Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,806
Quick preset (or use dates below)
Clear Filters
Showing 6,721 - 6,740 of 13,934 CVEs
CVE-2026-6030 MEDIUM - 6.3

A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /del1.php. This manipulation of the argument toolname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Published: Apr 10, 2026
Source: NVD
CVE-2026-4432 MEDIUM - 6.5

The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, m...

Published: Apr 10, 2026
Source: NVD
CVE-2025-14545 MEDIUM - 6.5

The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process.

Vendor: Unknown
Product: YML for Yandex Market
Published: Apr 10, 2026
Source: NVD
CVE-2026-6011 MEDIUM - 5.6

A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fetch.ts of the component assertPublicHostname Handler. Executing a manipulation can lead to server-side request forgery. The attack can be executed remot...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6010 MEDIUM - 6.3

A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Performing a manipulation of the argument Q1 results in sql injection. Remote exploitation of the attack i...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6007 MEDIUM - 6.3

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

Published: Apr 10, 2026
Source: NVD
CVE-2026-6006 MEDIUM - 6.3

A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the pu...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6005 MEDIUM - 6.3

A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument hem_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been pu...

Published: Apr 10, 2026
Source: NVD
CVE-2026-2305 MEDIUM - 6.4

The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_code`, `aFhfc_body_code`, and `aFhfc_footer_code` post meta values in all versions up to, and including, 2.3. This is due to the plugin outputting these meta values without any sa...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6000 MEDIUM - 4.3

A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The expl...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5999 MEDIUM - 6.3

A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confi...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5998 MEDIUM - 5.3

A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. The e...

Published: Apr 10, 2026
Source: NVD
CVE-2026-4977 MEDIUM - 4.3

The UsersWP โ€“ Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level permission validation in the upload_file_remove() AJAX handle...

Published: Apr 10, 2026
Source: NVD
CVE-2026-4664 MEDIUM - 5.3

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta...

Published: Apr 10, 2026
Source: NVD
CVE-2026-4305 MEDIUM - 6.1

The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' parameter in all versions up to, and including, 1.0.16 due to insufficient input validation. This makes it possible for unauthenticated attack...

Published: Apr 10, 2026
Source: NVD
CVE-2026-4057 MEDIUM - 4.3

The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capab...

Published: Apr 10, 2026
Source: NVD
CVE-2026-2712 MEDIUM - 5.4

The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability checks in the `receive_heartbeat()` function in `includes/class-wp-optimize-heartbeat.php` in all versions up to, and including, 4.5.0. This is due to the Heartbeat handler directly i...

Published: Apr 10, 2026
Source: NVD
CVE-2026-1924 MEDIUM - 4.3

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on the `ahsc_ajax_reset_options()` function. This makes it possible for unauthenticated attackers to reset all plugin settin...

Published: Apr 10, 2026
Source: NVD
CVE-2026-1263 MEDIUM - 6.4

The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.0 due to insufficient input sanitization, insufficient output escaping, and missing capabilities checks in the 'webling_admin_save_form' and 'webling_admin_save_memb...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5987 MEDIUM - 4.7

A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemarkerView.java of the component FreeMarker Template Handler. Su...

Published: Apr 09, 2026
Source: NVD