| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49106 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | ||
| CVE-2026-49105 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | ||
| CVE-2026-49104 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. | ||
| CVE-2026-49085 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | ||
| CVE-2026-49067 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. | ||
| CVE-2026-48886 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. | ||
| CVE-2026-48881 | Cri | 0.59 | 9.1 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. | ||
| CVE-2026-48836 | Cri | 0.65 | 10.0 | 0.01 | Jun 15, 2026 | Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | ||
| CVE-2026-45439 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. | ||
| CVE-2026-42665 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. | ||
| CVE-2026-42639 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. | ||
| CVE-2026-42386 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. | ||
| CVE-2026-42381 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions. | ||
| CVE-2026-40798 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions. | ||
| CVE-2026-40772 | Cri | 0.65 | 10.0 | 0.01 | Jun 15, 2026 | Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions. | ||
| CVE-2026-40771 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. | ||
| CVE-2026-39591 | Cri | 0.64 | 9.9 | 0.00 | Jun 15, 2026 | Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions. | ||
| CVE-2026-39583 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions. | ||
| CVE-2026-39530 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. | ||
| CVE-2026-39519 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions. | ||
| CVE-2026-39512 | Cri | 0.53 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions. | ||
| CVE-2026-39511 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions. | ||
| CVE-2026-39502 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. | ||
| CVE-2026-39493 | Cri | 0.53 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. | ||
| CVE-2026-39492 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | ||
| CVE-2026-39465 | Cri | 0.59 | 9.1 | 0.01 | Jun 15, 2026 | Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions. | ||
| CVE-2026-39441 | Cri | 0.53 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions. | ||
| CVE-2026-34901 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. | ||
| CVE-2026-27053 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. | ||
| CVE-2026-50890 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||
| CVE-2026-50887 | Cri | 0.59 | 9.1 | 0.00 | Jun 15, 2026 | A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl. | ||
| CVE-2026-50886 | Cri | 0.59 | 9.1 | 0.00 | Jun 15, 2026 | Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request. | ||
| CVE-2026-50883 | Cri | 0.62 | 9.6 | 0.01 | Jun 15, 2026 | An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload. | ||
| CVE-2026-50880 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request. | ||
| CVE-2026-50873 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file. | ||
| CVE-2026-50872 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request. | ||
| CVE-2026-50871 | Cri | 0.64 | 9.8 | 0.03 | Jun 15, 2026 | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. | ||
| CVE-2026-50869 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request. | ||
| CVE-2026-49952 | Cri | 0.52 | 9.1 | 0.04 | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter… | ||
| CVE-2026-48114 | Cri | 0.57 | 9.8 | 0.00 | Jun 15, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegistration.dbInsert() builds an INSERT against… | ||
| CVE-2026-45390 | Cri | 0.59 | 9.1 | 0.01 | Jun 15, 2026 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file… | ||
| CVE-2026-45389 | Cri | 0.59 | 9.1 | 0.00 | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and… | ||
| CVE-2026-45388 | Cri | 0.59 | 9.1 | 0.00 | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage). | ||
| CVE-2026-39196 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to access sensitive database information via crafted SQL statements. | ||
| CVE-2026-39006 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. | ||
| CVE-2026-38812 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information. | ||
| CVE-2026-38329 | Cri | 0.57 | 9.8 | 0.01 | Jun 15, 2026 | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a… | ||
| CVE-2026-38065 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. | ||
| CVE-2026-38064 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. | ||
| CVE-2026-38063 | Cri | 0.64 | 9.8 | 0.02 | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. |
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
- risk 0.59cvss 9.1epss 0.00
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
- risk 0.53cvss 9.3epss 0.00
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
- risk 0.53cvss 9.3epss 0.00
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
- risk 0.59cvss 9.1epss 0.01
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
- risk 0.53cvss 9.3epss 0.00
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
- risk 0.64cvss 9.8epss 0.00
Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
- risk 0.59cvss 9.1epss 0.00
A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.
- risk 0.59cvss 9.1epss 0.00
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
- risk 0.62cvss 9.6epss 0.01
An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.
- risk 0.64cvss 9.8epss 0.01
An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.03
An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.
- risk 0.64cvss 9.8epss 0.01
An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.
- risk 0.52cvss 9.1epss 0.04
Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter…
- risk 0.57cvss 9.8epss 0.00
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegistration.dbInsert() builds an INSERT against…
- risk 0.59cvss 9.1epss 0.01
In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file…
- risk 0.59cvss 9.1epss 0.00
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and…
- risk 0.59cvss 9.1epss 0.00
In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).
- risk 0.64cvss 9.8epss 0.00
Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to access sensitive database information via crafted SQL statements.
- risk 0.64cvss 9.8epss 0.01
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
- risk 0.64cvss 9.8epss 0.00
RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.
- risk 0.57cvss 9.8epss 0.01
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a…
- risk 0.64cvss 9.8epss 0.02
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.
- risk 0.64cvss 9.8epss 0.02
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.
- risk 0.64cvss 9.8epss 0.02
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.