Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,604
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,361 - 7,380 of 13,554 CVEs
CVE-2018-25243 MEDIUM - 6.2

Microsoft FastTube 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 1900 characters into the search bar and trigger a crash when the search ope...

Vendor: FastTube
Product: FastTube
Published: Apr 04, 2026
Source: NVD
CVE-2018-25242 MEDIUM - 6.2

Microsoft One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled ex...

Vendor: OneSearch
Product: One Search
Published: Apr 04, 2026
Source: NVD
CVE-2018-25240 MEDIUM - 6.2

Microsoft Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 8145 characters into the search bar and trigger a search operation to cause t...

Vendor: Watchr
Product: Watchr
Published: Apr 04, 2026
Source: NVD
CVE-2018-25239 MEDIUM - 6.2

Microsoft Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that...

Vendor: SmartVPN
Product: Smart VPN
Published: Apr 04, 2026
Source: NVD
CVE-2018-25238 MEDIUM - 6.2

Microsoft VSCO 1.1.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string through the search functionality. Attackers can paste a buffer of 5000 characters into the search bar and navigate back to trigger an applic...

Vendor: vsco
Product: VSCO
Published: Apr 04, 2026
Source: NVD
CVE-2016-20053 MEDIUM - 5.3

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the users endpoint with hidden fields conta...

Vendor: Redaxo
Product: Redaxo CMS
Published: Apr 04, 2026
Source: NVD
CVE-2016-20051 MEDIUM - 5.3

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST reques...

Vendor: Snewscms
Product: Snews CMS Cross Site Request Forgery
Published: Apr 04, 2026
Source: NVD
CVE-2016-20050 MEDIUM - 6.2

NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a crafted payload containing 388 bytes of data followed by 4 bytes of EIP overwrite into the Hostna...

Vendor: Foundstone
Product: NetSchedScan
Published: Apr 04, 2026
Source: NVD
CVE-2026-3309 MEDIUM - 6.5

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content โ€“ ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing fi...

Published: Apr 04, 2026
Source: NVD
CVE-2026-0626 MEDIUM - 6.4

The WPFunnels โ€“ Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output e...

Published: Apr 04, 2026
Source: NVD
CVE-2025-14938 MEDIUM - 5.3

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is due to missing authorization and capability checks on the AJAX endpoint handling file uploa...

Vendor: purethemes
Product: Listeo-Core - Directory Plugin by Purethemes
Published: Apr 04, 2026
Source: NVD
CVE-2026-2826 MEDIUM - 4.3

The Kadence Blocks โ€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `upload_files` capability in the `process_pattern` REST API endp...

Published: Apr 04, 2026
Source: NVD
CVE-2026-2437 MEDIUM - 6.4

The WP Travel Engine โ€“ Tour Booking Plugin โ€“ Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on use...

Published: Apr 04, 2026
Source: NVD
CVE-2026-2600 MEDIUM - 6.4

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping on user suppli...

Published: Apr 04, 2026
Source: NVD
CVE-2026-0738 MEDIUM - 6.4

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due to insufficient input sanitization and output escaping in the 'su_slide_link' attachment m...

Published: Apr 04, 2026
Source: NVD
CVE-2026-0737 MEDIUM - 6.4

The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitization and output escaping in the 'src' attribute of the su_lightbox shortcode. This makes i...

Published: Apr 04, 2026
Source: NVD
CVE-2026-0664 MEDIUM - 6.4

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Published: Apr 04, 2026
Source: NVD
CVE-2026-0552 MEDIUM - 6.4

The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all versions up to, and including, 5.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...

Published: Apr 04, 2026
Source: NVD
CVE-2025-15064 MEDIUM - 6.4

The Ultimate Member โ€“ User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user description field in all versions up to, and including, 2.11.1 due to insufficient input sanitization ...

Vendor: ultimatemember
Product: Ultimate Member โ€“ User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2025-13368 MEDIUM - 6.4

The Xpro Addons โ€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Widget's 'onClick Event' setting in all versions up to, and including, 1.4.20 due to insufficient input sanitization and output escaping. This makes it possib...

Vendor: xpro
Product: Xpro Addons โ€” 140+ Widgets for Elementor
Published: Apr 04, 2026
Source: NVD