Total CVEs

131,459

Critical Severity

2,797

High Severity

9,990

Last 7 Days

1,142
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,341 - 2,360 of 27,864 CVEs
CVE-2025-28344 HIGH - 7.5

striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.

Published: May 13, 2026
Source: NVD
CVE-2025-28343 HIGH - 7.5

striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.

Published: May 13, 2026
Source: NVD
CVE-2024-55045 HIGH - 7.3

Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.

Published: May 13, 2026
Source: NVD
CVE-2024-51395 MEDIUM - 6.2

Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio, AP_SmartAudio.cpp components.

Published: May 13, 2026
Source: NVD
CVE-2024-51394 MEDIUM - 5.5

Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp components.

Published: May 13, 2026
Source: NVD
CVE-2020-37226 HIGH - 7.1

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' ...

Vendor: Joomsky
Product: J2 JOBS
Published: May 13, 2026
Source: NVD
CVE-2020-37225 MEDIUM - 6.4

Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in...

Vendor: Powie
Product: WHOIS Domain Check
Published: May 13, 2026
Source: NVD
CVE-2020-37224 HIGH - 7.1

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' ...

Vendor: Joomsky
Product: J2 JOBS
Published: May 13, 2026
Source: NVD
CVE-2020-37223 HIGH - 7.8

IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to...

Vendor: Iobit
Product: IObit Uninstaller
Published: May 13, 2026
Source: NVD
CVE-2020-37222 HIGH - 7.2

Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoint. Attackers can send POST requests to /web/?c=bbs&a=reply with HTML and JavaScript payloads in ...

Vendor: Kuicms
Product: Kuicms Php EE
Published: May 13, 2026
Source: NVD
CVE-2020-37221 HIGH - 8.4

Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encode...

Vendor: Drive-software
Product: Atomic Alarm Clock
Published: May 13, 2026
Source: NVD
CVE-2020-37220 HIGH - 7.5

Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can query the /api/system/deviceinfo endpoint without authentication to extract the SerialNumber field, then ...

Vendor: www.huawei.com
Product: Huawei HG630 Router
Published: May 13, 2026
Source: NVD
CVE-2020-37219 HIGH - 7.5

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories ...

Vendor: Fabrikar
Product: com_fabrik
Published: May 13, 2026
Source: NVD
CVE-2020-37218 HIGH - 8.2

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwpla...

Vendor: Hdwplayer
Product: com_hdwplayer
Published: May 13, 2026
Source: NVD
CVE-2020-37217 MEDIUM - 4.3

Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the admin.php?action=add_user endpoint with POST requests containi...

Vendor: Easy2pilot-v7
Product: Easy2Pilot
Published: May 13, 2026
Source: NVD
CVE-2020-37174 MEDIUM - 5.5

WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design tab textfields. Attackers can inject JavaScript code through fields like 'Text for block toggle&...

Vendor: HUSKY
Product: Products Filter Professional for WooCommerce
Published: May 13, 2026
Source: NVD
CVE-2020-37169 MEDIUM - 5.5

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-upgrade.php. Attackers can send POST requests with malicious pack values to include unintended PHP fil...

Vendor: Ultimate Member
Product: ultimate-member
Published: May 13, 2026
Source: NVD
CVE-2020-37168 CRITICAL - 9.8

Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, the...

Vendor: Paiement
Product: Ecommerce Systempay
Published: May 13, 2026
Source: NVD
CVE-2026-45375 CRITICAL - 9.0

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings โ†’ Marketplace UI...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/getLocalGraph, POST /api/sync/setSyncInterval, POST /api/storage/updateRecentDocViewTime, POST /api/st...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub