Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,720
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,661 - 6,680 of 35,133 CVEs
CVE-2026-45335 MEDIUM - 5.4

WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=InternoControle. Th...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 27, 2026
Source: NVD
CVE-2026-45027 MEDIUM - 5.9

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/Func...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: May 27, 2026
Source: NVD
CVE-2026-42790 HIGH - 8.1

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. pe...

Vendor: Erlang
Product: OTP
Published: May 27, 2026
Source: NVD
CVE-2026-38945 HIGH - 7.8

Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.

Published: May 27, 2026
Source: NVD
CVE-2026-38931 MEDIUM - 5.4

A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.

Published: May 27, 2026
Source: NVD
CVE-2026-38930 MEDIUM - 6.5

OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the name cookie parameter.

Published: May 27, 2026
Source: NVD
CVE-2025-70116 MEDIUM - 4.3

A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV).

Published: May 27, 2026
Source: NVD
CVE-2025-68712 MEDIUM - 5.5

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authen...

Published: May 27, 2026
Source: NVD
CVE-2022-41656 MEDIUM - 4.3

Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from n/a through 2.1.2.

Vendor: Bizswoop
Product: Account Manager for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-45162 HIGH - 8.0

Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub

Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation โ†’ Off-Site //host URL Injection

Vendor: composer
Product: symfony/routing
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other pla...

Published: May 27, 2026
Source: NVD
CVE-2026-9674 MEDIUM - 4.3

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.

Vendor: jenkins
Product: multijob
Published: May 27, 2026
Source: NVD
CVE-2026-6957 HIGH - 8.0

Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filesto...

Vendor: mattermost
Product: legal_hold
Published: May 27, 2026
Source: NVD

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

Vendor: Webmin
Product: Webmin
Published: May 27, 2026
Source: NVD
CVE-2026-49102 MEDIUM - 6.1

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

Vendor: Webmin
Product: Webmin
Published: May 27, 2026
Source: NVD
CVE-2026-49059 MEDIUM - 4.7

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.

Vendor: Facebook
Product: Facebook for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-49053 MEDIUM - 5.3

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

Vendor: Wpmet
Product: ElementsKit Elementor addons Lite
Published: May 27, 2026
Source: NVD
CVE-2026-49052 MEDIUM - 4.3

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

Vendor: Wpmet
Product: ElementsKit Elementor addons Lite
Published: May 27, 2026
Source: NVD