Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,541
Quick preset (or use dates below)
Clear Filters
Showing 2,441 - 2,460 of 13,446 CVEs
CVE-2026-9022 MEDIUM - 6.4

The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...

Published: May 27, 2026
Source: NVD
CVE-2026-48999 MEDIUM - 5.3

Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user cookies, hijack sessi...

Vendor: ZTE
Product: ZTE ZXUniPOS NDS-LTE
Published: May 27, 2026
Source: NVD
CVE-2026-2255 MEDIUM - 4.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can...

Published: May 27, 2026
Source: NVD
CVE-2026-2254 MEDIUM - 6.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

Published: May 27, 2026
Source: NVD
CVE-2025-15649 MEDIUM - 5.5

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes ...

Vendor: PMQS
Product: IO::Uncompress::Unzip
Published: May 27, 2026
Source: NVD
CVE-2026-9609 MEDIUM - 4.7

A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem ear...

Published: May 27, 2026
Source: NVD
CVE-2026-9156 MEDIUM - 6.5

Tanium addressed a denial of service vulnerability in Tanium Server.

Vendor: tanium
Product: server
Published: May 27, 2026
Source: NVD
CVE-2026-7493 MEDIUM - 5.3

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function...

Published: May 27, 2026
Source: NVD
CVE-2026-6565 MEDIUM - 6.4

The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endpoint kit title parameter in versions up to, and including, 2.5.0 due to insufficient in...

Published: May 27, 2026
Source: NVD

@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects

Vendor: npm
Product: @hapi/wreck
Published: May 27, 2026
Source: GitHub
CVE-2026-44646 MEDIUM - 5.3

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, Context.spawn() creates a child Context for the {% render %} tag but does not propagate the parent context's resolved ownPropertyOnly value, resulting in a silent bypass. The...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub
CVE-2026-9607 MEDIUM - 6.3

A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public an...

Published: May 27, 2026
Source: NVD
CVE-2026-8606 MEDIUM - 5.9

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security advisories package lookup feature. By directing requests to an internal management service and measu...

Vendor: github
Product: enterprise_server
Published: May 27, 2026
Source: NVD
CVE-2026-44645 MEDIUM - 6.5

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can be fully bypassed by a {% for %} (or {% tablerow %}) tag whose body is empty. The renderLimit option is documented in docs/source/tutorials/dos.md as th...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub
CVE-2026-44644 MEDIUM - 6.1

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a flaw in the strip_html filter logic. The strip_html filter is intended to remove HTML tags from a string before rendering, and is widely used as an XSS...

Vendor: npm
Product: liquidjs
Published: May 27, 2026
Source: GitHub
CVE-2026-44596 MEDIUM - 6.5

Yamcs has No Rate Limiting on Authentication Endpoint

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-44595 MEDIUM - 4.3

Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-44587 MEDIUM - 4.7

CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in string entries, causing the denylist to silently not match the content types it is intended to block. In lib/carrierwave/up...

Vendor: rubygems
Product: carrierwave
Published: May 27, 2026
Source: GitHub

Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations

Vendor: go
Product: github.com/kata-containers/kata-containers
Published: May 26, 2026
Source: GitHub

Kirby CMS's `pages.access` permission is not checked during rendering of page drafts

Vendor: composer
Product: getkirby/cms
Published: May 26, 2026
Source: GitHub