Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,081 - 2,100 of 13,055 CVEs
CVE-2026-44490 MEDIUM - 4.8

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the p...

Vendor: npm
Product: axios
Published: May 29, 2026
Source: GitHub

Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` which matches newlines (allowing embedded newlines to pass), TLSA `matchingType=0` has no upper bound on hex data length, and all validators return raw input without zone-file escapin...

Vendor: composer
Product: froxlor/froxlor
Published: May 29, 2026
Source: GitHub
CVE-2026-49325 MEDIUM - 4.6

Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via ...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-49316 MEDIUM - 4.6

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN e...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-47696 MEDIUM - 4.3

WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST parameter. The endpoint contains a TODO for real Authorize.Net charging, hardcodes $paymentSuccess...

Vendor: WWBN
Product: AVideo
Published: May 29, 2026
Source: NVD
CVE-2026-47694 MEDIUM - 5.4

WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScript in a category description, which executes when ...

Vendor: WWBN
Product: AVideo
Published: May 29, 2026
Source: NVD
CVE-2026-10075 MEDIUM - 5.3

DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.

Vendor: Interinfo
Product: DreamMaker
Published: May 29, 2026
Source: NVD
CVE-2026-10074 MEDIUM - 4.9

DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.

Vendor: Interinfo
Product: DreamMaker
Published: May 29, 2026
Source: NVD
CVE-2026-10061 MEDIUM - 6.3

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor explains:...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 29, 2026
Source: NVD
CVE-2026-10060 MEDIUM - 6.3

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the pu...

Vendor: TRENDnet
Product: TEW-432BRP
Published: May 29, 2026
Source: NVD
CVE-2026-49324 MEDIUM - 4.6

Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-vehicle network to permanently immobilize the motorcycle. The WCM enforces a brute-force lockout on the ...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-49323 MEDIUM - 4.3

Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-9811 MEDIUM - 5.4

A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields....

Published: May 29, 2026
Source: NVD
CVE-2026-9557 MEDIUM - 6.4

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP requests from the hosting server, enabling internal network reconnaissance or forcing requests to arbitrar...

Published: May 29, 2026
Source: NVD
CVE-2025-12714 MEDIUM - 5.3

The Rank Math SEO โ€“ AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to mod...

Vendor: rankmath
Product: Rank Math SEO โ€“ AI SEO Tools to Dominate SEO Rankings
Published: May 29, 2026
Source: NVD
CVE-2026-9189 MEDIUM - 5.3

The Contact Form 7 โ€“ PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal wi...

Published: May 29, 2026
Source: NVD
CVE-2026-10058 MEDIUM - 4.8

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

Vendor: ITP Technology
Product: ITS Intelligent SCADA System
Published: May 29, 2026
Source: NVD
CVE-2026-10057 MEDIUM - 4.8

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

Vendor: ITP Technology
Product: ITS Intelligent SCADA System
Published: May 29, 2026
Source: NVD
CVE-2026-10052 MEDIUM - 4.1

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network ...

Vendor: Red Hat
Product: Red Hat Quay 3
Published: May 29, 2026
Source: NVD
CVE-2026-10039 MEDIUM - 4.9

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...

Vendor: shabti
Product: Frontend Admin by DynamiApps
Published: May 29, 2026
Source: NVD