CVE Monitor
286267 CVEs found
CVE-2026-54815
CRITICAL
17 Jun 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.
CVE-2026-54816
HIGH
17 Jun 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.
CVE-2026-54817
MEDIUM
17 Jun 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.
CVE-2026-54818
HIGH
17 Jun 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.
CVE-2026-54417
HIGH
17 Jun 2026
An integer overflow in the mtar_next() function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next() computes the offset to the next record as round_up(h.size, 512) + sizeof(mtar_raw_header_t) using 32-bit arithmetic. When the header size field is a multiple of 512 in the range 0xFFFFFC01-0xFFFFFE00 (e.g. 0xFFFFFE00), the addition wraps to 0, so mtar_next() seeks to the current record position instead of advancing. As a result, mtar_find() and any loop that iterates entries with mtar_next() repeat indefinitely over the same record, hanging the process at 100% CPU with no recovery.
CVE-2026-54819
CRITICAL
17 Jun 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.
CVE-2025-60230
CRITICAL
17 Jun 2026
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
CVE-2026-10641
HIGH
17 Jun 2026
Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cind_handle(), which assigns a per-entry counter index and calls cind_handle_values() for each list element. cind_handle_values() then wrote hf->ind_table[index] = i without verifying that index is within the 20-element int8_t ind_table[] array of struct bt_hfp_hf. Because the parser places no cap on the number of +CIND: list entries, a remote Attendant Gateway (a malicious, compromised, or spoofed peer the device connects to over Bluetooth) can send a response with more than 20 recognized indicator entries and drive index arbitrarily large, writing a small attacker-positioned value past the array into adjacent struct fields (feature masks, SDP/version state, the calls[] array, work/atomic bookkeeping) and potentially beyond the static connection pool slot. This yields memory corruption and at least denial of service of the Bluetooth host, triggered by a single malformed AT response with no user interaction. The sibling consumer ag_indicator_handle_values() already performed the equivalent bounds check; this commit adds the same index >= ARRAY_SIZE(hf->ind_table) guard to close the gap. Affects builds with CONFIG_BT_HFP_HF enabled; introduced with the original HFP HF CIND parser (~v1.7) and present through v4.4.0.
CVE-2025-60229
CRITICAL
17 Jun 2026
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
CVE-2026-49268
HIGH
17 Jun 2026
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.
CVE-2026-52716
MEDIUM
17 Jun 2026
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
CVE-2026-52707
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
CVE-2026-49108
CRITICAL
17 Jun 2026
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
CVE-2026-40757
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
CVE-2026-40756
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
CVE-2026-40752
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
CVE-2026-40738
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
CVE-2026-40733
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
CVE-2026-40720
HIGH
17 Jun 2026
Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
CVE-2026-39590
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
CVE-2026-39576
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
CVE-2026-39560
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
CVE-2026-39559
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
CVE-2026-39556
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
CVE-2026-39523
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.