cve.li

Recent

CVE-2026-11374CWE-340CWE-330CWE-287

Account Takeover via Predictable SSO Ticket Generation

Published 2026-06-23 by Zohocorp

CVE-2026-10521CWE-425

Authenticated unintended access to critical program parameters

Published 2026-06-23 by CERTVDE

CVE-2026-9733CWE-340CWE-338

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter

Published 2026-06-23 by CPANSec

CVE-2026-8379

Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download

Published 2026-06-23 by WPScan

CVE-2026-8378

Frontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scripting via File Rename

Published 2026-06-23 by WPScan

CVE-2026-8172

Simple Basic Contact Form <= 20250114 - Reflected XSS

Published 2026-06-23 by WPScan

CVE-2026-8163

Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter

Published 2026-06-23 by WPScan

CVE-2026-7842

Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter

Published 2026-06-23 by WPScan

CVE-2026-12866CWE-94

Published 2026-06-23 by snyk

CVE-2026-55654CWE-125

Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination

Published 2026-06-23 by redhat

Load more ↓