Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,815
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,001 - 5,020 of 13,483 CVEs
CVE-2026-6525 MEDIUM - 5.5

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

Vendor: wireshark
Product: wireshark
Published: May 02, 2026
Source: NVD
CVE-2026-4790 MEDIUM - 5.4

The Premium Addons for Elementor โ€“ Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and including, 4.11.70 due to insufficient input sanitization and output escaping. This makes it...

Published: May 02, 2026
Source: NVD
CVE-2026-7627 MEDIUM - 6.3

A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component sync_ea_from_file. Such manipulation of the argument ea_name leads to path traversal. The attack can be launched remotel...

Published: May 02, 2026
Source: NVD
CVE-2026-7612 MEDIUM - 4.7

A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the file /edit_user.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be...

Published: May 02, 2026
Source: NVD
CVE-2026-7609 MEDIUM - 6.3

A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been published...

Vendor: trendnet
Product: tew-821dap_firmware
Published: May 02, 2026
Source: NVD
CVE-2026-5077 MEDIUM - 5.4

The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping when rendering the_title() inside HTML attribute context in the home blog section template. This makes it possible for authenticated ...

Published: May 02, 2026
Source: NVD
CVE-2026-7608 MEDIUM - 5.5

A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exploit is now public and may be used. The vendor explains: "That firmware version will only work on our hardware versi...

Vendor: trendnet
Product: tew-821dap_firmware
Published: May 02, 2026
Source: NVD
CVE-2026-4024 MEDIUM - 5.3

The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax` and `wp_ajax_nopriv` h...

Published: May 02, 2026
Source: NVD
CVE-2026-6457 MEDIUM - 6.5

The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to, and including, 1.13.19 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu...

Published: May 02, 2026
Source: NVD
CVE-2026-6449 MEDIUM - 5.3

The Booking for Appointments and Events Calendar โ€“ Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking ha...

Published: May 02, 2026
Source: NVD
CVE-2026-4650 MEDIUM - 5.3

The FundPress โ€“ WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and including 2.0.8. This is due to missing authorization and nonce verification in the donate_action_status() AJAX handler, which is registered to be accessible to unauthenticated users v...

Published: May 02, 2026
Source: NVD
CVE-2026-7605 MEDIUM - 6.3

A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file CommonController.java of the component uploadImgByHttpE...

Published: May 02, 2026
Source: NVD
CVE-2026-6916 MEDIUM - 6.4

The Jeg Kit for Elementor โ€“ Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sg_content_number_prefix' parameter in all versions up to, and including, 3.1.0 due to insufficient input sanitization...

Published: May 02, 2026
Source: NVD
CVE-2026-6812 MEDIUM - 4.4

The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via the ona_activate_child_theme. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating...

Published: May 02, 2026
Source: NVD
CVE-2026-6447 MEDIUM - 4.4

The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

Published: May 02, 2026
Source: NVD
CVE-2026-7604 MEDIUM - 6.3

A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiController.call of the file OpenApiController.java of the component OpenApi Service. Such manipulation of the argument originUrl database leads to server-side request forgery. It is possib...

Published: May 02, 2026
Source: NVD
CVE-2026-7603 MEDIUM - 6.3

A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch of the file FileDownloadUtils.jav of the component LoadFile Endpoint. This manipulation of the argument files causes server-side request forgery. It is possible to initiate the att...

Published: May 02, 2026
Source: NVD
CVE-2026-6446 MEDIUM - 5.4

The My Social Feeds โ€“ Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability verification) and no...

Published: May 02, 2026
Source: NVD
CVE-2026-4658 MEDIUM - 6.4

The Essential Blocks โ€“ Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and including, 6.0.4. T...

Published: May 02, 2026
Source: NVD
CVE-2025-14726 MEDIUM - 6.5

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpo...

Vendor: trustindex
Product: Widgets for Social Photo Feed
Published: May 02, 2026
Source: NVD