Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-39512 — WordPress GeoDirectory plugin <= 2.8.152 - SQL Injection vulnerability

Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.

geodirectory | Remote | Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.3 CRITICAL
CVE-2026-39511 — WordPress WP Photo Album Plus plugin <= 9.1.08.001 - SQL Injection vulnerability

Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.

Remote | Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.3 CRITICAL
CVE-2026-39502 — WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability

Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

Remote | Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.3 CRITICAL
CVE-2026-39493 — WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.

simply_schedule_appointments | Remote | Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.3 CRITICAL
CVE-2026-39492 — WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability

Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

Remote | Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.1 CRITICAL
CVE-2026-39465 — WordPress Responsive Slider by MetaSlider plugin <= 3.106.0 - Remote Code Execution (RCE)…

Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.

slider\,_gallery\,_and_carousel | Remote | Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.3 CRITICAL
CVE-2026-39441 — WordPress Feed KuantoKusta for WooCommerce – Free plugin <= 5.3 - SQL Injection vulnerabi…

Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.

Remote | Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.8 CRITICAL
CVE-2026-34901 — WordPress iControlWP plugin <= 5.5.3 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

Remote | Authentication
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.8 CRITICAL
CVE-2026-27053 — WordPress Broadcast Live Video plugin < 7.1.3 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
9.8 CRITICAL
CVE-2026-50890 — Grocy SQL Injection

Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive da…

Remote | Injection
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.1 CRITICAL
CVE-2026-50887 — shlink SSRF

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

Remote | Server-Side Request Forgery
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.1 CRITICAL
CVE-2026-50886 — Project Firefly III: Webhook Internal Resource Scanning

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.

Remote | Authorization
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.6 CRITICAL
CVE-2026-50883 — matze wastebin HTML Injection

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.

Remote | Cross-Site Scripting
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.8 CRITICAL
CVE-2026-50880 — YouTransfer Arbitrary Code Execution

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.

Remote | Injection
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.8 CRITICAL
CVE-2026-50873 — Flatnotes Arbitrary Code Execution via File Upload

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.

Remote | Misconfiguration
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.8 CRITICAL
CVE-2026-50872 — fossar selfoss Command Injection

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP reque…

Remote | Injection
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.8 CRITICAL
CVE-2026-50871 — kanishka-linux Reminiscence OS Command Injection

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted…

Remote | Injection
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.8 CRITICAL
CVE-2026-50869 — Bludit Directory Traversal

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

Remote | Path Traversal
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.3 CRITICAL
CVE-2026-49952 — Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore…

Remote | Authentication
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
9.8 CRITICAL
CVE-2026-48114 — Metacat has an unauthenticated SQL injection vulnerability

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endp…

Remote | Injection
Jun 15, 2026 Jun 16, 2026
Jun 15, 2026
Jun 16, 2026
Showing 20 of 758 Results