Recent CVEs (Last 30 days)

7160 CVEs found

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

Published: 2026-05-06
Products: 0

In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Published: 2026-05-06
Products: 20
Vendors:
google unisoc

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Published: 2026-05-06
Products: 20
Vendors:
google unisoc

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Published: 2026-05-06
Products: 20
Vendors:
google unisoc

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Published: 2026-05-06
Products: 20
Vendors:
google unisoc

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Published: 2026-05-06
Products: 20
Vendors:
google unisoc

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Published: 2026-05-06
Products: 8
Vendors:
google unisoc
CVE-2026-7572
4.4 MEDIUM

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial ...

Published: 2026-05-06
Products: 3
Vendors:
linux microsoft rapid7
CVE-2026-7573
5.0 MEDIUM

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (...

Published: 2026-05-06
Products: 2
Vendors:
linux rapid7
CVE-2026-3208
5.3 MEDIUM

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all vers...

Published: 2026-05-06
Products: 0
CVE-2026-5753
6.5 MEDIUM

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::sa...

Published: 2026-05-06
Products: 0
CVE-2026-2306
4.3 MEDIUM

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all...

Published: 2026-05-06
Products: 0

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator w...

Published: 2026-05-06
Products: 0

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle databa...

Published: 2026-05-06
Products: 0

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actio...

Published: 2026-05-06
Products: 0
CVE-2026-35253
4.7 MEDIUM

Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected is v0.22.0. Easily exploitable vulnerability allows unauthenticated attacker wi...

Published: 2026-05-06
Products: 1
Vendors:
oracle
CVE-2026-35254
6.1 MEDIUM

Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated attacker with netwo...

Published: 2026-05-06
Products: 1
Vendors:
oracle
CVE-2026-6344
4.9 MEDIUM

The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNot...

Published: 2026-05-06
Products: 0
CVE-2026-6672
6.4 MEDIUM

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.2.7. This is due to ...

Published: 2026-05-06
Products: 0

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, a...

Published: 2026-05-06
Products: 0