Critical · CVSS 9.8
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection.
This issue affects Creatify: from n/a through 1.5.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 7.5
Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
Critical · CVSS 9.8
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Nexio <= 1.10.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Iona <= 1.0.8 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Corbesier <= 1.15.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Deliciosa <= 1.10.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
Critical · CVSS 9.8
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Especio <= 1.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Food Drop <= 1.3 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 7.5
Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Wanium <= 1.9.8 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
Medium · CVSS 6.5
Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.6
Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Kelly Young <= 1.1.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Abelle <= 1.22 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Mission <= 1.22 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Dom <= 1.24 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Putter <= 1.17 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Top Dog <= 1.0.5 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Medeus <= 1.14 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Printo <= 1.11 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Gita <= 1.11 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Grecko <= 5.17 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in WineShop <= 3.17 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Choreo <= 1.6 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Eros <= 1.3 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Spike <= 1.2 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in ITactics <= 1.0 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Roneous <= 2.1.5 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Truemag <= 4.3.14.2 versions.
Published Jun 16, 2026 · Updated Jun 17, 2026
Medium · CVSS 4.3
In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Resurs <= 1.3 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.1
Unauthenticated Local File Inclusion in Quirky <= 1.23 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026
High · CVSS 8.8
Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.
Published Jun 17, 2026 · Updated Jun 17, 2026