Total CVEs

137,067

Critical Severity

3,268

High Severity

12,166

Last 7 Days

1,414
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,141 - 3,160 of 33,472 CVEs
CVE-2019-25737 HIGH - 7.2

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft...

Vendor: Screets
Product: Live Chat Unlimited
Published: Jun 04, 2026
Source: NVD
CVE-2019-25736 HIGH - 8.4

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe o...

Vendor: Labf
Product: LabF nfsAxe
Published: Jun 04, 2026
Source: NVD
CVE-2019-25735 HIGH - 8.4

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execu...

Vendor: Allplayer
Product: AllPlayer
Published: Jun 04, 2026
Source: NVD
CVE-2019-25734 MEDIUM - 4.0

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint wit...

Vendor: Web-Dorado
Product: Contact Form Maker
Published: Jun 04, 2026
Source: NVD
CVE-2019-25733 HIGH - 8.4

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigg...

Vendor: nsauditor
Product: NetShareWatcher
Published: Jun 04, 2026
Source: NVD
CVE-2019-25732 HIGH - 8.2

PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the query parameter to ext...

Vendor: eitube
Product: EI-Tube
Published: Jun 04, 2026
Source: NVD
CVE-2019-25731 HIGH - 7.2

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST requests to /gmusic/zuzconso...

Vendor: Zuz
Product: Zuz Music
Published: Jun 04, 2026
Source: NVD
CVE-2019-25730 HIGH - 8.2

Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to ex...

Vendor: Themerig
Product: Listing Hub CMS
Published: Jun 04, 2026
Source: NVD
CVE-2019-25729 CRITICAL - 9.8

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec...

Vendor: simcy_creative
Product: PDF Signer
Published: Jun 04, 2026
Source: NVD
CVE-2019-25728 HIGH - 8.2

Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including login.php, indexframe.php,...

Vendor: care2x
Product: Care2x
Published: Jun 04, 2026
Source: NVD
CVE-2019-25727 CRITICAL - 9.8

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter...

Vendor: ad-manager-wd
Product: Ad Manager WD
Published: Jun 04, 2026
Source: NVD
CVE-2019-25726 HIGH - 8.2

All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id pa...

Vendor: Nicheoffice
Product: All in One Video Downloader
Published: Jun 04, 2026
Source: NVD
CVE-2026-44486 HIGH - 7.5

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios ...

Vendor: npm
Product: axios
Published: Jun 04, 2026
Source: GitHub
CVE-2026-4104 CRITICAL - 9.8

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.

Published: Jun 04, 2026
Source: NVD

This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability by intercepting network traffic to obtain sensitive authentication information, which could lead to ...

Vendor: GX INDIA
Product: GX Earth 2022, GX Earth 1010
Published: Jun 04, 2026
Source: NVD

This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary and executing OS commands on the targeted device...

Vendor: GX INDIA
Product: GX Earth 2022, GX Earth 1010
Published: Jun 04, 2026
Source: NVD
CVE-2026-10843 HIGH - 7.2

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.

Vendor: Red Hat
Product: Red Hat OpenShift Container Platform 4
Published: Jun 04, 2026
Source: NVD
CVE-2026-10840 CRITICAL - 9.6

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluste...

Vendor: Red Hat
Product: Builds for Red Hat OpenShift, OpenShift Pipelines
Published: Jun 04, 2026
Source: NVD

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a hig...

Vendor: snowflake
Product: Streamlit
Published: Jun 04, 2026
Source: NVD

A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local host. The attack is ...

Vendor: lfprojects
Product: MLflow
Published: Jun 04, 2026
Source: NVD