Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,221 - 8,240 of 36,689 CVEs
CVE-2026-38931 MEDIUM - 5.4

A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.

Published: May 27, 2026
Source: NVD
CVE-2026-38930 MEDIUM - 6.5

OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the name cookie parameter.

Published: May 27, 2026
Source: NVD
CVE-2025-70116 MEDIUM - 4.3

A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV).

Published: May 27, 2026
Source: NVD
CVE-2025-68712 MEDIUM - 5.5

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authen...

Published: May 27, 2026
Source: NVD
CVE-2022-41656 MEDIUM - 4.3

Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from n/a through 2.1.2.

Vendor: Bizswoop
Product: Account Manager for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-45162 HIGH - 8.0

Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub

Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation โ†’ Off-Site //host URL Injection

Vendor: composer
Product: symfony/routing
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other pla...

Published: May 27, 2026
Source: NVD
CVE-2026-9674 MEDIUM - 4.3

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.

Vendor: jenkins
Product: multijob
Published: May 27, 2026
Source: NVD
CVE-2026-6957 HIGH - 8.0

Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filesto...

Vendor: mattermost
Product: legal_hold
Published: May 27, 2026
Source: NVD

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

Vendor: Webmin
Product: Webmin
Published: May 27, 2026
Source: NVD
CVE-2026-49102 MEDIUM - 6.1

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

Vendor: Webmin
Product: Webmin
Published: May 27, 2026
Source: NVD
CVE-2026-49059 MEDIUM - 4.7

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.

Vendor: Facebook
Product: Facebook for WooCommerce
Published: May 27, 2026
Source: NVD
CVE-2026-49053 MEDIUM - 5.3

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

Vendor: Wpmet
Product: ElementsKit Elementor addons Lite
Published: May 27, 2026
Source: NVD
CVE-2026-49052 MEDIUM - 4.3

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

Vendor: Wpmet
Product: ElementsKit Elementor addons Lite
Published: May 27, 2026
Source: NVD
CVE-2026-49051 MEDIUM - 4.3

Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.

Vendor: Prasad Kirpekar
Product: WP Meta and Date Remover
Published: May 27, 2026
Source: NVD
CVE-2026-49047 MEDIUM - 4.3

Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27.

Vendor: DearHive
Product: DearFlip
Published: May 27, 2026
Source: NVD
CVE-2026-49046 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 2.9.5.

Vendor: Arjun Thakur
Product: Duplicate Page and Post
Published: May 27, 2026
Source: NVD
CVE-2026-49045 MEDIUM - 4.3

Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11.

Vendor: WP Media
Product: Adminimize
Published: May 27, 2026
Source: NVD