32 vulnerabilities across 15 products scored HIGH or above on June 17, 2026.

  • ๐Ÿ”ด CRITICAL: 1
  • ๐ŸŸ  HIGH: 31

๐Ÿ”ด [CRITICAL] pip/langflow

1 CVE | CVSS 3.1: 9.3 | AAS 12.4

  • cpe:2.3:a:pip:langflow:*:*:*:*:*:*:*:*

Langflow, the open-source AI application builder distributed via pip, is affected by a critical unauthenticated file upload vulnerability (CVE-2026-55450, CVSS 9.3 CRITICAL). The flaw allows remote attackers with nothing more than network access to upload unlimited data to the server without authentication, leading to disk space exhaustion and denial of service. The server response also leaks the absolute file path of uploaded files, which could aid in chaining additional attacks.

Organizations running Langflow instances should treat this as an urgent priority, particularly any deployments exposed to untrusted networks. Review the vendor advisory at the link above, apply any available patches or mitigations, and restrict network access to Langflow endpoints until a fix is confirmed in place.

Vendor Advisory


๐ŸŸ  [HIGH] tinyhumansai/openhuman

1 CVE | CVSS 4.0: 9.4 | AAS 10.8

  • cpe:2.3:a:tinyhumansai:openhuman:*:*:*:*:*:*:*:*

OpenHuman desktop agent versions through 0.54.0 are affected by a high-severity command execution bypass vulnerability (CVE-2026-55743, CVSS 9.4 HIGH). The default Supervised security policy’s shell command allowlist can be circumvented through two combined flaws: incomplete blocking of dangerous find flags such as -execdir and -okdir, and improper handling of environment variable assignments, allowing an attacker to execute arbitrary OS commands with the privileges of the desktop user.

Teams deploying OpenHuman as a desktop AI agent should update immediately to a version that includes the fix referenced in the vendor commit. Until patched, consider restricting shell tool access or switching to a more restrictive security policy to limit exposure.

Vendor Advisory


๐ŸŸ  [HIGH] f5/nginx_open_source

2 CVEs | CVSS 4.0: 9.2 | AAS 10.7

  • cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*

NGINX Open Source and NGINX Plus are affected by 2 vulnerabilities, including at least one rated HIGH (CVSS 9.2), involving the HTTP/2 proxy and gRPC modules. When specific conditions are met, including proxy_http_version set to 2 or grpc_pass in use, ignore_invalid_headers set to off, and large_client_header_buffers sized above 2 megabytes, a remote unauthenticated attacker could exploit these flaws by sending oversized headers during upstream connection establishment.

Organizations running NGINX Open Source prior to 1.31.2 or 1.30.3, or NGINX Plus prior to R37 P2.1 or R36 P6, should prioritize upgrading immediately. Review the F5 advisory at the link above for full details, and audit configurations for the affected directives to assess exposure in the interim.

Vendor Advisory


๐ŸŸ  [HIGH] themeton/lagom

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:themeton:lagom:*:*:*:*:*:*:*:*

The Lagom WordPress theme by Themeton, versions through 2.0, is affected by a critical PHP object injection vulnerability due to deserialization of untrusted data (CVE-2025-60229, CVSS 9.8 HIGH). An attacker could exploit this flaw to inject arbitrary objects, potentially leading to remote code execution, data exfiltration, or full site compromise depending on available gadget chains within the application environment.

WordPress administrators using the Lagom theme should check for an updated version from Themeton immediately and apply it as soon as available. Review the Patchstack advisory at the link above for additional mitigation guidance, and consider disabling the theme in favor of an alternative if no patch is yet available.

Vendor Advisory


๐ŸŸ  [HIGH] loginpress/loginpress_pro

1 CVE | CVSS 3.1: 9.8 | AAS 10.6

  • cpe:2.3:a:loginpress:loginpress_pro:*:*:*:*:*:*:*:* (< 6.2.3)

LoginPress Pro, a commercial WordPress login page customization plugin, versions through 6.2.2 are affected by an unauthenticated privilege escalation vulnerability (CVE-2026-49058, CVSS 9.8 HIGH). This flaw allows a remote attacker with no prior authentication to elevate privileges, potentially gaining full administrative access to the WordPress site.

Any organization running LoginPress Pro should update beyond version 6.2.2 immediately or deactivate the plugin until a patched version is available. Review the Patchstack advisory at the link above for further details and assess affected sites for signs of unauthorized account creation or privilege changes.

Vendor Advisory


๐ŸŸ  [HIGH] pip/open-webui

6 CVEs | CVSS 3.1: 8.7 | AAS 10.5

  • cpe:2.3:a:pip:open-webui:*:*:*:*:*:*:*:* (< 0.6.7)

Open WebUI, the popular self-hosted web interface for LLMs, is affected by 6 vulnerabilities, including multiple rated HIGH (CVSS up to 8.7). The lead vulnerability involves a stored cross-site scripting flaw where Mermaid diagram blocks rendered with a loose security level allow attacker-controlled JavaScript execution in a victim’s browser under the application origin, enabling session hijacking, data theft, or further compromise.

Organizations running Open WebUI should review the vendor advisories on GitHub and update to a patched version as soon as one is available. Given the number of issues disclosed and the stored nature of the XSS flaw, teams should also audit existing uploaded Markdown files and restrict access to untrusted users in the interim.

Vendor Advisory


๐ŸŸ  [HIGH] google/android

11 CVEs | CVSS 4.0: 10.0 | AAS 10.4

  • cpe:2.3:a:google:android:*:*:*:*:*:*:*:*

Google Android 17 is affected by 11 vulnerabilities, including at least one rated CRITICAL (CVSS 10.0). The most severe is a use-after-free race condition in the NFC stack that enables local privilege escalation without user interaction or additional execution privileges, and multiple additional flaws span other Android components.

Enterprise mobility and MDM teams managing Android 17 devices should apply the latest Android security bulletin patches immediately. Review the full advisory at the link above for component-level detail, and prioritize devices with NFC enabled given the zero-interaction exploitation path of the lead vulnerability.

Vendor Advisory


๐ŸŸ  [HIGH] extendons/wordpress_&_woocommerce_scraper_plugin,_import_data_from_any_site

1 CVE | CVSS 3.1: 10.0 | AAS 10.3

  • cpe:2.3:a:extendons:wordpress_woocommerce_scraper_plugin_import_data_from_any_site:*:*:*:*:*:*:*:* (< 1.0.8)

The WordPress & WooCommerce Scraper Plugin (Import Data from Any Site) by Extendons, versions through 1.0.7, is affected by an unauthenticated arbitrary file upload vulnerability (CVE-2025-69129, CVSS 10.0 HIGH). This flaw allows a remote attacker with no authentication to upload arbitrary files, including web shells, directly to the server, enabling full site and potentially full server compromise.

Any WordPress site running this plugin should deactivate and remove it immediately until a patched version is confirmed available from the vendor. Review the Patchstack advisory at the link above, inspect affected servers for signs of unauthorized file uploads or web shells, and consider a full integrity check of the WordPress installation.

Vendor Advisory


๐ŸŸ  [HIGH] tips_and_tricks_hq/wp_emember

1 CVE | CVSS 3.1: 9.3 | AAS 10.3

  • cpe:2.3:a:tips_and_tricks_hq:wp_emember:*:*:*:*:*:*:*:* (< 10.9.4)

WP eMember, a WordPress membership management plugin by Tips and Tricks HQ, versions prior to 10.9.4 are affected by an unauthenticated SQL injection vulnerability (CVE-2026-54811, CVSS 9.3 HIGH). This flaw allows a remote attacker with no authentication to execute arbitrary SQL queries against the WordPress database, potentially extracting sensitive user data, credentials, or gaining full control of the site.

WordPress administrators running WP eMember should update to version 10.9.4 or later immediately. Review the Patchstack advisory at the link above for additional details, and audit database logs and user accounts on affected sites for any signs of unauthorized access or data exfiltration.

Vendor Advisory


๐ŸŸ  [HIGH] creative_themes/blocksy_companion_pro

2 CVEs | CVSS 3.1: 9.9 | AAS 10.2

  • cpe:2.3:a:creative_themes:blocksy_companion_pro:*:*:*:*:*:*:*:* (< 2.1.38)
  • cpe:2.3:a:creative_themes:blocksy_companion_pro:*:*:*:*:*:*:*:* (< 2.1.29)

Blocksy Companion Pro, a premium WordPress plugin by Creative Themes, versions through 2.1.37 are affected by 2 vulnerabilities, including at least one rated HIGH (CVSS 9.9). The most severe flaw allows a user with as little as Contributor-level access to achieve remote code execution on the server, enabling full site and potentially full server compromise.

WordPress administrators using Blocksy Companion Pro should update beyond version 2.1.37 immediately or deactivate the plugin until a patch is available. Review the Patchstack advisory at the link above for details on both vulnerabilities, and audit contributor-level accounts on affected sites for any signs of unauthorized activity.

Vendor Advisory


๐ŸŸ  [HIGH] studio_keren_aga_ltd./unlimited_elements_for_elementor_(premium)

1 CVE | CVSS 3.1: 9.9 | AAS 10.2

  • cpe:2.3:a:studio_keren_aga:unlimited_elements_for_elementor_premium:*:*:*:*:*:*:*:* (< 2.0.7)

Unlimited Elements for Elementor (Premium) by Studio Keren Aga Ltd., versions through 2.0.6, is affected by an arbitrary file upload vulnerability exploitable by users with Contributor-level access (CVE-2026-27041, CVSS 9.9 HIGH). This flaw allows a low-privileged authenticated attacker to upload arbitrary files, including malicious PHP scripts or web shells, leading to full site and potentially full server compromise.

WordPress administrators running this plugin should update beyond version 2.0.6 immediately or deactivate it until a patched version is available. Review the Patchstack advisory at the link above, audit contributor-level user accounts for suspicious activity, and inspect the server for any unauthorized file uploads.

Vendor Advisory


๐ŸŸ  [HIGH] dassault_systรจmes/solidworks_visualize

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:dassault_syst_mes:solidworks_visualize:*:*:*:*:*:*:*:* (>= 2024)

SOLIDWORKS Visualize by Dassault Systรจmes, spanning Desktop Releases 2024 through 2026, is affected by a path traversal vulnerability that allows an attacker to write arbitrary files on the server (CVE-2026-10094, CVSS 9.8 HIGH). Arbitrary file write of this nature can lead to remote code execution, configuration tampering, or full system compromise depending on the deployment environment.

Organizations running SOLIDWORKS Visualize should update to patched service pack levels immediately: Release 2024 beyond SP5, Release 2025 beyond SP5, or Release 2026 beyond SP2.1. Review the Dassault Systรจmes security advisory at the link above for full remediation details, and assess affected systems for any signs of unauthorized file modifications.

Vendor Advisory


๐ŸŸ  [HIGH] emv/creatify

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:emv:creatify:*:*:*:*:*:*:*:* (< 1.5)

The Creatify WordPress theme by EMV, versions through 1.5, is affected by a PHP object injection vulnerability due to deserialization of untrusted data (CVE-2025-60236, CVSS 9.8 HIGH). Depending on available gadget chains within the WordPress environment, an attacker could exploit this flaw to achieve remote code execution, access sensitive data, or fully compromise the site.

WordPress administrators using the Creatify theme should check for an updated version immediately and apply it as soon as available. Review the Patchstack advisory at the link above for additional guidance, and consider switching to an alternative theme if no patch has been released.

Vendor Advisory


๐ŸŸ  [HIGH] emv/the_hospital

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:emv:the_hospital:*:*:*:*:*:*:*:* (< 1.8.1)

The Hospital (nrghospital) WordPress theme by EMV, versions through 1.8.1, is affected by a PHP object injection vulnerability due to deserialization of untrusted data (CVE-2025-60231, CVSS 9.8 HIGH). An attacker could exploit this flaw to inject arbitrary objects, potentially leading to remote code execution, data exfiltration, or full site compromise depending on available gadget chains in the WordPress environment.

WordPress administrators using The Hospital theme should check for a patched version from the vendor immediately and apply it as soon as available. Review the Patchstack advisory at the link above for further details, and consider deactivating the theme in favor of an alternative if no fix has been released.

Vendor Advisory


๐ŸŸ  [HIGH] themeton/the_barber_shop

1 CVE | CVSS 3.1: 9.8 | AAS 10.1

  • cpe:2.3:a:themeton:the_barber_shop:*:*:*:*:*:*:*:* (< 1.9)

The Barber Shop WordPress theme by Themeton, versions through 1.9, is affected by a PHP object injection vulnerability caused by deserialization of untrusted data (CVE-2025-60230, CVSS 9.8 HIGH). Exploitation could allow an attacker to inject arbitrary objects into the application, potentially leading to remote code execution, data theft, or full site compromise depending on the gadget chains available in the WordPress installation.

WordPress administrators using The Barber Shop theme should check for an updated version from Themeton and apply it immediately. Review the Patchstack advisory at the link above for additional guidance, and consider switching to an alternative theme if no patch is currently available.

Vendor Advisory