Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,281 - 7,300 of 35,345 CVEs
CVE-2026-42730 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.7.29.

Vendor: Stylemix
Product: MasterStudy LMS
Published: May 27, 2026
Source: NVD
CVE-2026-42729 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2.

Vendor: Property Hive
Product: PropertyHive
Published: May 27, 2026
Source: NVD
CVE-2026-42728 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2.

Vendor: HT Plugins
Product: HT Contact Form 7
Published: May 27, 2026
Source: NVD
CVE-2026-42727 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a thro...

Vendor: RealMag777
Product: Active Products Tables for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-42726 MEDIUM - 6.5

Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5.

Vendor: Strategy11 Team
Product: AWP Classifieds
Published: May 27, 2026
Source: NVD
CVE-2026-42725 MEDIUM - 6.5

Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2...

Vendor: WP Wham
Product: Checkout Files Upload for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-3349 MEDIUM - 6.1

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter on the redirect page in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated att...

Published: May 27, 2026
Source: NVD
CVE-2026-3348 MEDIUM - 4.4

The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (Description, Title, and other fields) in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authent...

Published: May 27, 2026
Source: NVD
CVE-2026-3012 HIGH - 8.0

A flaw was found in Sambaโ€™s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to i...

Published: May 27, 2026
Source: NVD
CVE-2026-2288 MEDIUM - 4.8

The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leve...

Published: May 27, 2026
Source: NVD
CVE-2026-2280 MEDIUM - 4.8

The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and ab...

Published: May 27, 2026
Source: NVD
CVE-2025-0898 MEDIUM - 6.5

The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on th...

Published: May 27, 2026
Source: NVD

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destr...

Published: May 27, 2026
Source: NVD
CVE-2026-49002 CRITICAL - 9.1

Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.

Vendor: ZTE
Product: ZXUniPOS NDS-LTE
Published: May 27, 2026
Source: NVD
CVE-2026-48968 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows DOM-Based XSS. This issue affects Master Slider: from n/a through 3.10.8.

Vendor: Averta
Product: Master Slider
Published: May 27, 2026
Source: NVD
CVE-2026-48877 MEDIUM - 6.5

Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0.

Vendor: Tom
Product: GenerateBlocks
Published: May 27, 2026
Source: NVD
CVE-2026-40852 HIGH - 7.2

A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, i...

Vendor: MB connect line, Helmholz
Product: mbNET/mbNET.rokey, mbNET.mini, REX200/250, REX100
Published: May 27, 2026
Source: NVD
CVE-2026-40851 HIGH - 8.4

A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This can result in a total loss of confidentiality, integrity and availability.

Vendor: MB connect line, Helmholz
Product: mbNET/mbNET.rokey, mbNET.mini, REX200/250, REX100
Published: May 27, 2026
Source: NVD
CVE-2026-40850 HIGH - 7.5

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Vendor: MB connect line, Helmholz
Product: mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: May 27, 2026
Source: NVD
CVE-2026-40849 MEDIUM - 6.5

An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Vendor: MB connect line, Helmholz
Product: mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: May 27, 2026
Source: NVD