CVE Vulnerability Database

Search and browse 3,823 known security vulnerabilities. Filter by severity, vendor, product, and year.

3,823 vulnerabilities found
CVE-2026-9757
7.5 high

The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, which only covers $_POST

May 30, 2026
CVE-2026-7465
8.8 high

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. E

May 30, 2026
CVE-2026-7459
7.5 high

The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_perm

May 30, 2026
CVE-2026-10111
7.3 high

A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The proje

May 30, 2026
CVE-2026-10110
7.3 high

A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may

May 30, 2026
CVE-2026-47123
7.5 high

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / References headers. The notification reply path (notify

May 29, 2026
CVE-2026-46599
7.5 high

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

May 29, 2026
CVE-2026-46527
7.5 high

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwarded-For header whose value parses to no valid

Yhirose Cpp-Httplib May 29, 2026
CVE-2026-44422
7.5 high

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two po

Freerdp Freerdp May 29, 2026
CVE-2026-44421
8.8 high

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX

Freerdp Freerdp May 29, 2026
CVE-2026-44420
8.8 high

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process

Freerdp Freerdp May 29, 2026
CVE-2026-44285
7.7 high

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi

May 29, 2026
CVE-2026-49374
7.6 high

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

Jetbrains Teamcity May 29, 2026
CVE-2026-49373
7.1 high

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Jetbrains Teamcity May 29, 2026
CVE-2026-49372
7.5 high

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49371
7.1 high

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

Jetbrains Teamcity May 29, 2026
CVE-2026-49368
8.7 high

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Jetbrains Youtrack May 29, 2026
CVE-2026-49367
8.0 high

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

Jetbrains Intellij Idea May 29, 2026
CVE-2026-49366
7.8 high

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

Jetbrains Intellij Idea May 29, 2026
CVE-2026-42941
8.3 high

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

Macgregor Interschalt Vdr G4E Firmware May 29, 2026
CVE-2026-42929
8.3 high

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

Macgregor Interschalt Vdr G4E Firmware May 29, 2026
CVE-2026-6824
8.4 high

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or

May 29, 2026
CVE-2026-5768
8.8 high

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggeri

May 29, 2026
CVE-2026-44697
8.6 high

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi-gigabyte heaps on t

May 29, 2026