Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,978
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,221 - 2,240 of 12,388 CVEs
CVE-2026-10073 HIGH - 7.5

DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.

Vendor: Interinfo
Product: DreamMaker
Published: May 29, 2026
Source: NVD
CVE-2026-10072 HIGH - 7.2

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Vendor: Interinfo
Product: DreamMaker
Published: May 29, 2026
Source: NVD
CVE-2026-48527 HIGH - 8.7

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by in...

Vendor: haxtheweb
Product: haxcms-nodejs, haxcms-php
Published: May 29, 2026
Source: NVD
CVE-2026-9809 HIGH - 7.6

A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user ...

Published: May 29, 2026
Source: NVD
CVE-2026-9808 HIGH - 7.1

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass own...

Published: May 29, 2026
Source: NVD
CVE-2025-41281 HIGH - 7.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL conne...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41280 HIGH - 7.8

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41279 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41278 HIGH - 7.8

Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41271 HIGH - 7.5

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41267 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41266 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41265 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2026-46579 HIGH - 7.4

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a ...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: May 29, 2026
Source: NVD
CVE-2026-42965 HIGH - 7.7

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metada...

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: May 29, 2026
Source: NVD
CVE-2026-6075 HIGH - 8.1

The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an adm...

Published: May 29, 2026
Source: NVD
CVE-2026-10056 HIGH - 7.5

CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeove...

Vendor: Network Optix
Product: Nx Witness VMS
Published: May 29, 2026
Source: NVD
CVE-2026-4776 HIGH - 7.1

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.

Published: May 29, 2026
Source: NVD
CVE-2025-11262 HIGH - 7.2

The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Vendor: linkwhspr
Product: Link Whisper Free
Published: May 29, 2026
Source: NVD
CVE-2025-11993 HIGH - 8.8

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via t...

Vendor: sbthemes
Product: WooCommerce Infinite Scroll and Ajax Pagination
Published: May 29, 2026
Source: NVD