Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
Showing 4,241 - 4,260 of 13,630 CVEs
CVE-2026-8081 MEDIUM - 6.3

A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploit...

Vendor: router-for-me
Product: cliproxyapi
Published: May 07, 2026
Source: NVD
CVE-2026-40610 MEDIUM - 5.5

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifac...

Vendor: pip
Product: bentoml
Published: May 07, 2026
Source: GitHub
CVE-2026-36388 MEDIUM - 5.4

A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application an...

Published: May 07, 2026
Source: NVD
CVE-2026-36387 MEDIUM - 6.5

A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE.

Published: May 07, 2026
Source: NVD
CVE-2026-36341 MEDIUM - 5.4

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint

Published: May 07, 2026
Source: NVD
CVE-2025-4397 MEDIUM - 6.8

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

Published: May 07, 2026
Source: NVD
CVE-2025-4386 MEDIUM - 6.8

Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.โ€‹

Published: May 07, 2026
Source: NVD
CVE-2026-41689 MEDIUM - 6.0

Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an administrator-configured local-target allowlist for every logged-in user. Any normal user can fully control a webhook URL, headers, and body, then use Wallos...

Vendor: ellite
Product: Wallos
Published: May 07, 2026
Source: NVD
CVE-2026-41687 MEDIUM - 4.3

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in endpoints/subscription/add.php (line 42) and endpoints/payments/add.php (line 40) uses an inline IP validation check (FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE) that does ...

Vendor: ellite
Product: Wallos
Published: May 07, 2026
Source: NVD

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decimal.new("1e1000000000")) is accepted without error. Su...

Vendor: ericmj
Product: decimal
Published: May 07, 2026
Source: NVD
CVE-2025-67202 MEDIUM - 6.1

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

Published: May 07, 2026
Source: NVD
CVE-2026-8080 MEDIUM - 5.4

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template element attribute handling logic. The app...

Vendor: misp
Product: misp
Published: May 07, 2026
Source: NVD
CVE-2026-33589 MEDIUM - 6.5

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.

Vendor: Open Notebook
Product: Open Notebook
Published: May 07, 2026
Source: NVD
CVE-2026-27415 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affects BEAR: from n/a through 1.1.5.

Vendor: PluginUs.Net
Product: BEAR
Published: May 07, 2026
Source: NVD
CVE-2026-44407 MEDIUM - 4.7

A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.

Vendor: ZTE
Product: ZXCLOUD iRAI
Published: May 07, 2026
Source: NVD
CVE-2026-27421 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.

Vendor: WProyal
Product: Royal Elementor Addons
Published: May 07, 2026
Source: NVD
CVE-2026-27416 MEDIUM - 5.3

Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.

Vendor: bPlugins
Product: PDF Poster
Published: May 07, 2026
Source: NVD
CVE-2026-27329 MEDIUM - 5.3

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: from n/a through 4.12.0.

Vendor: YITH
Product: YITH WooCommerce Wishlist
Published: May 07, 2026
Source: NVD
CVE-2026-25468 MEDIUM - 5.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8.

Vendor: weDevs
Product: Happy Addons for Elementor
Published: May 07, 2026
Source: NVD
CVE-2026-25436 MEDIUM - 5.3

Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.

Vendor: WProyal
Product: Royal Elementor Addons
Published: May 07, 2026
Source: NVD