Total CVEs

132,098

Critical Severity

2,824

High Severity

10,104

Last 7 Days

1,584
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,261 - 2,280 of 28,503 CVEs
CVE-2021-47975 HIGH - 7.2

WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbit...

Vendor: Wplearnmanager
Product: WP Learn Manager
Published: May 16, 2026
Source: NVD
CVE-2021-47974 HIGH - 7.8

VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories like C:\Program Files\VX Search to execute arbitrary...

Vendor: Vxsearch
Product: VX Search
Published: May 16, 2026
Source: NVD
CVE-2021-47973 HIGH - 7.5

Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an ...

Vendor: sticky-notes
Product: Sticky Notes Widget
Published: May 16, 2026
Source: NVD
CVE-2021-47972 HIGH - 7.5

Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can paste large payloads of repeated characters into note fields to trigger application crashes and ma...

Vendor: sticky-notes-color-widgets
Product: Sticky Notes Color Widgets
Published: May 16, 2026
Source: NVD
CVE-2021-47971 HIGH - 7.5

My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an applicat...

Vendor: my-notes-safe
Product: My Notes Safe
Published: May 16, 2026
Source: NVD
CVE-2021-47970 HIGH - 7.5

Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload containing 350000 repeated characters and paste it into a note field to trigger application crash an...

Vendor: macaron-notes-great-notebook
Product: Macaron Notes Gear Notebook
Published: May 16, 2026
Source: NVD
CVE-2021-47969 HIGH - 7.5

Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350,000 repeated characters and paste it twice into a new note to cause the applicatio...

Vendor: color-notes
Product: Color Notes
Published: May 16, 2026
Source: NVD
CVE-2021-47957 MEDIUM - 6.4

Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute in the browsers of al...

Vendor: Cookielawinfo
Product: Cookie Law Bar
Published: May 16, 2026
Source: NVD
CVE-2021-47956 HIGH - 8.2

EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers can send POST requests to insert.php with malicious firstname values to extract sensitive database i...

Vendor: Egavilanmedia
Product: EgavilanMedia PHPCRUD
Published: May 16, 2026
Source: NVD
CVE-2021-47955 MEDIUM - 5.4

CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality. Attackers can upload SVG files containing embedded script tags to the browse.php endpoint, which ar...

Vendor: CouchCMS
Product: CouchCMS
Published: May 16, 2026
Source: NVD
CVE-2021-47954 HIGH - 8.2

LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extrac...

Vendor: LayerBB
Product: LayerBB
Published: May 16, 2026
Source: NVD
CVE-2021-47952 CRITICAL - 9.8

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deseria...

Vendor: Jsonpickle
Product: python jsonpickle
Published: May 16, 2026
Source: NVD
CVE-2021-47942 HIGH - 7.5

Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, the...

Vendor: Home-Assistant
Product: Home Assistant Community Store (HACS)
Published: May 16, 2026
Source: NVD
CVE-2021-47934 MEDIUM - 5.3

MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profil...

Vendor: MyBB
Product: MyBB Timeline Plugin
Published: May 16, 2026
Source: NVD
CVE-2020-37247 HIGH - 7.8

Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privi...

Vendor: Kite
Product: Kite
Published: May 16, 2026
Source: NVD
CVE-2020-37246 MEDIUM - 6.2

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access se...

Vendor: Supsystic
Product: Backup
Published: May 16, 2026
Source: NVD
CVE-2020-37245 HIGH - 7.5

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stor...

Vendor: Supsystic
Product: Digital Publications
Published: May 16, 2026
Source: NVD
CVE-2020-37244 HIGH - 8.2

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payl...

Vendor: Supsystic
Product: Membership
Published: May 16, 2026
Source: NVD
CVE-2020-37243 HIGH - 8.2

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit ...

Vendor: Supsystic
Product: Pricing Table
Published: May 16, 2026
Source: NVD
CVE-2020-37242 HIGH - 8.2

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based bli...

Vendor: Supsystic
Product: Ultimate Maps
Published: May 16, 2026
Source: NVD