Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 5,961 - 5,980 of 12,679 CVEs
CVE-2026-30459 HIGH - 7.1

An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.

Vendor: thedaylightstudio
Product: fuel_cms
Published: Apr 16, 2026
Source: NVD
CVE-2026-5785 HIGH - 8.1

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.

Published: Apr 16, 2026
Source: NVD
CVE-2026-3489 HIGH - 7.5

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ...

Published: Apr 16, 2026
Source: NVD
CVE-2026-23772 HIGH - 7.3

Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: Storage Manager
Published: Apr 16, 2026
Source: NVD
CVE-2024-2374 HIGH - 7.5

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources...

Vendor: wso2
Product: api_manager
Published: Apr 16, 2026
Source: NVD
CVE-2025-14868 HIGH - 8.8

The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform...

Vendor: shahinurislam
Product: Career Section
Published: Apr 16, 2026
Source: NVD
CVE-2026-41035 HIGH - 7.4

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerab...

Vendor: Samba
Product: rsync
Published: Apr 16, 2026
Source: NVD
CVE-2026-3876 HIGH - 7.2

The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismati...

Published: Apr 16, 2026
Source: NVD
CVE-2026-1620 HIGH - 8.8

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insufficient sanitization of the template name parameter in the `lae_get_template_part()` function, which uses an inadequate `str_replace()` approach...

Published: Apr 16, 2026
Source: NVD
CVE-2026-5050 HIGH - 7.5

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 7.0.0 due to successful_request() handlers calculating a local signature but not validating Ds_Signature from the request bef...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3614 HIGH - 8.8

The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing capability check on the `wp_ajax_acymailing_router` AJAX handler. This makes it possible for authenticated attackers, with Subscriber-level access and a...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3599 HIGH - 7.5

The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-json/InkXEProductDesignerLite/add-item-to-cart REST API endpoint in all versions up to, and including, 2.1.2. This is due to insuffic...

Published: Apr 16, 2026
Source: NVD
CVE-2026-22619 HIGH - 7.8

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package.Β This security issue has been fixed in the latest version of Eaton IPP software which is available on the...

Vendor: Eaton
Product: IPP software
Published: Apr 16, 2026
Source: NVD
CVE-2023-3634 HIGH - 8.8

In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of undocumented test mode which could lead to a complete loss of confidentiality, integrity and availability.

Published: Apr 16, 2026
Source: NVD
CVE-2026-6351 HIGH - 7.5

MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files.

Published: Apr 16, 2026
Source: NVD
CVE-2026-6348 HIGH - 8.8

WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed.

Published: Apr 16, 2026
Source: NVD
CVE-2026-41015 HIGH - 7.4

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1....

Vendor: radare
Product: radare2
Published: Apr 16, 2026
Source: NVD
CVE-2026-40474 HIGH - 7.6

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permission is never enforced at runtime. Since GymConfig is...

Vendor: pip
Product: wger
Published: Apr 16, 2026
Source: GitHub
CVE-2026-40960 HIGH - 8.1

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.

Vendor: Luanti
Product: Luanti
Published: Apr 16, 2026
Source: NVD
CVE-2026-40502 HIGH - 8.8

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execut...

Vendor: HKUDS
Product: OpenHarness
Published: Apr 16, 2026
Source: NVD