Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,421 - 7,440 of 35,345 CVEs
CVE-2026-7614 MEDIUM - 4.3

The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the OPH_options function. This makes it possible for unauthenticated attackers to update the plugin's c...

Published: May 27, 2026
Source: NVD
CVE-2026-6268 HIGH - 7.1

The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against ...

Published: May 27, 2026
Source: NVD
CVE-2026-9236 MEDIUM - 4.3

The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the cmac_campaigns_action function. This makes it p...

Published: May 27, 2026
Source: NVD
CVE-2026-8450 CRITICAL - 9.1

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '...

Published: May 27, 2026
Source: NVD
CVE-2026-6287 MEDIUM - 5.4

The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and out...

Published: May 27, 2026
Source: NVD
CVE-2026-49000 MEDIUM - 5.3

An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.

Vendor: ZTE
Product: ZXUniPOS NDS-LTE
Published: May 27, 2026
Source: NVD
CVE-2025-14481 MEDIUM - 4.3

The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to insufficient authorization checks in the Meta Search REST API endpoint that fail to verify post ownership. This makes it possible for authenticated attacke...

Vendor: yoast
Product: Yoast SEO – Advanced SEO with real-time guidance and built-in AI
Published: May 27, 2026
Source: NVD
CVE-2026-9022 MEDIUM - 6.4

The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor...

Published: May 27, 2026
Source: NVD
CVE-2026-48999 MEDIUM - 5.3

Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically loaded and executed in the victim's browser.Attackers can thereby steal user cookies, hijack sessi...

Vendor: ZTE
Product: ZTE ZXUniPOS NDS-LTE
Published: May 27, 2026
Source: NVD
CVE-2026-48962 HIGH - 7.3

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through ...

Vendor: PMQS
Product: IO::Compress
Published: May 27, 2026
Source: NVD
CVE-2026-48961 HIGH - 7.3

IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, caus...

Vendor: PMQS
Product: IO::Compress
Published: May 27, 2026
Source: NVD
CVE-2026-48959 HIGH - 7.5

IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration....

Vendor: PMQS
Product: IO::Uncompress::Unzip
Published: May 27, 2026
Source: NVD
CVE-2026-2255 MEDIUM - 4.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can...

Published: May 27, 2026
Source: NVD
CVE-2026-2254 MEDIUM - 6.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

Published: May 27, 2026
Source: NVD
CVE-2026-2253 HIGH - 7.7

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

Published: May 27, 2026
Source: NVD
CVE-2025-15649 MEDIUM - 5.5

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes ...

Vendor: PMQS
Product: IO::Uncompress::Unzip
Published: May 27, 2026
Source: NVD
CVE-2026-9632 HIGH - 8.8

A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible t...

Published: May 27, 2026
Source: NVD
CVE-2026-9631 HIGH - 8.8

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer ov...

Published: May 27, 2026
Source: NVD
CVE-2026-9628 HIGH - 8.8

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer ove...

Published: May 27, 2026
Source: NVD
CVE-2026-9627 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely...

Published: May 27, 2026
Source: NVD