Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
Showing 2,341 - 2,360 of 12,907 CVEs
CVE-2026-7465 HIGH - 8.8

The Spectra Gutenberg Blocks โ€“ Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. E...

Published: May 30, 2026
Source: NVD
CVE-2026-7459 HIGH - 7.5

The Simple History โ€“ Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_perm...

Published: May 30, 2026
Source: NVD
CVE-2026-10111 HIGH - 7.3

A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The proje...

Vendor: sambitraj
Product: STUDENT-MANAGEMENT-SYSTEM
Published: May 30, 2026
Source: NVD
CVE-2026-10110 HIGH - 7.3

A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may ...

Vendor: code-projects
Product: Student Details Management System
Published: May 30, 2026
Source: NVD
CVE-2026-47409 HIGH - 8.1

praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47414 HIGH - 7.6

praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47406 HIGH - 8.1

praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47405 HIGH - 8.8

PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-47399 HIGH - 8.8

PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub
CVE-2026-48169 HIGH - 8.8

PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API

Vendor: pip
Product: praisonai-platform
Published: May 29, 2026
Source: GitHub

PraisonAI has an Arbitrary File Write in Python API

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub

PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47398 HIGH - 8.1

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

Vendor: pip
Product: PraisonAI
Published: May 29, 2026
Source: GitHub
CVE-2026-47231 HIGH - 8.1

Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders

Vendor: composer
Product: admidio/admidio
Published: May 29, 2026
Source: GitHub

ouroboros-ai Vulnerable to Remote Code Execution via Untrusted Project-Directory .env

Vendor: pip
Product: ouroboros-ai
Published: May 29, 2026
Source: GitHub
CVE-2026-47201 HIGH - 8.5

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerable to XML Signature Wrapping when validating upstream SAML responses. An attacker with any account at the upstream IdP can reuse a valid signed ass...

Vendor: go
Product: goauthentik.io
Published: May 29, 2026
Source: GitHub

CC-Tweaked has an SSRF Protection Bypass with NAT64

Vendor: maven
Product: cc.tweaked:cc-tweaked-1.21-core
Published: May 29, 2026
Source: GitHub
CVE-2026-48557 HIGH - 8.8

Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() preserving inner .ph...

Vendor: spatie
Product: laravel-medialibrary
Published: May 29, 2026
Source: NVD
CVE-2026-48555 HIGH - 7.4

Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.

Vendor: spatie
Product: laravel-medialibrary
Published: May 29, 2026
Source: NVD

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21 and 3.1.26.

Vendor: verbb
Product: formie
Published: May 29, 2026
Source: NVD