Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,350
Quick preset (or use dates below)
Clear Filters
Showing 3,761 - 3,780 of 13,622 CVEs
CVE-2026-4663 MEDIUM - 5.3

The iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3.7. This is due to the plugin exposing a REST API endpoint /wp-json/ipospays/v1/save_settings with 'permission_callback' set to '__return_true', which allows un...

Published: May 12, 2026
Source: NVD
CVE-2026-4301 MEDIUM - 4.3

The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() ...

Published: May 12, 2026
Source: NVD
CVE-2026-3604 MEDIUM - 4.9

The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...

Published: May 12, 2026
Source: NVD
CVE-2026-2300 MEDIUM - 6.4

The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and including, 1.0.9. This is due to the use of regex-based HTML processing (`preg_replace`) that does not properly handle HTML attribute boundaries when repla...

Published: May 12, 2026
Source: NVD
CVE-2026-1681 MEDIUM - 6.1

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both the echo request and the resulting echo reply ...

Published: May 12, 2026
Source: NVD
CVE-2026-1185 MEDIUM - 5.4

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.

Vendor: axis
Product: axis_os
Published: May 12, 2026
Source: NVD
CVE-2026-0804 MEDIUM - 6.7

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker co...

Vendor: axis
Product: axis_os
Published: May 12, 2026
Source: NVD
CVE-2026-0802 MEDIUM - 6.0

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convi...

Vendor: axis
Product: axis_os
Published: May 12, 2026
Source: NVD
CVE-2026-0541 MEDIUM - 6.7

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an a...

Vendor: axis
Product: axis_os
Published: May 12, 2026
Source: NVD
CVE-2026-7257 MEDIUM - 4.4

** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to download and decrypt a backup configuration file.

Vendor: zyxel
Product: wre6505_firmware
Published: May 12, 2026
Source: NVD
CVE-2026-7255 MEDIUM - 6.5

** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to brute-force the password and bypass authentication.

Vendor: zyxel
Product: wre6505_firmware
Published: May 12, 2026
Source: NVD
CVE-2026-40137 MEDIUM - 6.1

SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on co...

Vendor: SAP_SE
Product: Business Server Pages Application (TAF_APPLAUNCHER)
Published: May 12, 2026
Source: NVD
CVE-2026-40136 MEDIUM - 4.3

SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised resulting in a low impact on availability. There is no impact on confidentiality and integrity of ...

Vendor: SAP_SE
Product: SAP Financial Consolidation
Published: May 12, 2026
Source: NVD
CVE-2026-40135 MEDIUM - 6.5

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of un...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server for ABAP and ABAP Platform
Published: May 12, 2026
Source: NVD
CVE-2026-40134 MEDIUM - 4.3

Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availabili...

Vendor: SAP_SE
Product: SAP Incentive and Commission Management
Published: May 12, 2026
Source: NVD
CVE-2026-40133 MEDIUM - 6.3

Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability may prevent the leg...

Vendor: SAP_SE
Product: SAP S/4HANA Condition Maintenance
Published: May 12, 2026
Source: NVD
CVE-2026-40132 MEDIUM - 5.4

Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This vulnerability also enables the attacker to change the default settings and modi...

Vendor: SAP_SE
Product: SAP Strategic Enterprise Management (BSP application Balanced Scorecard Wizard)
Published: May 12, 2026
Source: NVD
CVE-2026-40129 MEDIUM - 4.3

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in ...

Vendor: SAP_SE
Product: SAP Application Server ABAP for SAP NetWeaver and ABAP Platform
Published: May 12, 2026
Source: NVD
CVE-2026-34258 MEDIUM - 4.7

SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This vulnerability has a low ...

Vendor: SAP_SE
Product: SAPUI5 (Search UI)
Published: May 12, 2026
Source: NVD
CVE-2026-27682 MEDIUM - 4.7

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the i...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Published: May 12, 2026
Source: NVD