CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 11d ago | 9.1 | The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution. |
| 11d ago | 9.6 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
| 11d ago | 9.6 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
| 11d ago | 9.6 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 11d ago | 9.6 | Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
| 11d ago | 9.6 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
| 11d ago | 9.6 | Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 11d ago | 9.6 | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
| 11d ago | 9.3 | A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6. |
| 11d ago | 9.8 | Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites. |
| Exploit 11d ago | 9.8 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. |
| Exploit 11d ago | 9.8 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root. |
| Exploit 11d ago | 9.8 | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses. |
| Exploit 11d ago | 10 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site. |
| 11d ago | 10 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day. |
| 11d ago | 9 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments. |
| Exploit 12d ago | 9.8 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity. |
| Exploit 12d ago | 9.1 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. |
| 12d ago | 10 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. |
| 12d ago | 9.8 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. |
| 12d ago | 9.3 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. |
| 12d ago | 9.8 | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. |