Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,430
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,021 - 1,040 of 11,951 CVEs
CVE-2026-11456 HIGH - 7.3

A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php of the component HTTP GET Request Handler. Such manipulation of the argument gblOrgID leads to sql injection. The attack may be launched remotely. The exploit is publicly availabl...

Vendor: Chanjet
Product: CRM
Published: Jun 07, 2026
Source: NVD
CVE-2026-11452 HIGH - 7.3

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_USER_PWD Handler. The manipulation of the argument Password leads to command injection. The attack can be initiated remotely. Upgrading to version 4.8....

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 07, 2026
Source: NVD
CVE-2026-11451 HIGH - 7.3

A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulation of the argument media_dir can lead to command injection. It is possible to launch the attack remotely. Upgrading to version 4....

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 07, 2026
Source: NVD
CVE-2026-11450 HIGH - 7.3

A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. Performing a manipulation of the argument dev_name results in command injection. It is possible to initiate the attack remotel...

Vendor: GL.iNet
Product: GL-MT3000
Published: Jun 07, 2026
Source: NVD
CVE-2026-26422 HIGH - 8.4

clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.

Vendor: Clash Verge Rev
Product: clash-verge-service-ipc
Published: Jun 06, 2026
Source: NVD
CVE-2026-11437 HIGH - 7.3

A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publi...

Vendor: perfree
Product: go-fastdfs-web
Published: Jun 06, 2026
Source: NVD
CVE-2026-11435 HIGH - 7.3

A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor wa...

Vendor: Jinher
Product: OA
Published: Jun 06, 2026
Source: NVD
CVE-2026-11413 HIGH - 8.8

A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclos...

Vendor: JingDong
Product: JD Cloud Box AX6600
Published: Jun 06, 2026
Source: NVD
CVE-2026-10725 HIGH - 7.5

Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the "HTTP/2 bomb"). The headers_decode method materialises a full key+val...

Vendor: CRUX
Product: Protocol::HTTP2
Published: Jun 06, 2026
Source: NVD
CVE-2026-9851 HIGH - 7.2

The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a non...

Published: Jun 06, 2026
Source: NVD
CVE-2026-7537 HIGH - 7.2

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for aut...

Published: Jun 06, 2026
Source: NVD
CVE-2026-8901 HIGH - 7.2

The Integration for Freshsales โ€“ Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes i...

Published: Jun 06, 2026
Source: NVD
CVE-2026-8438 HIGH - 7.2

The All-In-One Security (AIOS) โ€“ Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output escaping in the column_default() method o...

Published: Jun 06, 2026
Source: NVD
CVE-2026-9290 HIGH - 7.5

The WP User Manager โ€“ User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php fi...

Published: Jun 06, 2026
Source: NVD
CVE-2026-7654 HIGH - 8.8

The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()` function, which pro...

Published: Jun 05, 2026
Source: NVD
CVE-2026-11416 HIGH - 8.1

MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured download directory with a filename taken directly from remote cloud API metadata without basename normali...

Vendor: jxxghp
Product: MoviePilot
Published: Jun 05, 2026
Source: NVD

Twig: Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points

Vendor: composer
Product: twig/twig
Published: Jun 05, 2026
Source: GitHub
CVE-2026-36785 HIGH - 7.5

Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Published: Jun 05, 2026
Source: NVD
CVE-2026-11422 HIGH - 7.1

Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers c...

Vendor: shd101wyy
Product: Markdown Preview Enhanced, crossnote
Published: Jun 05, 2026
Source: NVD
CVE-2026-47743 HIGH - 8.7

Shopper: Multiple data integrity and disclosure issues in admin Livewire components

Vendor: composer
Product: shopper/framework
Published: Jun 05, 2026
Source: GitHub