Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,428
Quick preset (or use dates below)
Clear Filters
Showing 3,261 - 3,280 of 13,079 CVEs
CVE-2018-25348 HIGH - 8.2

Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values containing SQL commands to ...

Published: May 23, 2026
Source: NVD
CVE-2018-25347 HIGH - 7.1

WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_la...

Published: May 23, 2026
Source: NVD
CVE-2018-25346 HIGH - 7.1

WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the...

Published: May 23, 2026
Source: NVD
CVE-2018-25345 HIGH - 8.4

10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerability in the host name field that allows attackers to bypass SafeSEH protections and execute arbitrary code. Attackers can craft a malicious payload in the host name or address field and trigger the vulnerability through the Trac...

Published: May 23, 2026
Source: NVD
CVE-2018-25344 HIGH - 8.4

10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite. Attackers can craft a malicious registration key string wit...

Published: May 23, 2026
Source: NVD
CVE-2018-25342 HIGH - 8.2

Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in search.php. Attackers can send GET requests with malicious SQL payloads like SLEEP commands to ...

Published: May 23, 2026
Source: NVD
CVE-2018-25341 HIGH - 8.2

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensit...

Published: May 23, 2026
Source: NVD
CVE-2018-25340 HIGH - 8.2

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to category.php with UNION-based SQL injection payloads in the id parameter to extract sensi...

Published: May 23, 2026
Source: NVD
CVE-2026-46300 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache...

Vendor: linux
Product: linux_kernel
Published: May 23, 2026
Source: NVD
CVE-2026-43503 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when moving frags from ...

Published: May 23, 2026
Source: NVD
CVE-2026-9295 HIGH - 8.8

A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipulation of the argument vapurl results in buffer overflow. The attack can be initiated remotely. The ex...

Published: May 23, 2026
Source: NVD
CVE-2026-9294 HIGH - 8.8

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack rem...

Published: May 23, 2026
Source: NVD
CVE-2026-9284 HIGH - 8.2

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` end...

Published: May 23, 2026
Source: NVD
CVE-2026-6898 HIGH - 8.8

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Sub...

Published: May 23, 2026
Source: NVD
CVE-2026-6897 HIGH - 8.8

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attack...

Published: May 23, 2026
Source: NVD
CVE-2026-6895 HIGH - 8.8

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns...

Published: May 23, 2026
Source: NVD
CVE-2026-6419 HIGH - 8.8

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscribe...

Published: May 23, 2026
Source: NVD
CVE-2026-47125 HIGH - 8.8

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in every project's compose file, is missing an admin a...

Vendor: go
Product: github.com/getarcaneapp/arcane/backend
Published: May 23, 2026
Source: GitHub

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adv...

Vendor: npm
Product: parse-server
Published: May 23, 2026
Source: GitHub
CVE-2026-46717 HIGH - 8.5

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /a...

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 23, 2026
Source: GitHub