Total CVEs

132,098

Critical Severity

2,824

High Severity

10,104

Last 7 Days

1,584
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,221 - 2,240 of 28,503 CVEs
CVE-2018-25325 HIGH - 7.5

Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename paramete...

Vendor: woocommerce-csvimport
Product: WooCommerce CSV-Importer
Published: May 17, 2026
Source: NVD
CVE-2018-25324 MEDIUM - 6.2

Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspath values to simple_...

Vendor: Simple-Fields
Product: Simple Fields
Published: May 17, 2026
Source: NVD
CVE-2018-25323 HIGH - 8.4

Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH cha...

Vendor: Alloksoft
Product: Allok AVI DivX MPEG to DVD Converter
Published: May 17, 2026
Source: NVD
CVE-2018-25322 HIGH - 8.4

Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk data followed by structured shellcode and place it in the Lic...

Vendor: alloksoft
Product: Fast AVI MPEG Splitter
Published: May 17, 2026
Source: NVD
CVE-2018-25321 MEDIUM - 4.3

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via Wlan...

Vendor: Tp-link
Product: TL-WR720NMbps Wireless N Router
Published: May 17, 2026
Source: NVD
CVE-2018-25320 CRITICAL - 9.8

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to est...

Vendor: acl
Product: ACL Analytics
Published: May 17, 2026
Source: NVD
CVE-2018-25319 HIGH - 7.1

Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Attackers can send GET requests to the event_add.php page with malicious myevents_id values to extract o...

Vendor: wende60
Product: Redaxo CMS Addon MyEvents
Published: May 17, 2026
Source: NVD
CVE-2026-8752 MEDIUM - 5.3

A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to improper access contro...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8751 HIGH - 7.3

A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The expl...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8750 MEDIUM - 5.3

A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be executed remotely. The e...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8747 MEDIUM - 6.3

A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been made...

Published: May 17, 2026
Source: NVD
CVE-2026-8746 MEDIUM - 4.3

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF. The manipulation results in use after free. The attack can be launched remotely. The exploit has been released to the pub...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8745 MEDIUM - 4.3

A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit is publicly available and...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8744 MEDIUM - 4.3

A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing a manipulation can lead to denial of service. It is possible to launch the attack remotely. The explo...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8743 MEDIUM - 6.3

A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit has been made pub...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8741 LOW - 3.1

A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH Packet Handler. Such manipulation leads to race condition. The attack may be performed from remote. A high complexity level is ...

Vendor: emqx
Product: emqx
Published: May 17, 2026
Source: NVD
CVE-2026-8740 MEDIUM - 6.3

A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes ...

Published: May 17, 2026
Source: NVD
CVE-2026-8739 MEDIUM - 5.3

A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptogr...

Published: May 17, 2026
Source: NVD
CVE-2026-8738 MEDIUM - 6.5

A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component...

Published: May 17, 2026
Source: NVD
CVE-2026-8737 MEDIUM - 5.3

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument ...

Published: May 17, 2026
Source: NVD