Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,741 - 5,760 of 34,871 CVEs

Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.

Vendor: Acer
Product: Predator Connect W6x
Published: May 29, 2026
Source: NVD

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

Vendor: Acer
Product: Predator Connect W6x
Published: May 29, 2026
Source: NVD

The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.

Vendor: Acer
Product: Predator Connect W6x
Published: May 29, 2026
Source: NVD

Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.

Vendor: Acer
Product: Predator Connect W6x
Published: May 29, 2026
Source: NVD
CVE-2026-10058 MEDIUM - 4.8

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

Vendor: ITP Technology
Product: ITS Intelligent SCADA System
Published: May 29, 2026
Source: NVD
CVE-2026-10057 MEDIUM - 4.8

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

Vendor: ITP Technology
Product: ITS Intelligent SCADA System
Published: May 29, 2026
Source: NVD
CVE-2026-10056 HIGH - 7.5

CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeove...

Vendor: Network Optix
Product: Nx Witness VMS
Published: May 29, 2026
Source: NVD
CVE-2026-10052 MEDIUM - 4.1

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network ...

Vendor: Red Hat
Product: Red Hat Quay 3
Published: May 29, 2026
Source: NVD
CVE-2026-10039 MEDIUM - 4.9

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...

Vendor: shabti
Product: Frontend Admin by DynamiApps
Published: May 29, 2026
Source: NVD
CVE-2026-9243 MEDIUM - 6.4

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the ca...

Published: May 29, 2026
Source: NVD
CVE-2026-4776 HIGH - 7.1

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.

Published: May 29, 2026
Source: NVD
CVE-2026-49322 MEDIUM - 4.3

Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Inf...

Vendor: Indian Motorcycle (Polaris Inc.)
Product: Scout Bobber + Tech
Published: May 29, 2026
Source: NVD
CVE-2026-3655 CRITICAL - 9.8

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the ...

Published: May 29, 2026
Source: NVD
CVE-2025-11262 HIGH - 7.2

The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Vendor: linkwhspr
Product: Link Whisper Free
Published: May 29, 2026
Source: NVD
CVE-2026-9714 MEDIUM - 6.4

The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and including, 1.2 This is due to insufficient input sanitization and output escaping in the showmodule_shortcode() function, ...

Published: May 29, 2026
Source: NVD
CVE-2026-9493 MEDIUM - 6.5

Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific query function to access other users' EC order details.

Published: May 29, 2026
Source: NVD
CVE-2026-8732 CRITICAL - 9.8

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call...

Published: May 29, 2026
Source: NVD
CVE-2026-6324 MEDIUM - 4.8

A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious HTTP request. This vulnerability occurs when libsoup operates behind a non-libsoup proxy server or as a proxy in front of...

Published: May 29, 2026
Source: NVD
CVE-2026-6275 MEDIUM - 6.4

The StatCounter โ€“ Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The function is hooked to w...

Published: May 29, 2026
Source: NVD
CVE-2025-14042 MEDIUM - 6.4

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in all versions up to, and including, 13.4.1. This is due to insufficient input sanitization and output escaping on us...

Vendor: themesuite
Product: Automotive Car Dealership Business WordPress Theme
Published: May 29, 2026
Source: NVD