CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2025-69115

    Last Modified: 20 Jun 2026

    Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2025-69111

    Last Modified: 26 Jun 2026

    Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.

    Published: 17 Jun 2026
    8.1
    High

    CVE-2025-69106

    Last Modified: 26 Jun 2026

    Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2025-68524

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2025-59554

    Last Modified: 20 Jun 2026

    Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

    Published: 17 Jun 2026
    5.3
    Medium

    CVE-2025-15657

    Last Modified: 17 Jun 2026

    Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.

    Published: 17 Jun 2026
    7.7
    High

    CVE-2026-54193

    Last Modified: 17 Jun 2026

    Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2025-59872

    Last Modified: 26 Jun 2026

    HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code

    Published: 17 Jun 2026
    6.2
    Medium

    CVE-2026-11975

    Last Modified: 17 Jun 2026

    Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute arbitrary JavaScript via the ShortContent and FullContent fields, which are stored without HTML sanitization and rendered unencoded via @Html.Raw()

    Published: 17 Jun 2026
    3.1
    Low

    CVE-2025-62340

    Last Modified: 20 Jun 2026

    HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2024-37496

    Last Modified: 20 Jun 2026

    Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.

    Published: 17 Jun 2026
    6.5
    Medium

    CVE-2024-37210

    Last Modified: 20 Jun 2026

    Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.

    Published: 17 Jun 2026
    6.5
    Medium

    CVE-2024-35690

    Last Modified: 17 Jun 2026

    Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2024-35648

    Last Modified: 20 Jun 2026

    Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.

    Published: 17 Jun 2026
    5.3
    Medium

    CVE-2024-33909

    Last Modified: 17 Jun 2026

    Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.

    Published: 17 Jun 2026
    8.3
    High

    CVE-2024-32949

    Last Modified: 17 Jun 2026

    Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2024-32729

    Last Modified: 17 Jun 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.

    Published: 17 Jun 2026
    8.4
    High

    CVE-2026-11858

    Last Modified: 20 Jun 2026

    Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The update service runs as NT AUTHORITY\SYSTEM and exposes a .NET Remoting interface over a named pipe without sufficient access controls or authorization. A local authenticated low-privileged user can connect to the interface and invoke privileged update methods such as Update(). This allows arbitrary file write and delete operations with SYSTEM privileges and can be used to achieve local privilege escalation.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2024-24709

    Last Modified: 17 Jun 2026

    Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11.

    Published: 17 Jun 2026
    8.4
    High

    CVE-2026-11857

    Last Modified: 20 Jun 2026

    Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the .NET Remoting service. The service is configured with TypeFilterLevel.Full and is bound to local interfaces only through named pipes. A local authenticated attacker can connect to the local named pipe, obtain the .NET Remoting endpoint, and send specially crafted serialized objects. Successful exploitation results in arbitrary code execution in the context of the update process with NT AUTHORITY\SYSTEM privileges. Network-only exploitation is not possible and local host access with an authenticated user session is required.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2025-31013

    Last Modified: 26 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2024-31435

    Last Modified: 20 Jun 2026

    : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2024-33685

    Last Modified: 20 Jun 2026

    Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.

    Published: 17 Jun 2026
    5.1
    Medium

    CVE-2026-10839

    Last Modified: 17 Jun 2026

    Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users to malicious sites following login procedures or interaction with the interface, resulting in limited impact on confidentiality and integrity.

    Published: 17 Jun 2026
    5.1
    Medium

    CVE-2026-10837

    Last Modified: 17 Jun 2026

    Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, when opened by a victim, cause the victim to be redirected to domains controlled by the attacker, enabling phishing or deception attacks with limited impact on confidentiality and integrity.

    Published: 17 Jun 2026
    5.1
    Medium

    CVE-2026-10836

    Last Modified: 18 Jun 2026

    Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A successful exploit could result in the generation of manipulated links or responses, potentially leading to limited information disclosure or compromising the integrity of dependent services.

    Published: 17 Jun 2026
    7.2
    High

    CVE-2026-5667

    Last Modified: 17 Jun 2026

    Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2024-34810

    Last Modified: 20 Jun 2026

    Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2026-54811

    Last Modified: 26 Jun 2026

    Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-54807

    Last Modified: 20 Jun 2026

    Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-54806

    Last Modified: 17 Jun 2026

    Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

    Published: 17 Jun 2026
    8.8
    High

    CVE-2026-54805

    Last Modified: 20 Jun 2026

    Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

    Published: 17 Jun 2026
    7.6
    High

    CVE-2026-54804

    Last Modified: 20 Jun 2026

    Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-54803

    Last Modified: 20 Jun 2026

    Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-54802

    Last Modified: 26 Jun 2026

    Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.

    Published: 17 Jun 2026
    6.8
    Medium

    CVE-2026-54196

    Last Modified: 17 Jun 2026

    Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-54195

    Last Modified: 17 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-54192

    Last Modified: 17 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-54189

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-54188

    Last Modified: 20 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2026-54187

    Last Modified: 20 Jun 2026

    Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

    Published: 17 Jun 2026
    9.3
    Critical

    CVE-2026-54186

    Last Modified: 18 Jun 2026

    Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

    Published: 17 Jun 2026
    8.5
    High

    CVE-2026-54185

    Last Modified: 20 Jun 2026

    Subscriber SQL Injection in Cornerstone < 7.8.8 versions.

    Published: 17 Jun 2026
    8.2
    High

    CVE-2026-54184

    Last Modified: 20 Jun 2026

    Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-52706

    Last Modified: 20 Jun 2026

    Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.

    Published: 17 Jun 2026
    9
    Critical

    CVE-2026-52705

    Last Modified: 20 Jun 2026

    Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.

    Published: 17 Jun 2026
    7.4
    High

    CVE-2026-52698

    Last Modified: 20 Jun 2026

    Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2.3 versions.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-52696

    Last Modified: 20 Jun 2026

    Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-49778

    Last Modified: 26 Jun 2026

    Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-49767

    Last Modified: 17 Jun 2026

    Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.

    Published: 17 Jun 2026