Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,428
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,301 - 3,320 of 13,241 CVEs
CVE-2018-25336 MEDIUM - 5.3

Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML forms targeting endpoints , and to change user credentials, passwords, and affiliate account detai...

Vendor: Joomlaextensions
Product: Joomla! extension jCart for OpenCart
Published: May 17, 2026
Source: NVD
CVE-2018-25334 MEDIUM - 5.4

Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but an attacker can use the hashtag parameter to inject an encoded payload and bypass the CSRF prot...

Vendor: Bylancer
Product: Zechat
Published: May 17, 2026
Source: NVD
CVE-2018-25331 MEDIUM - 6.1

Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which r...

Vendor: zenar
Product: Zenar Content Management System
Published: May 17, 2026
Source: NVD
CVE-2018-25327 MEDIUM - 5.3

Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify ...

Vendor: Joomsky
Product: JS Jobs
Published: May 17, 2026
Source: NVD
CVE-2018-25324 MEDIUM - 6.2

Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspath values to simple_...

Vendor: Simple-Fields
Product: Simple Fields
Published: May 17, 2026
Source: NVD
CVE-2018-25321 MEDIUM - 4.3

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via Wlan...

Vendor: Tp-link
Product: TL-WR720NMbps Wireless N Router
Published: May 17, 2026
Source: NVD
CVE-2026-8752 MEDIUM - 5.3

A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to improper access contro...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8750 MEDIUM - 5.3

A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be executed remotely. The e...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8747 MEDIUM - 6.3

A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been made...

Published: May 17, 2026
Source: NVD
CVE-2026-8746 MEDIUM - 4.3

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF. The manipulation results in use after free. The attack can be launched remotely. The exploit has been released to the pub...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8745 MEDIUM - 4.3

A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit is publicly available and...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8744 MEDIUM - 4.3

A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing a manipulation can lead to denial of service. It is possible to launch the attack remotely. The explo...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8743 MEDIUM - 6.3

A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit has been made pub...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8740 MEDIUM - 6.3

A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes ...

Published: May 17, 2026
Source: NVD
CVE-2026-8739 MEDIUM - 5.3

A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptogr...

Published: May 17, 2026
Source: NVD
CVE-2026-8738 MEDIUM - 6.5

A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component...

Published: May 17, 2026
Source: NVD
CVE-2026-8737 MEDIUM - 5.3

A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument ...

Published: May 17, 2026
Source: NVD
CVE-2026-8736 MEDIUM - 4.1

A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController. Performing a manipulation of the argument uniqueFileName results in path traversal. The attack may be carri...

Published: May 17, 2026
Source: NVD
CVE-2026-8735 MEDIUM - 6.3

A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit is publicly available ...

Published: May 17, 2026
Source: NVD
CVE-2026-8733 MEDIUM - 6.3

A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and c...

Published: May 17, 2026
Source: NVD