Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,302
Quick preset (or use dates below)
Clear Filters
Showing 3,641 - 3,660 of 13,079 CVEs
CVE-2026-8734 HIGH - 7.3

A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Interface. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed...

Published: May 17, 2026
Source: NVD
CVE-2026-8719 HIGH - 8.8

The AI Engine โ€“ The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be...

Published: May 17, 2026
Source: NVD
CVE-2026-8725 HIGH - 7.3

A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been ...

Published: May 17, 2026
Source: NVD
CVE-2026-46728 HIGH - 8.2

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

Vendor: denx
Product: U-Boot
Published: May 16, 2026
Source: NVD
CVE-2021-47980 HIGH - 7.1

Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in t...

Vendor: Getfuelcms
Product: Fuel CMS
Published: May 16, 2026
Source: NVD
CVE-2021-47979 HIGH - 8.8

WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete ...

Vendor: Miniorange
Product: Backup and Restore
Published: May 16, 2026
Source: NVD
CVE-2021-47977 HIGH - 7.5

WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via admin-ajax.php with ...

Vendor: Gotmls
Product: Malware Security and Bruteforce Firewall
Published: May 16, 2026
Source: NVD
CVE-2021-47976 HIGH - 8.8

TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can authenticate, retrieve a CSRF token from the plugin event page, and upload malicious PHP files to th...

Vendor: Textpattern
Product: TextPattern CMS
Published: May 16, 2026
Source: NVD
CVE-2021-47975 HIGH - 7.2

WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbit...

Vendor: Wplearnmanager
Product: WP Learn Manager
Published: May 16, 2026
Source: NVD
CVE-2021-47974 HIGH - 7.8

VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories like C:\Program Files\VX Search to execute arbitrary...

Vendor: Vxsearch
Product: VX Search
Published: May 16, 2026
Source: NVD
CVE-2021-47973 HIGH - 7.5

Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an ...

Vendor: sticky-notes
Product: Sticky Notes Widget
Published: May 16, 2026
Source: NVD
CVE-2021-47972 HIGH - 7.5

Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can paste large payloads of repeated characters into note fields to trigger application crashes and ma...

Vendor: sticky-notes-color-widgets
Product: Sticky Notes Color Widgets
Published: May 16, 2026
Source: NVD
CVE-2021-47971 HIGH - 7.5

My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an applicat...

Vendor: my-notes-safe
Product: My Notes Safe
Published: May 16, 2026
Source: NVD
CVE-2021-47970 HIGH - 7.5

Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload containing 350000 repeated characters and paste it into a note field to trigger application crash an...

Vendor: macaron-notes-great-notebook
Product: Macaron Notes Gear Notebook
Published: May 16, 2026
Source: NVD
CVE-2021-47969 HIGH - 7.5

Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350,000 repeated characters and paste it twice into a new note to cause the applicatio...

Vendor: color-notes
Product: Color Notes
Published: May 16, 2026
Source: NVD
CVE-2021-47956 HIGH - 8.2

EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers can send POST requests to insert.php with malicious firstname values to extract sensitive database i...

Vendor: Egavilanmedia
Product: EgavilanMedia PHPCRUD
Published: May 16, 2026
Source: NVD
CVE-2021-47954 HIGH - 8.2

LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extrac...

Vendor: LayerBB
Product: LayerBB
Published: May 16, 2026
Source: NVD
CVE-2021-47942 HIGH - 7.5

Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, the...

Vendor: Home-Assistant
Product: Home Assistant Community Store (HACS)
Published: May 16, 2026
Source: NVD
CVE-2020-37247 HIGH - 7.8

Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privi...

Vendor: Kite
Product: Kite
Published: May 16, 2026
Source: NVD
CVE-2020-37245 HIGH - 7.5

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stor...

Vendor: Supsystic
Product: Digital Publications
Published: May 16, 2026
Source: NVD