Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,257
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,241 - 8,260 of 35,861 CVEs
CVE-2026-9517 HIGH - 7.3

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be e...

Published: May 26, 2026
Source: NVD
CVE-2026-9515 MEDIUM - 6.3

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin_version results in os command injection. The attack may be launched remotely....

Published: May 26, 2026
Source: NVD
CVE-2026-8376 CRITICAL - 9.8

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a la...

Vendor: perl
Product: perl
Published: May 26, 2026
Source: NVD
CVE-2026-9514 MEDIUM - 6.3

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is di...

Published: May 25, 2026
Source: NVD
CVE-2026-9513 MEDIUM - 6.3

A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument host_time can lead to os command injection. The attack can be launched remotely. ...

Published: May 25, 2026
Source: NVD
CVE-2026-9512 MEDIUM - 6.3

A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be i...

Published: May 25, 2026
Source: NVD
CVE-2026-48837 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.

Vendor: Unlimited Elements
Product: Unlimited Elements For Elementor
Published: May 25, 2026
Source: NVD
CVE-2026-45438 HIGH - 7.5

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

Vendor: WebToffee
Product: Smart Coupons for WooCommerce
Published: May 25, 2026
Source: NVD
CVE-2026-45435 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.

Vendor: Melapress
Product: WP Activity Log
Published: May 25, 2026
Source: NVD
CVE-2026-45217 MEDIUM - 6.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7.

Vendor: ThemeHigh
Product: Stripe Payment Gateway for WooCommerce
Published: May 25, 2026
Source: NVD
CVE-2026-45216 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.

Vendor: StoreApps
Product: Smart Manager
Published: May 25, 2026
Source: NVD
CVE-2026-45209 HIGH - 7.5

Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.

Vendor: edward_plainview
Product: MyCryptoCheckout
Published: May 25, 2026
Source: NVD
CVE-2026-42776 MEDIUM - 6.3

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.

Vendor: WP Sunshine
Product: Sunshine Photo Cart
Published: May 25, 2026
Source: NVD
CVE-2026-42774 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.

Vendor: Crocoblock
Product: JetEngine
Published: May 25, 2026
Source: NVD
CVE-2026-42773 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOne Store Manager allows Blind SQL Injection. This issue affects eMagicOne Store Manager: from n/a through 1.3.2.

Vendor: eMagicOne
Product: eMagicOne Store Manager
Published: May 25, 2026
Source: NVD
CVE-2026-42763 MEDIUM - 6.5

Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue affects SePay Gateway: from n/a through 1.1.20.

Vendor: SePay team
Product: SePay Gateway
Published: May 25, 2026
Source: NVD
CVE-2026-39436 HIGH - 7.1

Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.

Vendor: bgermann
Product: CformsII
Published: May 25, 2026
Source: NVD
CVE-2026-32389 MEDIUM - 5.4

Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2.

Vendor: Linethemes
Product: NanoCare
Published: May 25, 2026
Source: NVD
CVE-2026-24937 HIGH - 7.2

Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue affects Broadcast Live Video: from n/a before 7.1.3.

Vendor: VideoWhisper.com
Product: Broadcast Live Video
Published: May 25, 2026
Source: NVD
CVE-2026-9511 MEDIUM - 6.3

A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The expl...

Published: May 25, 2026
Source: NVD