CVE-2026-39580 - WordPress Micdrop theme <= 1.3.1 - PHP Object Injection vulnerability
CVE ID :CVE-2026-39580
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39580
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40736 - WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40736
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40736
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40739 - WordPress LuxeDrive theme <= 1.4 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40739
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40739
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40751 - WordPress Ashtanga theme <= 1.2 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40751
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40751
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40754 - WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40754
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40754
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40755 - WordPress TechLink theme <= 1.3 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40755
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40755
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40758 - WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40758
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40758
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40759 - WordPress Esmée theme <= 1.4 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40759
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40759
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40760 - WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40760
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40760
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-40761 - WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability
CVE ID :CVE-2026-40761
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40761
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48869 - WordPress Enfold theme <= 7.1.4 - Reflected Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-48869
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48869
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49057 - WordPress JobSearch plugin <= 3.2.7 - Broken Access Control vulnerability
CVE ID :CVE-2026-49057
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49057
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49080 - WordPress wpDataTables plugin <= 7.3.6 - SQL Injection vulnerability
CVE ID :CVE-2026-49080
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49080
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49113 - WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerability
CVE ID :CVE-2026-49113
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49113
Published : June 16, 2026, 8:57 p.m. | 1 hour, 3 minutes ago
Description :Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11410 - OS Command Injection in BigPond Cable (BPA) Configuration in TP-Link TL-WR940N
CVE ID :CVE-2026-11410
Published : June 16, 2026, 9:03 p.m. | 57 minutes ago
Description :An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11410
Published : June 16, 2026, 9:03 p.m. | 57 minutes ago
Description :An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11409 - OS Command Injection in IPv6 PPPoE Configuration in TP-Link TL-WR940N
CVE ID :CVE-2026-11409
Published : June 16, 2026, 9:03 p.m. | 56 minutes ago
Description :An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-11409
Published : June 16, 2026, 9:03 p.m. | 56 minutes ago
Description :An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48055 - Streambert: Arbitrary File Write (Zip Slip) via Subtitle Extraction
CVE ID :CVE-2026-48055
Published : June 16, 2026, 9:17 p.m. | 42 minutes ago
Description :Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries. The destination file path is constructed by concatenating the raw archive entry name (extracted.name) directly to the temporary directory path. If a malicious ZIP archive containing directory traversal sequences is processed, it escapes the temporary directory boundaries. The application then writes the extracted payload anywhere on the host filesystem subject to the application's current write permissions. This issue has been fixed in version 2.5.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48055
Published : June 16, 2026, 9:17 p.m. | 42 minutes ago
Description :Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries. The destination file path is constructed by concatenating the raw archive entry name (extracted.name) directly to the temporary directory path. If a malicious ZIP archive containing directory traversal sequences is processed, it escapes the temporary directory boundaries. The application then writes the extracted payload anywhere on the host filesystem subject to the application's current write permissions. This issue has been fixed in version 2.5.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49073 - WordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerability
CVE ID :CVE-2026-49073
Published : June 16, 2026, 9:23 p.m. | 37 minutes ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-49073
Published : June 16, 2026, 9:23 p.m. | 37 minutes ago
Description :Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39598 - WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability
CVE ID :CVE-2026-39598
Published : June 16, 2026, 9:24 p.m. | 36 minutes ago
Description :Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39598
Published : June 16, 2026, 9:24 p.m. | 36 minutes ago
Description :Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-25470 - WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.47 - Remote Code Execution (RCE) vulnerability
CVE ID :CVE-2026-25470
Published : June 16, 2026, 9:25 p.m. | 34 minutes ago
Description :Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-25470
Published : June 16, 2026, 9:25 p.m. | 34 minutes ago
Description :Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48779 - ws: Memory exhaustion DoS from tiny fragments and data chunks
CVE ID :CVE-2026-48779
Published : June 16, 2026, 9:26 p.m. | 34 minutes ago
Description :ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48779
Published : June 16, 2026, 9:26 p.m. | 34 minutes ago
Description :ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...