CVE Find is a real-time vulnerability database indexing 357 887 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1735 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-9862 |
2026-06-15 16h16 +00:00 |
Fortra's
Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in ... OS Command Injection |
9.8 |
Critical |
|
CVE-2026-5242 |
2026-06-15 14h16 +00:00 |
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy... |
8.8 |
High |
|
CVE-2026-52704 |
2026-06-15 14h16 +00:00 |
Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce P... Code Injection |
10 |
Critical |
|
CVE-2026-49111 |
2026-06-15 14h16 +00:00 |
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalati... Improper Privilege Management |
8.8 |
High |
|
CVE-2026-49062 |
2026-06-15 14h16 +00:00 |
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows ... |
8.8 |
High |
|
CVE-2018-25436 |
2026-06-15 14h16 +00:00 |
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulne... File Inclusion |
9.8 |
Critical |
|
CVE-2016-20075 |
2026-06-15 14h16 +00:00 |
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows... Authorization problems |
8.8 |
High |
|
CVE-2016-20073 |
2026-06-15 14h16 +00:00 |
Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unau... SQL Injection |
8.2 |
High |
|
CVE-2016-20072 |
2026-06-15 14h16 +00:00 |
BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unaut... SQL Injection |
8.2 |
High |
|
CVE-2016-20071 |
2026-06-15 14h16 +00:00 |
The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injecti... SQL Injection |
8.2 |
High |