Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,281 - 8,300 of 35,861 CVEs
CVE-2026-43827 MEDIUM - 6.5

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: May 25, 2026
Source: NVD
CVE-2026-24597 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This issue affects Organization chart: from n/a through 1.7.5.

Vendor: WpDevArt
Product: Organization chart
Published: May 25, 2026
Source: NVD
CVE-2026-24574 MEDIUM - 6.5

Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.

Vendor: Recorp
Product: Export WP Page to Static HTML/CSS
Published: May 25, 2026
Source: NVD
CVE-2026-24545 MEDIUM - 4.3

Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.

Vendor: Nikki Blight
Product: QR Redirector
Published: May 25, 2026
Source: NVD
CVE-2026-9498 MEDIUM - 6.3

A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used in a template engine. ...

Published: May 25, 2026
Source: NVD
CVE-2026-9497 MEDIUM - 6.3

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this dis...

Published: May 25, 2026
Source: NVD
CVE-2026-9486 MEDIUM - 4.3

A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Published: May 25, 2026
Source: NVD
CVE-2026-9485 LOW - 3.5

A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is ...

Published: May 25, 2026
Source: NVD
CVE-2026-9484 MEDIUM - 6.3

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. T...

Published: May 25, 2026
Source: NVD
CVE-2026-48849 MEDIUM - 4.4

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48848 HIGH - 7.2

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48846 MEDIUM - 6.5

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48845 MEDIUM - 6.5

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48844 HIGH - 7.5

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48843 HIGH - 7.2

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for...

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-48842 HIGH - 8.1

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Vendor: Roundcube
Product: Webmail
Published: May 25, 2026
Source: NVD
CVE-2026-24546 MEDIUM - 5.3

Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.

Vendor: Ruben Garcia
Product: GamiPress
Published: May 25, 2026
Source: NVD
CVE-2026-9483 MEDIUM - 6.3

A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has been made public and...

Published: May 25, 2026
Source: NVD
CVE-2026-9482 HIGH - 8.8

A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be...

Published: May 25, 2026
Source: NVD