Total
330 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-57664 | 2026-06-26 | N/A | 4.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions. | |||||
| CVE-2026-57633 | 2026-06-26 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions. | |||||
| CVE-2026-56060 | 2026-06-26 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | |||||
| CVE-2026-54824 | 2026-06-26 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions. | |||||
| CVE-2026-9307 | 2026-06-17 | N/A | N/A | ||
| A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service. | |||||
| CVE-2026-7864 | 2026-06-17 | N/A | N/A | ||
| SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information. | |||||
| CVE-2026-52694 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. | |||||
| CVE-2026-49077 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2. | |||||
| CVE-2026-49068 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions. | |||||
| CVE-2026-49066 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions. | |||||
| CVE-2026-49056 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions. | |||||
| CVE-2026-48878 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions. | |||||
| CVE-2026-44749 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected. | |||||
| CVE-2026-44743 | 2026-06-17 | N/A | 3.7 LOW | ||
| Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application leaks sensitive information .This has a low impact on the confidentiality of the data. There is no impact on integrity and availability of the application. | |||||
| CVE-2026-43654 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2026-06-17 | N/A | 7.5 HIGH |
| The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory. | |||||
| CVE-2026-42660 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. | |||||
| CVE-2026-42644 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10. | |||||
| CVE-2026-42047 | 1 Inngest | 1 Inngest | 2026-06-17 | N/A | 8.6 HIGH |
| Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serve() HTTP handler. The serve() handler implements GET, POST, and PUT methods. Requests using PATCH, OPTIONS, or DELETE fall through to a generic handler that returns diagnostic information. A change introduced in v3.22.0 caused this diagnostic response to include the contents of process.env, exposing any secrets, API keys, or credentials present in the environment. An application is vulnerable if its serve() endpoint is reachable via PATCH, OPTIONS, or DELETE requests, which is common in setups like Next.js Pages Router or Express's app.use(...). Not affected are Next.js App Router handlers that export only GET, POST, and PUT, and applications using the connect worker method. This issue has been fixed in version 3.54.0. To work around this issue if upgrading is not immediately possible, restrict the serve() endpoint at the framework or reverse-proxy layer to accept only GET, POST, and PUT. The Inngest serve() endpoint does not require any other HTTP methods. | |||||
| CVE-2026-41339 | 1 Openclaw | 1 Openclaw | 2026-06-17 | N/A | 4.3 MEDIUM |
| OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin authenticated clients. Non-admin clients can recover host-specific filesystem paths and deployment details, enabling host fingerprinting and facilitating chained attacks. | |||||
| CVE-2026-41335 | 1 Openclaw | 1 Openclaw | 2026-06-17 | N/A | 5.3 MEDIUM |
| OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that exposes version and assistant agent identifiers. Attackers can extract sensitive fingerprinting information from the Control UI bootstrap payload to identify system versions and agent configurations. | |||||
