Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,939
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,461 - 2,480 of 12,388 CVEs
CVE-2026-7797 HIGH - 7.5

The Appointment Booking Calendar โ€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied paramete...

Published: May 28, 2026
Source: NVD
CVE-2026-7634 HIGH - 7.2

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

Published: May 28, 2026
Source: NVD
CVE-2026-7052 HIGH - 7.2

The HT Contact Form โ€“ Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible ...

Published: May 28, 2026
Source: NVD
CVE-2026-6455 HIGH - 8.1

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the ...

Published: May 28, 2026
Source: NVD
CVE-2026-44604 HIGH - 7.0

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specia...

Published: May 28, 2026
Source: NVD
CVE-2026-9009 HIGH - 8.8

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly into call_user_...

Published: May 28, 2026
Source: NVD
CVE-2026-9795 HIGH - 7.3

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended securi...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-7802 HIGH - 8.8

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscrib...

Published: May 28, 2026
Source: NVD
CVE-2026-32995 HIGH - 7.5

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying roo...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: May 28, 2026
Source: NVD
CVE-2026-2374 HIGH - 7.2

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['P...

Published: May 28, 2026
Source: NVD
CVE-2026-8915 HIGH - 8.8

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.

Vendor: samsung
Product: escargot
Published: May 28, 2026
Source: NVD
CVE-2026-46414 HIGH - 8.8

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46402 HIGH - 8.1

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause U...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-45322 HIGH - 7.8

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD

compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal

Vendor: pip
Product: compliance-trestle
Published: May 27, 2026
Source: GitHub
CVE-2026-47717 HIGH - 7.5

FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations

Vendor: npm
Product: fuxa-server
Published: May 27, 2026
Source: GitHub

Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs

Vendor: go
Product: github.com/kata-containers/kata-containers
Published: May 27, 2026
Source: GitHub

Pimcore has a CustomReports Share Bypass

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub
CVE-2026-9208 HIGH - 8.8

Tanium addressed an unauthorized code execution vulnerability in Connect.

Vendor: tanium
Product: connect
Published: May 27, 2026
Source: NVD
CVE-2026-45332 HIGH - 7.5

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The /_api/user-collectio...

Vendor: composer
Product: automad/automad
Published: May 27, 2026
Source: GitHub