CVE-2025-69115
Last Modified: 20 Jun 2026Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.
CVE-2025-69111
Last Modified: 26 Jun 2026Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
CVE-2025-69106
Last Modified: 26 Jun 2026Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
CVE-2025-68524
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.
CVE-2025-59554
Last Modified: 20 Jun 2026Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
CVE-2025-15657
Last Modified: 17 Jun 2026Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.
CVE-2026-54193
Last Modified: 17 Jun 2026Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
CVE-2025-59872
Last Modified: 26 Jun 2026HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
CVE-2026-11975
Last Modified: 17 Jun 2026Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute arbitrary JavaScript via the ShortContent and FullContent fields, which are stored without HTML sanitization and rendered unencoded via @Html.Raw()
CVE-2025-62340
Last Modified: 20 Jun 2026HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
CVE-2024-37496
Last Modified: 20 Jun 2026Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7.
CVE-2024-37210
Last Modified: 20 Jun 2026Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.
CVE-2024-35690
Last Modified: 17 Jun 2026Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded Sensitive Data. This issue affects Widget Options: from n/a through 4.0.1.
CVE-2024-35648
Last Modified: 20 Jun 2026Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.
CVE-2024-33909
Last Modified: 17 Jun 2026Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.
CVE-2024-32949
Last Modified: 17 Jun 2026Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8.
CVE-2024-32729
Last Modified: 17 Jun 2026Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.
CVE-2026-11858
Last Modified: 20 Jun 2026Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The update service runs as NT AUTHORITY\SYSTEM and exposes a .NET Remoting interface over a named pipe without sufficient access controls or authorization. A local authenticated low-privileged user can connect to the interface and invoke privileged update methods such as Update(). This allows arbitrary file write and delete operations with SYSTEM privileges and can be used to achieve local privilege escalation.
CVE-2024-24709
Last Modified: 17 Jun 2026Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11.
CVE-2026-11857
Last Modified: 20 Jun 2026Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to insecure deserialization in the .NET Remoting service. The service is configured with TypeFilterLevel.Full and is bound to local interfaces only through named pipes. A local authenticated attacker can connect to the local named pipe, obtain the .NET Remoting endpoint, and send specially crafted serialized objects. Successful exploitation results in arbitrary code execution in the context of the update process with NT AUTHORITY\SYSTEM privileges. Network-only exploitation is not possible and local host access with an authenticated user session is required.
CVE-2025-31013
Last Modified: 26 Jun 2026Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6.
CVE-2024-31435
Last Modified: 20 Jun 2026: Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6.
CVE-2024-33685
Last Modified: 20 Jun 2026Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1.
CVE-2026-10839
Last Modified: 17 Jun 2026Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users to malicious sites following login procedures or interaction with the interface, resulting in limited impact on confidentiality and integrity.
CVE-2026-10837
Last Modified: 17 Jun 2026Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could create manipulated links that, when opened by a victim, cause the victim to be redirected to domains controlled by the attacker, enabling phishing or deception attacks with limited impact on confidentiality and integrity.
CVE-2026-10836
Last Modified: 18 Jun 2026Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A successful exploit could result in the generation of manipulated links or responses, potentially leading to limited information disclosure or compromising the integrity of dependent services.
CVE-2026-5667
Last Modified: 17 Jun 2026Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump Water Heaters / HEMS-Compatible Adapters / Wireless LAN Adapters (for Japan); Bathroom Dryer / Heater / Ventilation Systems (for Japan); Adapters for Airflow Ventilation Systems, Heat Pump Chilled / Hot Water Systems, and Ventilation / Air-Conditioning System Air Resorts (for Japan); Lossnay Central Ventilation Systems (for Japan); Smart Switches for Ventilation Fans and Lossnay (for Japan); IH Cooking Heaters (for Japan); and Rice Cookers (for Japan) allows an attacker within Wi-Fi radio range of an affected product to access the affected product using a hard-coded SSID and password, thereby obtaining device data such as operation status, room set temperature, and room temperature; changing the air-conditioner or Wi-Fi settings; or causing Wi-Fi communication to enter a denial-of-service (DoS) condition.
CVE-2024-34810
Last Modified: 20 Jun 2026Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10.
CVE-2026-54811
Last Modified: 26 Jun 2026Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
CVE-2026-54807
Last Modified: 20 Jun 2026Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
CVE-2026-54806
Last Modified: 17 Jun 2026Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
CVE-2026-54805
Last Modified: 20 Jun 2026Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
CVE-2026-54804
Last Modified: 20 Jun 2026Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
CVE-2026-54803
Last Modified: 20 Jun 2026Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.
CVE-2026-54802
Last Modified: 26 Jun 2026Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
CVE-2026-54196
Last Modified: 17 Jun 2026Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.
CVE-2026-54195
Last Modified: 17 Jun 2026Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
CVE-2026-54192
Last Modified: 17 Jun 2026Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
CVE-2026-54189
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54188
Last Modified: 20 Jun 2026Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54187
Last Modified: 20 Jun 2026Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2026-54186
Last Modified: 18 Jun 2026Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.
CVE-2026-54185
Last Modified: 20 Jun 2026Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
CVE-2026-54184
Last Modified: 20 Jun 2026Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
CVE-2026-52706
Last Modified: 20 Jun 2026Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
CVE-2026-52705
Last Modified: 20 Jun 2026Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
CVE-2026-52698
Last Modified: 20 Jun 2026Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2.3 versions.
CVE-2026-52696
Last Modified: 20 Jun 2026Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
CVE-2026-49778
Last Modified: 26 Jun 2026Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
CVE-2026-49767
Last Modified: 17 Jun 2026Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
