CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60236
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.

Jun 17, 2026
CVE-2025-60231
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.

Jun 17, 2026
CVE-2025-60230
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.

Jun 17, 2026
CVE-2025-60229
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.

Jun 17, 2026
CVE-2025-59554
9.3 CRITICAL

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

Jun 17, 2026
CVE-2026-54811
9.3 CRITICAL

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

Jun 17, 2026
CVE-2026-54807
9.8 CRITICAL

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

Jun 17, 2026
CVE-2026-54806
9.8 CRITICAL

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

Jun 17, 2026
CVE-2026-54803
9.8 CRITICAL

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.

Jun 17, 2026
CVE-2026-54194
9.8 CRITICAL

Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.

Jun 17, 2026
CVE-2026-54187
9.3 CRITICAL

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

Jun 17, 2026
CVE-2026-54186
9.3 CRITICAL

Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

Jun 17, 2026
CVE-2026-52706
9.8 CRITICAL

Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.

Jun 17, 2026
CVE-2026-52705
9.0 CRITICAL

Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.

Jun 17, 2026
CVE-2026-50203
9.1 CRITICAL

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination …

Jun 17, 2026
CVE-2026-49767
9.8 CRITICAL

Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.

Jun 17, 2026
CVE-2026-49107
9.8 CRITICAL

Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.

Jun 17, 2026
CVE-2026-49084
9.3 CRITICAL

Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.

Jun 17, 2026
CVE-2026-49080
9.3 CRITICAL

Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.

Jun 17, 2026
CVE-2026-49079
9.3 CRITICAL

Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.

Jun 17, 2026
CVE-2026-49076
9.3 CRITICAL

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

Jun 17, 2026
CVE-2026-49075
9.8 CRITICAL

Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.

Jun 17, 2026
CVE-2026-49058
9.8 CRITICAL

Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

Jun 17, 2026
CVE-2026-48875
9.3 CRITICAL

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

Jun 17, 2026
CVE-2026-48781
9.9 CRITICAL

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape …

Jun 17, 2026
CVE-2026-48745
9.3 CRITICAL

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, …

Jun 17, 2026
CVE-2026-48616
9.3 CRITICAL

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat …

Jun 17, 2026
CVE-2026-48055
10.0 CRITICAL

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was …

Jun 17, 2026
CVE-2026-42380
9.8 CRITICAL

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

Jun 17, 2026
CVE-2026-40783
9.9 CRITICAL

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

Jun 17, 2026
CVE-2026-40749
9.9 CRITICAL

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

Jun 17, 2026
CVE-2026-40748
9.9 CRITICAL

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

Jun 17, 2026
CVE-2026-40747
9.9 CRITICAL

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

Jun 17, 2026
CVE-2026-40746
9.9 CRITICAL

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

Jun 17, 2026
CVE-2026-40725
9.8 CRITICAL

Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

Jun 17, 2026
CVE-2026-39596
9.3 CRITICAL

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

Jun 17, 2026
CVE-2026-39589
9.9 CRITICAL

Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.

Jun 17, 2026
CVE-2026-39529
9.8 CRITICAL

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

Jun 17, 2026
CVE-2026-39438
9.3 CRITICAL

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

Jun 17, 2026
CVE-2026-32967
9.1 CRITICAL

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, …

Jun 17, 2026
CVE-2026-32966
9.8 CRITICAL

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended …

Jun 17, 2026
CVE-2026-27429
9.8 CRITICAL

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

Jun 17, 2026
CVE-2026-27395
9.8 CRITICAL

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

Jun 17, 2026
CVE-2026-27041
9.9 CRITICAL

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

Jun 17, 2026
CVE-2026-25470
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This …

Jun 17, 2026
CVE-2026-25446
9.9 CRITICAL

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

Jun 17, 2026
CVE-2026-24611
9.1 CRITICAL

Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.

Jun 17, 2026
CVE-2026-22340
9.3 CRITICAL

Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions.

Jun 17, 2026
CVE-2026-22332
9.3 CRITICAL

Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.

Jun 17, 2026
CVE-2026-22327
9.9 CRITICAL

Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.

Jun 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.