Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,341 - 2,360 of 13,080 CVEs
CVE-2026-47104 MEDIUM - 4.0

libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer...

Vendor: libusb
Product: libusb
Published: May 27, 2026
Source: NVD
CVE-2026-3676 MEDIUM - 6.5

IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced enviro...

Vendor: ibm
Product: cloud_application_performance_managemen
Published: May 27, 2026
Source: NVD
CVE-2026-2607 MEDIUM - 5.1

IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: ย v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied MQ Advanced container images SC2: 9.4.0.6 through r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2...

Published: May 27, 2026
Source: NVD
CVE-2026-2340 MEDIUM - 6.5

A flaw was found in Sambaโ€™s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share c...

Vendor: redhat
Product: openshift_container_platform
Published: May 27, 2026
Source: NVD
CVE-2026-23679 MEDIUM - 6.2

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exce...

Vendor: libusb
Product: libusb
Published: May 27, 2026
Source: NVD
CVE-2025-3633 MEDIUM - 5.4

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functional...

Vendor: ibm
Product: cognos_analytics
Published: May 27, 2026
Source: NVD
CVE-2024-40684 MEDIUM - 5.9

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier ...

Vendor: IBM
Product: Operations Analytics - Log Analysis
Published: May 27, 2026
Source: NVD
CVE-2024-28765 MEDIUM - 5.3

IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

Vendor: IBM
Product: SDI, Security Directory Integrator
Published: May 27, 2026
Source: NVD
CVE-2026-9689 MEDIUM - 4.2

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks ...

Vendor: redhat
Product: build_of_keycloak
Published: May 27, 2026
Source: NVD
CVE-2026-42751 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18.

Vendor: wpdevelop
Product: Booking Manager
Published: May 27, 2026
Source: NVD
CVE-2026-42750 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.

Vendor: Nexcess
Product: WPComplete
Published: May 27, 2026
Source: NVD
CVE-2026-42744 MEDIUM - 6.5

Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Manipulating Hidden Fields.This issue affects Ads by WPQuads: from n/a through <= 3.0.2.

Vendor: Ads by WPQuads
Product: Ads by WPQuads
Published: May 27, 2026
Source: NVD
CVE-2026-42732 MEDIUM - 6.5

Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Input Data Manipulation.This issue affects Ads by WPQuads: from n/a through <= 3.0.2.

Vendor: Ads by WPQuads
Product: Ads by WPQuads
Published: May 27, 2026
Source: NVD
CVE-2026-42726 MEDIUM - 6.5

Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5.

Vendor: Strategy11 Team
Product: AWP Classifieds
Published: May 27, 2026
Source: NVD
CVE-2026-42725 MEDIUM - 6.5

Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2...

Vendor: WP Wham
Product: Checkout Files Upload for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-3349 MEDIUM - 6.1

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated att...

Published: May 27, 2026
Source: NVD
CVE-2026-3348 MEDIUM - 4.4

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (Description, Title, and other fields) in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authent...

Published: May 27, 2026
Source: NVD
CVE-2026-2288 MEDIUM - 4.8

The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leve...

Published: May 27, 2026
Source: NVD
CVE-2026-2280 MEDIUM - 4.8

The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and ab...

Published: May 27, 2026
Source: NVD
CVE-2025-0898 MEDIUM - 6.5

The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on th...

Published: May 27, 2026
Source: NVD