Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,527
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,981 - 11,000 of 13,246 CVEs
CVE-2025-7631 HIGH - 8.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. Co. Tumeva News Software allows SQL Injection.This issue affects Tumeva News Software: thro...

Published: Feb 17, 2026
Source: NVD
CVE-2026-1216 HIGH - 7.2

The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticat...

Published: Feb 17, 2026
Source: NVD
CVE-2026-2592 HIGH - 7.7

The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token pr...

Published: Feb 17, 2026
Source: NVD
CVE-2025-12062 HIGH - 8.8

The WP Maps โ€“ Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-l...

Vendor: flippercode
Product: WP Maps โ€“ Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
Published: Feb 17, 2026
Source: NVD
CVE-2026-2474 HIGH - 7.5

Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supplied, the expression length + 1u causes an inte...

Published: Feb 16, 2026
Source: NVD
CVE-2026-2001 HIGH - 8.8

The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' function in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with subscriber-level a...

Published: Feb 16, 2026
Source: NVD
CVE-2026-2567 HIGH - 7.2

A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the file /cgi-bin/nas.cgi. Performing a manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public ...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: Feb 16, 2026
Source: NVD
CVE-2026-2566 HIGH - 7.2

A security vulnerability has been detected in Wavlink WL-NU516U1 up to 130/260. This affects the function sub_406194 of the file /cgi-bin/adm.cgi. Such manipulation of the argument firmware_url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed ...

Published: Feb 16, 2026
Source: NVD
CVE-2019-25395 HIGH - 7.2

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads ...

Vendor: Smoothwall
Product: Smoothwall Express
Published: Feb 16, 2026
Source: NVD
CVE-2019-25394 HIGH - 7.2

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted payloads in parameters like INIT, HANGUP, SPEAKER_ON, SPEAKER_O...

Vendor: Smoothwall
Product: Smoothwall Express
Published: Feb 16, 2026
Source: NVD
CVE-2019-25379 HIGH - 7.2

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit POST requests with script payloads in the REDIRECT_PAGE or CHILDREN parameters to ex...

Vendor: Smoothwall
Product: Smoothwall Express
Published: Feb 16, 2026
Source: NVD
CVE-2026-2564 HIGH - 8.1

A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly co...

Published: Feb 16, 2026
Source: NVD
CVE-2026-2101 HIGH - 8.7

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.

Published: Feb 16, 2026
Source: NVD
CVE-2026-26930 HIGH - 7.2

SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.

Vendor: SmarterTools
Product: SmarterMail
Published: Feb 16, 2026
Source: NVD
CVE-2025-65716 HIGH - 8.8

An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.

Published: Feb 16, 2026
Source: NVD
CVE-2025-65715 HIGH - 7.8

An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.

Published: Feb 16, 2026
Source: NVD
CVE-2026-2447 HIGH - 8.8

Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.

Vendor: mozilla
Product: firefox
Published: Feb 16, 2026
Source: NVD
CVE-2026-1335 HIGH - 7.8

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

Published: Feb 16, 2026
Source: NVD
CVE-2026-1334 HIGH - 7.8

An Out-Of-Bounds Read vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

Published: Feb 16, 2026
Source: NVD
CVE-2026-1333 HIGH - 7.8

A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

Published: Feb 16, 2026
Source: NVD