Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,970
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 701 - 720 of 3,394 CVEs
CVE-2026-42757 CRITICAL - 9.9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253.

Vendor: Saleswonder Team: Tobias
Product: WebinarIgnition
Published: May 27, 2026
Source: NVD
CVE-2026-42756 CRITICAL - 9.9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP &#8211; Compress / Optimize Ima...

Vendor: Ludwig You
Product: QuickWebP &#8211; Compress / Optimize Images &amp; Convert WebP | SEO Friendly
Published: May 27, 2026
Source: NVD
CVE-2026-42755 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.

Vendor: RealMag777
Product: TableOn
Published: May 27, 2026
Source: NVD
CVE-2026-42748 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.

Vendor: WPify
Product: WPify Woo Czech
Published: May 27, 2026
Source: NVD
CVE-2026-42747 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6.

Vendor: hassantafreshi
Product: Easy Form Builder
Published: May 27, 2026
Source: NVD
CVE-2026-42740 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Tainacan: from n/a through <= 1.0.3.

Vendor: tainacan
Product: Tainacan
Published: May 27, 2026
Source: NVD
CVE-2026-42731 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.

Vendor: miniOrange
Product: miniorange otp verification
Published: May 27, 2026
Source: NVD
CVE-2026-42727 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a thro...

Vendor: RealMag777
Product: Active Products Tables for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-49002 CRITICAL - 9.1

Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.

Vendor: ZTE
Product: ZXUniPOS NDS-LTE
Published: May 27, 2026
Source: NVD
CVE-2025-12686 CRITICAL - 9.8

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation Manager (BSM) before 1.3.2-65648 and Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.

Vendor: Synology
Product: BeeStation Manager (BSM), BeeStation OS
Published: May 27, 2026
Source: NVD
CVE-2026-8760 CRITICAL - 9.8

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never eva...

Published: May 27, 2026
Source: NVD
CVE-2026-8450 CRITICAL - 9.1

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '...

Published: May 27, 2026
Source: NVD
CVE-2026-44632 CRITICAL - 9.1

Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`

Vendor: maven
Product: org.yamcs:yamcs-core
Published: May 27, 2026
Source: GitHub
CVE-2026-9642 CRITICAL - 9.8

There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView project.

Vendor: deltaww
Product: diaview
Published: May 26, 2026
Source: NVD
CVE-2026-44451 CRITICAL - 9.3

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSou...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44450 CRITICAL - 9.9

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution ...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44449 CRITICAL - 9.1

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename is concatenated directly into the smbclient -c script without validation. smbcli...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-44444 CRITICAL - 9.1

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json with a preinstall, posti...

Vendor: prolix-oc
Product: Lumiverse
Published: May 26, 2026
Source: NVD
CVE-2026-48689 CRITICAL - 9.8

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an i...

Vendor: pavel-odintsov
Product: fastnetmon
Published: May 26, 2026
Source: NVD
CVE-2026-3660 CRITICAL - 9.8

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.

Vendor: ibm
Product: engineering_lifecycle_management
Published: May 26, 2026
Source: NVD