Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,298
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,061 - 7,080 of 12,780 CVEs
CVE-2018-25245 HIGH - 7.5

Microsoft 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the search bar to trigger an application crash.

Vendor: 7Tik
Product: 7 Tik
Published: Apr 04, 2026
Source: NVD
CVE-2018-25241 HIGH - 7.5

Microsoft VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled except...

Vendor: VPNBrowser
Product: VPN Browser+
Published: Apr 04, 2026
Source: NVD
CVE-2016-20061 HIGH - 7.8

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execu...

Vendor: Sheedantivirus
Product: sheed AntiVirus
Published: Apr 04, 2026
Source: NVD
CVE-2016-20060 HIGH - 7.8

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious co...

Vendor: Hotspotshield
Product: Hotspot Shield
Published: Apr 04, 2026
Source: NVD
CVE-2016-20059 HIGH - 7.8

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service...

Vendor: Iobit
Product: IObit Malware Fighter
Published: Apr 04, 2026
Source: NVD
CVE-2016-20058 HIGH - 7.8

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system...

Vendor: Netgate
Product: NETGATE AMITI Antivirus
Published: Apr 04, 2026
Source: NVD
CVE-2016-20057 HIGH - 7.8

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or ...

Vendor: Netgate
Product: NETGATE Registry Cleaner
Published: Apr 04, 2026
Source: NVD
CVE-2016-20056 HIGH - 7.8

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service resta...

Vendor: Spy-Emergency
Product: Spy Emergency
Published: Apr 04, 2026
Source: NVD
CVE-2016-20055 HIGH - 7.8

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when the service restarts or...

Vendor: Iobit
Product: IObit Advanced SystemCare
Published: Apr 04, 2026
Source: NVD
CVE-2026-3666 HIGH - 8.8

The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal sequences. This makes it possible for authenticated attackers, with subscriber level access and above...

Published: Apr 04, 2026
Source: NVD
CVE-2026-2936 HIGH - 7.2

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

Published: Apr 04, 2026
Source: NVD
CVE-2026-1233 HIGH - 7.5

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mement...

Published: Apr 04, 2026
Source: NVD
CVE-2026-5425 HIGH - 7.2

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...

Published: Apr 04, 2026
Source: NVD
CVE-2026-3445 HIGH - 7.1

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content โ€“ ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on...

Published: Apr 04, 2026
Source: NVD
CVE-2026-4896 HIGH - 8.1

The WCFM โ€“ Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`, ...

Published: Apr 04, 2026
Source: NVD
CVE-2026-35464 HIGH - 7.5

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in this set and passes the existing path restriction because the ...

Vendor: pip
Product: pyload-ng
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35463 HIGH - 8.8

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only app...

Vendor: pip
Product: pyload-ng
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35457 HIGH - 8.2

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0...

Vendor: rust
Product: libp2p-rendezvous
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35405 HIGH - 7.5

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer can register. A malicious peer can just keep registering unique namespaces in a loop and the server happily accepts ev...

Vendor: rust
Product: libp2p-rendezvous
Published: Apr 04, 2026
Source: GitHub

The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulnerability in coder/code-marketplace allowed a malicious VSIX file to write arbitrary files outside the extension directory. ExtractZip passed raw zip entry names to a callback that w...

Vendor: go
Product: github.com/coder/code-marketplace
Published: Apr 04, 2026
Source: GitHub