Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,257
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,981 - 4,000 of 13,249 CVEs
CVE-2021-47948 MEDIUM - 5.4

WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers can inject malicious HTML including image tags and scripts into the Help Text field during payment f...

Vendor: invoicing
Product: Payments Plugin GetPaid
Published: May 10, 2026
Source: NVD
CVE-2021-47947 MEDIUM - 6.4

Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edit.php. Attackers can inject JavaScript payloads through the file name field that execute in...

Vendor: Projectsend
Product: Projectsend
Published: May 10, 2026
Source: NVD
CVE-2021-47946 MEDIUM - 5.3

OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiting malicious pages. Attackers can craft CSRF payloads that change victim email addresses and account ...

Vendor: Opencart
Product: OpenCart
Published: May 10, 2026
Source: NVD
CVE-2021-47931 MEDIUM - 6.4

Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary Ja...

Vendor: Exponentcms
Product: Exponent CMS
Published: May 10, 2026
Source: NVD
CVE-2021-47929 MEDIUM - 6.4

Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is...

Vendor: Filterable-Portfolio
Product: Filterable Portfolio Gallery
Published: May 10, 2026
Source: NVD
CVE-2021-47927 MEDIUM - 6.4

WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScri...

Vendor: Wpsymposiumpro
Product: WP Symposium Pro
Published: May 10, 2026
Source: NVD
CVE-2021-47926 MEDIUM - 6.4

Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in us...

Vendor: Form2Email
Product: Contact Form to Email
Published: May 10, 2026
Source: NVD
CVE-2021-47925 MEDIUM - 6.4

CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters or SVG file attachme...

Vendor: Cmdbuild
Product: CMDBuild
Published: May 10, 2026
Source: NVD
CVE-2021-47924 MEDIUM - 6.4

Ultimate Product Catalog 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code w...

Vendor: Etoilewebdesign
Product: Ultimate Product Catalog
Published: May 10, 2026
Source: NVD
CVE-2021-47922 MEDIUM - 6.4

Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of use...

Vendor: Soliloquywp
Product: Slider by Soliloquy
Published: May 10, 2026
Source: NVD
CVE-2021-47910 MEDIUM - 6.4

AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that...

Vendor: Accesspressthemes
Product: AccessPress Social Icons
Published: May 10, 2026
Source: NVD
CVE-2021-47907 MEDIUM - 6.4

Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers o...

Vendor: Rocketsoft
Product: Rocket LMS
Published: May 10, 2026
Source: NVD
CVE-2026-8244 MEDIUM - 5.3

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI Interface. The manipulation of the argument clientVersion leads to improper authentication. It is possible to initiate the attack remotely. The exploit i...

Published: May 10, 2026
Source: NVD
CVE-2026-8243 MEDIUM - 5.3

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be performed from remote. The vendor was conta...

Published: May 10, 2026
Source: NVD
CVE-2026-8241 MEDIUM - 5.3

A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to ...

Published: May 10, 2026
Source: NVD
CVE-2026-8235 MEDIUM - 5.5

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulation results in os command injection. The exploit is now public and may be used. The patch is identified...

Published: May 10, 2026
Source: NVD
CVE-2026-8233 MEDIUM - 4.6

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The vendor was contacte...

Published: May 10, 2026
Source: NVD
CVE-2026-8231 MEDIUM - 6.3

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public ...

Published: May 10, 2026
Source: NVD
CVE-2026-8230 MEDIUM - 6.3

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The ...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: May 10, 2026
Source: NVD
CVE-2026-8229 MEDIUM - 6.3

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Remote exploitation of the attack is possible. The exploit is now...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: May 10, 2026
Source: NVD