Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,909
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,681 - 2,700 of 12,473 CVEs
CVE-2026-36539 HIGH - 7.3

Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any attacker on the LAN can send a single HTTP GET request and instantly retrieve administrator credentials, WiFi password...

Published: May 27, 2026
Source: NVD
CVE-2026-36538 HIGH - 7.3

Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacker with access to the device to authenticate as root and gain full control of the underlying operating...

Published: May 27, 2026
Source: NVD
CVE-2026-36045 HIGH - 7.3

picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.

Published: May 27, 2026
Source: NVD
CVE-2026-36044 HIGH - 8.8

@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js ...

Published: May 27, 2026
Source: NVD
CVE-2026-1933 HIGH - 7.1

A flaw was found in Sambaโ€™s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only e...

Vendor: redhat
Product: openshift_container_platform
Published: May 27, 2026
Source: NVD
CVE-2026-1718 HIGH - 7.1

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.

Vendor: ibm
Product: db2
Published: May 27, 2026
Source: NVD
CVE-2024-56462 HIGH - 7.2

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.

Vendor: IBM
Product: QRadar
Published: May 27, 2026
Source: NVD
CVE-2026-48906 HIGH - 8.1

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.

Vendor: tassos.gr
Product: Novarain/Tassos Framework (plg_system_nrframework), Convert Forms, EngageBox, Google Structured Data, Advanced Custom Fields, Smile Pack, Tassos Code Snippets, MailChimp Auto-Subscribe
Published: May 27, 2026
Source: NVD
CVE-2026-45843 HIGH - 8.2

In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neither helper bounds-checks against isize, a...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-42762 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows DOM-Based XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: May 27, 2026
Source: NVD
CVE-2026-42760 HIGH - 7.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25.

Vendor: revmakx
Product: Backup and Staging by WP Time Capsule
Published: May 27, 2026
Source: NVD
CVE-2026-42759 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Super Assistent amazonsimpleadmin allows Stored XSS.This issue affects Affiliate Super Assistent: from n/a through <= 1.10.1.

Vendor: Timo
Product: Affiliate Super Assistent
Published: May 27, 2026
Source: NVD
CVE-2026-42754 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon favicon-by-realfavicongenerator allows Reflected XSS.This issue affects Favicon: from n/a through <= 1.3.46.

Vendor: phbernard
Product: Favicon
Published: May 27, 2026
Source: NVD
CVE-2026-42753 HIGH - 7.3

Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.

Vendor: WC Lovers
Product: WCFM Membership
Published: May 27, 2026
Source: NVD
CVE-2026-42749 HIGH - 7.1

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0.

Vendor: Themeisle
Product: Disable Comments for Any Post Types (Remove comments)
Published: May 27, 2026
Source: NVD
CVE-2026-42746 HIGH - 7.3

Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Retrieve Embedded Sensitive Data.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

Vendor: ZAYTECH
Product: Smart Online Order for Clover
Published: May 27, 2026
Source: NVD
CVE-2026-42745 HIGH - 7.3

Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Authentication Bypass.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

Vendor: ZAYTECH
Product: Smart Online Order for Clover
Published: May 27, 2026
Source: NVD
CVE-2026-42739 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced IP Blocker: from n/a through <= 8.10.7.

Vendor: IniLerm
Product: Advanced IP Blocker
Published: May 27, 2026
Source: NVD
CVE-2026-42738 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

Vendor: ZAYTECH
Product: Smart Online Order for Clover
Published: May 27, 2026
Source: NVD
CVE-2026-42737 HIGH - 8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: May 27, 2026
Source: NVD