Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

630
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,741 - 1,760 of 27,228 CVEs
CVE-2026-4609 HIGH - 7.1

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level ...

Published: May 13, 2026
Source: NVD
CVE-2026-4608 MEDIUM - 6.5

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis...

Published: May 13, 2026
Source: NVD
CVE-2026-4607 MEDIUM - 4.3

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_i...

Published: May 13, 2026
Source: NVD

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-...

Vendor: mtrudel
Product: bandit
Published: May 13, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1.Socket':read_data/2 in lib/bandit/http1/socket.ex ignores the caller-supplied :length opti...

Vendor: mtrudel
Product: bandit
Published: May 13, 2026
Source: NVD
CVE-2026-37430 HIGH - 7.3

An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.

Published: May 13, 2026
Source: NVD
CVE-2026-37429 MEDIUM - 6.5

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII) via a crafted SQL ...

Published: May 13, 2026
Source: NVD
CVE-2026-37428 MEDIUM - 6.5

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive database information, including users' Personally Identifiable Information (PII).

Published: May 13, 2026
Source: NVD
CVE-2026-6177 HIGH - 7.2

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts A...

Published: May 13, 2026
Source: NVD
CVE-2026-42961 MEDIUM - 4.3

ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-42950 MEDIUM - 4.3

ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-42948 MEDIUM - 4.8

Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.

Vendor: ELECOM CO.,LTD.
Product: WAB-BE187-M, WAB-BE72-M, WAB-BE36-M, WAB-BE36-S
Published: May 13, 2026
Source: NVD
CVE-2026-42062 CRITICAL - 9.8

ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required.

Vendor: ELECOM CO.,LTD.
Product: WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, WRC-W702-B
Published: May 13, 2026
Source: NVD
CVE-2026-40621 CRITICAL - 9.8

ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.

Vendor: ELECOM CO.,LTD.
Product: WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, WRC-W702-B
Published: May 13, 2026
Source: NVD
CVE-2026-3426 MEDIUM - 4.3

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_widget() and reset_all_widgets() functions in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with Author...

Published: May 13, 2026
Source: NVD
CVE-2026-3425 HIGH - 8.8

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above...

Published: May 13, 2026
Source: NVD
CVE-2026-35506 HIGH - 7.2

ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.

Vendor: ELECOM CO.,LTD.
Product: WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, WRC-W702-B
Published: May 13, 2026
Source: NVD
CVE-2026-25107 MEDIUM - 6.5

ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.

Vendor: ELECOM CO.,LTD.
Product: WRC-X1800GS-B, WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B, WRC-X3000GST2-B, WRC-X1800GSA-B, WRC-X1800GSH-B, WRC-X6000QS-G, WRC-X6000QSA-G, WRC-X6000XS-G, WRC-X6000XST-G, WRC-XE5400GS-G, WRC-XE5400GSA-G
Published: May 13, 2026
Source: NVD
CVE-2026-7168 MEDIUM - 5.3

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for...

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD
CVE-2026-7009 MEDIUM - 5.3

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

Vendor: haxx
Product: curl
Published: May 13, 2026
Source: NVD