CVE Monitor
286267 CVEs found
CVE-2026-39445
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
CVE-2026-39442
HIGH
17 Jun 2026
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
CVE-2025-69175
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
CVE-2025-69174
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Etude <= 1.6 versions.
CVE-2025-69170
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
CVE-2025-69166
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.
CVE-2025-69164
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.
CVE-2025-69158
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Granola <= 1.13 versions.
CVE-2025-69157
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.
CVE-2025-69144
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.
CVE-2025-69140
HIGH
17 Jun 2026
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
CVE-2025-69130
HIGH
17 Jun 2026
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.
CVE-2025-69127
CRITICAL
17 Jun 2026
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
CVE-2025-69126
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.
CVE-2025-69123
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.
CVE-2025-69120
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.
CVE-2025-69115
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.
CVE-2025-69111
CRITICAL
17 Jun 2026
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
CVE-2025-69106
HIGH
17 Jun 2026
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
CVE-2025-68524
HIGH
17 Jun 2026
Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.
CVE-2025-59554
CRITICAL
17 Jun 2026
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
CVE-2025-15657
MEDIUM
17 Jun 2026
Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.
CVE-2026-54193
HIGH
17 Jun 2026
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
CVE-2025-59872
MEDIUM
17 Jun 2026
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
CVE-2026-11975
MEDIUM
17 Jun 2026
Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute arbitrary JavaScript via the ShortContent and FullContent fields, which are stored without HTML sanitization and rendered unencoded via @Html.Raw()