Export limit exceeded: 396094 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3326 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-24228 | 1 Nvidia | 2 Nemo, Nemo Framework | 2026-06-17 | 7.8 High |
| NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure. | ||||
| CVE-2025-71321 | 1 Mmaitre314 | 1 Picklescan | 2026-06-17 | 9.8 Critical |
| picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution. | ||||
| CVE-2026-39442 | 2 Presslayouts, Wordpress | 2 Pressmart, Wordpress | 2026-06-17 | 8.1 High |
| Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. | ||||
| CVE-2026-27410 | 2 Veronalabs, Wordpress | 2 Slimstat Analytics, Wordpress | 2026-06-17 | 6.5 Medium |
| Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions. | ||||
| CVE-2026-54806 | 2 Melapress, Wordpress | 2 Wp Activity Log, Wordpress | 2026-06-17 | 9.8 Critical |
| Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. | ||||
| CVE-2026-49107 | 2 Thrivethemes, Wordpress | 2 Thrive Apprentice, Wordpress | 2026-06-17 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. | ||||
| CVE-2026-54194 | 2 Themefusion, Wordpress | 2 Fusion Builder, Wordpress | 2026-06-17 | 9.8 Critical |
| Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. | ||||
| CVE-2026-39557 | 2 Elated-themes, Wordpress | 2 Neobeat, Wordpress | 2026-06-17 | 8.1 High |
| Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions. | ||||
| CVE-2026-40739 | 2 Mikado-themes, Wordpress | 2 Luxedrive, Wordpress | 2026-06-17 | 8.1 High |
| Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions. | ||||
| CVE-2026-40754 | 2 Elated-themes, Wordpress | 2 Roisin, Wordpress | 2026-06-17 | 8.1 High |
| Unauthenticated PHP Object Injection in Roisin <= 1.4 versions. | ||||
| CVE-2026-48775 | 2 Langchain, Langchain-ai | 3 Langgraph-checkpoint, Langgraph, Langgraph-checkpoint | 2026-06-16 | 6.8 Medium |
| LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning "checkpoint-store write access" into code execution in the application runtime. This issue has been fixed in version 4.1.1. | ||||
| CVE-2026-50589 | 1 Openstack | 1 Ironic | 2026-06-16 | 5.3 Medium |
| In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash. | ||||
| CVE-2026-10748 | 1 Sonatype | 1 Nexus Repository Manager | 2026-06-16 | N/A |
| An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0. | ||||
| CVE-2026-39481 | 2 Wordpress, Wpchill | 2 Wordpress, Modula Image Gallery | 2026-06-16 | 7.2 High |
| Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions. | ||||
| CVE-2026-39474 | 2 Metaphorcreations, Wordpress | 2 Post Duplicator, Wordpress | 2026-06-16 | 8.8 High |
| Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions. | ||||
| CVE-2026-39499 | 2 Wombat Plugins, Wordpress | 2 Advanced Product Fields Product Addons For Woocommerce, Wordpress | 2026-06-16 | 7.2 High |
| Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions. | ||||
| CVE-2026-49769 | 2 Tomdever, Wordpress | 2 Wpforo Forum, Wordpress | 2026-06-16 | 9.8 Critical |
| Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | ||||
| CVE-2026-39434 | 2 Webappick, Wordpress | 2 Ctx Feed, Wordpress | 2026-06-16 | 7.2 High |
| Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions. | ||||
| CVE-2026-39472 | 2 Wordpress, Wpovernight | 2 Wordpress, Woocommerce Pdf Invoices\& Packing Slips | 2026-06-16 | 7.2 High |
| Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | ||||
| CVE-2026-49768 | 2 Happyforms, Wordpress | 2 Happyforms, Wordpress | 2026-06-16 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | ||||