Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,081 - 7,100 of 35,175 CVEs

In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_get_next_key() list_next_entry() never returns NULL -- when the current element is the last entry it wraps to the list head via container_of(). The subsequent NULL check is therefor...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in arena_vm_close on fork arena_vm_open() only bumps vml->mmap_count but never registers the child VMA in arena->vma_list. The vml->vma always points at the parent VMA, so after parent munmap the p...

Vendor: Linux
Product: Linux
Published: May 27, 2026
Source: NVD
CVE-2026-42762 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows DOM-Based XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: May 27, 2026
Source: NVD
CVE-2026-42761 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a thro...

Vendor: RealMag777
Product: Active Products Tables for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-42760 HIGH - 7.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25.

Vendor: revmakx
Product: Backup and Staging by WP Time Capsule
Published: May 27, 2026
Source: NVD
CVE-2026-42759 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Super Assistent amazonsimpleadmin allows Stored XSS.This issue affects Affiliate Super Assistent: from n/a through <= 1.10.1.

Vendor: Timo
Product: Affiliate Super Assistent
Published: May 27, 2026
Source: NVD
CVE-2026-42758 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.

Vendor: Saleswonder Team: Tobias
Product: WebinarIgnition
Published: May 27, 2026
Source: NVD
CVE-2026-42757 CRITICAL - 9.9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253.

Vendor: Saleswonder Team: Tobias
Product: WebinarIgnition
Published: May 27, 2026
Source: NVD
CVE-2026-42756 CRITICAL - 9.9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP &#8211; Compress / Optimize Ima...

Vendor: Ludwig You
Product: QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly
Published: May 27, 2026
Source: NVD
CVE-2026-42755 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.

Vendor: RealMag777
Product: TableOn
Published: May 27, 2026
Source: NVD
CVE-2026-42754 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon favicon-by-realfavicongenerator allows Reflected XSS.This issue affects Favicon: from n/a through <= 1.3.46.

Vendor: phbernard
Product: Favicon
Published: May 27, 2026
Source: NVD
CVE-2026-42753 HIGH - 7.3

Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.

Vendor: WC Lovers
Product: WCFM Membership
Published: May 27, 2026
Source: NVD
CVE-2026-42751 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18.

Vendor: wpdevelop
Product: Booking Manager
Published: May 27, 2026
Source: NVD
CVE-2026-42750 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.

Vendor: Nexcess
Product: WPComplete
Published: May 27, 2026
Source: NVD
CVE-2026-42749 HIGH - 7.1

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0.

Vendor: Themeisle
Product: Disable Comments for Any Post Types (Remove comments)
Published: May 27, 2026
Source: NVD
CVE-2026-42748 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.

Vendor: WPify
Product: WPify Woo Czech
Published: May 27, 2026
Source: NVD
CVE-2026-42747 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6.

Vendor: hassantafreshi
Product: Easy Form Builder
Published: May 27, 2026
Source: NVD
CVE-2026-42746 HIGH - 7.3

Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Retrieve Embedded Sensitive Data.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

Vendor: ZAYTECH
Product: Smart Online Order for Clover
Published: May 27, 2026
Source: NVD
CVE-2026-42745 HIGH - 7.3

Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Authentication Bypass.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

Vendor: ZAYTECH
Product: Smart Online Order for Clover
Published: May 27, 2026
Source: NVD
CVE-2026-42744 MEDIUM - 6.5

Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Manipulating Hidden Fields.This issue affects Ads by WPQuads: from n/a through <= 3.0.2.

Vendor: Ads by WPQuads
Product: Ads by WPQuads
Published: May 27, 2026
Source: NVD