Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,201 - 7,220 of 13,554 CVEs
CVE-2026-3177 MEDIUM - 5.3

The Charitable โ€“ Donation Plugin for WordPress โ€“ Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of incoming Stripe webhoo...

Published: Apr 07, 2026
Source: NVD
CVE-2026-4079 MEDIUM - 6.5

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

Vendor: guaven
Product: sql_chart_builder
Published: Apr 07, 2026
Source: NVD
CVE-2026-1900 MEDIUM - 6.5

The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.

Vendor: linkwhisper
Product: link_whisper
Published: Apr 07, 2026
Source: NVD
CVE-2025-15611 MEDIUM - 5.4

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can crea...

Vendor: Unknown
Product: Popup Box
Published: Apr 07, 2026
Source: NVD
CVE-2026-1839 MEDIUM - 6.5

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versi...

Vendor: pip
Product: transformers
Published: Apr 07, 2026
Source: NVD
CVE-2025-65116 MEDIUM - 5.5

Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop ...

Published: Apr 07, 2026
Source: NVD
CVE-2026-20446 MEDIUM - 4.3

In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV...

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Apr 07, 2026
Source: NVD
CVE-2026-20431 MEDIUM - 6.5

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106...

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Apr 07, 2026
Source: NVD
CVE-2026-5719 MEDIUM - 6.3

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be u...

Published: Apr 07, 2026
Source: NVD
CVE-2025-13044 MEDIUM - 6.2

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

Vendor: IBM
Product: Concert
Published: Apr 07, 2026
Source: NVD
CVE-2026-5705 MEDIUM - 4.3

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the atta...

Published: Apr 07, 2026
Source: NVD
CVE-2026-35480 MEDIUM - 6.2

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.22.0, the DAG-CBOR decoder uses collection sizes declared in CBOR headers as...

Vendor: go
Product: github.com/ipld/go-ipld-prime
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35475 MEDIUM - 6.1

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET with no URL validation or whitelist check, then used verbatim in a header("Location: ...") call. This vulnerability is fixed in 3.6.9.

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD
CVE-2026-35474 MEDIUM - 6.1

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The redirect parameter is taken directly from $_GET with no URL validation or whitelist check, then used verbatim in a header("Location: ...") call. This vulnerability is fixed...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD
CVE-2026-35473 MEDIUM - 6.1

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IentradaControle. The ...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD
CVE-2026-35404 MEDIUM - 4.7

Open edX Platform enables the authoring and delivery of online learning at any scale. he view_survey endpoint accepts a redirect_url GET parameter that is passed directly to HttpResponseRedirect() without any URL validation. When a non-existent survey name is provided, the server issues an immediate...

Vendor: openedx
Product: openedx-platform
Published: Apr 06, 2026
Source: NVD
CVE-2026-22675 MEDIUM - 5.4

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft reque...

Vendor: OCS Inventory
Product: OCS Inventory NG Server
Published: Apr 06, 2026
Source: NVD
CVE-2026-5683 MEDIUM - 5.5

A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack must originate from the local network. The explo...

Published: Apr 06, 2026
Source: NVD
CVE-2026-35472 MEDIUM - 6.1

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=EstoqueControle. Th...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD
CVE-2026-35399 MEDIUM - 6.1

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inject malicious scripts through a backup filename. This could lead to unauthorized execution of malicious code in the victim's browser, compromising session data or executing ac...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD