Total CVEs

131,269

Critical Severity

2,778

High Severity

9,907

Last 7 Days

1,030
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 901 - 920 of 27,674 CVEs
CVE-2026-9010 HIGH - 7.5

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL qu...

Published: May 20, 2026
Source: NVD
CVE-2026-9003 HIGH - 7.5

E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Published: May 20, 2026
Source: NVD
CVE-2026-7637 CRITICAL - 9.8

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in...

Published: May 20, 2026
Source: NVD

mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue fields into DataTables rows, and renders several of those fields as HTML without...

Published: May 20, 2026
Source: NVD
CVE-2026-24215 MEDIUM - 5.7

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24214 HIGH - 8.0

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24213 HIGH - 8.0

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24210 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24209 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24208 MEDIUM - 5.3

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24207 CRITICAL - 9.8

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24206 HIGH - 7.3

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.

Vendor: NVIDIA
Product: Triton Inference Server
Published: May 20, 2026
Source: NVD
CVE-2026-24163 HIGH - 7.5

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.

Vendor: NVIDIA
Product: TensorRT-LLM
Published: May 20, 2026
Source: NVD
CVE-2026-24160 MEDIUM - 5.5

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: TensorRT-LLM
Published: May 20, 2026
Source: NVD
CVE-2026-24142 MEDIUM - 6.3

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

Vendor: NVIDIA
Product: TensorRT-LLM
Published: May 20, 2026
Source: NVD
CVE-2025-33255 HIGH - 7.5

NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.

Vendor: NVIDIA
Product: TensorRT-LLM
Published: May 20, 2026
Source: NVD
CVE-2025-15369 MEDIUM - 5.3

The Xpro Addons โ€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create publis...

Vendor: xpro
Product: Xpro Addons โ€” 140+ Widgets for Elementor
Published: May 20, 2026
Source: NVD
CVE-2026-8685 MEDIUM - 6.5

The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL ...

Published: May 20, 2026
Source: NVD
CVE-2026-8627 MEDIUM - 6.1

The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is due to the correct_prices_page() function echoing $_SERVER['PHP_SELF'] into a form's action attribute wi...

Published: May 20, 2026
Source: NVD
CVE-2026-8626 MEDIUM - 6.1

The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Published: May 20, 2026
Source: NVD