Search Results (29944 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-49084 2 Jetimpex Inc., Wordpress 2 Jetengine, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
CVE-2026-52705 2 Bdthemes, Wordpress 2 Sigmaforms Pro – Ai Generated Forms, Wordpress 2026-06-20 9 Critical
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
CVE-2026-52706 2 Jetimpex Inc., Wordpress 2 Jetengine, Wordpress 2026-06-20 9.8 Critical
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
CVE-2026-54187 2 Jetimpex Inc., Wordpress 2 Jetengine, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2026-54803 2 Cozyvision, Wordpress 2 Sms Alert Order Notifications, Wordpress 2026-06-20 9.8 Critical
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.
CVE-2026-54807 2 Themegrill, Wordpress 2 Registration Form For Woocommerce, Wordpress 2026-06-20 9.8 Critical
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
CVE-2025-59554 2 Advanced Ads Gmbh, Wordpress 2 Advanced Ads – Tracking, Wordpress 2026-06-20 9.3 Critical
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
CVE-2026-49108 2 Park Of Ideas, Wordpress 2 Moderno, Wordpress 2026-06-20 9.8 Critical
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
CVE-2025-60229 2 Themeton, Wordpress 2 Lagom, Wordpress 2026-06-20 9.8 Critical
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
CVE-2025-60230 2 Themeton, Wordpress 2 The Barber Shop, Wordpress 2026-06-20 9.8 Critical
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
CVE-2026-54819 2 Webilia Inc., Wordpress 2 Listdom, Wordpress 2026-06-20 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.
CVE-2026-54815 2 Cargo Rd, Wordpress 2 Cargo Shipping Location For Woocommerce, Wordpress 2026-06-20 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.
CVE-2025-60231 2 Emv, Wordpress 2 The Hospital, Wordpress 2026-06-20 9.8 Critical
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
CVE-2025-60236 2 Emv, Wordpress 2 Creatify, Wordpress 2026-06-20 9.8 Critical
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
CVE-2026-54808 2 Wordpress, Wp Travel 2 Wordpress, Wp Travel Gutenberg Blocks 2026-06-20 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.
CVE-2026-54809 2 Villatheme, Wordpress 2 Gift4u, Wordpress 2026-06-20 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.
CVE-2025-71320 2 Mmaitre314, Picklescan 2 Picklescan, Picklescan 2026-06-20 9.8 Critical
picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary code execution when the pickle is deserialized.
CVE-2025-71323 2 Mmaitre314, Picklescan 2 Picklescan, Picklescan 2026-06-20 9.8 Critical
picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickle files using ctypes.WinDLL to load kernel32.dll and execute arbitrary commands, bypassing sandbox protections and gadget chain detection.
CVE-2026-53873 2 Mmaitre314, Picklescan 2 Picklescan, Picklescan 2026-06-20 9.8 Critical
picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious pickle files calling profile.run(statement) to execute arbitrary Python code while picklescan reports zero security issues.
CVE-2026-53805 1 Nv-tlabs 1 Gen3c 2026-06-20 9.8 Critical
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.