Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,101 - 7,120 of 35,175 CVEs
CVE-2026-42740 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Tainacan: from n/a through <= 1.0.3.

Vendor: tainacan
Product: Tainacan
Published: May 27, 2026
Source: NVD
CVE-2026-42739 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced IP Blocker: from n/a through <= 8.10.7.

Vendor: IniLerm
Product: Advanced IP Blocker
Published: May 27, 2026
Source: NVD
CVE-2026-42738 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

Vendor: ZAYTECH
Product: Smart Online Order for Clover
Published: May 27, 2026
Source: NVD
CVE-2026-42737 HIGH - 8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.

Vendor: e4jvikwp
Product: VikBooking Hotel Booking Engine & PMS
Published: May 27, 2026
Source: NVD
CVE-2026-42736 HIGH - 7.5

Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Better Messages: from n/a through <= 2.14.16.

Vendor: wordplus
Product: BP Better Messages
Published: May 27, 2026
Source: NVD
CVE-2026-42735 HIGH - 8.2

Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.

Vendor: Iqonic Design
Product: KiviCare
Published: May 27, 2026
Source: NVD
CVE-2026-42734 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows Reflected XSS.This issue affects Geo Mashup: from n/a through <= 1.13.19.

Vendor: Dylan Kuhn
Product: Geo Mashup
Published: May 27, 2026
Source: NVD
CVE-2026-42733 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS currency-switcher allows DOM-Based XSS.This issue affects WPCS: from n/a through <= 1.3.1.

Vendor: RealMag777
Product: WPCS
Published: May 27, 2026
Source: NVD
CVE-2026-42732 MEDIUM - 6.5

Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Input Data Manipulation.This issue affects Ads by WPQuads: from n/a through <= 3.0.2.

Vendor: Ads by WPQuads
Product: Ads by WPQuads
Published: May 27, 2026
Source: NVD
CVE-2026-42731 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.

Vendor: miniOrange
Product: miniorange otp verification
Published: May 27, 2026
Source: NVD
CVE-2026-42730 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.7.29.

Vendor: Stylemix
Product: MasterStudy LMS
Published: May 27, 2026
Source: NVD
CVE-2026-42729 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2.

Vendor: Property Hive
Product: PropertyHive
Published: May 27, 2026
Source: NVD
CVE-2026-42728 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2.

Vendor: HT Plugins
Product: HT Contact Form 7
Published: May 27, 2026
Source: NVD
CVE-2026-42727 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a thro...

Vendor: RealMag777
Product: Active Products Tables for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-42726 MEDIUM - 6.5

Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5.

Vendor: Strategy11 Team
Product: AWP Classifieds
Published: May 27, 2026
Source: NVD
CVE-2026-42725 MEDIUM - 6.5

Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2...

Vendor: WP Wham
Product: Checkout Files Upload for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-3349 MEDIUM - 6.1

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated att...

Published: May 27, 2026
Source: NVD
CVE-2026-3348 MEDIUM - 4.4

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (Description, Title, and other fields) in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authent...

Published: May 27, 2026
Source: NVD
CVE-2026-3012 HIGH - 8.0

A flaw was found in Sambaโ€™s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to i...

Published: May 27, 2026
Source: NVD
CVE-2026-2288 MEDIUM - 4.8

The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leve...

Published: May 27, 2026
Source: NVD