Total CVEs

140,303

Critical Severity

3,711

High Severity

13,353

Last 7 Days

1,801
Quick preset (or use dates below)
Clear Filters
Showing 5,321 - 5,340 of 13,353 CVEs
CVE-2026-7607 HIGH - 8.8

A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Udpate. The manipulation of the argument str leads to buffer overflow. The attack may be initiated remotely. The vendor explains: "That firmware ver...

Vendor: trendnet
Product: tew-821dap_firmware
Published: May 02, 2026
Source: NVD
CVE-2026-6229 HIGH - 7.2

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadshee...

Published: May 02, 2026
Source: NVD
CVE-2026-2052 HIGH - 8.8

The Widget Options โ€“ Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on user-supplied Display Logic...

Published: May 02, 2026
Source: NVD
CVE-2026-7647 HIGH - 8.1

The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the wppb_request_users_pins_action_callba...

Published: May 02, 2026
Source: NVD
CVE-2026-7049 HIGH - 7.2

The PixelYourSite Pro โ€“ Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 via the scan_video. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating fro...

Published: May 02, 2026
Source: NVD
CVE-2026-5113 HIGH - 7.2

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escap...

Published: May 02, 2026
Source: NVD
CVE-2026-5112 HIGH - 7.2

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate()...

Published: May 02, 2026
Source: NVD
CVE-2026-5111 HIGH - 7.2

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validati...

Published: May 02, 2026
Source: NVD
CVE-2026-5110 HIGH - 7.2

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nes...

Published: May 02, 2026
Source: NVD
CVE-2026-5109 HIGH - 7.2

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted valu...

Published: May 02, 2026
Source: NVD
CVE-2026-7641 HIGH - 8.8

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary sit...

Published: May 02, 2026
Source: NVD
CVE-2026-6963 HIGH - 8.8

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update...

Published: May 02, 2026
Source: NVD
CVE-2026-43824 HIGH - 7.7

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

Vendor: argoproj
Product: Argo CD
Published: May 02, 2026
Source: NVD
CVE-2026-7598 HIGH - 7.3

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is ...

Vendor: libssh2
Product: libssh2
Published: May 01, 2026
Source: NVD
CVE-2026-7594 HIGH - 7.3

A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the component MCP Interface. The manipulation of the argument statusFile results in path traversal. The attack can be executed remotely. The exploit is now public ...

Published: May 01, 2026
Source: NVD
CVE-2026-7593 HIGH - 7.3

A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the component MCP Interface. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The...

Published: May 01, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembly path in 'Elixir.Bandit.WebSocket.Connection':handle_frame/3 in lib/bandit/websocket/connection.ex appends eve...

Vendor: mtrudel
Product: bandit
Published: May 01, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage-deflate compression is enabled. 'Elixir.Bandit.WebSocket.PerMessageDeflate':inflate/2 in lib/bandit/websocke...

Vendor: mtrudel
Product: bandit
Published: May 01, 2026
Source: NVD
CVE-2026-7592 HIGH - 7.3

A weakness has been identified in itsourcecode Courier Management System 1.0. This affects an unknown function of the file /edit_staff.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public an...

Published: May 01, 2026
Source: NVD
CVE-2026-7590 HIGH - 7.3

A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The affected element is an unknown function of the file branch_monkey_mcp/bridge_and_local_actions/routes/advanced.py of the component Preview Endpoint. Such manipulation of the argument...

Published: May 01, 2026
Source: NVD