CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-12308
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12307
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12306
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12305
7.5 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12304
9.1 CRITICAL

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12303
4.3 MEDIUM

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12302
6.5 MEDIUM

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12301
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12300
5.3 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12299
5.4 MEDIUM

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and …

Jun 16, 2026
CVE-2026-12298
5.4 MEDIUM

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12297

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird …

Jun 16, 2026
CVE-2026-12296

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12295

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12294

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12293
9.8 CRITICAL

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12292

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12291

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12290
8.1 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12289
8.8 HIGH

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-8484

A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the …

Jun 16, 2026
CVE-2026-40750
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects …

Jun 16, 2026
CVE-2026-12225

syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user …

Jun 16, 2026
CVE-2026-10829

A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of …

Jun 16, 2026
CVE-2026-10828

A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and …

Jun 16, 2026
CVE-2026-8442
8.1 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to …

Jun 16, 2026
CVE-2026-8176
7.5 HIGH

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and …

Jun 16, 2026
CVE-2026-5416
8.8 HIGH

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in …

Jun 16, 2026
CVE-2026-54198
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.

Jun 16, 2026
CVE-2026-54197
6.5 MEDIUM

Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

Jun 16, 2026
CVE-2026-54191
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.

Jun 16, 2026
CVE-2026-54190
6.5 MEDIUM

Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

Jun 16, 2026
CVE-2026-52715
9.3 CRITICAL

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

Jun 16, 2026
CVE-2026-52714
5.9 MEDIUM

Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.

Jun 16, 2026
CVE-2026-52712
7.6 HIGH

Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.

Jun 16, 2026
CVE-2026-52711
7.5 HIGH

Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

Jun 16, 2026
CVE-2026-49774
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a …

Jun 16, 2026
CVE-2026-49772
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. …

Jun 16, 2026
CVE-2026-40809
6.5 MEDIUM

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.

Jun 16, 2026
CVE-2026-39581
8.5 HIGH

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

Jun 16, 2026
CVE-2026-39574
9.3 CRITICAL

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

Jun 16, 2026
CVE-2026-39490
7.5 HIGH

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

Jun 16, 2026
CVE-2026-39437
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.

Jun 16, 2026
CVE-2026-2381
6.5 MEDIUM

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function …

Jun 16, 2026
CVE-2026-10825

A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially …

Jun 16, 2026
CVE-2025-68045
7.5 HIGH

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

Jun 16, 2026
CVE-2026-8444
8.8 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up …

Jun 16, 2026
CVE-2026-46331

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range …

Jun 16, 2026
CVE-2026-10093
6.4 MEDIUM

The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all …

Jun 16, 2026
CVE-2025-9912
6.3 MEDIUM

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands …

Jun 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.