Total
9932 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-40776 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions. | |||||
| CVE-2026-40775 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions. | |||||
| CVE-2026-40774 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions. | |||||
| CVE-2026-40773 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions. | |||||
| CVE-2026-40763 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1056. | |||||
| CVE-2026-40743 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions. | |||||
| CVE-2026-40742 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio AB Testing: from n/a through <= 8.2.8. | |||||
| CVE-2026-40741 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions. | |||||
| CVE-2026-40740 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7. | |||||
| CVE-2026-40730 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6. | |||||
| CVE-2026-40729 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5. | |||||
| CVE-2026-40728 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3. | |||||
| CVE-2026-40623 | 1 Senselive | 2 X3500, X3500 Firmware | 2026-06-17 | N/A | 8.1 HIGH |
| A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watchdog timers, reconnect intervals, and service ports can be set to unsupported or unsafe values. These configuration changes directly affect core device behaviour and recovery mechanisms. The lack of proper validation and safeguards allows critical system functions to be altered in a manner that can destabilize device operation or render the device persistently unavailable. | |||||
| CVE-2026-40601 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes POST /api/chart/:chart_id/query without authentication. The endpoint only checks team.allowReportRefresh and does not verify that the target chart belongs to a public report, that the project is public, or that sharing policy allows the operation. An unauthenticated attacker who knows a chart identifier can trigger a data refresh and retrieve the current data of private charts. This issue has been patched in version 5.0.0. | |||||
| CVE-2026-40592 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the reply being undone. In a shared mailbox, one agent can therefore recall another agent's just-sent reply during the 15-second undo window. Version 1.8.214 fixes the vulnerability. | |||||
| CVE-2026-40581 | 2026-06-17 | N/A | 8.1 HIGH | ||
| ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft a malicious page that, when visited by an authenticated administrator, silently triggers deletion of targeted family records including associated notes, pledges, persons, and property data without any user interaction. This issue has been fixed in version 7.2.0. | |||||
| CVE-2026-40570 | 2026-06-17 | N/A | N/A | ||
| FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` returns complete customer profile data to any authenticated user without verifying mailbox access. An attacker only needs a valid email address to retrieve all customer PII. Version 1.8.213 fixes the issue. | |||||
| CVE-2026-40480 | 2026-06-17 | N/A | N/A | ||
| ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization checks. Although the legacy PersonView.php page enforces canEditPerson() restrictions, the API layer omits this check. Any authenticated user with only EditSelf privileges can enumerate and read other members' records, exposing sensitive PII including names, addresses, phone numbers, and email addresses. This issue has been fixed in version 7.2.0. | |||||
| CVE-2026-40474 | 1 Wger | 1 Wger | 2026-06-17 | N/A | 7.6 HIGH |
| wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permission is never enforced at runtime. Since GymConfig is an ownerless singleton, any authenticated user can modify the global gym configuration, triggering save() side effects that bulk-update user profile gym assignments — a vertical privilege escalation to installation-wide configuration control. This issue is fixed in version 2.5. | |||||
| CVE-2026-40349 | 1 Leepeuker | 1 Movary | 2026-06-17 | N/A | 8.8 HIGH |
| Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a user edit their own profile, but it updates the sensitive `isAdmin` field without any admin-only authorization check. Version 0.71.1 patches the issue. | |||||
