Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

791
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 941 - 960 of 27,228 CVEs
CVE-2018-25330 HIGH - 8.2

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users...

Vendor: Joomlaextensions
Product: Joomla! extension EkRishta
Published: May 17, 2026
Source: NVD
CVE-2018-25329 HIGH - 7.5

WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url values to access sensiti...

Vendor: wp-with-spritz
Product: WP with Spritz
Published: May 17, 2026
Source: NVD
CVE-2018-25328 HIGH - 8.4

VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return address to execute ar...

Vendor: vxsearch
Product: VX Search
Published: May 17, 2026
Source: NVD
CVE-2018-25327 MEDIUM - 5.3

Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify ...

Vendor: Joomsky
Product: JS Jobs
Published: May 17, 2026
Source: NVD
CVE-2018-25326 HIGH - 7.5

Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_...

Vendor: wp-google-drive
Product: Google Drive
Published: May 17, 2026
Source: NVD
CVE-2018-25325 HIGH - 7.5

Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename paramete...

Vendor: woocommerce-csvimport
Product: WooCommerce CSV-Importer
Published: May 17, 2026
Source: NVD
CVE-2018-25324 MEDIUM - 6.2

Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspath values to simple_...

Vendor: Simple-Fields
Product: Simple Fields
Published: May 17, 2026
Source: NVD
CVE-2018-25323 HIGH - 8.4

Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH cha...

Vendor: Alloksoft
Product: Allok AVI DivX MPEG to DVD Converter
Published: May 17, 2026
Source: NVD
CVE-2018-25322 HIGH - 8.4

Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk data followed by structured shellcode and place it in the Lic...

Vendor: alloksoft
Product: Fast AVI MPEG Splitter
Published: May 17, 2026
Source: NVD
CVE-2018-25321 MEDIUM - 4.3

TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via Wlan...

Vendor: Tp-link
Product: TL-WR720NMbps Wireless N Router
Published: May 17, 2026
Source: NVD
CVE-2018-25320 CRITICAL - 9.8

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to est...

Vendor: acl
Product: ACL Analytics
Published: May 17, 2026
Source: NVD
CVE-2018-25319 HIGH - 7.1

Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Attackers can send GET requests to the event_add.php page with malicious myevents_id values to extract o...

Vendor: wende60
Product: Redaxo CMS Addon MyEvents
Published: May 17, 2026
Source: NVD
CVE-2026-8752 MEDIUM - 5.3

A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to improper access contro...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8751 HIGH - 7.3

A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The expl...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8750 MEDIUM - 5.3

A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be executed remotely. The e...

Vendor: h2o
Product: h2o
Published: May 17, 2026
Source: NVD
CVE-2026-8747 MEDIUM - 6.3

A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been made...

Published: May 17, 2026
Source: NVD
CVE-2026-8746 MEDIUM - 4.3

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF. The manipulation results in use after free. The attack can be launched remotely. The exploit has been released to the pub...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8745 MEDIUM - 4.3

A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit is publicly available and...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8744 MEDIUM - 4.3

A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing a manipulation can lead to denial of service. It is possible to launch the attack remotely. The explo...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD
CVE-2026-8743 MEDIUM - 6.3

A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit has been made pub...

Vendor: open5gs
Product: open5gs
Published: May 17, 2026
Source: NVD