| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49076 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1. | ||
| CVE-2026-49075 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. | ||
| CVE-2026-49058 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. | ||
| CVE-2026-48875 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. | ||
| CVE-2026-48797 | Cri | 0.60 | — | 0.01 | Jun 17, 2026 | Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration,… | ||
| CVE-2026-48781 | Cri | 0.57 | 9.9 | 0.00 | Jun 17, 2026 | Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without… | ||
| CVE-2026-48745 | Cri | 0.53 | 9.3 | 0.00 | Jun 17, 2026 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an… | ||
| CVE-2026-48616 | Cri | 0.53 | 9.3 | 0.00 | Jun 17, 2026 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the… | ||
| CVE-2026-48055 | Cri | 0.65 | 10.0 | 0.01 | Jun 17, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames… | ||
| CVE-2026-42380 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. | ||
| CVE-2026-40783 | Cri | 0.64 | 9.9 | 0.01 | Jun 17, 2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. | ||
| CVE-2026-40749 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. | ||
| CVE-2026-40748 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | ||
| CVE-2026-40747 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. | ||
| CVE-2026-40746 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. | ||
| CVE-2026-40725 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. | ||
| CVE-2026-39596 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. | ||
| CVE-2026-39589 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. | ||
| CVE-2026-39529 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. | ||
| CVE-2026-39438 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. | ||
| CVE-2026-32967 | Cri | 0.52 | 9.1 | 0.01 | Jun 17, 2026 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | ||
| CVE-2026-32966 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | ||
| CVE-2026-27429 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. | ||
| CVE-2026-27395 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | ||
| CVE-2026-27041 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. | ||
| CVE-2026-25470 | Cri | 0.65 | 10.0 | 0.01 | Jun 17, 2026 | Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions. | ||
| CVE-2026-25446 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. | ||
| CVE-2026-24611 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. | ||
| CVE-2026-22340 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. | ||
| CVE-2026-22332 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. | ||
| CVE-2026-22327 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. | ||
| CVE-2026-12440 | Cri | 0.62 | 9.6 | 0.00 | Jun 17, 2026 | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-10094 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server. | ||
| CVE-2026-0092 | Cri | 0.65 | — | 0.00 | Jun 17, 2026 | In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2025-69179 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. | ||
| CVE-2025-69129 | Cri | 0.65 | 10.0 | 0.00 | Jun 17, 2026 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | ||
| CVE-2025-69122 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. | ||
| CVE-2025-69108 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. | ||
| CVE-2025-60218 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. | ||
| CVE-2025-60205 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. | ||
| CVE-2024-52488 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions. | ||
| CVE-2026-46978 | Cri | 0.65 | 10.0 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Solaris.… | ||
| CVE-2026-46964 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access… | ||
| CVE-2026-46963 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access… | ||
| CVE-2026-46949 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | ||
| CVE-2026-46946 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | ||
| CVE-2026-46945 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | ||
| CVE-2026-46944 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | ||
| CVE-2026-46933 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | ||
| CVE-2026-46930 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with… |
- risk 0.60cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1.
- risk 0.64cvss 9.8epss 0.01
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.
- risk 0.60cvss —epss 0.01
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration,…
- risk 0.57cvss 9.9epss 0.00
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without…
- risk 0.53cvss 9.3epss 0.00
Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an…
- risk 0.53cvss 9.3epss 0.00
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the…
- risk 0.65cvss 10.0epss 0.01
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames…
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.
- risk 0.64cvss 9.9epss 0.01
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.
- risk 0.52cvss 9.1epss 0.01
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
- risk 0.57cvss 9.8epss 0.01
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
- risk 0.64cvss 9.9epss 0.00
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
- risk 0.59cvss 9.1epss 0.00
Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.
- risk 0.62cvss 9.6epss 0.00
Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.64cvss 9.8epss 0.00
A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server.
- risk 0.65cvss —epss 0.00
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.
- risk 0.65cvss 10.0epss 0.00
Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
- risk 0.65cvss 10.0epss 0.00
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Solaris.…
- risk 0.64cvss 9.9epss 0.00
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access…
- risk 0.64cvss 9.9epss 0.00
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access…
- risk 0.59cvss 9.1epss 0.00
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
- risk 0.59cvss 9.1epss 0.00
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
- risk 0.59cvss 9.1epss 0.00
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
- risk 0.59cvss 9.1epss 0.00
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
- risk 0.64cvss 9.9epss 0.00
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
- risk 0.59cvss 9.1epss 0.00
Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with…