Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
Showing 6,221 - 6,240 of 13,900 CVEs
CVE-2025-46605 MEDIUM - 6.2

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-35153 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privil...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-35074 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker wit...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-35073 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command injection vulnerability. A high privileged attacker wit...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-35072 MEDIUM - 6.7

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. A hig...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-23779 MEDIUM - 6.7

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with l...

Vendor: Dell
Product: PowerProtect Data Domain
Published: Apr 17, 2026
Source: NVD
CVE-2026-6494 MEDIUM - 5.3

A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control char...

Published: Apr 17, 2026
Source: NVD
CVE-2026-6439 MEDIUM - 4.4

The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. This is due to insufficient input sanitization and output escaping in the videozen_conf() function. The 'lang' POST parameter is stored directly via update_option() without...

Published: Apr 17, 2026
Source: NVD
CVE-2026-6451 MEDIUM - 4.3

The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation on all eight AJAX deletion handlers: vehicles_cfmw_d_vehicle, contacts_cfmw_d_contact, suppliers_cfmw_d_supplier, receipt...

Published: Apr 17, 2026
Source: NVD
CVE-2026-40002 MEDIUM - 5.0

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting this vulnerability, an attacker can write files to specific par...

Vendor: ZTE
Product: Red Magic 11 Pro (NX809J)
Published: Apr 17, 2026
Source: NVD
CVE-2026-6441 MEDIUM - 4.3

The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOptions() function, which is exposed via two AJAX hooks: wp_ajax_updateOptions (class-canto.php line 231)...

Published: Apr 17, 2026
Source: NVD
CVE-2026-5797 MEDIUM - 5.3

The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_t...

Published: Apr 17, 2026
Source: NVD
CVE-2026-34018 MEDIUM - 6.3

An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.

Vendor: CubeCart Limited
Product: CubeCart
Published: Apr 17, 2026
Source: NVD
CVE-2026-6080 MEDIUM - 6.5

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on the 'date' parameter combined with direct interpolation into a SQL fragment before being passed to $wpdb->prepare(). This makes it possible fo...

Published: Apr 17, 2026
Source: NVD
CVE-2026-5502 MEDIUM - 5.3

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including 3.9.8. This is due to a missing authorization check in the tutor_update_course_content_order() function. The function only validates the...

Published: Apr 17, 2026
Source: NVD
CVE-2026-5427 MEDIUM - 5.3

The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks in the kubio_rest_pre_insert_import_assets() function, which is hooked to the rest_pre_insert_{post_type} filter for posts, pages, templates, and...

Published: Apr 17, 2026
Source: NVD
CVE-2026-5234 MEDIUM - 5.3

The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::create_payment_intent_for_transaction action is registered as a public action (no authentication required)...

Published: Apr 17, 2026
Source: NVD
CVE-2026-4853 MEDIUM - 4.9

The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3.1.19.8. This is due to insufficient input validation on the fileName parameter in the file upload handler. The plugin sanitizes...

Published: Apr 17, 2026
Source: NVD
CVE-2026-3330 MEDIUM - 4.9

The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Li...

Published: Apr 17, 2026
Source: NVD
CVE-2026-5052 MEDIUM - 5.3

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1....

Vendor: go
Product: github.com/hashicorp/vault
Published: Apr 17, 2026
Source: NVD