Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,669
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,821 - 6,840 of 13,554 CVEs
CVE-2026-34757 MEDIUM - 5.1

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_stru...

Vendor: pnggroup
Product: libpng
Published: Apr 09, 2026
Source: NVD
CVE-2025-70811 MEDIUM - 4.3

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality.

Published: Apr 09, 2026
Source: NVD
CVE-2025-45806 MEDIUM - 6.1

A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Published: Apr 09, 2026
Source: NVD
CVE-2026-3005 MEDIUM - 6.4

The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' shortcode in all versions up to, and including, 0.94.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo...

Published: Apr 09, 2026
Source: NVD
CVE-2026-2519 MEDIUM - 5.3

The Online Scheduling and Appointment Booking System โ€“ Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the co...

Published: Apr 09, 2026
Source: NVD
CVE-2026-34538 MEDIUM - 6.5

Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model d...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 09, 2026
Source: NVD
CVE-2026-5848 MEDIUM - 4.7

A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler. Performing a manipulation of the argument dbUrl results in code injection. The atta...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5847 MEDIUM - 4.3

A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file /db/moviedb.sql of the component SQL Database Backup File Handler. Such manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disc...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5840 MEDIUM - 4.7

A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /admin/check_availability.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been relea...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5839 MEDIUM - 4.7

A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the file /admin/add-subcategory.php. Such manipulation of the argument sucatdescription leads to sql injection. The attack may be launched remotely. The exploit is publicly available a...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5838 MEDIUM - 4.7

A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5742 MEDIUM - 6.4

The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data in badge widgets. This makes it possible for ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4336 MEDIUM - 6.4

The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.ph...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5833 MEDIUM - 5.3

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been dis...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5357 MEDIUM - 6.4

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4429 MEDIUM - 6.4

The OSM โ€“ OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attribute of the [osm_map_v3] shortcode in all versions up to and including 6.1.15. This is due to insufficient input sanitization and o...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4124 MEDIUM - 5.4

The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler only verifies a nonce (check_ajax_referer) but performs no capability checks via current_user_can(). Furthermore, the nonce ('ziggeo_ajax_nonce�...

Published: Apr 09, 2026
Source: NVD
CVE-2026-3574 MEDIUM - 4.4

The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Fo...

Published: Apr 09, 2026
Source: NVD
CVE-2026-3568 MEDIUM - 4.3

The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist,...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5831 MEDIUM - 6.3

A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading to...

Published: Apr 09, 2026
Source: NVD