Total CVEs

138,500

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,017
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,401 - 3,420 of 12,518 CVEs
CVE-2020-37247 HIGH - 7.8

Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privi...

Vendor: Kite
Product: Kite
Published: May 16, 2026
Source: NVD
CVE-2020-37245 HIGH - 7.5

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stor...

Vendor: Supsystic
Product: Digital Publications
Published: May 16, 2026
Source: NVD
CVE-2020-37244 HIGH - 8.2

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payl...

Vendor: Supsystic
Product: Membership
Published: May 16, 2026
Source: NVD
CVE-2020-37243 HIGH - 8.2

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit ...

Vendor: Supsystic
Product: Pricing Table
Published: May 16, 2026
Source: NVD
CVE-2020-37242 HIGH - 8.2

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based bli...

Vendor: Supsystic
Product: Ultimate Maps
Published: May 16, 2026
Source: NVD
CVE-2020-37232 HIGH - 7.8

Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Attackers can place malicious executables in the system root path that will be executed with LocalSystem ...

Vendor: Iobit
Product: Advanced System Care Service
Published: May 16, 2026
Source: NVD
CVE-2020-37231 HIGH - 7.8

Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with...

Vendor: Cybertronsoft
Product: Privacy Drive
Published: May 16, 2026
Source: NVD
CVE-2020-37230 HIGH - 7.8

Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path. Attackers can insert a malicious executable into the service path and execute it with LocalSystem p...

Vendor: Syncplify
Product: Syncplify.me Server!
Published: May 16, 2026
Source: NVD
CVE-2020-37229 HIGH - 7.8

OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unquoted path. Attackers can place a malicious executable in a directory within the service path that wil...

Vendor: Oki
Product: OKI sPSV Port Manager
Published: May 16, 2026
Source: NVD
CVE-2020-37227 HIGH - 8.8

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to exe...

Vendor: Heliossolutions
Product: HS Brand Logo Slider
Published: May 16, 2026
Source: NVD
CVE-2026-8657 HIGH - 8.2

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property ...

Published: May 16, 2026
Source: NVD
CVE-2026-8700 HIGH - 7.3

Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Published: May 15, 2026
Source: NVD
CVE-2026-8696 HIGH - 7.5

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability...

Vendor: radare
Product: radare2
Published: May 15, 2026
Source: NVD
CVE-2026-8686 HIGH - 7.5

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users should upgrade to v5.0.1.

Vendor: freertos
Product: coremqtt
Published: May 15, 2026
Source: NVD
CVE-2026-46408 HIGH - 7.6

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter the payment flow without verifying cart ownership. A logged-in attacker can therefore reuse another u...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2026-46407 HIGH - 8.1

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to load another administrator's REST API token list by supplying that user's admin_id. This ...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2026-46367 HIGH - 7.6

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject event handlers, stealing admin session cookies and achieving f...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46366 HIGH - 7.5

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46359 HIGH - 7.5

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break ou...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-44826 HIGH - 7.5

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-add endpoint. Submitting a negative integer is accepted by the server and treated as a normal positive ...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD