Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,385
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,501 - 2,520 of 33,671 CVEs
CVE-2023-54352 CRITICAL - 9.8

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and...

Vendor: WP Travel Kit
Product: Travelscape
Published: Jun 08, 2026
Source: NVD
CVE-2023-54351 HIGH - 7.2

WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored and e...

Vendor: Sonaar
Product: Sonaar Music Plugin
Published: Jun 08, 2026
Source: NVD
CVE-2023-54350 HIGH - 7.5

WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create m...

Vendor: webandprint
Product: Augmented Reality
Published: Jun 08, 2026
Source: NVD
CVE-2022-50953 MEDIUM - 6.2

WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing di...

Vendor: brooks24
Product: admin-word-count-column
Published: Jun 08, 2026
Source: NVD
CVE-2021-47984 MEDIUM - 6.4

WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the fieldnameDomain parameter. Attackers can inject JavaScript payloads through the plugin settings form at opt...

Vendor: WP24
Product: WP24 Domain Check
Published: Jun 08, 2026
Source: NVD
CVE-2021-47983 MEDIUM - 6.4

WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script pay...

Vendor: mra13
Product: Accept Stripe Payments
Published: Jun 08, 2026
Source: NVD
CVE-2021-47982 MEDIUM - 6.4

WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter th...

Vendor: maxfoundry
Product: WP-Paginate
Published: Jun 08, 2026
Source: NVD
CVE-2026-11474 HIGH - 7.3

A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown function of the file service/RegisterService.php of the component Registration Endpoint. Performing a manipulation of the argument stimg results in unrestr...

Vendor: Kushan2k
Product: student-management-system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11473 MEDIUM - 6.3

A vulnerability was identified in jflyfox jfinal_cms up to 5.1.0. This impacts the function list of the file AdvicefeedbackController.java. Such manipulation of the argument orderBy leads to sql injection. The attack can be launched remotely. The project was informed of the problem early through an ...

Vendor: jflyfox
Product: jfinal_cms
Published: Jun 08, 2026
Source: NVD
CVE-2026-11472 HIGH - 7.3

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be ...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11471 HIGH - 7.3

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection. It is possible to launch the attack remotely. The exploit has been made public a...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11470 MEDIUM - 6.3

A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename lea...

Vendor: hs-web
Product: hsweb-framework
Published: Jun 08, 2026
Source: NVD
CVE-2026-11469 MEDIUM - 4.7

A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-boot/src/main/java/com/jsh/erp/service/PlatformConfigService.java of the component platformConfig Add Endpoint. Executing a manipulation of the argument platformValue can lead to se...

Vendor: jishenghua
Product: jshERP
Published: Jun 08, 2026
Source: NVD

A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation of the argument room results in cross site scripting. The attack is possible to be carried out rem...

Vendor: SourceCodester
Product: Hospitals Patient Records Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11467 MEDIUM - 5.4

A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component addAccountHeadAndDetail Endpoint. Such manipulation of the arg...

Vendor: jishenghua
Product: jshERP
Published: Jun 08, 2026
Source: NVD
CVE-2026-11466 MEDIUM - 5.4

A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The ...

Vendor: zilliztech
Product: deep-searcher
Published: Jun 07, 2026
Source: NVD

A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors. The attack may be launched remotely. ...

Vendor: songquanpeng
Product: one-api
Published: Jun 07, 2026
Source: NVD

A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipulation of the argument salt leads to information d...

Product: JeecgBoot
Published: Jun 07, 2026
Source: NVD
CVE-2026-11463 HIGH - 7.3

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a manipulation can lead to type confusion. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was...

Vendor: USCiLab
Product: Cereal
Published: Jun 07, 2026
Source: NVD
CVE-2026-11462 HIGH - 7.3

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorizati...

Vendor: Chengdu Everbrite Network Technology
Product: BeikeShop
Published: Jun 07, 2026
Source: NVD