Total CVEs

138,076

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,879
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 921 - 940 of 3,396 CVEs
CVE-2026-6512 CRITICAL - 9.1

The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbit...

Published: May 14, 2026
Source: NVD
CVE-2026-6510 CRITICAL - 9.8

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated atta...

Published: May 14, 2026
Source: NVD
CVE-2026-6271 CRITICAL - 9.8

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes re...

Published: May 14, 2026
Source: NVD
CVE-2026-8181 CRITICAL - 9.8

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application ...

Published: May 14, 2026
Source: NVD
CVE-2026-8500 CRITICAL - 9.8

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.

Published: May 13, 2026
Source: NVD
CVE-2026-45158 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is f...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44442 CRITICAL - 9.9

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 16.9.1.

Vendor: frappe
Product: erpnext
Published: May 13, 2026
Source: NVD
CVE-2026-44194 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formattin...

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-44193 CRITICAL - 9.1

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.

Vendor: opnsense
Product: core
Published: May 13, 2026
Source: NVD
CVE-2026-45714 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using th...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-45053 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the we...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2026-44377 CRITICAL - 9.1

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty templa...

Vendor: cubecart
Product: v6
Published: May 13, 2026
Source: NVD
CVE-2025-27851 CRITICAL - 9.3

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate a...

Published: May 13, 2026
Source: NVD
CVE-2026-22599 CRITICAL - 7.2

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could inject arbitrary datab...

Vendor: npm
Product: @strapi/content-type-builder
Published: May 13, 2026
Source: GitHub
CVE-2026-45411 CRITICAL - 9.8

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the ...

Vendor: patriksimek
Product: vm2
Published: May 13, 2026
Source: NVD
CVE-2026-41225 CRITICAL - 9.1

A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2020-37168 CRITICAL - 9.8

Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, the...

Vendor: Paiement
Product: Ecommerce Systempay
Published: May 13, 2026
Source: NVD
CVE-2026-45375 CRITICAL - 9.0

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings β†’ Marketplace UI...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: May 13, 2026
Source: GitHub
CVE-2026-45083 CRITICAL - 9.8

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the b...

Vendor: maven
Product: io.goobi.viewer:viewer-core
Published: May 13, 2026
Source: GitHub
CVE-2026-42062 CRITICAL - 9.8

ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required.

Vendor: ELECOM CO.,LTD.
Product: WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, WRC-W702-B
Published: May 13, 2026
Source: NVD