the setsockopt(=
) path (reuseport_attach_prog() or reuseport_detach_prog()), sk_reuseport_p= rog_free() is called without waiting for RCU readers to complete, resulting=
in various bugs. Let's defer freeing the reuseport cBPF prog after one RCU=
grace period. Note "e"BPF prog is safe as is unless the fast path starts t=
o touch fields destroyed in bpf_prog_put_deferred() and __bpf_prog_put_nore= f(). [0]: BUG: KASAN: vmalloc-out-of-bounds in reuseport_select_sock+0xedc/= 0x1220 net/core/sock_reuseport.c:596 Read of size 4 at addr ffffc9000051e00=
4 by task slowme/10208 CPU: 6 UID: 1000 PID: 10208 Comm: slowme Not tainted=
7.0.0-geb7ac95ff75e #32 PREEMPT(full) Hardware name: QEMU Ubuntu 24.04 PC =
v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/= 2014 Call Trace: <IRQ> dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120=
print_address_description mm/kasan/report.c:378 [inline] print_report+0xca= /0x240 mm/kasan/report.c:482 kasan_report+0x118/0x150 mm/kasan/report.c:595=
reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596 udp4_lib_= lookup2+0x3bc/0x950 net/ipv4/udp.c:495 __udp4_lib_lookup+0x768/0xe20 net/ip= v4/udp.c:723 __udp4_lib_lookup_skb+0x297/0x390 net/ipv4/udp.c:752 __udp4_li= b_rcv+0x1312/0x2620 net/ipv4/udp.c:2752 ip_protocol_deliver_rcu+0x282/0x440=
net/ipv4/ip_input.c:207 ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_in= put.c:241 NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318 NF_HOOK+0x30c/0= x3a0 include/linux/netfilter.h:318 __netif_receive_skb_one_core net/core/de= v.c:6181 [inline] __netif_receive_skb net/core/dev.c:6294 [inline] process_= backlog+0xaa4/0x1960 net/core/dev.c:6645 __napi_poll+0xae/0x340 net/core/de= v.c:7709 napi_poll net/core/dev.c:7772 [inline] net_rx_action+0x5d7/0xf50 n= et/core/dev.c:7929 handle_softirqs+0x22b/0x870 kernel/softirq.c:622 do_soft= irq+0x76/0xd0 kernel/softirq.c:523 </IRQ> <TASK> __local_bh_ena= ble_ip+0xf8/0x130 kernel/softirq.c:450 local_bh_enable include/linux/bottom= _half.h:33 [inline] rcu_read_unlock_bh include/linux/rcupdate.h:924 [inline=
] __dev_queue_xmit+0x1dd7/0x3710 net/core/dev.c:4890 neigh_output include/n= et/neighbour.h:556 [inline] ip_finish_output2+0xca9/0x1070 net/ipv4/ip_outp= ut.c:237 NF_HOOK_COND include/linux/netfilter.h:307 [inline] ip_output+0x29= f/0x450 net/ipv4/ip_output.c:438 ip_send_skb+0x45/0xc0 net/ipv4/ip_output.c= :1508 udp_send_skb+0xb04/0x1510 net/ipv4/udp.c:1195 udp_sendmsg+0x1a71/0x23=
50 net/ipv4/udp.c:1485 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_= sendmsg net/socket.c:742 [inline] __sys_sendto+0x554/0x680 net/socket.c:220=
6 __do_sys_sendto net/socket.c:2213 [inline] __se_sys_sendto net/socket.c:2= 209 [inline] __x64_sys_sendto+0xde/0x100 net/socket.c:2209 do_syscall_x64 a= rch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x160/0xf80 arch/x86/e= ntry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x4= 15a2d Code: b3 66 2e 0f 1f 84 00 00 00 00 00 66 90 f3 0f 1e fa 48 89 f8 48 =
89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3=
d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:000= 07f6bc31e41e8 EFLAGS: 00000212 ORIG_RAX: 000000000000002c RAX: ffffffffffff= ffda RBX: 00007f6bc31e4cdc RCX: 0000000000415a2d RDX: 0000000000000001 RSI:=
00007f6bc31e421f RDI: 0000000000000003 RBP: 00007f6bc31e4240 R08: 00007f6b= c31e4220 R09: 0000000000000010 R10: 0000000000000000 R11: ---truncated---</=
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52910" target=3D= "_blank" rel=3D"noopener">CVE-2026-52910</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ksm= bd: scope conn->binding slowpath to bound sessions only When the binding=
SESSION_SETUP sets conn->binding =3D true, the flag stays set after the=
call so that the global session lookup in ksmbd_session_lookup_all() can f= ind the session, which was not added to conn->sessions. Because the flag=
is connection-wide, the global lookup path will also resolve any other ses= sion by id if asked. Tighten the global lookup so that the returned session=
must have this connection registered in its channel xarray (sess->ksmbd= _chann_list). The channel entry is installed by the existing binding_sessio=
n path in ntlm_authenticate()/krb5_authenticate() when a SESSION_SETUP comp= letes successfully, so this condition is a strict equivalent of "this conne= ction has been accepted as a channel of this session". Connections that hav=
e not bound to a given session cannot reach it via the global table. The ex= isting conn->binding gate for entering the slowpath is preserved so that=
non-binding connections keep the fast-path-only behavior, and the session-= >state check is unchanged.</td>
<td>2026-06-21</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52911" target=3D= "_blank" rel=3D"noopener">CVE-2026-52911</a></td>
</tr>
<td class=3D"vendor-product">liquidfiles--liquidfiles</td>
<td>Liquidfiles versions before 4.2.12 are affected by a broken access cont= rol vulnerability resulting in privilege escalation from an Admin in a seco= ndary domain to a Sysadmin by modifying a group in their managed secondary = (non-default) group.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12673" target=3D= "_blank" rel=3D"noopener">CVE-2026-12673</a></td>
</tr>
<td class=3D"vendor-product">LLDAP--LLDAP v0.6.2</td>
<td>An input handling flaw in the HTTP refresh token process of LLDAP v0.6.=
2 allows attackers to cause a Denial of Service (DoS) via sending a crafted=
refresh-token header.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50889" target=3D= "_blank" rel=3D"noopener">CVE-2026-50889</a></td>
</tr>
<td class=3D"vendor-product">LMS--LMS</td>
<td>An SQL Injection vulnerability exists in LMS (LAN Management System) be= fore commit=C2=A04cb30a7=C2=A0within the "tarifflist.php" module due to ins= ufficient sanitization of the POST "tg[]" parameter. The application direct=
ly concatenates user-supplied array values into an SQL query using "implode= ()", allowing authenticated attackers to perform Error-Based SQL injection = and extract sensitive database information.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40455" target=3D= "_blank" rel=3D"noopener">CVE-2026-40455</a></td>
</tr>
<td class=3D"vendor-product">LMS--LMS</td>
<td>An OS Command Injection vulnerability exists in LMS (LAN Management Sys= tem)=C2=A0before commit 9fcb4de due to an IP address parameter being passed=
to the "exec()" function without proper validation, allowing attackers to = execute arbitrary operating system commands.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40456" target=3D= "_blank" rel=3D"noopener">CVE-2026-40456</a></td>
</tr>
<td class=3D"vendor-product">LMS--LMS</td>
<td>A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN=
Management System)=C2=A0before commit 9c5651b in the "dbrecover.php" and "= netremap.php" modules where unsanitized GET parameters are directly embedde=
d into HTML output. This allows an attacker to inject arbitrary JavaScript = when an authenticated user clicks a crafted link, provided the required con= ditions (such as a network defined in the system) are met.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40457" target=3D= "_blank" rel=3D"noopener">CVE-2026-40457</a></td>
</tr>
<td class=3D"vendor-product">LY Corporation--Armeria</td>
<td>A vulnerability has been identified in armeria-xds versions 1.38.0 thro= ugh 1.39.0, where DataSourceStream in the xDS module can resolve control-pl= ane-supplied filenames and environment variables without restriction, allow= ing a compromised or semi-trusted xDS control plane to read arbitrary local=
files and environment variables on the xDS client host.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11752" target=3D= "_blank" rel=3D"noopener">CVE-2026-11752</a></td>
</tr>
<td class=3D"vendor-product">matze--wastebin v3.4.1</td>
<td>An HTML injection vulnerability in the /src/highlight.rs component of m= atze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a cr= afted payload.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50883" target=3D= "_blank" rel=3D"noopener">CVE-2026-50883</a></td>
</tr>
<td class=3D"vendor-product">mcp-tool-shop-org--backpropagate</td> <td>Backpropagate is a Python library for fine-tuning large language models=
on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI e= xposes a training control plane without authentication: dataset upload, mod=
el load, training start/stop, multi-run orchestration, GGUF export, and Hug= gingFace Hub push. The CLI accepts two operator-facing flags intended as se= curity controls: --auth user:pass - documented as "require HTTP Basic authe= ntication on every request to the UI." and--share - documented as "expose t=
he UI on a public address; requires --auth." When --auth user:pass is passe=
d, the CLI prints Auth: enabled (user: <username>) to confirm to the = operator that authentication is active, then exports BACKPROPAGATE_UI_AUTH= =3Duser:pass to the subprocess that launches the Reflex backend. The Reflex=
backend (backpropagate/ui_app/**) never reads BACKPROPAGATE_UI_AUTH. No au= thentication middleware is registered. No request-level guard runs. No WebS= ocket upgrade guard runs. Any client that reaches the bound port - local or=
remote, depending on whether --share is used - has full UI access. An inli=
ne comment at backpropagate/cli.py:1217-1218 in the v1.1.0 source documents=
the gap: "For Phase 1 the variable is exported but Reflex doesn't read it = yet." This comment was internal-facing; the user-facing documentation (READ= ME, CHANGELOG, SHIP_GATE) advertised the contract as enforced. An attacker = who reaches the bound port can read uploaded datasets, trigger arbitrary tr= aining runs against any local base models as well as read their paths, trig= ger HuggingFace Hub pushes and cause disk-fill DoS. This issue has been fix=
ed in version 1.2.0. If developers cannot immediately upgrade to 1.2.0 run = backprop ui with no flags so it binds to localhost, use SSH port-forwarding=
(ssh -L 7860:localhost:7860 <training-host>) instead of --share for = remote access, and audit any host previously launched with --share, re-issu= ing any HF tokens used during those sessions.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48797" target=3D= "_blank" rel=3D"noopener">CVE-2026-48797</a></td>
</tr>
<td class=3D"vendor-product">Micro-Star International Co., Ltd.--RadiX AX66=
00 WiFi 6 Tri-Band Gaming Router</td>
<td>RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injec= tion vulnerability, which may lead to arbitrary command execution with the = root privilege by a user who logs in to the web console as an administrator= .</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53876" target=3D= "_blank" rel=3D"noopener">CVE-2026-53876</a></td>
</tr>
<td class=3D"vendor-product">Microchip--GridTime 3000</td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cr= oss-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-= Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 throu=
gh 1.1r0.0.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12619" target=3D= "_blank" rel=3D"noopener">CVE-2026-12619</a></td>
</tr>
<td class=3D"vendor-product">Microchip--GridTime 3000</td>
<td>The GridTime 3000 GNSS Time Server leaks the access token in the URL pa= rameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03=
through 1.1r0.0.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12620" target=3D= "_blank" rel=3D"noopener">CVE-2026-12620</a></td>
</tr>
<td class=3D"vendor-product">Microchip--GridTime 3000</td>
<td>Improper neutralization of input during web page generation XSS vulnera= bility in the GridTime 3000 (password reset form) allows XSS. This issue af= fects GridTime 3000: from 1.0r0.03 before 1.2r0.0.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12621" target=3D= "_blank" rel=3D"noopener">CVE-2026-12621</a></td>
</tr>
<td class=3D"vendor-product">Microchip--GridTime 3000</td>
<td>The GridTime 3000 GNSS Time Server has an open redirect vulnerability i=
n the password change form submission. This issue affects GridTime 3000: fr=
om 1.0r0.03 through 1.1r0.0.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12622" target=3D= "_blank" rel=3D"noopener">CVE-2026-12622</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--HEIF Image Extensions</td> <td>Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read beca= use CHEIFItemInfoEntry_GetDataSize can return success while leaving the rep= orted data size as 0. This causes a caller to make a 1-byte allocation. Lat= er, CopyPixels computes copy_size =3D stride * abs(roi_height) but does not=
check the source buffer length before a memmove call.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-62821" target=3D= "_blank" rel=3D"noopener">CVE-2025-62821</a></td>
</tr>
<td class=3D"vendor-product">microsoft--kiota-typescript</td> <td>@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Ki= ota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-previ= ew.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documen= ted as stripping `Authorization` and `Cookie` from cross-origin redirect ta= rgets, but the default `scrubSensitiveHeaders` callback in `RedirectHandler= Options` uses case-sensitive property deletion (`delete headers.Authorizati= on`, `delete headers.Cookie`) on a headers object that `FetchRequestAdapter= .getRequestFromRequestInformation` has already lower-cased. The delete ther= efore targets keys that do not exist, the scrub is a no-op, and any Bearer = token or Cookie attached by a kiota-generated SDK is forwarded to an attack= er-controlled host across a 30x redirect. This is reachable in the default = middleware chain (`MiddlewareFactory.getDefaultMiddlewares`) with no custom=
configuration, and applies to every kiota-generated TypeScript SDK that us=
es `BaseBearerTokenAuthenticationProvider` or any other authentication prov= ider that sets the `Authorization` request header. Version 1.0.0-preview.10=
2 patches the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49336" target=3D= "_blank" rel=3D"noopener">CVE-2026-49336</a></td>
</tr>
<td class=3D"vendor-product">Microvert--MEmu Android Emulator 9.2.7.0</td> <td>An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local atta= cker to escalate privileges via the MemuService.exe component.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36213" target=3D= "_blank" rel=3D"noopener">CVE-2026-36213</a></td>
</tr>
<td class=3D"vendor-product">Mitsubishi Electric Corporation--Mitsubishi El= ectric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP</td>
<td>Integer Overflow or Wraparound vulnerability in the EtherNet/IP functio=
n of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-= EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-= service (DoS) condition in the affected product by rapidly establishing a l= arge number of TCP connections to it, resulting in an inconsistency in the = product's internal connection management process and triggering improper me= mory access.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8805" target=3D"= _blank" rel=3D"noopener">CVE-2026-8805</a></td>
</tr>
<td class=3D"vendor-product">Mitsubishi Electric Corporation--Mitsubishi El= ectric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP</td> <td>Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC=
iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a = remote attacker to cause a denial-of-service (DoS) condition in the affecte=
d product by continuously sending a large number of communication packets t=
o the Ethernet port of the product in a short period of time, increasing th=
e processing load of the product, preventing the internal anomaly-detection=
processing from being performed, and causing the communication function to=
stop.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8806" target=3D"= _blank" rel=3D"noopener">CVE-2026-8806</a></td>
</tr>
<td class=3D"vendor-product">Mitsubishi Electric Corporation--Room Air Cond= itioners (for Japan) MSZ-BKR2223-W</td>
<td>Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room=
Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for = Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters = for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators = (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless = LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (fo=
r Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot=
Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for = Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for=
Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); = and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of=
an affected product to access the affected product using a hard-coded SSID=
and password, thereby obtaining device data such as operation status, room=
set temperature, and room temperature; changing the air-conditioner or Wi-=
Fi settings; or causing Wi-Fi communication to enter a denial-of-service (D= oS) condition.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5667" target=3D"= _blank" rel=3D"noopener">CVE-2026-5667</a></td>
</tr>
<td class=3D"vendor-product">Moxa--NPort 6000 Series</td>
<td>A denial-of-service vulnerability exists in NPort devices because of im= proper access control on the command port. The command interface does not p= roperly validate whether a sender is associated with a valid data port sess= ion before accepting break signal commands. A remote attacker with network = access can send crafted requests to disrupt serial communication for an act= ive user session.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10831" target=3D= "_blank" rel=3D"noopener">CVE-2026-10831</a></td>
</tr>
<td class=3D"vendor-product">Moxa--NPort 6000-G2 Series</td>
<td>A denial-of-service vulnerability exists in the WebSocket API due to in= sufficient validation and handling of JSON-based requests. A low-privileged=
authenticated attacker can send a specially crafted request that causes se= rvice disruption and may result in an unexpected device reboot.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10825" target=3D= "_blank" rel=3D"noopener">CVE-2026-10825</a></td>
</tr>
<td class=3D"vendor-product">Moxa--NPort W2150A-W4/W2250A-W4 Series</td>
<td>A format string vulnerability has been found in the "alias" parameter o=
f the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Seri=
es version 1.5 and prior. This vulnerability stems from insufficient input = validation and improper handling of externally supplied format strings. An = attacker could exploit this vulnerability by sending crafted input to the w=
eb service, causing unintended memory disclosure. Successful exploitation m=
ay allow an attacker to leak sensitive memory contents and determine critic=
al memory addresses, potentially bypassing Address Space Layout Randomizati=
on (ASLR) protections.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10828" target=3D= "_blank" rel=3D"noopener">CVE-2026-10828</a></td>
</tr>
<td class=3D"vendor-product">Moxa--NPort W2150A-W4/W2250A-W4 Series</td>
<td>A stack-based buffer overflow vulnerability has been found in the NPort=
W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability ste=
ms from insufficient input validation of=C2=A0user-supplied input in the "S= erver location" parameter on the Basic settings page.=C2=A0An attacker coul=
d exploit this vulnerability by sending crafted input to the web service, r= esulting in memory corruption. Successful exploitation of this vulnerabilit=
y could allow remote code execution on the target system with root privileg= es.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10829" target=3D= "_blank" rel=3D"noopener">CVE-2026-10829</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Privilege escalation in the Graphics: WebRender component. This vulnera= bility was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Th= underbird 152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12289" target=3D= "_blank" rel=3D"noopener">CVE-2026-12289</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and = Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12290" target=3D= "_blank" rel=3D"noopener">CVE-2026-12290</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Use-after-free in the Networking: HTTP component. This vulnerability wa=
s fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird=
152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12291" target=3D= "_blank" rel=3D"noopener">CVE-2026-12291</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Incorrect boundary conditions in the Web Audio component. This vulnerab= ility was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Th= underbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12292" target=3D= "_blank" rel=3D"noopener">CVE-2026-12292</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Use-after-free in the Graphics: WebGPU component. This vulnerability wa=
s fixed in Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12293" target=3D= "_blank" rel=3D"noopener">CVE-2026-12293</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Sandbox escape in the DOM: Workers component. This vulnerability was fi= xed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152=
, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12294" target=3D= "_blank" rel=3D"noopener">CVE-2026-12294</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Sandbox escape in the DOM: Navigation component. This vulnerability was=
fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird = 152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12295" target=3D= "_blank" rel=3D"noopener">CVE-2026-12295</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Sandbox escape in the Security: Process Sandboxing component. This vuln= erability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, an=
d Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12296" target=3D= "_blank" rel=3D"noopener">CVE-2026-12296</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Sandbox escape due to incorrect boundary conditions in the Networking c= omponent. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, = Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12297" target=3D= "_blank" rel=3D"noopener">CVE-2026-12297</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12298" target=3D= "_blank" rel=3D"noopener">CVE-2026-12298</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>JIT miscompilation in the DOM: Core & HTML component. This vulnerab= ility was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thu= nderbird 152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12299" target=3D= "_blank" rel=3D"noopener">CVE-2026-12299</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12300" target=3D= "_blank" rel=3D"noopener">CVE-2026-12300</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12301" target=3D= "_blank" rel=3D"noopener">CVE-2026-12301</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Mitigation bypass in the DOM: Security component. This vulnerability wa=
s fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird=
152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12302" target=3D= "_blank" rel=3D"noopener">CVE-2026-12302</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Information disclosure due to incorrect boundary conditions in the Grap= hics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thu= nderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12303" target=3D= "_blank" rel=3D"noopener">CVE-2026-12303</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Same-origin policy bypass in the Networking: Cookies component. This vu= lnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, = and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12304" target=3D= "_blank" rel=3D"noopener">CVE-2026-12304</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12305" target=3D= "_blank" rel=3D"noopener">CVE-2026-12305</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12306" target=3D= "_blank" rel=3D"noopener">CVE-2026-12306</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12307" target=3D= "_blank" rel=3D"noopener">CVE-2026-12307</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12308" target=3D= "_blank" rel=3D"noopener">CVE-2026-12308</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12309" target=3D= "_blank" rel=3D"noopener">CVE-2026-12309</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12310" target=3D= "_blank" rel=3D"noopener">CVE-2026-12310</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Information disclosure, sandbox escape in the Security: Process Sandbox= ing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140= .12, Thunderbird 152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12311" target=3D= "_blank" rel=3D"noopener">CVE-2026-12311</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12312" target=3D= "_blank" rel=3D"noopener">CVE-2026-12312</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Information disclosure, sandbox escape in the Security: Process Sandbox= ing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140= .12, Thunderbird 152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12313" target=3D= "_blank" rel=3D"noopener">CVE-2026-12313</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12314" target=3D= "_blank" rel=3D"noopener">CVE-2026-12314</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Mitigation bypass in the DOM: Security component. This vulnerability wa=
s fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbir=
d 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12315" target=3D= "_blank" rel=3D"noopener">CVE-2026-12315</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Mitigation bypass in the DOM: Security component. This vulnerability wa=
s fixed in Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12316" target=3D= "_blank" rel=3D"noopener">CVE-2026-12316</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Firefox 152. This vulnerability was fixed in=
Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12317" target=3D= "_blank" rel=3D"noopener">CVE-2026-12317</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Incorrect boundary conditions in the Libraries component in NSS. This v= ulnerability was fixed in Firefox 152 and Thunderbird 152.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12318" target=3D= "_blank" rel=3D"noopener">CVE-2026-12318</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Denial-of-service in the Audio/Video: Playback component. This vulnerab= ility was fixed in Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12319" target=3D= "_blank" rel=3D"noopener">CVE-2026-12319</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Information disclosure in the Password Manager component. This vulnerab= ility was fixed in Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12320" target=3D= "_blank" rel=3D"noopener">CVE-2026-12320</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>JIT miscompilation in the JavaScript: WebAssembly component. This vulne= rability was fixed in Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12321" target=3D= "_blank" rel=3D"noopener">CVE-2026-12321</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Clickjacking issue in the Widget: Gtk component. This vulnerability was=
fixed in Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12322" target=3D= "_blank" rel=3D"noopener">CVE-2026-12322</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Spoofing issue in the DOM: Core & HTML component. This vulnerabilit=
y was fixed in Firefox 152 and Thunderbird 152.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12323" target=3D= "_blank" rel=3D"noopener">CVE-2026-12323</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Incorrect boundary conditions in the Graphics: CanvasWebGL component. T= his vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird=
152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12324" target=3D= "_blank" rel=3D"noopener">CVE-2026-12324</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Denial-of-service in the Graphics: ImageLib component. This vulnerabili=
ty was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunde= rbird 152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12325" target=3D= "_blank" rel=3D"noopener">CVE-2026-12325</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of = these bugs showed evidence of memory corruption and we presume that with en= ough effort some of these could have been exploited to run arbitrary code. = This vulnerability was fixed in Firefox 152 and Thunderbird 152.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12326" target=3D= "_blank" rel=3D"noopener">CVE-2026-12326</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.1=
1, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of m= emory corruption and we presume that with enough effort some of these could=
have been exploited to run arbitrary code. This vulnerability was fixed in=
Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12327" target=3D= "_blank" rel=3D"noopener">CVE-2026-12327</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, T= hunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs = showed evidence of memory corruption and we presume that with enough effort=
some of these could have been exploited to run arbitrary code. This vulner= ability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, T= hunderbird 152, and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12328" target=3D= "_blank" rel=3D"noopener">CVE-2026-12328</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability w=
as fixed in Firefox ESR 140.12 and Thunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12329" target=3D= "_blank" rel=3D"noopener">CVE-2026-12329</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox</td>
<td>Incorrect boundary conditions in the Internationalization component. Th=
is vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and T= hunderbird 140.12.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12330" target=3D= "_blank" rel=3D"noopener">CVE-2026-12330</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox for iOS</td>
<td>Firefox for iOS used partial domain matching when attaching cookies to = PDF requests, allowing a malicious site on a suffix domain to receive cooki=
es belonging to the target site. This vulnerability was fixed in Firefox fo=
r iOS 152.0.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53899" target=3D= "_blank" rel=3D"noopener">CVE-2026-53899</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox for iOS</td>
<td>Firefox for iOS preserved cookies set on the initial PDF request across=
cross-origin HTTP redirects in TemporaryDocument, allowing a malicious sit=
e to inject arbitrary cookies into requests to an unrelated target domain. = This vulnerability was fixed in Firefox for iOS 152.0.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53900" target=3D= "_blank" rel=3D"noopener">CVE-2026-53900</a></td>
</tr>
<td class=3D"vendor-product">Netskope--Netskope Client</td>
<td>Netskope was notified about a potential gap in its Netskope Client for = Windows systems where a malicious insider with administrative privileges ca=
n potentially tamper with the customer IOCTL by sending crafted IOCTL reque= sts to the driver. A successful exploit can result in the bypassing of all = anti-tampering protections for the NSClient.Affected Product(s) and Version= (s) * Product Name: Netskope Client * Affected Platform: Windows * Affected=
Version: All version below R138</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15641" target=3D= "_blank" rel=3D"noopener">CVE-2025-15641</a></td>
</tr>
<td class=3D"vendor-product">Netskope--Netskope Client</td>
<td>Netskope is notified about a potential gap in its Netskoped Client for = Windows systems where a malicious insider with admin privileges can lead to=
bypassing the NSClient Tamper Protections due to weak Discretionary Access=
Control List (DACLs) on the service object and related registry keys,. * P= roduct Name: Netskope Client * Affected Platform: Windows * Affected Versio=
n: All version below R138</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15642" target=3D= "_blank" rel=3D"noopener">CVE-2025-15642</a></td>
</tr>
<td class=3D"vendor-product">Nginx--Nginx Proxy Manager v2.14.0</td> <td>Incorrect access control in the "Let's Encrypt" certificate download en= dpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obt= ain the TLS private key material via a crafted GET request.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50892" target=3D= "_blank" rel=3D"noopener">CVE-2026-50892</a></td>
</tr>
<td class=3D"vendor-product">nltk--nltk/nltk</td>
<td>A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows un= authenticated remote shutdown of the local WordNet Browser HTTP server when=
started in its default mode. The server listens on all interfaces and proc= esses a specific unauthenticated GET request (`/SHUTDOWN%20THE%20SERVER`) t=
o terminate the process immediately via `os._exit(0)`. This results in a de= nial of service, impacting service availability. The issue arises due to in= sufficient authentication and protection mechanisms for critical server fun= ctions.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12199" target=3D= "_blank" rel=3D"noopener">CVE-2026-12199</a></td>
</tr>
<td class=3D"vendor-product">nodejs--node</td>
<td>A flaw in Node.js Permission Model enforcement allows Bypass via `proce= ss.report.writeReport()` Path Misvalidation. This can lead to confidentiali=
ty impact or bypass of the intended security boundary under affected config= urations. This vulnerability affects all supported release lines: **Node.js=
22**, **Node.js 24**, and **Node.js 26**.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48617" target=3D= "_blank" rel=3D"noopener">CVE-2026-48617</a></td>
</tr>
<td class=3D"vendor-product">nodejs--node</td>
<td>A flaw in Node.js HTTP/2 server API can cause servers to keep accepting=
data even after sending a `GOAWAY` frame. This vulnerability affects two s= upported release lines: **Node.js 22** and **Node.js 24**.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48937" target=3D= "_blank" rel=3D"noopener">CVE-2026-48937</a></td>
</tr>
<td class=3D"vendor-product">Nokia--Nokia SR Linux</td>
<td>Nokia SR Linux is vulnerable to a local privilege escalation vulnerabil= ity. Successful exploitation of this vulnerability may allow an authenticat=
ed user to execute arbitrary commands with superuser privilege.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-9912" target=3D"= _blank" rel=3D"noopener">CVE-2025-9912</a></td>
</tr>
<td class=3D"vendor-product">Nokia--SR Linux</td>
<td>Nokia SR Linux is vulnerable to local privilege escalation vulnerabilit=
y due to unsanitized format validation. Successful exploitation of this vul= nerability may allow an authenticated user to execute arbitrary commands wi=
th superuser privileges.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-10262" target=3D= "_blank" rel=3D"noopener">CVE-2025-10262</a></td>
</tr>
<td class=3D"vendor-product">Nuxt--Nuxt</td>
<td>Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-s= ite scripting vulnerability in the NoScript component that writes slot cont= ent to innerHTML without escaping. Attackers can inject malicious scripts t= hrough untrusted data in NoScript slots, such as route.query parameters, wh= ich execute in the document context when the noscript tag is implicitly clo= sed by script tags.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56317" target=3D= "_blank" rel=3D"noopener">CVE-2026-56317</a></td>
</tr>
<td class=3D"vendor-product">Observeinc--Observeinc's Observe</td>
<td>An issue in Observeinc's Observe v.2026-01-28 and before allows a remot=
e attacker to obtain sensitive information via the CSV Log export component= .</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39007" target=3D= "_blank" rel=3D"noopener">CVE-2026-39007</a></td>
</tr>
<td class=3D"vendor-product">OCaml--OCaml-tar</td>
<td>In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in = its name allows escaping the current working directory. This is not desired=
behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses =
it anyway. The impact is that it allows arbitrary file writes outside of th=
e desired extraction directory (to an attacker that can reach a tar decompr= ession endpoint).</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45390" target=3D= "_blank" rel=3D"noopener">CVE-2026-45390</a></td>
</tr>
<td class=3D"vendor-product">OCaml--OCaml-TLS</td>
<td>In OCaml-TLS before 2.1.0, the client implementation does insufficient = checks of the certificate provided by the server, which allows impersonatio=
n with certificates that are not meant for server authentication (because o=
f KeyUsage and ExtendedKeyUsage).</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45388" target=3D= "_blank" rel=3D"noopener">CVE-2026-45388</a></td>
</tr>
<td class=3D"vendor-product">OCaml--OCaml-TLS</td>
<td>In OCaml-TLS before 2.1.0, the server implementation does insufficient = checks of the certificate provided by the client (when doing client authent= ication), which allows impersonation with certificates that are not meant f=
or client authentication (because of KeyUsage and ExtendedKeyUsage).</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45389" target=3D= "_blank" rel=3D"noopener">CVE-2026-45389</a></td>
</tr>
<td class=3D"vendor-product">Octopus Deploy--Octopus Server</td>
<td>In affected versions of Octopus Server with certain access levels it wa=
s possible to embed a Cross-Site Scripting Payload via artifacts.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8296" target=3D"= _blank" rel=3D"noopener">CVE-2026-8296</a></td>
</tr>
<td class=3D"vendor-product">OpenCPN--OpenCPN</td>
<td>A code injection vulnerability in the wxExecute() function of OpenCPN v= 5.12.0 allows attackers to execute arbitrary code via embedding shell metac= haracters.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-56814" target=3D= "_blank" rel=3D"noopener">CVE-2025-56814</a></td>
</tr>
<td class=3D"vendor-product">OpenSIPS--OpenSIPS Control Panel</td>
<td>A Time-Based Blind SQL Injection vulnerability in the alias_management = module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allow=
s authenticated attackers to execute arbitrary SQL commands via the 'table'=
GET parameter in alias_management.php.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36670" target=3D= "_blank" rel=3D"noopener">CVE-2026-36670</a></td>
</tr>
<td class=3D"vendor-product">OpenSolution--Quick.CMS</td>
<td>Quick.CMS deserializes user-controlled data received over plaintext HTT=
P without ensuring integrity or authenticity. This allows attackers to tamp=
er with serialized payloads in transit and inject malicious objects. Becaus=
e deserialization is performed without proper validation or class restricti= ons, crafted payloads can trigger dangerous magic methods (e.g., __wakeup()=
and __destruct()) and leverage gadget chains, resulting in arbitrary code = execution. Exploitation is triggered automatically when an administrator ac= cesses the admin panel. When successfully exploited, this vulnerability all= ows attackers to execute arbitrary code on the server via manipulated seria= lized data transmitted over an unprotected channel. This issue was mitigate=
d by limiting the communication to HTTPS in a patch for version 6.8 publish=
ed on 14.05.2026, deployments without this patch remain vulnerable.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11860" target=3D= "_blank" rel=3D"noopener">CVE-2026-11860</a></td>
</tr>
<td class=3D"vendor-product">Password Manager--Password Manager</td> <td>Improper handling of HTTP headers that allows a remote attacker to mani= pulate the value of the Host header using specially crafted requests. A suc= cessful exploit could result in the generation of manipulated links or resp= onses, potentially leading to limited information disclosure or compromisin=
g the integrity of dependent services.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10836" target=3D= "_blank" rel=3D"noopener">CVE-2026-10836</a></td>
</tr>
<td class=3D"vendor-product">Password Manager--Password Manager</td>
<td>Open redirection vulnerability due to insufficient validation of the X-= Forwarded-Host HTTP header. An attacker could create manipulated links that=
, when opened by a victim, cause the victim to be redirected to domains con= trolled by the attacker, enabling phishing or deception attacks with limite=
d impact on confidentiality and integrity.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10837" target=3D= "_blank" rel=3D"noopener">CVE-2026-10837</a></td>
</tr>
<td class=3D"vendor-product">Password Manager--Password Manager</td>
<td>Open redirection vulnerability in the authentication system allows an a= ttacker to use manipulated values in the X-Forwarded-Host header to alter t=
he URLs generated by the application. A successful exploit could redirect a= uthenticated users to malicious sites following login procedures or interac= tion with the interface, resulting in limited impact on confidentiality and=
integrity.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10839" target=3D= "_blank" rel=3D"noopener">CVE-2026-10839</a></td>
</tr>
<td class=3D"vendor-product">PEVANS--Socket</td>
<td>Socket versions before 2.041 for Perl have an out-of-bounds heap read. =
In Socket.xs, pack_ip_mreq_source() checks the length of its source argumen=
t before the argument is read, so the check tests the byte length carried o= ver from the preceding multiaddr argument instead. Both addresses occupy a = 4-byte field, so a valid multiaddr lets a source of any length pass the che= ck, and the source is then copied into the 4-byte imr_sourceaddr field with=
a fixed-size copy. A source shorter than 4 bytes is not rejected, and the = copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_s= ource() with a source value shorter than 4 bytes copies adjacent heap memor=
y into the returned packed structure.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12087" target=3D= "_blank" rel=3D"noopener">CVE-2026-12087</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 0.0.25 fails to detect malicious pickle files that us=
e timeit.timeit() in the __reduce__ method, allowing remote code execution.=
Attackers can craft pickle files that import dangerous libraries like os a=
nd execute arbitrary system commands, which evade picklescan detection and = execute when pickle.load() is called.</td>
<td>2026-06-21</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-71351" target=3D= "_blank" rel=3D"noopener">CVE-2025-71351</a></td>
</tr>
<td class=3D"vendor-product">picklescan--picklescan</td>
<td>picklescan before 1.0.3 contains a scanning bypass vulnerability in the=
scan_pytorch function that allows attackers to embed malicious magic numbe=
rs via dynamic eval using the __reduce__ trick. Attackers can craft malicio=
us PyTorch payloads that evade picklescan detection while remaining executa= ble, enabling arbitrary code execution when loaded with torch.load().</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53875" target=3D= "_blank" rel=3D"noopener">CVE-2026-53875</a></td>
</tr>
<td class=3D"vendor-product">Plane--Plane</td>
<td>Plane CE 1.3.1 allows a low-privileged project member to submit arbitra=
ry HTML/JS in the description_html field when creating an intake work item = through the API v1 intake endpoint.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10850" target=3D= "_blank" rel=3D"noopener">CVE-2026-10850</a></td>
</tr>
<td class=3D"vendor-product">PowerSchool--Employee Access Center</td> <td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cr= oss-site Scripting') vulnerability in PowerSchool Employee Access Center al= lows Cross-Site Scripting (XSS).=C2=A0This issue affects Employee Access Ce= nter: 23.10.=C2=A0It is possible to add in javascript code after the login = URL and have it be eval()'d in the page and execute in the context of the u= ser.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12425" target=3D= "_blank" rel=3D"noopener">CVE-2026-12425</a></td>
</tr>
<td class=3D"vendor-product">pragdave--earmark</td>
<td>Improper Neutralization of Script in Attributes in a Web Page vulnerabi= lity in pragdave earmark allows stored cross-site scripting via unescaped H= TML attribute values. 'Elixir.Earmark.Transform':_make_att1/2 in lib/earmar= k/transform.ex splices attribute values verbatim between two literal " byte=
s: [" ", name, "=3D\"", value, "\""]. Text nodes are routed through the exi= sting escape function which encodes " as &quot;, but attribute values n= ever visit that path. A markdown link whose URL or title contains a bare " = closes the attribute early and lets the trailing bytes be parsed by the bro= wser as fresh HTML attributes. For example, [click](
http://example.com/?a= =3Dx" onerror=3D"alert(1)) renders as <a href=3D"
http://example.com/?a= =3Dx" onerror=3D"alert(1)">click</a>, executing arbitrary JavaScri=
pt in the victim's browser. The earmark library is no longer maintained and=
has been retired on Hex. No patched version will be released. All releases=
from 1.4.1 onward are affected, and users should migrate to a maintained M= arkdown library such as MDEx. This issue affects earmark from 1.4.1 onward.= </td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48591" target=3D= "_blank" rel=3D"noopener">CVE-2026-48591</a></td>
</tr>
<td class=3D"vendor-product">prefecthq--prefecthq/prefect</td>
<td>Prefect version 3.6.23 is vulnerable to remote code execution due to im= proper handling of user-controlled input in the `GitRepository` storage cla= ss. The `commit_sha` parameter, which is passed to git commands, lacks vali= dation and does not include a `--` separator to distinguish user input from=
git flags. This allows attackers to inject arbitrary git flags, such as `-= -upload-pack`, enabling execution of external programs. Additionally, the `= directories` parameter can be exploited to inject git flags during sparse-c= heckout operations. These vulnerabilities allow any user with deployment cr= eation permissions to execute arbitrary commands on worker machines, compro= mising shared work pools in multi-tenant environments.</td>
<td>2026-06-20</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5366" target=3D"= _blank" rel=3D"noopener">CVE-2026-5366</a></td>
</tr>
<td class=3D"vendor-product">Progress Chef--Chef360</td>
<td>Impact A security issue has been identified in Chef 360 that could allo=
w unauthorized access to protected API endpoints under specific conditions.= =C2=A0This issue is due to improper handling of URL-encoded paths during re= quest processing. In certain scenarios, an authenticated request may bypass=
standard access controls gaining additional privileges, potentially allowi=
ng access to API endpoints that are intended to be restricted to higher-per= missioned roles.=C2=A0The impact is limited to environments where the affec= ted request patterns can be triggered and depends on specific deployment co= nfiguration and access controls in place. Resolution The issue has been add= ressed through product updates that improve request validation and enforce = strict path normalization before authorization checks.=C2=A0 Customers are = advised to update to the latest available version containing the fix, versi=
on 1.7.1 or later.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8100" target=3D"= _blank" rel=3D"noopener">CVE-2026-8100</a></td>
</tr>
<td class=3D"vendor-product">Progress Chef--Chef360</td>
<td>A static credential embedded in Chef 360 prior to v1.7.0 permitted unau= thenticated access to internal message queues. =C2=A0Queue messages contain=
ed tenant-specific identifiers. =C2=A0The credential has been rotated and r= eplaced with per-tenant access in subsequent versions, eliminating this acc= ess method entirely.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8668" target=3D"= _blank" rel=3D"noopener">CVE-2026-8668</a></td>
</tr>
<td class=3D"vendor-product">Project Firefly III--Project Firefly III v6.5.= 9</td>
<td>Incorrect access control in the webhook management component of Project=
Firefly III v6.5.9 allows attackers to scan internal resources via a craft=
ed POST request.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50886" target=3D= "_blank" rel=3D"noopener">CVE-2026-50886</a></td>
</tr>
<td class=3D"vendor-product">PTC--Windchill PDMLink</td>
<td>A critical remote code execution (RCE) vulnerability has been reported =
in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploite=
d through the deserialization of untrusted data.=C2=A0 * This advisory also=
applies to all CPS versions * The identified vulnerability also impacts Wi= ndchill and FlexPLM releases prior to 11.0 M030</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12569" target=3D= "_blank" rel=3D"noopener">CVE-2026-12569</a></td>
</tr>
<td class=3D"vendor-product">PublicCMS--PublicCMS</td>
<td>PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in=
the site configuration management module.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36521" target=3D= "_blank" rel=3D"noopener">CVE-2026-36521</a></td>
</tr>
<td class=3D"vendor-product">Python Software Foundation--CPython</td>
<td>To allow builds of Python to be run from an in-tree layout (rather than=
an installed file layout), the VPATH variable is defined at build time and=
used to locate certain landmarks - specifically, Modules/setup.local. When=
this landmark is found relative to VPATH relative to the executable, Pytho=
n assumes it is running in a source tree and generates a different default = sys.path. This code remains in release builds, so that release-ready builds=
can be built in-tree. On Windows, since builds are written to 'PCbuild/', = the value of VPATH is set to '..\..', which results in a landmark of '..\..= \Modules\setup.local'. This path is outside the install directory of Python=
, and may have different permissions, potentially allowing a low-privilege = user to create the landmark and an alternative `Lib` folder that will be di= scovered by an otherwise restricted install. Such a setup occurs with the l= egacy default install location for all users (in the now superseded EXE ins= taller), due to how Windows allows all users to create folders in the root = directory of their OS drive. Our recommended mitigation on Windows is to mi= grate away from the legacy installer and use the new [Python install manage= r](
https://www.python.org/downloads/latest/pymanager/) to install for the c= urrent user. Installs where the directory two levels above the Python insta= llation directory have equivalent permissions are unaffected (in general, a=
per-user install cannot be modified at all by other users, removing any es= calation of privilege risk, and could be directly modified by a privileged = user, making the potential tampering irrelevant). Alternative mitigations m= ight include preemptively creating and restricting access to a `Modules` di= rectory. Be aware that only 3.13 and 3.14 will receive updated legacy insta= llers - earlier fixes are only provided as sources. Platforms other than Wi= ndows allow VPATH to be overridden, but as they don't usually use a separat=
ed directory in the build for binaries, are unlikely to have a landmark ref= erence outside of the install directory. The landmark detection involving V= PATH is a fallback for when a more specific landmark - .\pybuilddir.txt - i=
s absent, and was included for compatibility. Future releases of Python wil=
l no longer include the fallback, and so builds will need to generate or pr= eserve the pybuilddir.txt file in order to work in-tree. This landmark file=
has been generated on Windows since 3.11, and on other platforms for longe= r.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12003" target=3D= "_blank" rel=3D"noopener">CVE-2026-12003</a></td>
</tr>
<td class=3D"vendor-product">Quanos Solutions GmbH--SCHEMA ST4</td>
<td>Quanos SCHEMA ST4 on-premises contains a local privilege escalation vul= nerability in the Client Update Service due to insecure deserialization in = the .NET Remoting service. The service is configured with TypeFilterLevel.F= ull and is bound to local interfaces only through named pipes. A local auth= enticated attacker can connect to the local named pipe, obtain the .NET Rem= oting endpoint, and send specially crafted serialized objects. Successful e= xploitation results in arbitrary code execution in the context of the updat=
e process with NT AUTHORITY\SYSTEM privileges. Network-only exploitation is=
not possible and local host access with an authenticated user session is r= equired.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11857" target=3D= "_blank" rel=3D"noopener">CVE-2026-11857</a></td>
</tr>
<td class=3D"vendor-product">Quanos Solutions GmbH--SCHEMA ST4</td>
<td>Quanos SCHEMA ST4 on-premises contains a local privilege escalation vul= nerability in the Client Update Service. The update service runs as NT AUTH= ORITY\SYSTEM and exposes a .NET Remoting interface over a named pipe withou=
t sufficient access controls or authorization. A local authenticated low-pr= ivileged user can connect to the interface and invoke privileged update met= hods such as Update(). This allows arbitrary file write and delete operatio=
ns with SYSTEM privileges and can be used to achieve local privilege escala= tion.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11858" target=3D= "_blank" rel=3D"noopener">CVE-2026-11858</a></td>
</tr>
<td class=3D"vendor-product">radvd-project--radvdump</td>
<td>radvd is a router advertisement daemon for IPv6. Prior to version 2.21,=
the `radvdump` utility shipped with radvd contains a stack buffer overflow=
in the Route Information option parser. When processing a crafted ICMPv6 R= outer Advertisement, `print_ff()` copies up to 2032 bytes from attacker-con= trolled packet data into a 16-byte `struct in6_addr` on the stack, overflow= ing by up to 2016 bytes. Note that the main `radvd` daemon is not affected =
by the vulnerability. Version 2.21 patches the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48715" target=3D= "_blank" rel=3D"noopener">CVE-2026-48715</a></td>
</tr>
<td class=3D"vendor-product">Rakuten--Send Anywhere</td>
<td>An issue was discovered in Rakuten Send Anywhere (File Transfer) for An= droid (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows un= trusted applications (with no permissions) to force arbitrary file download=
s into the app's scoped storage. The resulting files appear in the applicat= ion's trusted Received interface. These conditions establish a vector for a= rbitrary code execution if the payload is an APK file, or a denial-of-servi=
ce condition through resource exhaustion from oversized transfers.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-68713" target=3D= "_blank" rel=3D"noopener">CVE-2025-68713</a></td>
</tr>
<td class=3D"vendor-product">remotion-dev remotion--remotion-dev remotion v= 4.0.409</td>
<td>remotion-dev remotion v4.0.409 was discovered to contain a remote code = execution (RCE) vulnerability.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-30120" target=3D= "_blank" rel=3D"noopener">CVE-2026-30120</a></td>
</tr>
<td class=3D"vendor-product">remotion-dev remotion--remotion-dev remotion v= 4.0.409</td>
<td>remotion-dev remotion v4.0.409 was discovered to contain an arbitrary f= ile write vulnerability.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-30121" target=3D= "_blank" rel=3D"noopener">CVE-2026-30121</a></td>
</tr>
<td class=3D"vendor-product">Ricoh Company, Ltd.--Multiple printer drivers<=
<td>Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MIN= OLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vuln= erability is exploited, an attacker who can log in to a computer running an=
affected printer driver could elevate privileges by using a specially craf= ted driver.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50100" target=3D= "_blank" rel=3D"noopener">CVE-2026-50100</a></td>
</tr>
<td class=3D"vendor-product">Rocket.Chat--Rocket.Chat</td>
<td>Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13= .9, 7.10.13 has an access control vulnerability in Livechat files. Protecte=
d file downloads at /file-upload/:fileId/:name authorize livechat access us= ing rc_room_type=3Dl with rc_rid+rc_token, but the authorization path does = not verify that rc_rid matches the requested file's rid. Furthermore, :file=
Id is predictable via sequential MongoDB IDs, and :name can be anything, al= lowing unauthenticated discovery of all uploaded files.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48616" target=3D= "_blank" rel=3D"noopener">CVE-2026-48616</a></td>
</tr>
<td class=3D"vendor-product">Rocket.Chat--Rocket.Chat</td>
<td>Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <= ;8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthentic= ated file deletion. The deleteFileMessage Meteor method permanently deletes=
any uploaded file by ID without requiring authentication. When called via =
an unauthenticated DDP WebSocket connection, Meteor.userId() returns null, = causing the authorization check to be skipped. Execution falls through to F= ileUpload.getStore('Uploads').deleteById(fileID), which removes the file fr=
om storage and database unconditionally. File IDs are discoverable from pub= lic channel message payloads and download URLs.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48929" target=3D= "_blank" rel=3D"noopener">CVE-2026-48929</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--CompactLogix 5370</td>
<td>A security issue exists within=C2=A01769 CompactLogix controllers=C2=A0= due to the=C2=A0missing validation of sequence numbers and source IP addres= ses in the CIP protocol. This allows attacker to abuse the exposed Connecti=
on ID's visible on the web interface to perform denial-of-service attacks, = resulting in a=C2=A0minor fault.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-11694" target=3D= "_blank" rel=3D"noopener">CVE-2025-11694</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--CompactLogix 5370</td>
<td>A sensitive information disclosure security issue exists within the aff= ected CompactLogix controllers. The=C2=A0controller's=C2=A0web server expos=
es CIP Connection IDs on the diagnostics webpage, which are accessible to a=
ny unauthenticated user on the network. This information can be=C2=A0levera= ged=C2=A0by an attacker to construct malicious packets, leading to Denial-o= f-Service.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9307" target=3D"= _blank" rel=3D"noopener">CVE-2026-9307</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--CompactLogix, ControlLogi= x</td>
<td>A denial of service security issue exists in the affected product. The = security issue stems from a fault occurring when a crafted CIP message is s= ent. Devices with less memory are more likely to be affected. This can resu=
lt in a major nonrecoverable fault (MNRF). A program download is required t=
o recover.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11317" target=3D= "_blank" rel=3D"noopener">CVE-2026-11317</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--FactoryTalk Analytics Pav= ilionX</td>
<td>A security issue was=C2=A0identified=C2=A0in Pavilion due to improper= =C2=A0authorization=C2=A0enforcement in API endpoints.=C2=A0This vulnerabil= ity can=C2=A0allow an unauthorized actor to execute privileged operations, = including user/role management and other administrative actions.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14272" target=3D= "_blank" rel=3D"noopener">CVE-2025-14272</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--FactoryTalk Historian SE<=
<td>An authentication bypass security issue exists within FactoryTalk Histo= rian Site Edition. By continually sending requests to the login endpoint, a=
n attacker may obtain a valid authentication token.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-13036" target=3D= "_blank" rel=3D"noopener">CVE-2025-13036</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--FLEX I/O EtherNet/IP Adap= ters</td>
<td>A denial-of-service security issue exists within the 1794-AENTR adapter=
due to improper=C2=A0memory handling=C2=A0of CIP protocol requests. This= =C2=A0vulnerability=C2=A0can result in the=C2=A0adapter=C2=A0faulting and l= osing connection to=C2=A0its=C2=A0associated I/O modules, requiring a manua=
l reset to recover.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0646" target=3D"= _blank" rel=3D"noopener">CVE-2026-0646</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--FLEX I/O EtherNet/IP Adap= ters</td>
<td>An improper authentication security issue exists within the 1794-AENTR = adapter's embedded web server. The vulnerability allows an unauthenticated = attacker to change the device's web interface password by sending a crafted=
HTTP GET request to a specific endpoint, without any prior authentication = being=C2=A0required. If exploited, this could lead to unauthorized access, = account takeover, and loss of=C2=A0the=C2=A0device's embedded web server's= =C2=A0availability.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0647" target=3D"= _blank" rel=3D"noopener">CVE-2026-0647</a></td>
</tr>
<td class=3D"vendor-product">Roy Marples--NetworkConfiguartion/dhcpcd</td> <td>A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/d= hcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if= -options.c:1886), the code performs a member access on a NULL pointer of ty=
pe 'struct dhcp_opt' when an unexpected/invalid option token or parsing sta=
te causes the lookup to yield NULL. The instrumented fuzzing build reports = 'runtime error: member access within null pointer of type struct dhcp_opt' = and aborts.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-70102" target=3D= "_blank" rel=3D"noopener">CVE-2025-70102</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Micro</td>
<td>Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) = allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before=
4.3.0.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-30802" target=3D= "_blank" rel=3D"noopener">CVE-2026-30802</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Micro</td>
<td>Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Mic=
ro (Core Libraries) allows Overread Buffers.This issue affects Connext Micr=
o: from 4.0.0 before 4.3.0.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-30803" target=3D= "_blank" rel=3D"noopener">CVE-2026-30803</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Professional</td>
<td>Heap-based Buffer Overflow vulnerability in RTI Connext Professional (C= ore Libraries) allows Overflow Variables and Tags.This issue affects Connex=
t Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.= 1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.= 0.0 before 5.2.*.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2467" target=3D"= _blank" rel=3D"noopener">CVE-2026-2467</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Professional</td>
<td>Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerabi= lity in RTI Connext Professional (Queueing Service,Core Libraries,Persisten=
ce Service) allows Overflow Buffers, Overflow Buffers, Overflow Buffers.Thi=
s issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 b= efore 7.3.1.3, from 6.1.0 before 6.1.*.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2674" target=3D"= _blank" rel=3D"noopener">CVE-2026-2674</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Professional</td>
<td>Missing Authentication for Critical Function vulnerability in RTI Conne=
xt Professional (Security Plugins) allows Fake the Source of Data.This issu=
e affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before = 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 befor=
e 5.3.*.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2675" target=3D"= _blank" rel=3D"noopener">CVE-2026-2675</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Professional</td>
<td>Missing Authentication for Critical Function vulnerability in RTI Conne=
xt Professional (Security Plugins) allows Identity Spoofing.This issue affe= cts Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.*,=
from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.= </td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-30799" target=3D= "_blank" rel=3D"noopener">CVE-2026-30799</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Professional</td>
<td>Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libr= aries) allows Overread Buffers.This issue affects Connext Professional: fro=
m 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, f= rom 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.</=
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3894" target=3D"= _blank" rel=3D"noopener">CVE-2026-3894</a></td>
</tr>
<td class=3D"vendor-product">RTI--Connext Professional</td>
<td>Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') = vulnerability in RTI Connext Professional (Web Integration Service) allows = Filter Failure through Buffer Overflow.This issue affects Connext Professio= nal: from 7.4.0 before 7.*, from 7.0.0 before 7.3.1.3, from 6.1.2 before 6.= 1.*.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7300" target=3D"= _blank" rel=3D"noopener">CVE-2026-7300</a></td>
</tr>
<td class=3D"vendor-product">rui314--8cc</td>
<td>8cc is vulnerable to an Out of Bounds Read due to improper handling of = #line directives and GNU linemarkers. The compiler accepts attacker-control= led filename and line number metadata and later uses it without validation = when accessing source line arrays. By supplying invalid or oversized line n= umbers, an attacker can trigger out-of-bounds memory access and a crash. Ma= intainer of this project was notified early about this vulnerability, but d= idn't respond with the details of vulnerability or vulnerable version range=
. Version corresponding to the commit b480958 was tested and confirmed as v= ulnerable, other versions were not tested but might also be vulnerable.</td=
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50643" target=3D= "_blank" rel=3D"noopener">CVE-2026-50643</a></td>
</tr>
<td class=3D"vendor-product">Ruoyi--Ruoyi 4.8.2</td>
<td>Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interfac=
e /system/notice/add.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-37216" target=3D= "_blank" rel=3D"noopener">CVE-2026-37216</a></td>
</tr>
<td class=3D"vendor-product">Ruoyi--Ruoyi v.4.8.2</td>
<td>RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTab=
le endpoint. The issue affects the code generation module and may allow an = authenticated attacker with administrative privileges to access sensitive d= atabase information.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38812" target=3D= "_blank" rel=3D"noopener">CVE-2026-38812</a></td>
</tr>
<td class=3D"vendor-product">SEPPmail AG--Secure Email Gateway</td> <td>SEPPmail versions before 15.0.5 allow improper handling of attachment f= ilenames during encrypted PDF generation. An attacker can exploit this to c= reate new files outside the intended directory, potentially placing files i=
n web-accessible locations.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8811" target=3D"= _blank" rel=3D"noopener">CVE-2026-8811</a></td>
</tr>
<td class=3D"vendor-product">Shenzhen Liandian Communication Technology LTD= --V380 IP Camera / AppFHE1_V1.0.6.0</td>
<td>A broken authorization boundary in the RTSP media delivery pipeline of = Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppF= HE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the d= evice's credential-enforced live-view workflow and directly retrieve real-t= ime video stream data.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12527" target=3D= "_blank" rel=3D"noopener">CVE-2026-12527</a></td>
</tr>
<td class=3D"vendor-product">shlink--shlink v5.0.1</td>
<td>A Server-Side Request Forgery (SSRF) in the automatic short URL title r= esolution component of shlink v5.0.1 allows attackers to scan internal reso= urces via supplying a crafted longUrl.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50887" target=3D= "_blank" rel=3D"noopener">CVE-2026-50887</a></td>
</tr>
<td class=3D"vendor-product">SignalRGB--SignalRGB kernel driver</td>
<td>In SignalRGB versions prior to 1.3.7.0, the \.\SignalIo device object i=
s created without an explicit SDDL security descriptor and without FILE_DEV= ICE_SECURE_OPEN. This results in overly permissive default access control, = allowing any authenticated local user to obtain a handle to the device and = issue privileged IOCTLs.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8049" target=3D"= _blank" rel=3D"noopener">CVE-2026-8049</a></td>
</tr>
<td class=3D"vendor-product">SignalRGB--SignalRGB kernel driver</td>
<td>In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL han= dlers dereference the SystemBuffer pointer without first verifying that it =
is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL poin= ter dereference, resulting in a kernel crash.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8050" target=3D"= _blank" rel=3D"noopener">CVE-2026-8050</a></td>
</tr>
<td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
<td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGP= T's LoopVideoBLock allows users to input a video file and process the video=
, such as looping it 5 times or extending the time, and finally writing it =
to disk. However, there is no limit on the resources that can be allocated = during execution. For example, the number of loops is user-controllable and=
unlimited. When a malicious attacker loops too many times, the generated v= ideo is too large, and after writing it to disk, the disk space is exhauste=
d, eventually causing DoS. Version 0.6.63 patches the issue.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-32392" target=3D= "_blank" rel=3D"noopener">CVE-2025-32392</a></td>
</tr>
<td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
<td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Prior to 0.6.63, `StepT= hroughItemsBlock` can iterate all the contents in a list and send them to `= FileStoreBlock` for downloading one by one. Although `FileStoreBlock` has a= ccess time limits for downloading files, `StepThroughItemsBlock` can be use=
d to slowly iterate and download relatively small files (e.g., 100M) multip=
le times. `StepThroughItemsBlock` does not limit the number of loops. In ad= dition, `FileStoreBlock` does not limit the amount of disk space consumed i=
n the current working directory. When a malicious user chooses to download = too many videos, the disk space will eventually run out, causing a DoS. Ver= sion 0.6.63 patches the issue.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-32422" target=3D= "_blank" rel=3D"noopener">CVE-2025-32422</a></td>
</tr>
<td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
<td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Prior to 0.6.63, Screen= shotWebPageBlock will store the captured screenshots in a temporary directo= ry. `StepThroughItemsBlock` can be used to iterate `ScreenshotWebPageBlock`=
multiple times. `StepThroughItemsBlock` does not limit the number of loops=
. In addition, `ScreenshotWebPageBlock` does not limit the amount of disk s= pace consumed in the current working directory. When a malicious user choos=
es to screen shot many web pages, the disk space will eventually run out, c= ausing a DoS. Version 0.6.63 patches the issue.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-32424" target=3D= "_blank" rel=3D"noopener">CVE-2025-32424</a></td>
</tr>
<td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
<td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Prior to 0.6.63, `AddAu= dioToVideoBlock` will download and store the video and audio in a temporary=
directory without deleting before all noded are done. `StepThroughItemsBlo= ck` can be used to iterate `MediaDurationBlock` multiple times. `StepThroug= hItemsBlock` does not limit the number of loops. In addition, `AddAudioToVi= deoBlock` does not limit the amount of disk space consumed in the current w= orking directory and does not delete the video after outputing the result. = When a malicious user chooses to screen shot many web pages, the disk space=
will eventually run out, causing a DoS. Version 0.6.63 patches the issue.<=
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-32436" target=3D= "_blank" rel=3D"noopener">CVE-2025-32436</a></td>
</tr>
<td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
<td>AutoGPT is a workflow automation platform for creating, deploying, and = managing continuous artificial intelligence agents. Prior to 0.6.63, `Media= DurationBlock` will download and store the video in a temporary directory w= ithout deleting before all noded are done. `StepThroughItemsBlock` can be u= sed to iterate `MediaDurationBlock` multiple times. `StepThroughItemsBlock`=
does not limit the number of loops. In addition, `MediaDurationBlock ` doe=
s not limit the amount of disk space consumed in the current working direct= ory and does not delete the video after outputing the result. When a malici= ous user chooses to screen shot many web pages, the disk space will eventua= lly run out, causing a DoS. Version 0.6.63 patches the issue.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-32437" target=3D= "_blank" rel=3D"noopener">CVE-2025-32437</a></td>
</tr>
<td class=3D"vendor-product">Silver Leaf Technologies, Inc.--Worksnaps.net = Worksnaps</td>
<td>Worksnaps before version 1.6.20260201 contains hardcoded cloud credenti= als and related secret material in the Worksnaps client application binarie=
s. The exposed credentials included AWS access keys, S3 bucket names, and r= elated cloud access information. The originally exposed AWS credentials aut= henticated as the AWS account root identity and provided access to Worksnap=
s production cloud resources, including S3 buckets containing sensitive dat=
a such as screenshots of user desktops. An attacker with access to the affe= cted client binaries could extract or recover the credentials and use them =
to access affected Worksnaps cloud resources.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-10560" target=3D= "_blank" rel=3D"noopener">CVE-2025-10560</a></td>
</tr>
<td class=3D"vendor-product">SIMA GmbH--Bondix Server</td>
<td>OS command injection in the environment and tunnel configuration functi= onality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an aut= henticated attacker with configuration write access to execute arbitrary op= erating-system commands via crafted configuration values passed to server-s= ide scripts.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12104" target=3D= "_blank" rel=3D"noopener">CVE-2026-12104</a></td>
</tr>
<td class=3D"vendor-product">simplcommerce--SimplCommerce</td>
<td>Stored cross-site scripting (XSS) in NewsItemApiController=C2=A0In Simp= lCommerce prior to commit 6142d3b5=C2=A0allows an authenticated administrat=
or to execute arbitrary JavaScript via the ShortContent and FullContent fie= lds, which are stored without HTML=C2=A0sanitization and rendered unencoded=
via @Html.Raw()</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11975" target=3D= "_blank" rel=3D"noopener">CVE-2026-11975</a></td>
</tr>
<td class=3D"vendor-product">simplcommerce--SimplCommerce</td>
<td>Cross-site request forgery (CSRF) in NewsItemApiController in SimplComm= erce prior to commit 6233d73e allows an unauthenticated remote attacker to = create or modify news items as an administrator via a crafted form submitte=
d to `/api/news-items`, due to missing anti-CSRF protection.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9591" target=3D"= _blank" rel=3D"noopener">CVE-2026-9591</a></td>
</tr>
<td class=3D"vendor-product">Sismics--Sismics Docs v.1.11</td>
<td>Incorrect access control in the share-based read endpoints of Sismics D= ocs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoint=
s via a crafted request.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50885" target=3D= "_blank" rel=3D"noopener">CVE-2026-50885</a></td>
</tr>
<td class=3D"vendor-product">SNMP4J-Agent--SNMP4J-Agent 3.8.3</td>
<td>An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbi= trary code via the snmp4jCfgStoragePath component.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39006" target=3D= "_blank" rel=3D"noopener">CVE-2026-39006</a></td>
</tr>
<td class=3D"vendor-product">Sonatype--Nexus Repository</td>
<td>An authenticated user with the nx-licensing-create privilege can upload=
a specially crafted license file to execute arbitrary operating system com= mands as the Nexus process user in Sonatype Nexus Repository 3 versions bef= ore 3.92.0.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10748" target=3D= "_blank" rel=3D"noopener">CVE-2026-10748</a></td>
</tr>
<td class=3D"vendor-product">Sonatype--Nexus Repository Manager</td> <td>Sonatype Nexus Repository Manager before 3.93.0 contains an authorizati=
on vulnerability in the proxy repository configuration that allows a delega= ted repository administrator to disclose stored upstream proxy credentials.= </td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10741" target=3D= "_blank" rel=3D"noopener">CVE-2026-10741</a></td>
</tr>
<td class=3D"vendor-product">Sony Corporation--Optical Disc Archive Softwar=
e for Windows</td>
<td>Incorrect default permissions issue exists in Optical Disc Archive Soft= ware for Windows 5.5.3 and earlier. If this vulnerability is exploited, arb= itrary code may be executed with SYSTEM privileges.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50255" target=3D= "_blank" rel=3D"noopener">CVE-2026-50255</a></td>
</tr>
<td class=3D"vendor-product">sourcentis--mercator</td>
<td>Mercator is an open source web application that enables mapping of the = information system. Prior to version 2025.05.19, Mercator's Query Engine (`= /admin/queries/execute`) accepts a JSON DSL (`from` / `select` / `filters` =
/ `traverse` / `output`), translates it into an Eloquent query, and returns=
results as JSON. The controller method `QueryController::execute()` does n=
ot enforce an authorization gate, unlike `store()` and `massDestroy()` in t=
he same controller which are correctly protected. As a result, any authenti= cated account - including the read-only Auditor role - can query models bey= ond its intended scope, including the `User` model. Additionally, the `pass= word` column, although declared `$hidden`, is not excluded from filter pred= icates, which allows it to be used in `LIKE` conditions. The `schema()` and=
`schemaModel()` endpoints of the same controller are similarly unguarded. = The Query Engine is read-only; integrity and availability are not affected.=
Version 2025.05.19 patches the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49344" target=3D= "_blank" rel=3D"noopener">CVE-2026-49344</a></td>
</tr>
<td class=3D"vendor-product">sourcentis--mercator</td>
<td>Mercator is an open source web application that enables mapping of the = information system. Prior to version 2025.05.19, a Server-Side Request Forg= ery (SSRF) vulnerability exists in Mercator's CVE configuration panel (`/ad= min/config/parameters`). The `testProvider()` method in `ConfigurationContr= oller` passes user-supplied input directly to `curl_init()` without validat= ing the scheme, hostname, or destination IP address. An authenticated user = with the `configure` permission can force the Mercator server to issue arbi= trary outbound network requests. The suffix `/api/dbInfo` appended to the U=
RL can be bypassed by injecting a `#` fragment character (e.g. `
http://TARG= ET/PATH#`), allowing full control over the target URL. No scheme whitelist,=
host whitelist, or private/loopback IP block is applied. The `
telnet://` s= cheme can be used for internal port scanning; the `
gopher://` scheme enable=
s interaction with unauthenticated internal services (Redis, Memcached), po= tentially leading to Remote Code Execution under specific deployment condit= ions. Version 2025.05.19 patches the issue.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49345" target=3D= "_blank" rel=3D"noopener">CVE-2026-49345</a></td>
</tr>
<td class=3D"vendor-product">statping-ng--statping-ng v0.93.0</td> <td>Incorrect access control in statping-ng v0.93.0 allows attackers to esc= alate privileges to Administrator and access sensitive components.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50884" target=3D= "_blank" rel=3D"noopener">CVE-2026-50884</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A command injection vulnerability in the Rancher Manager cluster before=
2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanit= ized YAML parameters could allow remote attackers to break out of an image,=
and execute e.g. malicious containers.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44939" target=3D= "_blank" rel=3D"noopener">CVE-2026-44939</a></td>
</tr>
<td class=3D"vendor-product">syracom AG--Secure Login (2FA) for Jira</td> <td>syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbu= cket 3.4.0.x contains an authentication bypass vulnerability. An attacker w= ith valid credentials for a user account can bypass the two-factor authenti= cation flow by sending HTTP requests with a crafted User-Agent header conta= ining specific strings such as AtlassianMobileApp or JIRA. When such a User= -Agent is present, the plugin does not enforce the configured 2FA checks fo=
r protected web resources. Successful exploitation allows the attacker to a= ccess the affected Atlassian application as the compromised user without co= mpleting 2FA. If the compromised account has administrative privileges, the=
attacker can access administrative functionality and may disable the 2FA p= lugin or make arbitrary administrative changes. The issue is fixed in versi=
on 3.5.0.0.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12225" target=3D= "_blank" rel=3D"noopener">CVE-2026-12225</a></td>
</tr>
<td class=3D"vendor-product">team-alembic--ash_authentication</td> <td>Authentication Bypass by Spoofing vulnerability in team-alembic AshAuth= entication allows account takeover of local users via OAuth2/OIDC sign-in. = AshAuthentication's OAuth2 and OIDC family strategies matched the local use=
r by email address (an upsert on the email field, or a user-defined sign-in=
filter) rather than by the OpenID Connect iss/sub claim combination. Per O= penID Connect Core =C3=82=C2=A75.7, only iss/sub uniquely and stably identi= fies an end-user; other claims, including email, MUST NOT be used as unique=
identifiers. A provider login presenting a victim's email, including an un= verified email, a reused email, or an account with email_verified: false, r= esolved to and signed in as the victim's existing local account. An unauthe= nticated attacker who can register an account on any accepted OAuth provide=
r with the victim's email (or who benefits from provider-side email reuse o=
r reclamation) obtains the victim's full local privileges. The fix resolves=
users by the (strategy, sub) identity stored in a user identity resource, = and only links a new sub to an existing local account by email when the pro= vider's email_verified claim is trusted (trust_email_verified?). This issue=
affects ash_authentication from 0.1.0 before 4.14.0 and from 5.0.0-rc.0 be= fore 5.0.0-rc.10.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49757" target=3D= "_blank" rel=3D"noopener">CVE-2026-49757</a></td>
</tr>
<td class=3D"vendor-product">Tecrail--Responsive FileManager</td> <td>Responsive FileManager's allows an unauthenticated=C2=A0attacker to upl= oad files of any type and extension without restriction using dialog.php en= dpoint, leading to Remote Code Execution.=C2=A0 This project is unmaintaine=
d at the time of CVE assignment. The vulnerability was found in the latest = release=C2=A09.14.0</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5482" target=3D"= _blank" rel=3D"noopener">CVE-2026-5482</a></td>
</tr>
<td class=3D"vendor-product">Teldat--Regesta Smart HD-PLC - TLDPH16D2</td> <td>An attacker with access via network to the Regesta Smart HD-PLC of the = provider Teldat (in this case, NO registration action is required) who has = the vulnerable software could obtain privilege information by using the com= mand Version via the path: /upgrade/query.php?cmd=3Dp+3&3Bversion=C2=A0= resulting in a information disclosure.=C2=A0This issue affects Regesta Smar=
t HD-PLC - TLDPH16D2: 11.02.05.10.02.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27868" target=3D= "_blank" rel=3D"noopener">CVE-2026-27868</a></td>
</tr>
<td class=3D"vendor-product">Teldat--Regesta Smart HD-PLC - TLDPH16D2</td> <td>An attacker with access via network to the Regesta Smart HD-PLC of the = provider Teldat (in this case, NO registration action is required) who has = the vulnerable software could, with a Slow Loris attack, cause Denial of Se= rvice (DoS) on the web interface of the device.=C2=A0This issue affects Reg= esta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27869" target=3D= "_blank" rel=3D"noopener">CVE-2026-27869</a></td>
</tr>
<td class=3D"vendor-product">Teldat--Regesta Smart HD-PLC - TLDPH16D2</td> <td>An attacker with access via network to the Regesta Smart HD-PLC of the = provider Teldat (in this case, registration action IS required) who has the=
vulnerable software could, introduce arbitrary JavaScript by injecting a= =C2=A0Cross-site Scripting (XSS)=C2=A0 payload into the 'Hostname' field of=
the configuration file resulting in a=C2=A0XSS=C2=A0in the path /upgrade/q= uery.php?cmd=3Dp+3%3Bversion.=C2=A0This issue affects Regesta Smart HD-PLC =
- TLDPH16D2: 11.02.05.10.02.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27870" target=3D= "_blank" rel=3D"noopener">CVE-2026-27870</a></td>
</tr>
<td class=3D"vendor-product">Tenda --AC7 v15.03.06.44</td>
<td>Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability i=
n the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51843" target=3D= "_blank" rel=3D"noopener">CVE-2026-51843</a></td>
</tr>
<td class=3D"vendor-product">Tenda --AC7 v15.03.06.44</td>
<td>Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability i=
n the /goform/AdvSetMacMtuWan interface via the cloneType parameter.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51844" target=3D= "_blank" rel=3D"noopener">CVE-2026-51844</a></td>
</tr>
<td class=3D"vendor-product">Tenda --AC7 v15.03.06.44</td>
<td>Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability i=
n the /goform/AdvSetMacMtuWan interface via the mac parameter.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51845" target=3D= "_blank" rel=3D"noopener">CVE-2026-51845</a></td>
</tr>
<td class=3D"vendor-product">Tenda --AC7 v15.03.06.44</td>
<td>In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/= AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to = remote arbitrary code execution.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51846" target=3D= "_blank" rel=3D"noopener">CVE-2026-51846</a></td>
</tr>
<td class=3D"vendor-product">Tenda--Tenda 5G03</td>
<td>Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injectio=
n in the function action_unlock_sim via the pin parameter.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38060" target=3D= "_blank" rel=3D"noopener">CVE-2026-38060</a></td>
</tr>
<td class=3D"vendor-product">Tenda--Tenda 5G03</td>
<td>Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injectio=
n in the function action_set_volume via the volume parameter.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38061" target=3D= "_blank" rel=3D"noopener">CVE-2026-38061</a></td>
</tr>
<td class=3D"vendor-product">Tenda--Tenda 5G03</td>
<td>Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injectio=
n in the function action_set_rat_mode via the ratMode parameter.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38062" target=3D= "_blank" rel=3D"noopener">CVE-2026-38062</a></td>
</tr>
<td class=3D"vendor-product">Tenda--Tenda 5G03</td>
<td>Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injectio=
n in the function action_radio_on_with_ia_apn via the ia parameter.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38063" target=3D= "_blank" rel=3D"noopener">CVE-2026-38063</a></td>
</tr>
<td class=3D"vendor-product">Tenda--Tenda 5G03</td>
<td>Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injectio=
n in the function action_dial_call via the dialNumber parameter.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38064" target=3D= "_blank" rel=3D"noopener">CVE-2026-38064</a></td>
</tr>
<td class=3D"vendor-product">Tenda--Tenda 5G03</td>
<td>Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injectio=
n in the function action_ims_on_with_apn via the ims_apn parameter.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38065" target=3D= "_blank" rel=3D"noopener">CVE-2026-38065</a></td>
</tr>
<td class=3D"vendor-product">The Document Foundation--LibreOffice</td> <td>LibreOffice can import drawings in the DXF format used by CAD software.=
A heap buffer overflow existed when importing a DXF polyline. The point co= unt taken from the file was truncated to a 16-bit value when the point buff=
er was sized, while the full count was used to fill it, so a polyline whose=
point count exceeded the 16-bit range was written past the end of the buff= er. In fixed versions such oversized polylines are rejected.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6039" target=3D"= _blank" rel=3D"noopener">CVE-2026-6039</a></td>
</tr>
<td class=3D"vendor-product">The Document Foundation--LibreOffice</td>
<td>A heap use-after-free existed when importing the blank-width characters=
of an ODF number format. A position value read from the document was not c= hecked against the length of the format-code string, so a malformed number = format could be processed against memory outside that string. In fixed vers= ions the position is bounds-checked before use.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6040" target=3D"= _blank" rel=3D"noopener">CVE-2026-6040</a></td>
</tr>
<td class=3D"vendor-product">The Document Foundation--LibreOffice</td> <td>LibreOffice can import EMF+ graphics, which may be embedded in document=
s. A heap buffer overflow existed when importing an EMF+ gradient brush. Th=
e number of gradient blend points was read from the file and used to comput=
e an allocation size, but that multiplication could overflow, so a small bu= ffer was allocated and then filled as if it were large, writing past its en=
d. In fixed versions the blend-point count is checked against the data actu= ally available before allocating.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6045" target=3D"= _blank" rel=3D"noopener">CVE-2026-6045</a></td>
</tr>
<td class=3D"vendor-product">The Document Foundation--LibreOffice</td> <td>LibreOffice can import documents in the OOXML format (DOCX). A heap buf= fer overflow existed when replaying deferred parser events for a text box e= lement. A handler object was assumed to be of one type and written to at th=
at type's field layout, but it could be a smaller object, so the write land=
ed past the end of the allocation. In fixed versions the type is checked be= fore the write.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6047" target=3D"= _blank" rel=3D"noopener">CVE-2026-6047</a></td>
</tr>
<td class=3D"vendor-product">The Document Foundation--LibreOffice</td> <td>LibreOffice can import presentations in the legacy binary PPT format. A=
stack buffer overflow existed when importing a colour-replacement record. = Two fixed-size colour tables were filled from the file, but the write posit= ion was not reset between the two passes over the record, so a file whose c= ombined colour counts exceeded the table size wrote past the end of the tab= les on the stack. In fixed versions the unused second pass is no longer rea=
d into those tables.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8356" target=3D"= _blank" rel=3D"noopener">CVE-2026-8356</a></td>
</tr>
<td class=3D"vendor-product">The Document Foundation--LibreOffice</td> <td>LibreOffice Calc compiles cell formulas when opening a spreadsheet. A h= eap buffer overflow existed when compiling a very long formula made up of m= any opening tokens. The array that tracks nesting depth was allocated one e= lement too small for that worst case, so such a formula wrote one element p= ast its end. In fixed versions the array is sized to hold the largest possi= ble nesting.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8357" target=3D"= _blank" rel=3D"noopener">CVE-2026-8357</a></td>
</tr>
<td class=3D"vendor-product">The Document Foundation--LibreOffice</td> <td>LibreOffice Calc can import tracked changes from a spreadsheet document=
. A heap buffer overflow existed when a document reused the same change ide= ntifier for two different kinds of change. The importer then treated one ch= ange object as a different, larger type and wrote past the end of its alloc= ation. In fixed versions records with a duplicate identifier are rejected.<=
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8358" target=3D"= _blank" rel=3D"noopener">CVE-2026-8358</a></td>
</tr>
<td class=3D"vendor-product">theonedev--onedev</td>
<td>OneDev is a Git server with CI/CD, kanban, and packages. In versions 15= .0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR e= ntry getLinkName() without validating whether the target is an absolute pat=
h. A subsequent file entry in the same archive traverses the symlink, writi=
ng to arbitrary server-side locations. This is exploitable by any authentic= ated user with CI Job write access - no admin interaction required. This is=
an incomplete fix bypass of CVE-2021-21251 (GHSA-2w6j-wc8c-9mq2): that pat=
ch blocked .. path segments but did not address absolute symlink targets. T= his issue has been fixed in version 15.0.7.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49248" target=3D= "_blank" rel=3D"noopener">CVE-2026-49248</a></td>
</tr>
<td class=3D"vendor-product">ThingsBoard--ThingsBoard</td>
<td>ThingsBoard contains a prototype pollution vulnerability which may lead=
to arbitrary code execution within a sandboxed context by a user who can l=
og in to the affected product with the tenant administrator privilege (TENA= NT_ADMIN).</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53676" target=3D= "_blank" rel=3D"noopener">CVE-2026-53676</a></td>
</tr>
<td class=3D"vendor-product">ThingsBoard--ThingsBoard v4.3.0.1</td> <td>ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during t=
he OAuth authorization code exchange. The application improperly trusts use= r-supplied identity data within the user parameter of the /login/oauth2/cod=
e/ endpoint. By manipulating the email address in this JSON object, a remot=
e attacker can bypass authentication and gain full access to any existing u= ser account on the platform without possessing the target user's credential=
s. This results in a complete account takeover.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36537" target=3D= "_blank" rel=3D"noopener">CVE-2026-36537</a></td>
</tr>
<td class=3D"vendor-product">TIMLEGGE--Crypt::DSA</td>
<td>Crypt::DSA versions before 1.21 for Perl reused the nonce across signat= ures, leading to private-key recovery. Crypt::DSA::sign caches the per-sign= ature nonce material in the Key object without ever clearing it. The first = sign() on a Key object picks a nonce, and every later sign() on that same o= bject reuses it, producing an identical "r". Keys used to sign more than on=
ce with an affected version should be considered compromised.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12205" target=3D= "_blank" rel=3D"noopener">CVE-2026-12205</a></td>
</tr>
<td class=3D"vendor-product">TP-Link Systems Inc.--TL-WR940N v6</td>
<td>An authenticated OS command injection vulnerability exists in the IPv6 = PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of=
user input. An attacker with administrative access may exploit this issue =
to execute arbitrary system commands with elevated privileges.</td> <td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11409" target=3D= "_blank" rel=3D"noopener">CVE-2026-11409</a></td>
</tr>
<td class=3D"vendor-product">TP-Link Systems Inc.--TL-WR940N v6</td>
<td>An authenticated OS command injection vulnerability exists in the BigPo=
nd Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper san= itization of user input. An attacker with administrative access may exploit=
this issue to execute arbitrary system commands with elevated privileges.<=
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11410" target=3D= "_blank" rel=3D"noopener">CVE-2026-11410</a></td>
</tr>
<td class=3D"vendor-product">UBB Systems--UBB.threads</td>
<td>UBB.threads is vulnerable to Stored XSS via user posts and user profile=
fields. The application fails to properly sanitize user input, allowing lo=
w privileged attackers to inject arbitrary JavaScript that executes in a vi= ctim's browser upon viewing. Because vendor contact attempts were unsuccess= ful, the vulnerability has only been confirmed in version 7.7.5 but may als=
o affect other versions.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54219" target=3D= "_blank" rel=3D"noopener">CVE-2026-54219</a></td>
</tr>
<td class=3D"vendor-product">UBB Systems--UBB.threads</td>
<td>uBB.threads is vulnerable to a=C2=A0Cross-Site Request Forgery (CSRF) d=
ue to a lack of protective mechanisms. This allows an attacker to trick an = authenticated user into executing unintended actions. Because vendor contac=
t attempts were unsuccessful, the vulnerability has only been confirmed in = version 7.7.5 but may also affect other versions.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54220" target=3D= "_blank" rel=3D"noopener">CVE-2026-54220</a></td>
</tr>
<td class=3D"vendor-product">UBB Systems--UBB.threads</td>
<td>UBB.threads is vulnerable to=C2=A0Reflected XSS. The application improp= erly handles user input in certain requests, enabling attackers to execute = arbitrary JavaScript in the context of a victim's browser by tricking them = into clicking a crafted link.=C2=A0 Because vendor contact attempts were un= successful, the vulnerability has only been confirmed in version 7.7.5 but = may also affect other versions.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54221" target=3D= "_blank" rel=3D"noopener">CVE-2026-54221</a></td>
</tr>
<td class=3D"vendor-product">UBB Systems--UBB.threads</td>
<td>UBB.threads is vulnerable to Blind SQL Injection,=C2=A0allowing attacke=
rs with access to=C2=A0the Members in Control Panel=C2=A0to interact with t=
he underlying database. Due to insufficient input sanitization, an attacker=
can extract sensitive information, such as user credentials, by manipulati=
ng SQL queries through time-based or boolean-based techniques. Because vend=
or contact attempts were unsuccessful, the vulnerability has only been conf= irmed in version 7.7.5 but may also affect other versions.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54222" target=3D= "_blank" rel=3D"noopener">CVE-2026-54222</a></td>
</tr>
<td class=3D"vendor-product">UBB Systems--UBB.threads</td>
<td>UBB.threads is vulnerable to Path traversal, allowing attackers with pr= ivilege to edit templates to read and write any file on the application's s= erver that application has privileges to, what results in Remote Code Execu= tion.=C2=A0 Because vendor contact attempts were unsuccessful, the vulnerab= ility has only been confirmed in version 7.7.5 but may also affect other ve= rsions.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54223" target=3D= "_blank" rel=3D"noopener">CVE-2026-54223</a></td>
</tr>
<td class=3D"vendor-product">UBB Systems--UBB.threads</td>
<td>UBB.threads is vulnerable to Denial of Service (DoS). By sending multip=
le concurrent requests to view any user profile on instances with many regi= stered users, an authenticated attacker can easily exhaust database resourc=
es and completely deny access to the application for other users. Because v= endor contact attempts were unsuccessful, the vulnerability has only been c= onfirmed in version 7.7.5 but may also affect other versions.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54224" target=3D= "_blank" rel=3D"noopener">CVE-2026-54224</a></td>
</tr>
<td class=3D"vendor-product">umputun--remark42</td>
<td>Remark42 is a self-hosted comment engine for blogs, articles, or any ot= her place where readers can add comments. Versions 1.6.0 through 1.15.0 con= tain a Cross-Site Scripting (XSS) vulnerability exploitable through content= -type spoofing. The Remark42 image proxy fetches an arbitrary remote URL an=
d re-serves the response from Remark42's own origin. During the download ph= ase, the proxy determines whether the resource is an image by inspecting on=
ly the Content-Type header advertised by the remote server, never examining=
the actual bytes; during the serving phase, it instead derives the respons=
e Content-Type by sniffing those bytes with http.DetectContentType. An atta= cker can exploit this inconsistency by hosting a URL that advertises Conten= t-Type: image/png while returning an HTML/JavaScript body: the download che=
ck accepts it as an image, the serving path sniffs the body and emits Conte= nt-Type: text/html, and the browser renders the attacker-controlled HTML/Ja= vaScript as a document within Remark42's origin. Exploitation requires no R= emark42 account on the target instance; the attacker only needs to host the=
malicious upstream URL and deliver the proxy link to a victim by any means=
, such as email, direct message, or a link on another website. This issue h=
as been fixed in version 1.16.0.</td>
<td>2026-06-16</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48788" target=3D= "_blank" rel=3D"noopener">CVE-2026-48788</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Form Builder CP</td>
<td>The Form Builder CP WordPress plugin before 1.2.47 does not properly sa= nitize a form configuration value before storing it and using it as part of=
a client-side script execution, allowing authenticated users with Editor-l= evel access and above to perform Stored Cross-Site Scripting attacks agains=
t any visitor of a page rendering the affected form, even when the `unfilte= red_html` capability is disallowed (e.g. in a multisite network).</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9278" target=3D"= _blank" rel=3D"noopener">CVE-2026-9278</a></td>
</tr>
<td class=3D"vendor-product">Unknown--LearnPress</td>
<td>The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` c= ontext on one of its REST endpoint behind the `edit_users` capability, allo= wing unauthenticated visitors to retrieve each returned user's roles, full = capabilities map, extra capabilities, locale, and registration date via a c= rafted request</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8383" target=3D"= _blank" rel=3D"noopener">CVE-2026-8383</a></td>
</tr>
<td class=3D"vendor-product">Unknown--MagicForm</td>
<td>The MagicForm WordPress plugin through 0.1.3 does not properly validate=
the type of files uploaded through an unauthenticated AJAX action when a f= orm's per-field extension allowlist is left empty, allowing unauthenticated=
attackers to upload PHP files and execute arbitrary code on the server.</t=
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9815" target=3D"= _blank" rel=3D"noopener">CVE-2026-9815</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Taskbuilder</td>
<td>The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitis=
e a URL parameter before echoing it into inline JavaScript on a frontend pa=
ge containing one of its shortcodes, leading to a Reflected Cross-Site Scri= pting vulnerability that can be triggered against any logged-in user.</td> <td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9570" target=3D"= _blank" rel=3D"noopener">CVE-2026-9570</a></td>
</tr>
<td class=3D"vendor-product">Unknown--weMail: Email Marketing, Email Automa= tion, Newsletters, Subscribers & Email Optins for WooCommerce</td>
<td>The weMail: Email Marketing, Email Automation, Newsletters, Subscribers=
& Email Optins for WooCommerce WordPress plugin before 2.1.3 does not = properly escape a user-supplied parameter before reflecting it into an HTML=
attribute on a non-nonce-protected AJAX response, allowing unauthenticated=
attackers to deliver Reflected Cross-Site Scripting against any authentica= ted user (including administrators) via a crafted URL.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8089" target=3D"= _blank" rel=3D"noopener">CVE-2026-8089</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP Go Maps</td>
<td>The WP Go Maps WordPress plugin before 10.0.10 does not properly enforc=
e the marker approval filter on the admin-ajax fallback for its datatables = route, allowing unauthenticated visitors to retrieve marker records that th=
e site owner has not approved for public display, including their title, ca= tegory, address and description fields.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8385" target=3D"= _blank" rel=3D"noopener">CVE-2026-8385</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP Go Maps</td>
<td>The WP Go Maps WordPress plugin before 10.0.10 does not perform any app= roval-state filtering on its public single-marker REST endpoint, allowing u= nauthenticated users to retrieve marker records that an administrator has n=
ot yet approved for public display, including any PII placed in the address=
and description fields and the marker's geographic coordinates.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8386" target=3D"= _blank" rel=3D"noopener">CVE-2026-8386</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP Hotel Booking</td>
<td>The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce cap= ability checks in several of its AJAX handlers, allowing authenticated user=
s with Subscriber-level access to read other users' booking line items, enu= merate active coupons, and read pricing data.</td>
<td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9822" target=3D"= _blank" rel=3D"noopener">CVE-2026-9822</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP Magnific Popup</td>
<td>The WP Magnific Popup WordPress plugin through 1.0 does not properly es= cape user-controlled link URLs before injecting them into the DOM when disp= laying image load error messages, allowing authenticated attackers with Aut= hor-level access or above to perform Stored Cross-Site Scripting attacks ag= ainst any visiting user.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7850" target=3D"= _blank" rel=3D"noopener">CVE-2026-7850</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP MAPS PRO</td>
<td>The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthentica= ted AJAX action which, given a valid nonce that is publicly emitted on any = frontend page enqueuing its map script, unconditionally creates an administ= rator account and returns a magic-login URL granting interactive admin acce= ss.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8935" target=3D"= _blank" rel=3D"noopener">CVE-2026-8935</a></td>
</tr>
<td class=3D"vendor-product">urllib3--urllib3/urllib3</td>
<td>urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in i=
ts streaming API (`preload_content=3DFalse`) when using Brotli support. The=
issue arises due to three independent code paths in `response.py` that byp= ass the `max_length` protection introduced in version 2.6.0 to mitigate CVE= -2025-66471. Specifically, negative `max_length` values can be produced due=
to buffer arithmetic in `read()`, `flush_decoder` unconditionally override=
s `max_length` to `-1`, and `_flush_decoder()` passes no limit at all, defa= ulting to unlimited decompression. This allows a malicious HTTP server to t= rigger an out-of-memory (OOM) condition by decompressing large payloads int=
o memory, leading to a denial of service (DoS). The vulnerability affects u= rllib3 2.6.3 and Brotli 1.2.0 and impacts applications and libraries using = `requests` or `urllib3` to stream content from untrusted sources.</td> <td>2026-06-19</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9375" target=3D"= _blank" rel=3D"noopener">CVE-2026-9375</a></td>
</tr>
<td class=3D"vendor-product">vantage6--vantage6</td>
<td>vantage6 is an open-source infrastructure for privacy preserving analys= is. Prior to version 5.0.0, users can reset their MFA token via API routes = that send them an email. Currently the number of emails that is sent is not=
limited. This gives attackers the option to flood someones mailbox with a = lot of emails, and would have adverse effects on the SMTP server which may =
be seen as spam sender. Note resetting the MFA token requires a correct pas= sword, so the potential impact for this is very low. Version 5.0.0 fixes th=
e issue. No known workarounds are available.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-24769" target=3D= "_blank" rel=3D"noopener">CVE-2024-24769</a></td>
</tr>
<td class=3D"vendor-product">vantage6--vantage6</td>
<td>vantage6 is an open-source infrastructure for privacy preserving analys= is. Prior to version 5.0.0, if an attacker hacks into a vantage6 user's ema=
il account, they can 1) reset the password via email and then 2) reset the = 2FA token via email. This way they reduce 2FA to 1FA (email access). Note t= hat most email providers require 2FA to access email, so this issue is not = very likely to cause issues. Version 5.0.0 fixes the issue. No known workar= ounds are available.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-27928" target=3D= "_blank" rel=3D"noopener">CVE-2024-27928</a></td>
</tr>
<td class=3D"vendor-product">vantage6--vantage6</td>
<td>vantage6 is an open-source infrastructure for privacy preserving analys= is. Versions prior to 5.0.0 provide an initial user with username `root` an=
d password `root`. This is not ideal because attackers know that almost all=
vantage6 servers have a user with username `root` that probably has admin = rights, and the initial password is very weak and it is possible that admin= istrators forget to reset it. Version 5.0.0 fixes the issue. As a workaroun=
d, it is possible to delete the `root` user after it has been used to creat=
e other users.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54445" target=3D= "_blank" rel=3D"noopener">CVE-2026-54445</a></td>
</tr>
<td class=3D"vendor-product">vantage6--vantage6</td>
<td>vantage6 is an open-source infrastructure for privacy preserving analys= is. Prior to version 5.0.0, malicious algorithms can potentially access oth=
er algorithms input and output files. Version 5.0.0 fixes the issue. As a w= orkaround, verify and restrict the algorithm containers that are allowed to=
run on the node.</td>
<td>2026-06-17</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54533" target=3D= "_blank" rel=3D"noopener">CVE-2026-54533</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController 5400 Ha= rdware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)</td> <td>The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.1= 1.8130.22320, uses RS-485 communication between the server and the microcon= troller without cryptographic protection. An attacker with access to the co= mmunication path between the server and the microcontroller can sniff RS-48=
5 messages and replay previously observed messages. This can be used, for e= xample, to spoof a "quit alarm" message and continuously deactivate the saf=
e alarm.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34021" target=3D= "_blank" rel=3D"noopener">CVE-2026-34021</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Family = 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontrolle= r)</td>
<td>The=C2=A0Wertheim SafeController Family 65000, Controller 65000 - Assem= blyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with = hard-coded cryptographic keys to protect communication. An attacker in an a= dversary-in-the-middle position can decrypt the data traffic. During reasse= ssment, it was possible to break the encryption/decryption routine and decr= ypt messages without knowledge of the encryption key. It was also possible =
to gain knowledge about the encryption key by intercepting enough messages.= </td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34022" target=3D= "_blank" rel=3D"noopener">CVE-2026-34022</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, = contains an incorrect authorization vulnerability in the WebSocket communic= ation used by the SafeController WebMessageBroker. An authenticated attacke=
r with valid low-privileged branch user credentials can manipulate WebSocke=
t messages by specifying controller identifiers belonging to other branches=
. This allows the attacker to access restricted functions and resources in = other branches, including activating boxes outside of the user's authorized=
branch.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34023" target=3D= "_blank" rel=3D"noopener">CVE-2026-34023</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, = contains missing authorization checks on multiple web application endpoints=
. An authenticated attacker with minimal privileges can access endpoints th=
at are not visible in the frontend but remain directly reachable. This allo=
ws the attacker to perform restricted actions such as switching the user's = branch, uploading arbitrary files, downloading arbitrary files, and viewing=
details of arbitrary branches.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34024" target=3D= "_blank" rel=3D"noopener">CVE-2026-34024</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, = contains an IP restriction bypass vulnerability in the login process. The a= pplication restricts user logins based on the IP address associated with a = branch location, but the client IP address is derived from the HTTP X-Forwa= rded-For header when that header is present. An attacker with valid branch = user credentials can manipulate the X-Forwarded-For header during login to = spoof the expected branch IP address and obtain a valid authenticated sessi=
on from an unauthorized network location.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34025" target=3D= "_blank" rel=3D"noopener">CVE-2026-34025</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, cont= ains a path traversal vulnerability in the documentName parameter of the /s= afe/selfservice/openselfservicedocument endpoint. The application construct=
s a file path using attacker-controlled input without sufficient validation=
, allowing an authenticated attacker with any role or permission level to t= raverse out of the intended document directory and download arbitrary files=
accessible to the application. This includes, but is not limited to, appli= cation log files containing sensitive information and application binaries.= </td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34026" target=3D= "_blank" rel=3D"noopener">CVE-2026-34026</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, = contains insufficient server-side file type validation in the /safe/contrac= t/uploadcustomdocuments endpoint. The application validates uploaded files = based on the user-controlled HTTP Content-Type value and accepts the upload=
if this value contains an allowed string such as pdf, jpeg, tiff, or png. =
An authenticated attacker with any role or permission level can spoof the C= ontent-Type value and upload arbitrary file content.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34027" target=3D= "_blank" rel=3D"noopener">CVE-2026-34027</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, = exposes web-accessible file paths that are not protected by an authorizatio=
n scheme. An unauthenticated attacker can directly access HTTP endpoints to=
download files from locations such as /Resources/CompanyId_[ID]/Audio/ and=
/SafeData/.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34028" target=3D= "_blank" rel=3D"noopener">CVE-2026-34028</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>The=C2=A0Wertheim SafeController Software, AssemblyVersion 6.15.8328.28= 014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructu= re.Security.dll component. An attacker with access to the application files=
can reverse engineer the DLL and recover the hard-coded cryptographic key.=
This key can be used to decrypt the licence.whs file, which contains sensi= tive information about the licensing party and a second key that can be use=
d to decrypt other configuration files.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34029" target=3D= "_blank" rel=3D"noopener">CVE-2026-34029</a></td>
</tr>
<td class=3D"vendor-product">Wertheim GmbH--Wertheim SafeController Softwar=
e for VAULT ROOMS (Safe Deposit Locker System)</td>
<td>The=C2=A0Wertheim SafeController Software, AssemblyVersion 6.15.8328.28= 014, does not sufficiently validate the branch code when a new branch is cr= eated. The branch code is later used in multiple application functions, inc= luding filesystem path generation for uploaded files, profile pictures, and=
settings. An authenticated attacker with the settings_branches_manage priv= ilege can include path traversal sequences in the branch code and influence=
the final filesystem location used by affected file operations. This can a= llow files to be stored in unintended locations, subject to service-account=
write permissions and branch-code length restrictions.</td> <td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34030" target=3D= "_blank" rel=3D"noopener">CVE-2026-34030</a></td>
</tr>
<td class=3D"vendor-product">woodpecker-ci--woodpecker</td>
<td>Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to ve= rsion 3.14.1, a vulnerability in Woodpecker CI's gRPC layer allowed any aut= henticated agent to impersonate any other agent on the same server by injec= ting a forged `agent_id` value into outgoing gRPC metadata. The server corr= ectly verified the JWT token but then discarded the verified agent identity=
in favor of the client-supplied value. Version 3.14.1 patches the issue. A=
s a workaround, disable org agents (`WOODPECKER_DISABLE_USER_AGENT_REGISTRA= TION=3Dtrue`) and delete existing ones.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50141" target=3D= "_blank" rel=3D"noopener">CVE-2026-50141</a></td>
</tr>
<td class=3D"vendor-product">Xen--Xen</td>
<td>HVM guest I/O port accesses are subject to either emulation or at least=
translation. Translations are managed by the device model (via XEN_DOMCTL_= ioport_mapping), and hence the linked list used may changed at any time. Tr= aversal of those lists (while handling guest I/O port accesses) therefore n= eeds synchronizing with updates, which was missing so far.</td> <td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42487" target=3D= "_blank" rel=3D"noopener">CVE-2026-42487</a></td>
</tr>
<td class=3D"vendor-product">Xen--Xen</td>
<td>Some shadow paging errors paths will switch the page-tables without upd= ating the currently running vCPU reference. This causes a mismatch between = the loaded page-tables and the mapcache metadata which can lead to corrupti=
on of the mapcache.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42488" target=3D= "_blank" rel=3D"noopener">CVE-2026-42488</a></td>
</tr>
<td class=3D"vendor-product">Xen--Xen</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] To create and man= age guests, domctl operations are used by the control domain, a possible Xe= nstore domain, or by a domain controlling a particular guest. Some of these=
operations may not be executed in parallel, so a system-wide lock is used.=
The way that lock is acquired is, however, not providing any fairness. Thi=
s is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire w= ill, for some operations, occur ahead of any permission checking. This is C= VE-2026-42490.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42489" target=3D= "_blank" rel=3D"noopener">CVE-2026-42489</a></td>
</tr>
<td class=3D"vendor-product">Xen--Xen</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] To create and man= age guests, domctl operations are used by the control domain, a possible Xe= nstore domain, or by a domain controlling a particular guest. Some of these=
operations may not be executed in parallel, so a system-wide lock is used.=
The way that lock is acquired is, however, not providing any fairness. Thi=
s is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire w= ill, for some operations, occur ahead of any permission checking. This is C= VE-2026-42490.</td>
<td>2026-06-18</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42490" target=3D= "_blank" rel=3D"noopener">CVE-2026-42490</a></td>
</tr>
<td class=3D"vendor-product">YouTransfer--YouTransfer v1.0.6</td>
<td>An issue in the sendmail transport integration component of YouTransfer=
v1.0.6 allows attackers to execute arbitrary code via supplying a crafted = request.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50880" target=3D= "_blank" rel=3D"noopener">CVE-2026-50880</a></td>
</tr>
<td class=3D"vendor-product">Zhoros--SuperBin v1.0.0</td>
<td>An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a direct= ory traversal via supplying files with names containing traversal character= s.</td>
<td>2026-06-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50877" target=3D= "_blank" rel=3D"noopener">CVE-2026-50877</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
</div>
</div>
<style>body {
font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
l; font-style: normal; color: #333333;
}
</style>
=20
<div id=3D"mail_footer">
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/41d32ec" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"
https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"
https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"
https://www.cisa.gov/privacy-policy=
" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"
https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"
https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"
https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
: #757575;">=C2=A0 |=C2=A0 </span><a href=3D"
https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"
https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"
https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"
https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>
</div>
<div id=3D"tagline">
<hr>
<table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=
<tbody>
<td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to
cisa@toolazy.synchro.net using GovDelivery Com= munications Cloud, on behalf of: Cybersecurity and Infrastructure Security = Agency =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
<td align=3D"right" width=3D"11%"><a href=3D"
https://subscriberhelp.granicu= s.com/" target=3D"_blank" rel=3D"noopener"><img src=3D"
https://content.govd= elivery.com/images/govd-logo-dark.png" border=3D"0" alt=3D"GovDelivery logo=
" width=3D"115"></a></td>
</tr>
</tbody>
</table>
<style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
img {margin-left:0px; margin-right:0px;}</style>
</div>
</td>
</tr>
</table>
<img alt=3D"" src=3D"
https://links-2.govdelivery.com/CI0/0101019ef0cba494-c= e8609dc-a3b1-404b-938a-6a372e6286c1-000000/CtfBjf7wcFXmPrntEVFDNYrPAZg9KRX_= UGIZPC1Dqvs=3D452" style=3D"display: none; width: 1px; height: 1px;">
</body>
</html>
--===============1754896695755606665==--
--===============8762863052863791975==--