Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,970
Quick preset (or use dates below)
Clear Filters
Showing 441 - 460 of 3,520 CVEs
CVE-2023-54352 CRITICAL - 9.8

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and...

Vendor: WP Travel Kit
Product: Travelscape
Published: Jun 08, 2026
Source: NVD
CVE-2026-45779 CRITICAL - 9.8

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQL statements. Exploitation requires no authentication or user interaction and ca...

Vendor: ubccr
Product: xdmod
Published: Jun 05, 2026
Source: NVD
CVE-2026-45777 CRITICAL - 9.8

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web server hosting Open XDMoD with the privileges of the web server process. This could allow an attacker ...

Vendor: ubccr
Product: xdmod
Published: Jun 05, 2026
Source: NVD
CVE-2026-46389 CRITICAL - 10.0

UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak client authenticator (shipped by `uds-identity-config` an...

Vendor: defenseunicorns
Product: uds-identity-config
Published: Jun 05, 2026
Source: NVD
CVE-2026-10580 CRITICAL - 9.8

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel ...

Vendor: hippooo
Product: Hippoo Mobile App for WooCommerce
Published: Jun 05, 2026
Source: NVD
CVE-2026-45750 CRITICAL - 9.0

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the Termix File Manager component unsafely processes the path parameter and embeds it into a shell command execu...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45748 CRITICAL - 9.8

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 builds an SSH tunnel command by interpolating user-controlled host record fields (`endpointIP`, `endpointUsername`, `...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45746 CRITICAL - 9.0

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manager functionality in Termix contains a critical Broken Access Control vulnerability due to improper validation of the sessionId parameter. The backend tr...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-45744 CRITICAL - 9.9

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in Termix is vulnerable to OS command injection. The endpoint uses double-quote escaping for shell command construc...

Vendor: Termix-SSH
Product: Termix
Published: Jun 05, 2026
Source: NVD
CVE-2026-36500 CRITICAL - 9.1

An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.

Published: Jun 05, 2026
Source: NVD
CVE-2025-71318 CRITICAL - 9.8

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including L...

Vendor: Riello UPS
Product: NetMan 204
Published: Jun 05, 2026
Source: NVD
CVE-2025-71317 CRITICAL - 9.8

NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which du...

Vendor: Riello UPS
Product: NetMan 204
Published: Jun 05, 2026
Source: NVD
CVE-2026-47731 CRITICAL - 9.1

NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)

Vendor: pip
Product: ait-core
Published: Jun 05, 2026
Source: GitHub

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

Vendor: npm
Product: dbgate-api
Published: Jun 05, 2026
Source: GitHub

DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

Vendor: npm
Product: dbgate
Published: Jun 05, 2026
Source: GitHub
CVE-2026-47668 CRITICAL - 10.0

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

Vendor: npm
Product: dbgate-serve
Published: Jun 05, 2026
Source: GitHub
CVE-2026-9270 CRITICAL - 9.1

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change...

Vendor: binary
Product: datadog\
Published: Jun 05, 2026
Source: NVD
CVE-2026-11362 CRITICAL - 9.8

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, w...

Vendor: BINARY
Product: DataDog::DogStatsd
Published: Jun 05, 2026
Source: NVD
CVE-2026-10879 CRITICAL - 9.8

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four...

Vendor: HMBRAND
Product: DBI
Published: Jun 05, 2026
Source: NVD
CVE-2026-6274 CRITICAL - 9.8

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.

Published: Jun 05, 2026
Source: NVD