Total CVEs

125,872

Critical Severity

2,276

High Severity

7,883

Last 7 Days

1,163
Quick preset (or use dates below)
Clear Filters
Showing 161 - 180 of 8,730 CVEs
CVE-2026-42644 MEDIUM - 5.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10.

Vendor: WPDeveloper
Product: BetterDocs
Published: Apr 29, 2026
Source: NVD
CVE-2026-42643 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a through <= 4.4.11.

Vendor: StellarWP
Product: Image Widget
Published: Apr 29, 2026
Source: NVD
CVE-2026-42642 MEDIUM - 5.3

Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.

Vendor: StellarWP
Product: GiveWP
Published: Apr 29, 2026
Source: NVD
CVE-2026-42641 MEDIUM - 5.4

Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.

Vendor: ILLID
Product: Share This Image
Published: Apr 29, 2026
Source: NVD
CVE-2026-2902 MEDIUM - 6.1

The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frontend_rewrite' function's 'WPMETEOR[N]WPMETEOR' placeholder content in all versions up to, and including, 3.4.16 due to insufficient input sanitizatio...

Published: Apr 29, 2026
Source: NVD
CVE-2026-22745 MEDIUM - 5.3

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static reso...

Vendor: VMware
Product: Spring Framework
Published: Apr 29, 2026
Source: NVD
CVE-2026-4019 MEDIUM - 5.3

The Complianz โ€“ GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing...

Published: Apr 29, 2026
Source: NVD
CVE-2026-42412 MEDIUM - 6.5

Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1.

Vendor: weDevs
Product: WP User Frontend
Published: Apr 29, 2026
Source: NVD
CVE-2025-10503 MEDIUM - 6.1

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerabilit...

Vendor: WSO2
Product: WSO2 Identity Server
Published: Apr 29, 2026
Source: NVD
CVE-2026-23773 MEDIUM - 4.3

Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

Vendor: Dell
Product: Disk Library for mainframe DLm8700, Disk Library for mainframe DLm2700
Published: Apr 29, 2026
Source: NVD
CVE-2026-41310 MEDIUM - 5.3

OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure

Vendor: nuget
Product: OpenTelemetry.Exporter.Zipkin
Published: Apr 28, 2026
Source: GitHub
CVE-2026-7340 MEDIUM - 4.3

Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: Apr 28, 2026
Source: NVD
CVE-2026-40296 MEDIUM - 5.4

PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 28, 2026
Source: GitHub

PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 28, 2026
Source: GitHub
CVE-2026-32699 MEDIUM - 4.3

FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field

Vendor: composer
Product: facturascripts/facturascripts
Published: Apr 28, 2026
Source: GitHub
CVE-2026-30246 MEDIUM - 6.5

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

Vendor: go
Product: github.com/gofiber/fiber/v3
Published: Apr 28, 2026
Source: GitHub
CVE-2026-7318 MEDIUM - 5.9

A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path traversal. Attacking locally is a requirement. The exploit is now public and may be used. The project was ...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7317 MEDIUM - 5.0

A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The manipulation results in deserialization. The attack may be la...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7306 MEDIUM - 5.6

A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_token...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7305 MEDIUM - 6.3

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server-...

Published: Apr 28, 2026
Source: NVD