Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,261 - 9,280 of 13,211 CVEs
CVE-2026-3944 HIGH - 7.3

A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /att_add.php. This manipulation of the argument Name causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be uti...

Vendor: angeljudesuarez
Product: university_management_system
Published: Mar 11, 2026
Source: NVD
CVE-2026-3943 HIGH - 7.3

A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The manipulation of the argument suffix results in command injection. The attack can be launched remotely. The exploit has been made public and could be used....

Published: Mar 11, 2026
Source: NVD
CVE-2026-3178 HIGH - 7.2

The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' parameter in all versions up to, and including, 1.32.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

Published: Mar 11, 2026
Source: NVD
CVE-2026-3805 HIGH - 7.5

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

Vendor: haxx
Product: curl
Published: Mar 11, 2026
Source: NVD
CVE-2026-3231 HIGH - 7.2

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the `p...

Published: Mar 11, 2026
Source: NVD
CVE-2026-1993 HIGH - 8.8

The ExactMetrics โ€“ Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings. This makes it possible ...

Published: Mar 11, 2026
Source: NVD
CVE-2026-1992 HIGH - 8.8

The ExactMetrics โ€“ Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used in...

Published: Mar 11, 2026
Source: NVD
CVE-2026-1454 HIGH - 7.2

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits ce...

Published: Mar 11, 2026
Source: NVD
CVE-2026-1708 HIGH - 7.5

The Appointment Booking Calendar โ€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to the `db_where_conditions` method in the `TD_DB_Model` class failing to prevent the `append_where_sql...

Published: Mar 11, 2026
Source: NVD
CVE-2024-14026 HIGH - 7.8

A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the ...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Mar 11, 2026
Source: NVD
CVE-2026-31844 HIGH - 8.8

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL quer...

Vendor: Koha Community
Product: Koha
Published: Mar 11, 2026
Source: NVD
CVE-2026-3222 HIGH - 7.5

The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped in b...

Published: Mar 11, 2026
Source: NVD
CVE-2026-2626 HIGH - 8.1

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be furthe...

Published: Mar 11, 2026
Source: NVD
CVE-2026-2466 HIGH - 7.1

The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Published: Mar 11, 2026
Source: NVD
CVE-2026-20892 HIGH - 7.2

Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privileges to execute arbitrary commands.

Vendor: Micro Research Ltd.
Product: MR-GM5L-S1, MR-GM5A-L1
Published: Mar 11, 2026
Source: NVD
CVE-2026-2413 HIGH - 7.5

The Ally โ€“ Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where it is directly conca...

Published: Mar 11, 2026
Source: NVD
CVE-2025-13067 HIGH - 8.8

The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible ...

Vendor: wproyal
Product: Royal Addons for Elementor โ€“ Addons and Templates Kit for Elementor
Published: Mar 11, 2026
Source: NVD
CVE-2026-23816 HIGH - 7.2

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

Vendor: Hewlett Packard Enterprise (HPE)
Product: AOS-CX
Published: Mar 11, 2026
Source: NVD
CVE-2026-23815 HIGH - 7.2

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

Vendor: Hewlett Packard Enterprise (HPE)
Product: AOS-CX
Published: Mar 11, 2026
Source: NVD
CVE-2026-23814 HIGH - 8.8

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

Vendor: Hewlett Packard Enterprise (HPE)
Product: AOS-CX
Published: Mar 11, 2026
Source: NVD