Total CVEs

150,998

Critical Severity

5,040

High Severity

17,683

Last 7 Days

2,039
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,801 - 2,820 of 47,403 CVEs
CVE-2026-2406 MEDIUM - 6.5

Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 1202202...

Published: Jul 22, 2026
Source: NVD
CVE-2026-15787 MEDIUM - 6.4

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible fo...

Vendor: brainstormforce
Product: Ultimate Addons for Elementor
Published: Jul 22, 2026
Source: NVD

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

Vendor: joomlack.fr
Product: Page Builder CK extension for Joomla
Published: Jul 22, 2026
Source: NVD
CVE-2026-63047 HIGH - 7.5

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

Vendor: joomdonation.com
Product: Events Booking extension for Joomla
Published: Jul 22, 2026
Source: NVD

fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-...

Vendor: 101arrowz
Product: fflate
Published: Jul 22, 2026
Source: NVD
CVE-2026-3821 HIGH - 8.8

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue inย X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASHโ€™s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.

Published: Jul 22, 2026
Source: NVD
CVE-2026-14322 MEDIUM - 5.3

The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment.

Vendor: Unknown
Product: Timetics
Published: Jul 22, 2026
Source: NVD
CVE-2026-12987 HIGH - 7.5

The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. Th...

Vendor: Unknown
Product: Events Manager
Published: Jul 22, 2026
Source: NVD
CVE-2026-12968 HIGH - 8.8

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes i...

Vendor: Unknown
Product: Product Addons and Product Options With Custom Fields
Published: Jul 22, 2026
Source: NVD
CVE-2026-15802 HIGH - 8.1

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-le...

Vendor: Chimpstudio
Product: WP Foodbakery
Published: Jul 22, 2026
Source: NVD

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

Vendor: Veeam
Product: Backup and Replication
Published: Jul 22, 2026
Source: NVD
CVE-2026-16492 MEDIUM - 5.5

A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made available to the public and ...

Vendor: umijs
Product: umi
Published: Jul 22, 2026
Source: NVD
CVE-2026-16490 MEDIUM - 6.3

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /prescription.php. The manipulation of the argument editid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and ma...

Vendor: itsourcecode
Product: Hospital Management System
Published: Jul 22, 2026
Source: NVD
CVE-2026-63263 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource ...

Vendor: Elastic
Product: Elasticsearch
Published: Jul 22, 2026
Source: NVD
CVE-2026-63262 MEDIUM - 4.3

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

Vendor: Elastic
Product: Kibana
Published: Jul 22, 2026
Source: NVD
CVE-2026-16489 MEDIUM - 5.3

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local environment. The exploit ...

Product: jsforce
Published: Jul 22, 2026
Source: NVD
CVE-2026-16488 MEDIUM - 5.0

A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high com...

Vendor: QUSETIONS
Product: MiniCode-Python
Published: Jul 22, 2026
Source: NVD
CVE-2026-63261 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailab...

Vendor: Elastic
Product: Kibana
Published: Jul 21, 2026
Source: NVD
CVE-2026-63260 MEDIUM - 6.5

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payload. Processing this...

Vendor: Elastic
Product: Kibana
Published: Jul 21, 2026
Source: NVD
CVE-2026-63259 MEDIUM - 4.3

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

Vendor: Elastic
Product: Kibana
Published: Jul 21, 2026
Source: NVD