Total
9920 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-11858 | 2026-06-17 | N/A | N/A | ||
| Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The update service runs as NT AUTHORITY\SYSTEM and exposes a .NET Remoting interface over a named pipe without sufficient access controls or authorization. A local authenticated low-privileged user can connect to the interface and invoke privileged update methods such as Update(). This allows arbitrary file write and delete operations with SYSTEM privileges and can be used to achieve local privilege escalation. | |||||
| CVE-2026-48783 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint, /public/modify-subscription, could not change the persisted subscription tier, but it did execute enforcement-related side effects on the caller's own organization, including adjusting team-member enablement state, disabling integrations exceeding the asserted plan's limits, and resetting the scheduled-post cron when the asserted plan was the free tier. Impact is limited to the attacker's own organization and cannot be redirected at other tenants through this endpoint. This issue has been fixed in version 2.21.8. | |||||
| CVE-2026-54802 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. | |||||
| CVE-2026-49081 | 2026-06-17 | N/A | 8.2 HIGH | ||
| Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. | |||||
| CVE-2026-24575 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions. | |||||
| CVE-2024-33685 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1. | |||||
| CVE-2026-8383 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request | |||||
| CVE-2024-32949 | 2026-06-17 | N/A | 8.3 HIGH | ||
| Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8. | |||||
| CVE-2024-37496 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7. | |||||
| CVE-2025-69103 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions. | |||||
| CVE-2024-31435 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6. | |||||
| CVE-2024-33909 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1. | |||||
| CVE-2025-69137 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in Genemy <= 1.6.6 versions. | |||||
| CVE-2026-40722 | 2026-06-17 | N/A | 5.5 MEDIUM | ||
| Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6. | |||||
| CVE-2026-49057 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. | |||||
| CVE-2026-40726 | 2026-06-17 | N/A | 8.2 HIGH | ||
| Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions. | |||||
| CVE-2026-22343 | 2026-06-17 | N/A | 8.6 HIGH | ||
| Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. | |||||
| CVE-2026-39433 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions. | |||||
| CVE-2026-28380 | 1 Grafana | 1 Grafana | 2026-06-17 | N/A | 6.5 MEDIUM |
| Any Editor could delete any snapshot, even if they have no access to read or write them. | |||||
| CVE-2026-9187 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the action__remove_abandoned() function, which is registered to both the wp_ajax_remove_abandoned and wp_ajax_nopriv_remove_abandoned hooks. The handler takes a user-supplied recover_id parameter from $_POST and passes it directly to wp_delete_post() with the force-delete flag set to true, without verifying that the ID belongs to the plugin's own cf7af_data post type. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, or other content on the affected site by sending a single admin-ajax. | |||||
