Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,642
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 4,361 - 4,380 of 13,359 CVEs
CVE-2025-67202 MEDIUM - 6.1

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

Published: May 07, 2026
Source: NVD
CVE-2026-8080 MEDIUM - 5.4

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template element attribute handling logic. The app...

Vendor: misp
Product: misp
Published: May 07, 2026
Source: NVD
CVE-2026-33589 MEDIUM - 6.5

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.

Vendor: Open Notebook
Product: Open Notebook
Published: May 07, 2026
Source: NVD
CVE-2026-27415 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affects BEAR: from n/a through 1.1.5.

Vendor: PluginUs.Net
Product: BEAR
Published: May 07, 2026
Source: NVD
CVE-2026-44407 MEDIUM - 4.7

A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.

Vendor: ZTE
Product: ZXCLOUD iRAI
Published: May 07, 2026
Source: NVD
CVE-2026-27421 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.

Vendor: WProyal
Product: Royal Elementor Addons
Published: May 07, 2026
Source: NVD
CVE-2026-27416 MEDIUM - 5.3

Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.

Vendor: bPlugins
Product: PDF Poster
Published: May 07, 2026
Source: NVD
CVE-2026-27329 MEDIUM - 5.3

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: from n/a through 4.12.0.

Vendor: YITH
Product: YITH WooCommerce Wishlist
Published: May 07, 2026
Source: NVD
CVE-2026-25468 MEDIUM - 5.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elementor allows Retrieve Embedded Sensitive Data. This issue affects Happy Addons for Elementor: from n/a through 3.20.8.

Vendor: weDevs
Product: Happy Addons for Elementor
Published: May 07, 2026
Source: NVD
CVE-2026-25436 MEDIUM - 5.3

Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.

Vendor: WProyal
Product: Royal Elementor Addons
Published: May 07, 2026
Source: NVD
CVE-2025-68604 MEDIUM - 5.4

Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGraphQL: from n/a through 2.5.3.

Vendor: WPGraphQL
Product: WPGraphQL
Published: May 07, 2026
Source: NVD
CVE-2025-66105 MEDIUM - 5.3

Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8.

Vendor: Magepeople inc.
Product: Bus Ticket Booking with Seat Reservation
Published: May 07, 2026
Source: NVD
CVE-2025-62127 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Logo Slider allows DOM-Based XSS. This issue affects WEN Logo Slider: from n/a through 3.4.0.

Vendor: WEN Themes
Product: WEN Logo Slider
Published: May 07, 2026
Source: NVD
CVE-2025-2514 MEDIUM - 5.3

Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Bl...

Vendor: hitachi
Product: virtual_storage_one_block
Published: May 07, 2026
Source: NVD
CVE-2026-44406 MEDIUM - 5.7

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServic...

Vendor: ZTE
Product: ZXCLOUD iRAI
Published: May 07, 2026
Source: NVD
CVE-2026-8063 MEDIUM - 6.5

An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggregation pipeline to determine whether it begins with an Atlas Search stage. For $rankFusion and $scoreFusion, this inspection reads th...

Vendor: mongodb
Product: mongodb
Published: May 07, 2026
Source: NVD
CVE-2026-41413 MEDIUM - 5.0

Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a RequestAuthentication resource is created with a jwksUri pointing to an internal service, istiod makes an unauthenticated HTTP GET request to that URL without filtering out localhost o...

Vendor: istio
Product: istio
Published: May 07, 2026
Source: NVD
CVE-2026-44248 MEDIUM - 5.3

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the by...

Vendor: maven
Product: io.netty:netty-codec-mqtt
Published: May 07, 2026
Source: GitHub
CVE-2026-44003 MEDIUM - 5.3

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain catch, import, or async keywords. This fast-path bypass allows sandboxed code to directly access the internal VM2_INTERNAL_...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub
CVE-2026-44002 MEDIUM - 5.8

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandb...

Vendor: npm
Product: vm2
Published: May 07, 2026
Source: GitHub