Total CVEs

150,798

Critical Severity

4,991

High Severity

17,614

Last 7 Days

2,037
Quick preset (or use dates below)
Clear Filters
Showing 1,961 - 1,980 of 150,798 CVEs
CVE-2026-15401 HIGH - 7.2

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attac...

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: Jul 24, 2026
Source: NVD
CVE-2026-10033 HIGH - 7.3

The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON mana...

Vendor: EventON
Product: EventON Action User
Published: Jul 24, 2026
Source: NVD
CVE-2026-63317 MEDIUM - 5.6

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its fully-qualified name via Class.forName() and invoke its no-arg construct...

Vendor: Apache Software Foundation
Product: Apache OpenNLP
Published: Jul 24, 2026
Source: NVD

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted in...

Vendor: GNU
Product: coreutils
Published: Jul 24, 2026
Source: NVD

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, re...

Vendor: GNU
Product: coreutils
Published: Jul 24, 2026
Source: NVD
CVE-2026-49745 HIGH - 7.8

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jul 24, 2026
Source: NVD
CVE-2026-49744 HIGH - 7.8

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes v...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jul 24, 2026
Source: NVD
CVE-2026-49743 HIGH - 7.8

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlyin...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jul 24, 2026
Source: NVD

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containi...

Vendor: SUNNET Technology Co., Ltd.
Product: Corporate Training Management System
Published: Jul 24, 2026
Source: NVD
CVE-2026-15821 MEDIUM - 6.4

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

Vendor: brainstormforce
Product: SureDash – Community, Courses & Member Dashboard
Published: Jul 24, 2026
Source: NVD
CVE-2026-15739 MEDIUM - 6.4

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

Vendor: widgetpack
Product: Rich Showcase for Google Reviews
Published: Jul 24, 2026
Source: NVD
CVE-2026-15704 CRITICAL - 9.8

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSl...

Vendor: Eclipse Foundation
Product: Eclipse BaSyx Go Components
Published: Jul 24, 2026
Source: NVD
CVE-2026-15346 MEDIUM - 6.1

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthentic...

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: Jul 24, 2026
Source: NVD

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

Vendor: Octopus Deploy
Product: Octopus Server
Published: Jul 24, 2026
Source: NVD
CVE-2026-16910 MEDIUM - 5.5

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastr...

Vendor: Red Hat
Product: Red Hat OpenShift Update Service, Red Hat Quay 3
Published: Jul 24, 2026
Source: NVD
CVE-2026-16519 HIGH - 7.3

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location...

Vendor: GeoVision Inc.
Product: GV-IP Device Utility
Published: Jul 24, 2026
Source: NVD
CVE-2026-15755 MEDIUM - 6.4

The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.4.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with co...

Vendor: 100plugins
Product: Open User Map – Interactive Leaflet Maps
Published: Jul 24, 2026
Source: NVD
CVE-2026-15665 MEDIUM - 6.4

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it p...

Vendor: wpmanageninja
Product: Fluent Support – Helpdesk & Customer Support Ticket System
Published: Jul 24, 2026
Source: NVD
CVE-2026-15653 MEDIUM - 6.4

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it ...

Vendor: themeisle
Product: Visualizer – Tables & Charts Manager with Built-in AI Generator
Published: Jul 24, 2026
Source: NVD
CVE-2026-15648 MEDIUM - 6.4

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with cont...

Vendor: berocket
Product: Brands for WooCommerce
Published: Jul 24, 2026
Source: NVD