Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26060
Total
1950
Critical
7934
High
8196
Medium
CVE ID Severity Score Description Published
CVE-2018-25401 HIGH 8.2 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … May 29, 2026
CVE-2018-25400 HIGH 8.2 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … May 29, 2026
CVE-2018-25399 HIGH 8.2 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … May 29, 2026
CVE-2018-25398 HIGH 8.2 The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … May 29, 2026
CVE-2018-25397 MEDIUM 5.3 PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated … May 29, 2026
CVE-2018-25396 HIGH 7.5 Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request … May 29, 2026
CVE-2018-25395 HIGH 8.2 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter … May 29, 2026
CVE-2018-25394 HIGH 8.2 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the release_id parameter … May 29, 2026
CVE-2018-25393 MEDIUM 6.5 Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. … May 29, 2026
CVE-2018-25392 HIGH 7.1 MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters … May 29, 2026
CVE-2018-25391 HIGH 7.5 HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that … May 29, 2026
CVE-2018-25390 HIGH 8.2 HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter … May 29, 2026
CVE-2018-25389 HIGH 8.2 HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter … May 29, 2026
CVE-2018-25388 HIGH 8.8 HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload … May 29, 2026
CVE-2018-25387 MEDIUM 5.3 HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. … May 29, 2026
CVE-2018-25386 HIGH 8.2 HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. … May 29, 2026
CVE-2018-25385 HIGH 8.2 E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai … May 29, 2026
CVE-2018-25384 MEDIUM 5.4 Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can … May 29, 2026
CVE-2018-25383 HIGH 8.4 Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured … May 29, 2026
CVE-2018-25382 HIGH 8.2 Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can … May 29, 2026
CVE-2026-4290 CRITICAL 9.1 The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and … May 29, 2026
CVE-2026-45609 HIGH 7.2 mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF … May 29, 2026
CVE-2026-41159 UNKNOWN Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows … May 29, 2026
CVE-2026-41150 UNKNOWN Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service … May 29, 2026
CVE-2026-39292 UNKNOWN Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote … May 29, 2026