Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,621 - 2,640 of 13,146 CVEs
CVE-2026-24590 MEDIUM - 5.3

Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.

Vendor: VideoWhisper.com
Product: Paid Videochat Turnkey Site
Published: May 26, 2026
Source: NVD
CVE-2026-39655 MEDIUM - 5.3

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

Vendor: TeconceTheme
Product: Mayosis Core
Published: May 26, 2026
Source: NVD
CVE-2026-9534 MEDIUM - 6.3

A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit...

Published: May 26, 2026
Source: NVD
CVE-2026-9533 MEDIUM - 6.3

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate th...

Published: May 26, 2026
Source: NVD
CVE-2026-9532 MEDIUM - 6.3

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed f...

Published: May 26, 2026
Source: NVD
CVE-2026-3314 MEDIUM - 4.6

Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This is...

Published: May 26, 2026
Source: NVD
CVE-2026-9531 MEDIUM - 6.3

A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The ex...

Published: May 26, 2026
Source: NVD
CVE-2026-9527 MEDIUM - 4.3

A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly di...

Published: May 26, 2026
Source: NVD
CVE-2026-9524 MEDIUM - 6.3

A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor was contacted early a...

Published: May 26, 2026
Source: NVD
CVE-2026-9520 MEDIUM - 4.3

A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the component Sign-in. This manipulation of the argument Next causes cross site scripting. It is possible to ...

Published: May 26, 2026
Source: NVD
CVE-2026-9519 MEDIUM - 4.3

A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto-Redirect. The manipulation of the argument redirect results in cross site scripting. The attack may ...

Published: May 26, 2026
Source: NVD
CVE-2026-9518 MEDIUM - 4.3

A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. The manipulation of the argument Name leads to cross site scripting. The attack is possible to be carr...

Published: May 26, 2026
Source: NVD
CVE-2026-4795 MEDIUM - 6.5

A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0,ย GS1200-8v3 firmware versions through 1.00(ACPT.2)C0,ย  GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions th...

Published: May 26, 2026
Source: NVD
CVE-2026-9515 MEDIUM - 6.3

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin_version results in os command injection. The attack may be launched remotely....

Published: May 26, 2026
Source: NVD
CVE-2026-9514 MEDIUM - 6.3

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is di...

Published: May 25, 2026
Source: NVD
CVE-2026-9513 MEDIUM - 6.3

A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument host_time can lead to os command injection. The attack can be launched remotely. ...

Published: May 25, 2026
Source: NVD
CVE-2026-9512 MEDIUM - 6.3

A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be i...

Published: May 25, 2026
Source: NVD
CVE-2026-45435 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.

Vendor: Melapress
Product: WP Activity Log
Published: May 25, 2026
Source: NVD
CVE-2026-45217 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7.

Vendor: ThemeHigh
Product: Stripe Payment Gateway for WooCommerce
Published: May 25, 2026
Source: NVD
CVE-2026-42776 MEDIUM - 6.3

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.

Vendor: WP Sunshine
Product: Sunshine Photo Cart
Published: May 25, 2026
Source: NVD