Total CVEs

132,015

Critical Severity

2,817

High Severity

10,081

Last 7 Days

1,551
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,241 - 2,260 of 28,420 CVEs
CVE-2026-45008 MEDIUM - 6.5

phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../<path> in the client URL parameter to recursively delet...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-45007 MEDIUM - 4.3

phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authenticated user can enumerate system configuration metadata including permission model, cache backend, mail...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-44826 HIGH - 7.5

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-add endpoint. Submitting a negative integer is accepted by the server and treated as a normal positive ...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, collaborators.list, tables.metadata.list, explorations.list, and forms.list accept a database_id without verifying that the requesting user was a collaborator on that dat...

Vendor: mathesar-foundation
Product: mathesar
Published: May 15, 2026
Source: NVD

Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, explorations.replace, and explorations.delete operate on an exploration_id without verifying that the requesting user was a collaborator on the explorat...

Vendor: mathesar-foundation
Product: mathesar
Published: May 15, 2026
Source: NVD
CVE-2026-44366 MEDIUM - 6.1

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Vvveb CMS comment submission flow. The author field is submitted by an unauthenticated user on any public post pag...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2021-47968 MEDIUM - 6.4

Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to ...

Vendor: Podcastgenerator
Product: Podcast Generator
Published: May 15, 2026
Source: NVD
CVE-2021-47967 MEDIUM - 6.1

PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers can append malicious payloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, or i...

Vendor: Timeclock
Product: PHP Timeclock
Published: May 15, 2026
Source: NVD
CVE-2021-47966 HIGH - 8.2

PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database contents. Attackers can submit crafted POST requests with SQL payloads using SLEEP functions or RLIKE cond...

Vendor: Timeclock
Product: PHP Timeclock
Published: May 15, 2026
Source: NVD
CVE-2021-47965 CRITICAL - 9.8

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code ...

Vendor: wp-super-edit
Product: WP Super Edit
Published: May 15, 2026
Source: NVD
CVE-2021-47964 HIGH - 8.8

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the packageinfo.inc file and trigger...

Vendor: Schlix
Product: Schlix CMS
Published: May 15, 2026
Source: NVD
CVE-2021-47963 HIGH - 7.2

Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by injecting malicious payloads into markdown files stored within the application. Attackers can craft malicious markdown files with embedded JavaScript that executes system commands wh...

Vendor: AnotherNote
Product: Anote
Published: May 15, 2026
Source: NVD
CVE-2021-47962 MEDIUM - 6.4

Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to inject malicious HTML and JavaScript code. Attackers can inject script payloads into user profile fields at the edit_user endpoint, which execute in the ...

Vendor: savsofts
Product: Savsoft Quiz
Published: May 15, 2026
Source: NVD
CVE-2021-47959 HIGH - 7.5

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads ...

Vendor: Wpgraphql
Product: WPGraphQL
Published: May 15, 2026
Source: NVD
CVE-2021-47958 MEDIUM - 4.3

CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services a...

Vendor: CouchCMS
Product: CouchCMS
Published: May 15, 2026
Source: NVD
CVE-2026-45619 MEDIUM - 6.5

AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45610 MEDIUM - 5.7

AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45580 MEDIUM - 5.4

AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45578 HIGH - 8.8

AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45575 HIGH - 7.4

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri...

Vendor: maven
Product: com.oviva.telematik:epa4all-client
Published: May 15, 2026
Source: GitHub