Total CVEs

149,824

Critical Severity

4,834

High Severity

17,268

Last 7 Days

2,960
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 61 - 80 of 46,229 CVEs
CVE-2026-16462 CRITICAL - 9.8

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

Vendor: Weidmueller Interface
Product: PROCON-WEB SCADA
Published: Jul 28, 2026
Source: NVD
CVE-2026-14785 HIGH - 7.5

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

Vendor: mihail-chepovskiy
Product: Web Directory Free
Published: Jul 28, 2026
Source: NVD
CVE-2026-14328 HIGH - 8.8

The Eazy Plugin Manager โ€“ Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that...

Vendor: eazyplugins
Product: Eazy Plugin Manager โ€“ Powerful Plugin Management Solution for WordPress
Published: Jul 28, 2026
Source: NVD
CVE-2026-11841 CRITICAL - 9.4

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without ...

Vendor: SICK AG
Product: InspectorP61x, InspectorP62x, InspectorP65x, InspectorP63x, InspectorP64x
Published: Jul 28, 2026
Source: NVD
CVE-2026-11598 MEDIUM - 5.0

The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...

Vendor: lrnz
Product: Shortcodify
Published: Jul 28, 2026
Source: NVD
CVE-2026-10207 HIGH - 7.5

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which re...

Vendor: pickplugins
Product: PickPlugins Question Answer
Published: Jul 28, 2026
Source: NVD
CVE-2026-9680 MEDIUM - 5.8

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

Published: Jul 28, 2026
Source: NVD
CVE-2026-8167 MEDIUM - 6.1

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026.

Published: Jul 28, 2026
Source: NVD
CVE-2026-61376 HIGH - 7.2

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Vendor: ELECOM CO.,LTD.
Product: WAB-M1775-PS, WAB-S1775, WAB-M2133, WAB-I1750-PS, WAB-S1167-PS
Published: Jul 28, 2026
Source: NVD
CVE-2026-59764 HIGH - 7.2

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Vendor: ELECOM CO.,LTD.
Product: WRC-X3000GS3-B, WRC-X3000GS3A-B
Published: Jul 28, 2026
Source: NVD
CVE-2026-44387 MEDIUM - 5.2

ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Vendor: ELECOM CO.,LTD.
Product: WAB-M1775-PS, WAB-S1775, WAB-M2133, WAB-I1750-PS, WAB-S1167-PS
Published: Jul 28, 2026
Source: NVD
CVE-2026-15267 MEDIUM - 6.5

The Taskbuilder โ€“ Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the la...

Vendor: taskbuilder
Product: Taskbuilder โ€“ Project Management & Task Management Tool With Kanban Board
Published: Jul 28, 2026
Source: NVD
CVE-2026-14516 HIGH - 7.5

The Online Scheduling and Appointment Booking System โ€“ Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati...

Vendor: ladela
Product: Online Scheduling and Appointment Booking System โ€“ Bookly
Published: Jul 28, 2026
Source: NVD
CVE-2026-14171 MEDIUM - 6.1

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

Vendor: ads-tec Industrial IT
Product: DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
Published: Jul 28, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jul 28, 2026
Source: NVD
CVE-2026-14169 HIGH - 8.1

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

Vendor: ads-tec Industrial IT
Product: DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
Published: Jul 28, 2026
Source: NVD
CVE-2026-14168 HIGH - 8.8

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

Vendor: ads-tec Industrial IT
Product: DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
Published: Jul 28, 2026
Source: NVD
CVE-2026-14167 HIGH - 8.8

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

Vendor: ads-tec Industrial IT
Product: DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
Published: Jul 28, 2026
Source: NVD
CVE-2026-13161 HIGH - 7.5

The TrueBooker โ€“ Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient ...

Vendor: themetechmount
Product: TrueBooker โ€“ Appointment Booking and Scheduler System
Published: Jul 28, 2026
Source: NVD
CVE-2026-12800 HIGH - 7.5

The Premium Packages โ€“ Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the user-supplied...

Vendor: codename065
Product: Premium Packages โ€“ Sell Digital Products Securely
Published: Jul 28, 2026
Source: NVD