2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-69106 — File: Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69106

Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 14:17Z
HIGH

CVE-2025-66391 — Citrix: In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-66391

In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account. CVSSv3.1 8.8 (HIGH)

VNDCitrixTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2025-60236 — Deserialization: of Untrusted Data vulnerability in EMV Creatify allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-60236

Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2025-60231 — Deserialization: of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-60231

Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2025-60230 — Deserialization: of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-60230

Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2025-60229 — Deserialization: of Untrusted Data vulnerability in Themeton Lagom allows Object Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-60229

Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 14:17Z
CRIT

CVE-2025-59554 — SQL: Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-59554

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 13:45Z
MED

BloodHound CE v9.3.0

BloodHound releases·github.comCVE-2026-46625CVE-2026-44705

BloodHound CE v9.3.0 released with 60+ commits including bug fixes for two CVEs (CVE-2026-46625, CVE-2026-44705), dependency updates (Go 1.26.4, axios, DAWGS 0.5.5), new features (alerts system, privilege zone metrics, findings endpoint enhancements), and accessibility improvements. Notable changes include ADCS post-processing optimizations, embedded extensions preparation, and JIT Teleport configuration support.

SRFApplicationSWBloodhoundVNDSpecteropsTYPTool
42
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-54811 — SQL: Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54811

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-54807 — Privilege: Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54807

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-54806 — PHP: Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54806

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-54805 — Subscriber: Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54805

Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-54803 — Subscriber: Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54803

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 863VNDSubscriberTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-54194 — Contributor: PHP Object Injection in Fusion Builder <= 3.15.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54194

Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDContributorTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-54187 — SQL: Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54187

Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-54186 — SQL: Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54186

Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-54185 — Subscriber: SQL Injection in Cornerstone < 7.8.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54185

Subscriber SQL Injection in Cornerstone < 7.8.8 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-54184 — Direct: Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54184

Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. CVSSv3.1 8.2 (HIGH)

CWECWE 639VNDDirectTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-52706 — PHP: Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52706

Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-52705 — Arbitrary: Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52705

Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. CVSSv3.1 9.0 (CRITICAL)

CWECWE 434VNDArbitraryTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-50203 — SFTP: A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50203

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDSftpTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49767 — Broken: Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49767

Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288VNDBrokenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-49113 — Subscriber: Arbitrary Code Execution in Cornerstone < 7.8.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49113

Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 94VNDSubscriberTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49107 — PHP: Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49107

Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-49084 — SQL: Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49084

Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score