Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,181 - 9,200 of 36,778 CVEs
CVE-2026-27346 MEDIUM - 4.9

Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10.

Vendor: Kings Plugins
Product: B2BKing
Published: May 25, 2026
Source: NVD
CVE-2026-24592 MEDIUM - 5.3

Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.

Vendor: Lucian Apostol
Product: Auto Affiliate Links
Published: May 25, 2026
Source: NVD
CVE-2026-24586 MEDIUM - 5.4

Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Newses: from n/a through 2.0.0.77.

Vendor: Themeansar
Product: Newses
Published: May 25, 2026
Source: NVD
CVE-2026-24582 MEDIUM - 4.3

Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0.

Vendor: WPPOOL
Product: FlexTable
Published: May 25, 2026
Source: NVD
CVE-2026-24554 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This issue affects WPSubscription: from n/a through 1.9.1.

Vendor: Convers Lab
Product: WPSubscription
Published: May 25, 2026
Source: NVD
CVE-2026-24527 MEDIUM - 4.3

Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.

Vendor: Patterns in the cloud
Product: Autoship Cloud for WooCommerce Subscription Products
Published: May 25, 2026
Source: NVD
CVE-2025-62745 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28.

Vendor: PickPlugins
Product: Team Showcase
Published: May 25, 2026
Source: NVD
CVE-2026-9503 LOW - 3.3

A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been release...

Published: May 25, 2026
Source: NVD
CVE-2026-9502 MEDIUM - 5.3

A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and...

Published: May 25, 2026
Source: NVD
CVE-2026-9501 LOW - 3.3

A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has b...

Published: May 25, 2026
Source: NVD
CVE-2026-9500 MEDIUM - 5.3

A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The explo...

Published: May 25, 2026
Source: NVD

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

Vendor: PuTTY
Product: PuTTY
Published: May 25, 2026
Source: NVD
CVE-2026-48589 MEDIUM - 5.4

Apache Shiroโ€™s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. Thi...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: May 25, 2026
Source: NVD
CVE-2026-44598 MEDIUM - 5.4

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1,ย only when using shiro-jakarta-ee integration module. Users a...

Vendor: Apache Software Foundation
Product: Apache Shiro Jakarta EE module
Published: May 25, 2026
Source: NVD
CVE-2026-43828 MEDIUM - 6.5

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the ...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: May 25, 2026
Source: NVD
CVE-2026-43827 MEDIUM - 6.5

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: May 25, 2026
Source: NVD
CVE-2026-24597 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This issue affects Organization chart: from n/a through 1.7.5.

Vendor: WpDevArt
Product: Organization chart
Published: May 25, 2026
Source: NVD
CVE-2026-24574 MEDIUM - 6.5

Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.

Vendor: Recorp
Product: Export WP Page to Static HTML/CSS
Published: May 25, 2026
Source: NVD