Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,636
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,641 - 10,660 of 36,815 CVEs
CVE-2026-44366 MEDIUM - 6.1

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Vvveb CMS comment submission flow. The author field is submitted by an unauthenticated user on any public post pag...

Vendor: givanz
Product: Vvveb
Published: May 15, 2026
Source: NVD
CVE-2021-47968 MEDIUM - 6.4

Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to ...

Vendor: Podcastgenerator
Product: Podcast Generator
Published: May 15, 2026
Source: NVD
CVE-2021-47967 MEDIUM - 6.1

PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers can append malicious payloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, or i...

Vendor: Timeclock
Product: PHP Timeclock
Published: May 15, 2026
Source: NVD
CVE-2021-47966 HIGH - 8.2

PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database contents. Attackers can submit crafted POST requests with SQL payloads using SLEEP functions or RLIKE cond...

Vendor: Timeclock
Product: PHP Timeclock
Published: May 15, 2026
Source: NVD
CVE-2021-47965 CRITICAL - 9.8

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code ...

Vendor: wp-super-edit
Product: WP Super Edit
Published: May 15, 2026
Source: NVD
CVE-2021-47964 HIGH - 8.8

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the packageinfo.inc file and trigger...

Vendor: Schlix
Product: Schlix CMS
Published: May 15, 2026
Source: NVD
CVE-2021-47963 HIGH - 7.2

Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by injecting malicious payloads into markdown files stored within the application. Attackers can craft malicious markdown files with embedded JavaScript that executes system commands wh...

Vendor: AnotherNote
Product: Anote
Published: May 15, 2026
Source: NVD
CVE-2021-47962 MEDIUM - 6.4

Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to inject malicious HTML and JavaScript code. Attackers can inject script payloads into user profile fields at the edit_user endpoint, which execute in the ...

Vendor: savsofts
Product: Savsoft Quiz
Published: May 15, 2026
Source: NVD
CVE-2021-47959 HIGH - 7.5

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads ...

Vendor: Wpgraphql
Product: WPGraphQL
Published: May 15, 2026
Source: NVD
CVE-2021-47958 MEDIUM - 4.3

CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services a...

Vendor: CouchCMS
Product: CouchCMS
Published: May 15, 2026
Source: NVD
CVE-2026-45619 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS pinning via CURLOPT_RESOLVE, opening DNS-rebinding TOCTOU.

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45610 MEDIUM - 5.7

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the session-authenticated user, and...

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45580 MEDIUM - 5.4

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, without htmlspecialchars(). A canSt...

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45578 HIGH - 8.8

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never calling escapeshella...

Vendor: composer
Product: WWBN/AVideo
Published: May 15, 2026
Source: GitHub
CVE-2026-45575 HIGH - 7.4

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri...

Vendor: maven
Product: com.oviva.telematik:epa4all-client
Published: May 15, 2026
Source: GitHub
CVE-2026-45574 HIGH - 8.1

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient ide...

Vendor: maven
Product: com.oviva.telematik:epa4all-client
Published: May 15, 2026
Source: GitHub
CVE-2026-46474 HIGH - 7.5

Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

Vendor: TEODESIAN
Product: Trog::TOTP
Published: May 15, 2026
Source: NVD
CVE-2026-46491 HIGH - 8.6

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CAS ticket store by directly concatenating the configured ticket directory with an attacker-controlled ...

Vendor: composer
Product: simplesamlphp/simplesamlphp-module-casserver
Published: May 15, 2026
Source: GitHub
CVE-2026-44692 HIGH - 7.7

Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity instance, but then reads the target storage disk and path from request parameters. Because the requested...

Vendor: composer
Product: code16/sharp
Published: May 15, 2026
Source: GitHub
CVE-2026-45717 HIGH - 8.8

Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the same authorization level as the read endpoint (GET /a...

Vendor: npm
Product: @budibase/server
Published: May 15, 2026
Source: GitHub