Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 2,224 CVEs
CVE-2026-1843 HIGH - 7.2

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2024 HIGH - 7.5

The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1988 HIGH - 7.5

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is due to the `theme` parameter being directly concatenated into a file path without proper sanitizatio...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0753 HIGH - 7.2

The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0745 HIGH - 7.2

The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' function. This makes it possible for authenticated attackers, with Administrator-level access a...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2469 HIGH - 7.6

Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2144 HIGH - 8.1

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads direct...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0692 HIGH - 7.5

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-contro...

Published: Feb 14, 2026
Source: NVD
CVE-2026-24853 HIGH - 8.1

Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP is not allowed to connect to Caido on all endpoints. But this is bypassable by injecting a X-Forwarded-Host: 127.0.0.1:8080 header. This vulnerability...

Vendor: caido
Product: caido
Published: Feb 13, 2026
Source: NVD
CVE-2026-1844 HIGH - 7.2

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 12.4.0.2 due to insufficient input sanitization and output escaping. This makes ...

Published: Feb 13, 2026
Source: NVD
CVE-2026-1841 HIGH - 7.2

The PixelYourSite โ€“ Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 11.2.0 due to insufficient input sanitiza...

Published: Feb 13, 2026
Source: NVD
CVE-2025-15157 HIGH - 8.8

The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, ...

Vendor: starfishwp
Product: Starfish Review Generation & Marketing for WordPress
Published: Feb 13, 2026
Source: NVD
CVE-2026-2441 HIGH - 8.8

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Published: Feb 13, 2026
Source: NVD
CVE-2026-26208 HIGH - 7.8

ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows ...

Vendor: Alex4SSB
Product: ADB-Explorer
Published: Feb 13, 2026
Source: NVD
CVE-2026-26187 HIGH - 8.1

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage boundaries. The verifyRelPath function used strings.Has...

Vendor: treeverse
Product: lakeFS
Published: Feb 13, 2026
Source: NVD
CVE-2026-25991 HIGH - 7.7

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. The application fails to validate the destination URL after...

Vendor: TandoorRecipes
Product: recipes
Published: Feb 13, 2026
Source: NVD
CVE-2026-21878 HIGH - 7.5

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functionality where there is no validation of user-provided file paths, allowing attackers to write files to arbitrary direc...

Vendor: bacnet-stack
Product: bacnet-stack
Published: Feb 13, 2026
Source: NVD
CVE-2026-26268 HIGH - 8.0

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time the...

Vendor: cursor
Product: cursor
Published: Feb 13, 2026
Source: NVD
CVE-2025-70123 HIGH - 7.5

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places the UPF in an inconsistent state where a subsequent...

Published: Feb 13, 2026
Source: NVD
CVE-2025-70122 HIGH - 7.5

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-filter.go) when processing a declared length that ex...

Published: Feb 13, 2026
Source: NVD