Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,381 - 3,400 of 13,241 CVEs
CVE-2026-41967 MEDIUM - 5.9

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

Vendor: Huawei
Product: HarmonyOS
Published: May 15, 2026
Source: NVD
CVE-2026-41966 MEDIUM - 5.6

Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Vendor: Huawei
Product: HarmonyOS
Published: May 15, 2026
Source: NVD
CVE-2026-41965 MEDIUM - 5.6

Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

Vendor: Huawei
Product: HarmonyOS
Published: May 15, 2026
Source: NVD
CVE-2026-41961 MEDIUM - 5.9

Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.

Vendor: Huawei
Product: HarmonyOS
Published: May 15, 2026
Source: NVD
CVE-2026-41960 MEDIUM - 5.8

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

Vendor: Huawei
Product: HarmonyOS, EMUI
Published: May 15, 2026
Source: NVD
CVE-2026-8425 MEDIUM - 4.3

The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettings function. This makes it possible for unauthenticated attackers to change the Notify Odoo URL to an...

Published: May 15, 2026
Source: NVD
CVE-2026-7563 MEDIUM - 4.3

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it po...

Published: May 15, 2026
Source: NVD
CVE-2026-7046 MEDIUM - 4.9

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on ...

Published: May 15, 2026
Source: NVD
CVE-2026-6415 MEDIUM - 6.4

The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. Th...

Published: May 15, 2026
Source: NVD
CVE-2026-4683 MEDIUM - 6.5

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and including, 3.1.77. This makes it possible for unauthenticated attackers to overwrite the pl...

Published: May 15, 2026
Source: NVD
CVE-2026-6646 MEDIUM - 6.4

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortc...

Published: May 15, 2026
Source: NVD
CVE-2026-24662 MEDIUM - 5.4

Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the informa...

Vendor: Fujitsu Japan Limited
Product: Musetheque V4 Information Disclosure for IPKNOWLEDGE
Published: May 15, 2026
Source: NVD
CVE-2026-8612 MEDIUM - 5.3

WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache backend, WWW::Mechanize::Cached constructs a default Cache::FileCache under /tmp/FileCache without o...

Vendor: oalders
Product: www\
Published: May 15, 2026
Source: NVD
CVE-2026-6811 MEDIUM - 5.9

Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.

Published: May 14, 2026
Source: NVD
CVE-2026-45248 MEDIUM - 5.3

Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can access the endpoint without providing authentication credentials to obtain usern...

Vendor: hashgraph
Product: guardian
Published: May 14, 2026
Source: NVD
CVE-2026-45366 MEDIUM - 4.7

typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. registerManual() validates the discovery URL against an HT...

Vendor: npm
Product: @utcp/http
Published: May 14, 2026
Source: GitHub
CVE-2026-45787 MEDIUM - 9.1

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwor...

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub
CVE-2026-42573 MEDIUM - 6.1

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.

Vendor: npm
Product: svelte
Published: May 14, 2026
Source: GitHub
CVE-2026-42567 MEDIUM - 7.5

Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.

Vendor: npm
Product: svelte
Published: May 14, 2026
Source: GitHub
CVE-2026-45667 MEDIUM - 6.5

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessible without authentication and executes request.app.state.EMBEDDING_FUNCTION(...). This allows any unauthenticated caller to trigger embedding generati...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub