Total CVEs

132,383

Critical Severity

2,838

High Severity

10,163

Last 7 Days

1,761
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,341 - 4,360 of 28,788 CVEs
CVE-2021-47922 MEDIUM - 6.4

Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of use...

Vendor: Soliloquywp
Product: Slider by Soliloquy
Published: May 10, 2026
Source: NVD
CVE-2021-47910 MEDIUM - 6.4

AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that...

Vendor: Accesspressthemes
Product: AccessPress Social Icons
Published: May 10, 2026
Source: NVD
CVE-2021-47907 MEDIUM - 6.4

Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers o...

Vendor: Rocketsoft
Product: Rocket LMS
Published: May 10, 2026
Source: NVD
CVE-2026-8244 MEDIUM - 5.3

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI Interface. The manipulation of the argument clientVersion leads to improper authentication. It is possible to initiate the attack remotely. The exploit i...

Published: May 10, 2026
Source: NVD
CVE-2026-8243 MEDIUM - 5.3

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be performed from remote. The vendor was conta...

Published: May 10, 2026
Source: NVD
CVE-2026-8242 LOW - 3.7

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The attack is possible to be carried out remotely. A high degree...

Published: May 10, 2026
Source: NVD
CVE-2026-8241 MEDIUM - 5.3

A vulnerability has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to ...

Published: May 10, 2026
Source: NVD
CVE-2026-8235 MEDIUM - 5.5

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulation results in os command injection. The exploit is now public and may be used. The patch is identified...

Published: May 10, 2026
Source: NVD
CVE-2026-8234 HIGH - 8.8

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has...

Published: May 10, 2026
Source: NVD

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Vendor: libexpat project
Product: libexpat
Published: May 10, 2026
Source: NVD
CVE-2026-8233 MEDIUM - 4.6

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The vendor was contacte...

Published: May 10, 2026
Source: NVD
CVE-2026-8232 LOW - 3.5

A vulnerability was found in Dotouch XproUPF 2.0.0-release-088aa7c4. This impacts the function vlib_worker_loop in the library /usr/xpro/upf/tools/libs/libvlib.so of the component UPF Process. The manipulation results in denial of service. The vendor was contacted early about this disclosure.

Published: May 10, 2026
Source: NVD
CVE-2026-8231 MEDIUM - 6.3

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public ...

Published: May 10, 2026
Source: NVD
CVE-2026-7263 HIGH - 7.5

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial...

Vendor: php
Product: php
Published: May 10, 2026
Source: NVD
CVE-2026-6104 CRITICAL - 9.1

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead ...

Vendor: php
Product: php
Published: May 10, 2026
Source: NVD
CVE-2026-8230 MEDIUM - 6.3

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The ...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: May 10, 2026
Source: NVD
CVE-2026-8229 MEDIUM - 6.3

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Remote exploitation of the attack is possible. The exploit is now...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: May 10, 2026
Source: NVD
CVE-2026-8228 MEDIUM - 6.3

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command injection. The attack may be launched remotely. The exploit has been ...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: May 10, 2026
Source: NVD
CVE-2026-8227 MEDIUM - 6.3

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The ...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: May 10, 2026
Source: NVD
CVE-2026-8226 MEDIUM - 5.3

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public ...

Vendor: open5gs
Product: open5gs
Published: May 10, 2026
Source: NVD