Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,237
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 745 CVEs

FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users. ...

Vendor: FriendsOfShopware
Product: FroshPlatformAdminer
Published: Feb 09, 2026
Source: NVD
CVE-2026-2200 LOW - 2.4

A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the component API Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public a...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2165 HIGH - 7.3

A weakness has been identified in detronetdip E-commerce 1.0.0. Impacted is an unknown function of the file /Admin/assets/backend/seller/add_seller.php of the component Account Creation Endpoint. Executing a manipulation of the argument email can lead to missing authentication. The attack can be exe...

Published: Feb 08, 2026
Source: NVD
CVE-2026-2162 MEDIUM - 4.7

A vulnerability was determined in itsourcecode News Portal Project 1.0. This affects an unknown part of the file /admin/aboutus.php. This manipulation of the argument pagetitle causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Vendor: clive_21
Product: news_portal_project
Published: Feb 08, 2026
Source: NVD
CVE-2026-2156 LOW - 2.4

A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown function of the file /admin/announcement/index.php?view=add of the component Announcement Management Module. This manipulation causes cross site scripting. The attack is possible ...

Vendor: fabian
Product: online_student_management_system
Published: Feb 08, 2026
Source: NVD
CVE-2026-2088 HIGH - 7.3

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the publ...

Vendor: phpgurukul
Product: beauty_parlour_management_system
Published: Feb 07, 2026
Source: NVD
CVE-2026-25803 CRITICAL - 9.8

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full...

Vendor: denpiligrim
Product: 3dp-manager
Published: Feb 06, 2026
Source: NVD
CVE-2026-25651 MEDIUM - 6.1

client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulnerability. The middleware unconditionally redirects HTTP requests to HTTPS using the unvalidated Host h...

Vendor: tgies
Product: client-certificate-auth
Published: Feb 06, 2026
Source: NVD
CVE-2023-43637 MEDIUM - 6.7

Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be "arfoobarfoobarfo". This issue happens because "deriveVaultKey" calls "retrieveCloudKey" (which will always ...

Vendor: go
Product: github.com/lf-edge/eve
Published: Feb 04, 2026
Source: GitHub

Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Passster: from n/a through <= 4.2.25.

Vendor: WP Chill
Product: Passster
Published: Feb 03, 2026
Source: NVD
CVE-2026-25028 MEDIUM - 5.4

Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.1.

Vendor: Element Invader
Product: ElementInvader Addons for Elementor
Published: Feb 03, 2026
Source: NVD
CVE-2026-25027 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.7.1.

Vendor: ThemeMove
Product: Unicamp
Published: Feb 03, 2026
Source: NVD
CVE-2026-25024 MEDIUM - 5.4

Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site Request Forgery.This issue affects ThirstyAffiliates: from n/a through <= 3.11.9.

Vendor: Blair Williams
Product: ThirstyAffiliates
Published: Feb 03, 2026
Source: NVD
CVE-2026-25023 MEDIUM - 5.3

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP contest-code-checker allows Retrieve Embedded Sensitive Data.This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a throu...

Vendor: mdedev
Product: Run Contests, Raffles, and Giveaways with ContestsWP
Published: Feb 03, 2026
Source: NVD
CVE-2026-25022 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16.

Vendor: Iqonic Design
Product: KiviCare
Published: Feb 03, 2026
Source: NVD
CVE-2026-25021 MEDIUM - 5.4

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

Vendor: Mizan Themes
Product: Mizan Demo Importer
Published: Feb 03, 2026
Source: NVD
CVE-2026-25020 MEDIUM - 4.3

Missing Authorization vulnerability in WP connect WP Sync for Notion wp-sync-for-notion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sync for Notion: from n/a through <= 1.7.0.

Vendor: WP connect
Product: WP Sync for Notion
Published: Feb 03, 2026
Source: NVD
CVE-2026-25019 MEDIUM - 5.3

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.3.1.

Vendor: Vito Peleg
Product: Atarim
Published: Feb 03, 2026
Source: NVD
CVE-2026-25016 MEDIUM - 4.3

Missing Authorization vulnerability in Nelio Software Nelio Popups nelio-popups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio Popups: from n/a through <= 1.3.5.

Vendor: Nelio Software
Product: Nelio Popups
Published: Feb 03, 2026
Source: NVD
CVE-2026-25015 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.

Vendor: Stiofan
Product: UsersWP
Published: Feb 03, 2026
Source: NVD