CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2026-46734

    Last Modified: 25 Jun 2026

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47154

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Simple Metering cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47153

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47152

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47151

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47150

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47149

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47148

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Groups cluster may be impacted.

    Published: 25 Jun 2026
    6.7
    Medium

    CVE-2026-46732

    Last Modified: 25 Jun 2026

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47147

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices supporting the OTA Server cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47146

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-47145

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

    Published: 25 Jun 2026
    6.5
    Medium

    CVE-2026-56050

    Last Modified: 26 Jun 2026

    Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.

    Published: 25 Jun 2026
    8.7
    High

    CVE-2026-56122

    Last Modified: 26 Jun 2026

    Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sending HTTP GET requests with dot-dot-slash sequences that are not sanitized when serving static files from the configured webroot. Attackers can traverse outside the webroot directory using traversal-prefixed paths in a single HTTP request to read any file accessible to the servlet engine process, including sensitive system files when the service runs with elevated privileges.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-4526

    Last Modified: 26 Jun 2026

    In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

    Published: 25 Jun 2026
    9.8
    Critical

    CVE-2026-41120

    Last Modified: 25 Jun 2026

    Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

    Published: 25 Jun 2026
    8.4
    High

    CVE-2026-2815

    Last Modified: 26 Jun 2026

    Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

    Published: 25 Jun 2026
    8.3
    High

    CVE-2026-54848

    Last Modified: 26 Jun 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.

    Published: 25 Jun 2026
    7.5
    High

    CVE-2026-54829

    Last Modified: 25 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.

    Published: 25 Jun 2026
    7.2
    High

    CVE-2026-49506

    Last Modified: 26 Jun 2026

    Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

    Published: 25 Jun 2026
    7.8
    High

    CVE-2026-46733

    Last Modified: 25 Jun 2026

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

    Published: 25 Jun 2026
    9.3
    Critical

    CVE-2026-54836

    Last Modified: 26 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.

    Published: 25 Jun 2026
    5.3
    Medium

    CVE-2026-42389

    Last Modified: 25 Jun 2026

    This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

    Published: 25 Jun 2026
    8.1
    High

    CVE-2026-54842

    Last Modified: 25 Jun 2026

    Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.

    Published: 25 Jun 2026
    2.7
    Low

    CVE-2026-12755

    Last Modified: 25 Jun 2026

    Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.

    Published: 25 Jun 2026
    6.5
    Medium

    CVE-2026-57429

    Last Modified: 26 Jun 2026

    Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-56071

    Last Modified: 26 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.

    Published: 25 Jun 2026
    7.7
    High

    CVE-2026-56054

    Last Modified: 25 Jun 2026

    Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.

    Published: 25 Jun 2026
    8.8
    High

    CVE-2026-56053

    Last Modified: 26 Jun 2026

    Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-56051

    Last Modified: 29 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

    Published: 25 Jun 2026
    8.5
    High

    CVE-2026-56049

    Last Modified: 25 Jun 2026

    Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-56042

    Last Modified: 25 Jun 2026

    Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

    Published: 25 Jun 2026
    5.4
    Medium

    CVE-2026-56023

    Last Modified: 25 Jun 2026

    Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-56014

    Last Modified: 25 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

    Published: 25 Jun 2026
    6.5
    Medium

    CVE-2026-56013

    Last Modified: 29 Jun 2026

    Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-56006

    Last Modified: 26 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.

    Published: 25 Jun 2026
    7.1
    High

    CVE-2026-56005

    Last Modified: 25 Jun 2026

    Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.

    Published: 25 Jun 2026
    9.3
    Critical

    CVE-2026-54849

    Last Modified: 26 Jun 2026

    Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

    Published: 25 Jun 2026
    8.1
    High

    CVE-2026-54845

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

    Published: 25 Jun 2026
    7.5
    High

    CVE-2026-54844

    Last Modified: 29 Jun 2026

    Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.

    Published: 25 Jun 2026
    9.3
    Critical

    CVE-2026-54843

    Last Modified: 26 Jun 2026

    Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

    Published: 25 Jun 2026
    7.5
    High

    CVE-2026-54841

    Last Modified: 25 Jun 2026

    Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.

    Published: 25 Jun 2026
    8.5
    High

    CVE-2026-54838

    Last Modified: 26 Jun 2026

    Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

    Published: 25 Jun 2026
    7.5
    High

    CVE-2026-54830

    Last Modified: 29 Jun 2026

    Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

    Published: 25 Jun 2026
    7.5
    High

    CVE-2026-54828

    Last Modified: 26 Jun 2026

    Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

    Published: 25 Jun 2026
    9.9
    Critical

    CVE-2026-54823

    Last Modified: 25 Jun 2026

    Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

    Published: 25 Jun 2026
    8.5
    High

    CVE-2026-54822

    Last Modified: 26 Jun 2026

    Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

    Published: 25 Jun 2026
    7.4
    High

    CVE-2026-54821

    Last Modified: 26 Jun 2026

    Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

    Published: 25 Jun 2026
    7.5
    High

    CVE-2026-27366

    Last Modified: 29 Jun 2026

    Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

    Published: 25 Jun 2026
    6.5
    Medium

    CVE-2026-57619

    Last Modified: 25 Jun 2026

    Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

    Published: 25 Jun 2026