Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 8,381 - 8,400 of 13,041 CVEs
CVE-2026-3629 HIGH - 8.1

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. T...

Published: Mar 21, 2026
Source: NVD
CVE-2026-4528 HIGH - 7.3

A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery. Remote exploitation of...

Published: Mar 21, 2026
Source: NVD
CVE-2019-25581 HIGH - 8.2

i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive dat...

Vendor: I-Doit
Product: doit CMDB
Published: Mar 21, 2026
Source: NVD
CVE-2019-25580 HIGH - 8.2

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IM...

Vendor: Owndms
Product: ownDMS
Published: Mar 21, 2026
Source: NVD
CVE-2019-25579 HIGH - 7.5

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and ret...

Vendor: Phptransformer
Product: phpTransformer
Published: Mar 21, 2026
Source: NVD
CVE-2019-25578 HIGH - 8.2

phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to GeneratePDF.php with SQL payloads in the idnews parameter to extract sensit...

Vendor: Phptransformer
Product: phpTransformer
Published: Mar 21, 2026
Source: NVD
CVE-2019-25576 HIGH - 8.2

Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extrac...

Vendor: Keplerwallpapers
Product: Kepler Wallpaper Script
Published: Mar 21, 2026
Source: NVD
CVE-2019-25575 HIGH - 8.2

SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Attackers can send GET requests with crafted SQL payloads to extract sensitive data...

Vendor: Sourceforge
Product: SimplePress CMS
Published: Mar 21, 2026
Source: NVD
CVE-2019-25573 HIGH - 7.1

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET requests to index.php with m=admin, c=posts, a=index parameters and inject SQL code in the cat para...

Vendor: Greencms
Product: Green CMS
Published: Mar 21, 2026
Source: NVD
CVE-2019-25560 HIGH - 7.5

Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.

Vendor: Lyricvideocreator
Product: Lyric Video Creator
Published: Mar 21, 2026
Source: NVD
CVE-2019-25552 HIGH - 7.5

CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submitting an excessively long buffer to the password field. Attackers can paste a large string of repeated characters into the password input during the upload process to trigger an ap...

Vendor: Cewe-Photoworld
Product: CEWE PHOTO SHOW
Published: Mar 21, 2026
Source: NVD
CVE-2026-4373 HIGH - 7.5

The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without valid...

Published: Mar 21, 2026
Source: NVD
CVE-2026-4261 HIGH - 8.8

The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_profile_fields' function. This makes it p...

Published: Mar 21, 2026
Source: NVD
CVE-2026-3478 HIGH - 7.2

The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3 via the redux_p AJAX action in the bundled ReduxFramework library. The plugin registers a proxy endpoint (wp_ajax_nopriv_redux_p) that is accessible to unauthen...

Published: Mar 21, 2026
Source: NVD
CVE-2026-3334 HIGH - 8.8

The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and lack ...

Published: Mar 21, 2026
Source: NVD
CVE-2026-3003 HIGH - 7.2

The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜vagaro_code’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w...

Published: Mar 21, 2026
Source: NVD
CVE-2026-2941 HIGH - 8.8

The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, ...

Published: Mar 21, 2026
Source: NVD
CVE-2026-2468 HIGH - 7.5

The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to, and including, 1.2.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `get_user_...

Published: Mar 21, 2026
Source: NVD
CVE-2026-2440 HIGH - 7.2

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes the nonce required for submission, allowing una...

Published: Mar 21, 2026
Source: NVD
CVE-2026-2279 HIGH - 7.2

The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...

Published: Mar 21, 2026
Source: NVD