Total CVEs

137,202

Critical Severity

3,303

High Severity

12,233

Last 7 Days

1,469
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,261 - 3,280 of 33,607 CVEs
CVE-2026-10809 MEDIUM - 6.3

A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be use...

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10808 MEDIUM - 6.3

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10807 MEDIUM - 6.3

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image can lead to unrestricted upload. The attack may be launched remotely. Th...

Vendor: mjperpinosa
Product: stumasy
Published: Jun 04, 2026
Source: NVD
CVE-2026-10806 MEDIUM - 6.3

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post results in unrestricted upload. The attack may be initiated remotely. The exploit has been...

Vendor: mjperpinosa
Product: stumasy
Published: Jun 04, 2026
Source: NVD

The HCL BigFix Cloud Lifecycle Management is affected by Lack Of Input Validation. It may leads to an information exposure vulnerability. This low-level flaw allows unauthorized access.

Vendor: HCL
Product: BigFix Cloud Lifecycle Management
Published: Jun 04, 2026
Source: NVD
CVE-2025-59874 HIGH - 8.1

HCL Hive Telco Observability is affected by ย a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.

Vendor: HCL
Product: Hive
Published: Jun 04, 2026
Source: NVD
CVE-2025-46638 HIGH - 7.5

Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).

Vendor: Dell
Product: BSAFE SSL-J
Published: Jun 04, 2026
Source: NVD
CVE-2019-25745 HIGH - 8.2

WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious &#...

Vendor: jgwhite33
Product: Google Review Slider
Published: Jun 04, 2026
Source: NVD
CVE-2019-25744 MEDIUM - 6.4

WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads i...

Vendor: Popup-Builder
Product: Popup Builder
Published: Jun 04, 2026
Source: NVD
CVE-2019-25743 MEDIUM - 6.4

WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the post_t...

Vendor: Soliloquywp
Product: Soliloquy Lite
Published: Jun 04, 2026
Source: NVD
CVE-2019-25742 MEDIUM - 6.4

WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execute ...

Vendor: Fruitfulcode
Product: Zoner Real Estate
Published: Jun 04, 2026
Source: NVD
CVE-2019-25741 CRITICAL - 9.8

Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulner...

Vendor: Mobatek
Product: Mobatek MobaXterm
Published: Jun 04, 2026
Source: NVD
CVE-2019-25740 MEDIUM - 6.5

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2 parameter to delete arbitra...

Vendor: Joomsky
Product: JS Jobs
Published: Jun 04, 2026
Source: NVD
CVE-2019-25739 MEDIUM - 6.4

GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create_proposal endpoint that execute when administrators or other use...

Vendor: Gigtodoscript
Product: GigToDo
Published: Jun 04, 2026
Source: NVD
CVE-2019-25738 CRITICAL - 9.8

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to h...

Vendor: framework-y
Product: Hybrid Composer
Published: Jun 04, 2026
Source: NVD
CVE-2019-25737 HIGH - 7.2

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft...

Vendor: Screets
Product: Live Chat Unlimited
Published: Jun 04, 2026
Source: NVD
CVE-2019-25736 HIGH - 8.4

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe o...

Vendor: Labf
Product: LabF nfsAxe
Published: Jun 04, 2026
Source: NVD
CVE-2019-25735 HIGH - 8.4

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execu...

Vendor: Allplayer
Product: AllPlayer
Published: Jun 04, 2026
Source: NVD
CVE-2019-25734 MEDIUM - 4.0

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint wit...

Vendor: Web-Dorado
Product: Contact Form Maker
Published: Jun 04, 2026
Source: NVD
CVE-2019-25733 HIGH - 8.4

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigg...

Vendor: nsauditor
Product: NetShareWatcher
Published: Jun 04, 2026
Source: NVD