Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,230
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,181 - 4,200 of 13,249 CVEs
CVE-2025-66171 MEDIUM - 6.5

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs using backups of any other user of the env...

Vendor: Apache Software Foundation
Product: Apache CloudStack
Published: May 08, 2026
Source: NVD
CVE-2025-66170 MEDIUM - 6.5

The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and has access to specific APIs can list backups from any account in the environment. T...

Vendor: Apache Software Foundation
Product: Apache CloudStack
Published: May 08, 2026
Source: NVD
CVE-2026-7650 MEDIUM - 6.4

The E2Pdf โ€“ Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-download` shortcode in all versions up to, and including, 1.32.17. This is due to insufficient input sanitization and output escaping on the shor...

Published: May 08, 2026
Source: NVD
CVE-2026-7475 MEDIUM - 6.4

The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to, and including, 3.3.2. This is due to the custom post type being registered with `capability_type => 'post'` and `show_in_rest => true`...

Published: May 08, 2026
Source: NVD
CVE-2026-5341 MEDIUM - 6.4

The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...

Published: May 08, 2026
Source: NVD
CVE-2026-4935 MEDIUM - 6.5

The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

Published: May 08, 2026
Source: NVD
CVE-2025-67886 MEDIUM - 6.3

Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged us...

Published: May 08, 2026
Source: NVD
CVE-2024-33724 MEDIUM - 5.4

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

Published: May 08, 2026
Source: NVD
CVE-2024-33722 MEDIUM - 6.3

SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

Published: May 08, 2026
Source: NVD
CVE-2024-30167 MEDIUM - 6.3

/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.

Published: May 08, 2026
Source: NVD
CVE-2023-47268 MEDIUM - 5.3

In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.

Vendor: prusa3d
Product: prusaslicer
Published: May 08, 2026
Source: NVD
CVE-2026-42279 MEDIUM - 5.8

solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization when the caller has time-entries:update:all in the URL organization, allowing a known foreign time-ent...

Vendor: solidtime-io
Product: solidtime
Published: May 08, 2026
Source: NVD
CVE-2026-42277 MEDIUM - 6.5

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the caller is authenticated but never checks that the ...

Vendor: onyx-dot-app
Product: onyx
Published: May 08, 2026
Source: NVD
CVE-2026-42276 MEDIUM - 4.3

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session belongs to the call...

Vendor: onyx-dot-app
Product: onyx
Published: May 08, 2026
Source: NVD
CVE-2023-42345 MEDIUM - 6.1

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

Published: May 08, 2026
Source: NVD
CVE-2023-42343 MEDIUM - 6.1

A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

Published: May 08, 2026
Source: NVD
CVE-2022-45899 MEDIUM - 6.5

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

Published: May 08, 2026
Source: NVD
CVE-2022-26523 MEDIUM - 5.3

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.

Published: May 08, 2026
Source: NVD
CVE-2022-23961 MEDIUM - 6.1

In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.

Published: May 08, 2026
Source: NVD
CVE-2026-44298 MEDIUM - 4.1

Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can upload PDF invoice templates, which can call pdfContext.setOption('associated_files', ...) ins...

Vendor: kimai
Product: kimai
Published: May 08, 2026
Source: NVD