Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

977
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,721 - 7,740 of 35,348 CVEs
CVE-2026-9520 MEDIUM - 4.3

A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the component Sign-in. This manipulation of the argument Next causes cross site scripting. It is possible to ...

Published: May 26, 2026
Source: NVD
CVE-2026-9519 MEDIUM - 4.3

A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto-Redirect. The manipulation of the argument redirect results in cross site scripting. The attack may ...

Published: May 26, 2026
Source: NVD
CVE-2026-9518 MEDIUM - 4.3

A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. The manipulation of the argument Name leads to cross site scripting. The attack is possible to be carr...

Published: May 26, 2026
Source: NVD
CVE-2026-4795 MEDIUM - 6.5

A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0,ย GS1200-8v3 firmware versions through 1.00(ACPT.2)C0,ย  GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions th...

Published: May 26, 2026
Source: NVD
CVE-2026-42497 HIGH - 7.5

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim fi...

Vendor: BINGOS
Product: Archive::Tar
Published: May 26, 2026
Source: NVD
CVE-2026-42496 CRITICAL - 9.1

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guar...

Vendor: BINGOS
Product: Archive::Tar
Published: May 26, 2026
Source: NVD

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must...

Vendor: BackdropCMS
Product: GDPR cookies module for Backdrop CMS
Published: May 26, 2026
Source: NVD
CVE-2026-9517 HIGH - 7.3

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be e...

Published: May 26, 2026
Source: NVD
CVE-2026-9515 MEDIUM - 6.3

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin_version results in os command injection. The attack may be launched remotely....

Published: May 26, 2026
Source: NVD
CVE-2026-8376 CRITICAL - 9.8

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a la...

Vendor: perl
Product: perl
Published: May 26, 2026
Source: NVD
CVE-2026-9514 MEDIUM - 6.3

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is di...

Published: May 25, 2026
Source: NVD
CVE-2026-9513 MEDIUM - 6.3

A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument host_time can lead to os command injection. The attack can be launched remotely. ...

Published: May 25, 2026
Source: NVD
CVE-2026-9512 MEDIUM - 6.3

A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be i...

Published: May 25, 2026
Source: NVD
CVE-2026-48837 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.

Vendor: Unlimited Elements
Product: Unlimited Elements For Elementor
Published: May 25, 2026
Source: NVD
CVE-2026-45438 HIGH - 7.5

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

Vendor: WebToffee
Product: Smart Coupons for WooCommerce
Published: May 25, 2026
Source: NVD
CVE-2026-45435 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.

Vendor: Melapress
Product: WP Activity Log
Published: May 25, 2026
Source: NVD
CVE-2026-45217 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7.

Vendor: ThemeHigh
Product: Stripe Payment Gateway for WooCommerce
Published: May 25, 2026
Source: NVD
CVE-2026-45216 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.

Vendor: StoreApps
Product: Smart Manager
Published: May 25, 2026
Source: NVD
CVE-2026-45209 HIGH - 7.5

Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.

Vendor: edward_plainview
Product: MyCryptoCheckout
Published: May 25, 2026
Source: NVD
CVE-2026-42776 MEDIUM - 6.3

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.

Vendor: WP Sunshine
Product: Sunshine Photo Cart
Published: May 25, 2026
Source: NVD