CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2026-54808

    Last Modified: 20 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.

    Published: 17 Jun 2026
    7.3
    High

    CVE-2025-69189

    Last Modified: 20 Jun 2026

    Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3.

    Published: 17 Jun 2026
    8.6
    High

    CVE-2025-69128

    Last Modified: 20 Jun 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-60236

    Last Modified: 20 Jun 2026

    Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-60231

    Last Modified: 20 Jun 2026

    Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.

    Published: 17 Jun 2026
    8.7
    High

    CVE-2026-55738

    Last Modified: 10 Aug 2026

    A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source.

    Published: 17 Jun 2026
    8.5
    High

    CVE-2026-54813

    Last Modified: 26 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.

    Published: 17 Jun 2026
    6.9
    Medium

    CVE-2026-9591

    Last Modified: 18 Jun 2026

    Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-54814

    Last Modified: 25 Jun 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2026-54815

    Last Modified: 20 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-54816

    Last Modified: 17 Jun 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.

    Published: 17 Jun 2026
    6.5
    Medium

    CVE-2026-54817

    Last Modified: 17 Jun 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

    Published: 17 Jun 2026
    8.5
    High

    CVE-2026-54818

    Last Modified: 17 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

    Published: 17 Jun 2026
    8.7
    High

    CVE-2026-54417

    Last Modified: 10 Aug 2026

    An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next computes the offset to the next record as round_up(h.size, 512) + sizeof(mtar_raw_header_t) using 32-bit arithmetic.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2026-54819

    Last Modified: 20 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-60230

    Last Modified: 20 Jun 2026

    Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-10641

    Last Modified: 14 Jul 2026

    Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cind_handle(), which assigns a per-entry counter index and calls cind_handle_values() for each list element. cind_handle_values() then wrote hf->ind_table[index] = i without verifying that index is within the 20-element int8_t ind_table[] array of struct bt_hfp_hf. Because the parser places no cap on the number of +CIND: list entries, a remote Attendant Gateway (a malicious, compromised, or spoofed peer the device connects to over Bluetooth) can send a response with more than 20 recognized indicator entries and drive index arbitrarily large, writing a small attacker-positioned value past the array into adjacent struct fields (feature masks, SDP/version state, the calls[] array, work/atomic bookkeeping) and potentially beyond the static connection pool slot. This yields memory corruption and at least denial of service of the Bluetooth host, triggered by a single malformed AT response with no user interaction. The sibling consumer ag_indicator_handle_values() already performed the equivalent bounds check; this commit adds the same index >= ARRAY_SIZE(hf->ind_table) guard to close the gap. Affects builds with CONFIG_BT_HFP_HF enabled; introduced with the original HFP HF CIND parser (~v1.7) and present through v4.4.0.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-60229

    Last Modified: 20 Jun 2026

    Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.

    Published: 17 Jun 2026
    8.8
    High

    CVE-2026-49268

    Last Modified: 17 Jun 2026

    A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.

    Published: 17 Jun 2026
    6.5
    Medium

    CVE-2026-52716

    Last Modified: 17 Jun 2026

    Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-52707

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-49108

    Last Modified: 20 Jun 2026

    Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-40757

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-40756

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-40752

    Last Modified: 20 Jun 2026

    Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-40738

    Last Modified: 20 Jun 2026

    Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-40733

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-40720

    Last Modified: 25 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39590

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39576

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39560

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39559

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39556

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39523

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39445

    Last Modified: 20 Jun 2026

    Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2026-39442

    Last Modified: 17 Jun 2026

    Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69175

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69174

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69170

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69166

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69164

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69158

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69157

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69144

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2025-69140

    Last Modified: 26 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

    Published: 17 Jun 2026
    8.8
    High

    CVE-2025-69130

    Last Modified: 20 Jun 2026

    Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-69127

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69126

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69123

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69120

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.

    Published: 17 Jun 2026