Total CVEs

149,767

Critical Severity

4,827

High Severity

17,254

Last 7 Days

2,925
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 149,767 CVEs

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of distinct header names in ...

Vendor: ninenines
Product: cowboy
Published: Jul 28, 2026
Source: NVD

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK prefixed-integer decoder cow_hpack_common:dec_big_int/3 in src/co...

Vendor: ninenines
Product: cowlib
Published: Jul 28, 2026
Source: NVD
CVE-2026-58246 MEDIUM - 4.3

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate us...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server for ABAP
Published: Jul 28, 2026
Source: NVD
CVE-2026-16462 CRITICAL - 9.8

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

Vendor: Weidmueller Interface
Product: PROCON-WEB SCADA
Published: Jul 28, 2026
Source: NVD
CVE-2026-14785 HIGH - 7.5

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

Vendor: mihail-chepovskiy
Product: Web Directory Free
Published: Jul 28, 2026
Source: NVD
CVE-2026-14328 HIGH - 8.8

The Eazy Plugin Manager โ€“ Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that...

Vendor: eazyplugins
Product: Eazy Plugin Manager โ€“ Powerful Plugin Management Solution for WordPress
Published: Jul 28, 2026
Source: NVD
CVE-2026-11841 CRITICAL - 9.4

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without ...

Vendor: SICK AG
Product: InspectorP61x, InspectorP62x, InspectorP65x, InspectorP63x, InspectorP64x
Published: Jul 28, 2026
Source: NVD
CVE-2026-11598 MEDIUM - 5.0

The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...

Vendor: lrnz
Product: Shortcodify
Published: Jul 28, 2026
Source: NVD
CVE-2026-10207 HIGH - 7.5

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which re...

Vendor: pickplugins
Product: PickPlugins Question Answer
Published: Jul 28, 2026
Source: NVD
CVE-2026-9680 MEDIUM - 5.8

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

Published: Jul 28, 2026
Source: NVD
CVE-2026-8167 MEDIUM - 6.1

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026.

Published: Jul 28, 2026
Source: NVD
CVE-2026-61376 HIGH - 7.2

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Vendor: ELECOM CO.,LTD.
Product: WAB-M1775-PS, WAB-S1775, WAB-M2133, WAB-I1750-PS, WAB-S1167-PS
Published: Jul 28, 2026
Source: NVD
CVE-2026-59764 HIGH - 7.2

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Vendor: ELECOM CO.,LTD.
Product: WRC-X3000GS3-B, WRC-X3000GS3A-B
Published: Jul 28, 2026
Source: NVD
CVE-2026-44387 MEDIUM - 5.2

ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Vendor: ELECOM CO.,LTD.
Product: WAB-M1775-PS, WAB-S1775, WAB-M2133, WAB-I1750-PS, WAB-S1167-PS
Published: Jul 28, 2026
Source: NVD
CVE-2026-15267 MEDIUM - 6.5

The Taskbuilder โ€“ Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions up to, and including, 5.0.9. This is due to insufficient escaping on the user-supplied parameter and the la...

Vendor: taskbuilder
Product: Taskbuilder โ€“ Project Management & Task Management Tool With Kanban Board
Published: Jul 28, 2026
Source: NVD
CVE-2026-14516 HIGH - 7.5

The Online Scheduling and Appointment Booking System โ€“ Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati...

Vendor: ladela
Product: Online Scheduling and Appointment Booking System โ€“ Bookly
Published: Jul 28, 2026
Source: NVD
CVE-2026-14171 MEDIUM - 6.1

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

Vendor: ads-tec Industrial IT
Product: DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
Published: Jul 28, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jul 28, 2026
Source: NVD
CVE-2026-14169 HIGH - 8.1

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

Vendor: ads-tec Industrial IT
Product: DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
Published: Jul 28, 2026
Source: NVD
CVE-2026-14168 HIGH - 8.8

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

Vendor: ads-tec Industrial IT
Product: DVG-IRF1401, DVG-IRF1421, DVG-IRF3401, DVG-IRF3421, DVG-IRF3801, DVG-IRF3821
Published: Jul 28, 2026
Source: NVD