Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,702
Quick preset (or use dates below)
Clear Filters
Showing 4,301 - 4,320 of 13,195 CVEs
CVE-2026-45214 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xpro Elementor Addons: from n/a through <= 1.5.1.

Vendor: Xpro
Product: Xpro Elementor Addons
Published: May 12, 2026
Source: NVD
CVE-2026-45213 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1.

Vendor: RealMag777
Product: BEAR
Published: May 12, 2026
Source: NVD
CVE-2026-45211 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.1.

Vendor: Saad Iqbal
Product: APIExperts Square for WooCommerce
Published: May 12, 2026
Source: NVD
CVE-2026-42742 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6.

Vendor: Aman
Product: Views for WPForms
Published: May 12, 2026
Source: NVD
CVE-2026-42741 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend views-for-ninja-forms allows Blind SQL Injection.This issue affects Ninja Forms View...

Vendor: Aman
Product: Ninja Forms Views &#8211; Display &amp; Edit Ninja Forms Submissions on your site frontend
Published: May 12, 2026
Source: NVD
CVE-2026-41713 HIGH - 8.2

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.

Vendor: VMware
Product: Spring AI
Published: May 12, 2026
Source: NVD
CVE-2026-41712 HIGH - 7.5

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

Vendor: VMware
Product: Spring AI
Published: May 12, 2026
Source: NVD
CVE-2026-2465 HIGH - 8.8

Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026.

Published: May 12, 2026
Source: NVD
CVE-2026-8162 HIGH - 7.5

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value without try/catch. The...

Vendor: pillarjs
Product: multiparty
Published: May 12, 2026
Source: NVD
CVE-2026-8161 HIGH - 7.5

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.prototype property such as __proto__, constructor, or toString, the parser invokes .push() on the inherite...

Vendor: pillarjs
Product: multiparty
Published: May 12, 2026
Source: NVD
CVE-2026-8159 HIGH - 7.5

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a long header value can cause regex matching to take seconds, blocking the event loop. Impact: any service...

Vendor: pillarjs
Product: multiparty
Published: May 12, 2026
Source: NVD
CVE-2026-6001 HIGH - 8.8

Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042.

Published: May 12, 2026
Source: NVD
CVE-2026-44412 HIGH - 7.8

A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

Vendor: Siemens
Product: Solid Edge SE2026
Published: May 12, 2026
Source: NVD
CVE-2026-44411 HIGH - 7.8

A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted PAR files. An attacker could leverage this vulnerability to execute code in the context of the current ...

Vendor: Siemens
Product: Solid Edge SE2026
Published: May 12, 2026
Source: NVD
CVE-2026-33893 HIGH - 7.5

A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application contain...

Vendor: Siemens
Product: Teamcenter V2312, Teamcenter V2406, Teamcenter V2412, Teamcenter V2506, Teamcenter V2512
Published: May 12, 2026
Source: NVD
CVE-2026-33862 HIGH - 7.3

A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does no...

Vendor: Siemens
Product: Teamcenter V2312, Teamcenter V2406, Teamcenter V2412, Teamcenter V2506, Teamcenter V2512
Published: May 12, 2026
Source: NVD
CVE-2026-27662 HIGH - 7.7

Affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security mechanisms are in place. This could allow an unauthenticated attacker to gain unauthorized access to the web browser, potentially enabling the discovery of backdoors, performing ...

Published: May 12, 2026
Source: NVD
CVE-2026-25789 HIGH - 7.1

Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file to be uploaded. This would result in malitcious JavaScript execution in the context of the authentic...

Published: May 12, 2026
Source: NVD
CVE-2026-22925 HIGH - 7.5

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This could allow an attacker to render the service unavailable and cause denial-of-service conditions by o...

Vendor: Siemens
Product: SIMATIC CN 4100
Published: May 12, 2026
Source: NVD
CVE-2025-40947 HIGH - 7.5

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM...

Vendor: Siemens
Product: RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, RUGGEDCOM ROX RX1510, RUGGEDCOM ROX RX1511, RUGGEDCOM ROX RX1512, RUGGEDCOM ROX RX1524, RUGGEDCOM ROX RX1536, RUGGEDCOM ROX RX5000
Published: May 12, 2026
Source: NVD