Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,507
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 12,361 - 12,380 of 36,830 CVEs
CVE-2021-47946 MEDIUM - 5.3

OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiting malicious pages. Attackers can craft CSRF payloads that change victim email addresses and account ...

Vendor: Opencart
Product: OpenCart
Published: May 10, 2026
Source: NVD
CVE-2021-47945 HIGH - 7.8

Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem pr...

Vendor: argus
Product: Argus Surveillance DVR
Published: May 10, 2026
Source: NVD
CVE-2021-47944 HIGH - 7.5

memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an applica...

Vendor: memono
Product: Notepad
Published: May 10, 2026
Source: NVD
CVE-2021-47943 HIGH - 8.8

TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functionality. Attackers can upload a PHP shell via the Files section in the content area and execute comman...

Vendor: Textpattern
Product: TextPattern CMS
Published: May 10, 2026
Source: NVD
CVE-2021-47941 HIGH - 8.2

WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database info...

Vendor: Modalsurvey
Product: Survey & Poll
Published: May 10, 2026
Source: NVD
CVE-2021-47940 CRITICAL - 9.8

WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_fr...

Vendor: download-from-files
Product: Download From Files
Published: May 10, 2026
Source: NVD
CVE-2021-47939 HIGH - 8.8

Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with malicious PHP code in the...

Vendor: Evo
Product: Evolution CMS
Published: May 10, 2026
Source: NVD
CVE-2021-47938 HIGH - 8.8

ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat_code parameter. Attackers can authenticate, submit a POST request to /modules/system/ad...

Vendor: Impresscms
Product: ImpressCMS
Published: May 10, 2026
Source: NVD
CVE-2021-47937 HIGH - 8.8

e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to ...

Vendor: E107
Product: e107 CMS
Published: May 10, 2026
Source: NVD
CVE-2021-47936 CRITICAL - 9.8

OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system comman...

Vendor: Opencats
Product: OpenCATS
Published: May 10, 2026
Source: NVD
CVE-2021-47935 HIGH - 8.8

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with ...

Vendor: Sentry
Product: Sentry
Published: May 10, 2026
Source: NVD
CVE-2021-47933 CRITICAL - 9.8

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code executi...

Vendor: mstore
Product: MStore API
Published: May 10, 2026
Source: NVD
CVE-2021-47932 CRITICAL - 9.8

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to adm...

Vendor: thecartpress
Product: TheCartPress
Published: May 10, 2026
Source: NVD
CVE-2021-47931 MEDIUM - 6.4

Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary Ja...

Vendor: Exponentcms
Product: Exponent CMS
Published: May 10, 2026
Source: NVD
CVE-2021-47930 HIGH - 8.2

Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' fi...

Vendor: Balbooa
Product: Balbooa Joomla Forms Builder
Published: May 10, 2026
Source: NVD
CVE-2021-47929 MEDIUM - 6.4

Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is...

Vendor: Filterable-Portfolio
Product: Filterable Portfolio Gallery
Published: May 10, 2026
Source: NVD
CVE-2021-47928 HIGH - 8.2

Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id parameter. Attackers can craft malicious SQL queries using time-based or content-based blind injection techni...

Vendor: opencartextensions
Product: Extension TMD Vendor System
Published: May 10, 2026
Source: NVD
CVE-2021-47927 MEDIUM - 6.4

WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScri...

Vendor: Wpsymposiumpro
Product: WP Symposium Pro
Published: May 10, 2026
Source: NVD
CVE-2021-47926 MEDIUM - 6.4

Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in us...

Vendor: Form2Email
Product: Contact Form to Email
Published: May 10, 2026
Source: NVD
CVE-2021-47925 MEDIUM - 6.4

CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters or SVG file attachme...

Vendor: Cmdbuild
Product: CMDBuild
Published: May 10, 2026
Source: NVD