Search
3,911 CVEs · High severity
CVEs (3,911, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,911 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-7574 | HIGH | 8.7 | 2026-06-24 | Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence… | |
| CVE-2026-54639 | HIGH | 8.8 | 2026-06-24 | Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact us… | |
| CVE-2026-3652 | HIGH | 7.2 | 2026-06-24 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions u… | |
| CVE-2026-10091 | HIGH | 7.2 | 2026-06-24 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 d… | |
| CVE-2026-10092 | HIGH | 7.2 | 2026-06-24 | The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up to, and incl… | |
| CVE-2026-10735 | HIGH | Patched | 7.5 | 2026-06-24 | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin b… |
| CVE-2026-10749 | HIGH | Patched | 7.2 | 2026-06-24 | The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the … |
| CVE-2026-12095 | HIGH | 7.2 | 2026-06-24 | The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possi… | |
| CVE-2026-12100 | HIGH | 7.2 | 2026-06-24 | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible … | |
| CVE-2026-4297 | HIGH | 8.8 | 2026-06-24 | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capabili… | |
| CVE-2026-8705 | HIGH | 7.5 | 2026-06-24 | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions… | |
| CVE-2026-9178 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/… | |
| CVE-2026-9179 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and inc… | |
| CVE-2026-9643 | HIGH | 7.2 | 2026-06-24 | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, … | |
| CVE-2026-9709 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of … |
| CVE-2026-9710 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to ever… |
| CVE-2026-52912 | HIGH | Patched | 7.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the i… |
| CVE-2026-52915 | HIGH | Patched | 7.1 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists struct ip6t_opts stores at most IP6T_OPTS_OPTSNR op… |
| CVE-2026-52917 | HIGH | Patched | 7.1 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one path The SCTP exact sock_diag lookup can hold a tran… |
| CVE-2026-52918 | HIGH | Patched | 8.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll() walks the accept queue without synchronization, wh… |
| CVE-2026-52919 | HIGH | Patched | 7.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during shutdown batadv_tp_sender_shutdown() unconditionally… |
| CVE-2026-52920 | HIGH | Patched | 8.3 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries… |
| CVE-2026-52922 | HIGH | Patched | 7.5 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error batadv_dat_forward_data() calls pskb_copy_for_clone()… |
| CVE-2026-52923 | HIGH | Patched | 7.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the… |
| CVE-2026-52927 | HIGH | Patched | 7.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_from_user Luxiao Xu says: The function compat_mtw_fr… |