Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

974
Quick preset (or use dates below)
Clear Filters
Showing 3,221 - 3,240 of 13,527 CVEs
CVE-2026-8738 MEDIUM - 6.5

A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component...

Published: May 17, 2026
Source: NVD
CVE-2026-8737 MEDIUM - 5.3

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument ...

Published: May 17, 2026
Source: NVD
CVE-2026-8736 MEDIUM - 4.1

A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController. Performing a manipulation of the argument uniqueFileName results in path traversal. The attack may be carri...

Published: May 17, 2026
Source: NVD
CVE-2026-8735 MEDIUM - 6.3

A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit is publicly available ...

Published: May 17, 2026
Source: NVD
CVE-2026-8733 MEDIUM - 6.3

A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and c...

Published: May 17, 2026
Source: NVD
CVE-2026-8731 MEDIUM - 4.3

A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation of the argument client_pool leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disc...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8730 MEDIUM - 4.3

A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF. Executing a manipulation of the argument nfInstanceId can lead to denial of service. The attack may be performed from remote. The exploit has bee...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8729 MEDIUM - 4.3

A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/snssais results in denial of service. The attack is possible to be carried out remotely. The exploit i...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8728 MEDIUM - 4.3

A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. Such manipulation of the argument target-plmn-list leads to denial of service. The attack can be execu...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8724 MEDIUM - 4.7

A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been released to the public an...

Vendor: dataease
Product: dataease
Published: May 17, 2026
Source: NVD
CVE-2026-8723 MEDIUM - 5.3

### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). ### ...

Vendor: npm
Product: qs
Published: May 17, 2026
Source: NVD
CVE-2021-47981 MEDIUM - 5.4

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arb...

Vendor: Opensolution
Product: Quick.CMS
Published: May 16, 2026
Source: NVD
CVE-2021-47978 MEDIUM - 6.2

ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send requests with directory traversal sequences to access sensitive system files like /etc/passwd without au...

Vendor: Processmaker
Product: ProcessMaker
Published: May 16, 2026
Source: NVD
CVE-2021-47957 MEDIUM - 6.4

Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute in the browsers of al...

Vendor: Cookielawinfo
Product: Cookie Law Bar
Published: May 16, 2026
Source: NVD
CVE-2021-47955 MEDIUM - 5.4

CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality. Attackers can upload SVG files containing embedded script tags to the browse.php endpoint, which ar...

Vendor: CouchCMS
Product: CouchCMS
Published: May 16, 2026
Source: NVD
CVE-2021-47934 MEDIUM - 5.3

MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profil...

Vendor: MyBB
Product: MyBB Timeline Plugin
Published: May 16, 2026
Source: NVD
CVE-2020-37246 MEDIUM - 6.2

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access se...

Vendor: Supsystic
Product: Backup
Published: May 16, 2026
Source: NVD
CVE-2020-37241 MEDIUM - 5.3

bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts wit...

Vendor: Bloofox
Product: bloofoxCMS
Published: May 16, 2026
Source: NVD
CVE-2020-37240 MEDIUM - 6.4

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which ex...

Vendor: Codekernel
Product: Queue Management System
Published: May 16, 2026
Source: NVD
CVE-2020-37238 MEDIUM - 6.4

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other a...

Vendor: Cmsmadesimple
Product: CMS Made Simple
Published: May 16, 2026
Source: NVD