Total CVEs

131,648

Critical Severity

2,801

High Severity

10,044

Last 7 Days

1,241
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,821 - 1,840 of 28,053 CVEs
CVE-2021-47954 HIGH - 8.2

LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extrac...

Vendor: LayerBB
Product: LayerBB
Published: May 16, 2026
Source: NVD
CVE-2021-47952 CRITICAL - 9.8

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deseria...

Vendor: Jsonpickle
Product: python jsonpickle
Published: May 16, 2026
Source: NVD
CVE-2021-47942 HIGH - 7.5

Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, the...

Vendor: Home-Assistant
Product: Home Assistant Community Store (HACS)
Published: May 16, 2026
Source: NVD
CVE-2021-47934 MEDIUM - 5.3

MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profil...

Vendor: MyBB
Product: MyBB Timeline Plugin
Published: May 16, 2026
Source: NVD
CVE-2020-37247 HIGH - 7.8

Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privi...

Vendor: Kite
Product: Kite
Published: May 16, 2026
Source: NVD
CVE-2020-37246 MEDIUM - 6.2

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access se...

Vendor: Supsystic
Product: Backup
Published: May 16, 2026
Source: NVD
CVE-2020-37245 HIGH - 7.5

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stor...

Vendor: Supsystic
Product: Digital Publications
Published: May 16, 2026
Source: NVD
CVE-2020-37244 HIGH - 8.2

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payl...

Vendor: Supsystic
Product: Membership
Published: May 16, 2026
Source: NVD
CVE-2020-37243 HIGH - 8.2

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit ...

Vendor: Supsystic
Product: Pricing Table
Published: May 16, 2026
Source: NVD
CVE-2020-37242 HIGH - 8.2

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based bli...

Vendor: Supsystic
Product: Ultimate Maps
Published: May 16, 2026
Source: NVD
CVE-2020-37241 MEDIUM - 5.3

bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts wit...

Vendor: Bloofox
Product: bloofoxCMS
Published: May 16, 2026
Source: NVD
CVE-2020-37240 MEDIUM - 6.4

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which ex...

Vendor: Codekernel
Product: Queue Management System
Published: May 16, 2026
Source: NVD
CVE-2020-37239 CRITICAL - 9.8

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwri...

Vendor: Gegl
Product: libbabl
Published: May 16, 2026
Source: NVD
CVE-2020-37238 MEDIUM - 6.4

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other a...

Vendor: Cmsmadesimple
Product: CMS Made Simple
Published: May 16, 2026
Source: NVD
CVE-2020-37237 MEDIUM - 6.4

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality...

Vendor: Compo
Product: Composr CMS
Published: May 16, 2026
Source: NVD
CVE-2020-37236 MEDIUM - 6.4

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news addition interface. Attackers can inject JavaScript payloads via the title field in the admin panel that exe...

Vendor: Netartmedia
Product: NewsLister
Published: May 16, 2026
Source: NVD
CVE-2020-37235 MEDIUM - 6.4

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encode...

Vendor: themeftc
Product: Theme Wibar
Published: May 16, 2026
Source: NVD
CVE-2020-37234 MEDIUM - 6.2

Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' fiel...

Vendor: Internetdownloadmanager
Product: Internet Download Manager
Published: May 16, 2026
Source: NVD
CVE-2020-37233 MEDIUM - 6.4

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onloa...

Vendor: Wordpress
Product: Buddypress
Published: May 16, 2026
Source: NVD
CVE-2020-37232 HIGH - 7.8

Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Attackers can place malicious executables in the system root path that will be executed with LocalSystem ...

Vendor: Iobit
Product: Advanced System Care Service
Published: May 16, 2026
Source: NVD