NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2251 5.3 MEDIUM
Network
- - Se encontró una vulnerabilidad en elecV2 elecV2P hasta la versión 3.8.3. El elemento afectado es la función path.join del archivo /log/ del componente Wildcard Handler. La manipulación resulta en sal… CWE-22
Path Traversal
CVE-2026-5014 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2252 4.3 MEDIUM
Network
- - A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename cause… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-5015 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2253 4.3 MEDIUM
Network
- - Una vulnerabilidad fue determinada en elecV2 elecV2P hasta la versión 3.8.3. El elemento afectado es una función desconocida del archivo /logs del componente Endpoint. Esta manipulación del argumento… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-5015 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2254 7.3 HIGH
Network
- - A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-si… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5016 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2255 7.3 HIGH
Network
- - Una vulnerabilidad fue identificada en elecV2 elecV2P hasta 3.8.3. Esto afecta la función eAxios del archivo /mock del componente URL Gestor. Dicha manipulación del argumento req conduce a falsificac… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5016 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2256 6.4 MEDIUM
Network
- - The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization… CWE-79
Cross-site Scripting
CVE-2026-2602 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2257 6.4 MEDIUM
Network
- - El plugin Twentig para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'featuredImageSizeWidth' en versiones hasta la 1.9.7, inclusive, debido a una sanitización de e… CWE-79
Cross-site Scripting
CVE-2026-2602 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2258 5.3 MEDIUM
Local
- - A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the … CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-5023 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2259 5.3 MEDIUM
Local
- - Se ha encontrado una vulnerabilidad en DeDeveloper23 codebase-mcp hasta 3ec749d237dd8eabbeef48657cf917275792fde6. Esta vulnerabilidad afecta a la función getCodebase/getRemoteCodebase/saveCodebase de… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-5023 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2260 4.3 MEDIUM
Network
- - A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the a… CWE-99
Resource Injection
CVE-2026-5031 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2261 4.3 MEDIUM
Network
- - Se encontró una vulnerabilidad en BichitroGan ISP Billing Software 2025.3.20. Afecta a una función desconocida del archivo /?_route=settings/users-view/ del componente Endpoint. La manipulación del a… CWE-99
Resource Injection
CVE-2026-5031 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2262 3.3 LOW
Local
- - A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. Executing a manipulation of the argument tempr c… CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-5037 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2263 3.3 LOW
Local
- - Se determinó una vulnerabilidad en mxml hasta la versión 4.0.4. Este problema afecta a la función index_sort del archivo mxml-index.c del componente mxmlIndexNew. La ejecución de una manipulación del… CWE-119
CWE-121
Incorrect Access of Indexable Resource ('Range Error') 
Stack-based Buffer Overflow
CVE-2026-5037 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2264 4.7 MEDIUM
Network
- - A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument … CWE-74
CWE-77
Injection
Command Injection
CVE-2026-5041 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2265 4.7 MEDIUM
Network
- - Una vulnerabilidad fue identificada en el Sistema de Gestión de Membresías de la Cámara de Comercio de code-projects 1.0. Afectada es la función fwrite del archivo admin/pageMail.PHP. La manipulación… CWE-74
CWE-77
Injection
Command Injection
CVE-2026-5041 2026-04-25 01:36 2026-03-29 Show GitHub Exploit DB Packet Storm
2266 7.5 HIGH
Network
- - The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-3124 2026-04-25 01:36 2026-03-30 Show GitHub Exploit DB Packet Storm
2267 7.5 HIGH
Network
- - El plugin Download Monitor para WordPress es vulnerable a Referencia Directa Insegura a Objeto en todas las versiones hasta la 5.1.7, inclusive, a través de la función executePayment() debido a la fa… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-3124 2026-04-25 01:36 2026-03-30 Show GitHub Exploit DB Packet Storm
2268 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting Running stress-ng --schedpolicy 0 on an RT kernel on a big ma… NVD-CWE-noinfo
CVE-2026-23371 2026-04-25 01:36 2026-03-25 Show GitHub Exploit DB Packet Storm
2269 5.5 MEDIUM
Local
linux linux_kernel En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: sched/deadline: Solucionar la falta de ENQUEUE_REPLENISH durante la des-potenciación PI Ejecutar stress-ng --schedpolicy 0 en un… NVD-CWE-noinfo
CVE-2026-23371 2026-04-25 01:36 2026-03-25 Show GitHub Exploit DB Packet Storm
2270 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfc: rawsock: cancel tx_work before socket teardown In rawsock_release(), cancel any pending tx_work and purge the write queue be… NVD-CWE-noinfo
CVE-2026-23372 2026-04-25 01:36 2026-03-25 Show GitHub Exploit DB Packet Storm
2271 7.8 HIGH
Local
linux linux_kernel En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: nfc: rawsock: cancelar tx_work antes del desmontaje del socket En rawsock_release(), cancelar cualquier tx_work pendiente y purg… NVD-CWE-noinfo
CVE-2026-23372 2026-04-25 01:36 2026-03-25 Show GitHub Exploit DB Packet Storm
2272 8.2 HIGH
Network
flowiseai flowise Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacke… CWE-306
Missing Authentication for Critical Function
CVE-2026-41273 2026-04-25 01:35 2026-04-24 Show GitHub Exploit DB Packet Storm
2273 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac80211_config This triggers a WARN_ON in ieee80211_hw_conf_init and isn't the ex… NVD-CWE-noinfo
CVE-2026-23373 2026-04-25 01:35 2026-03-25 Show GitHub Exploit DB Packet Storm
2274 5.5 MEDIUM
Local
linux linux_kernel En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: wifi: rsi: No usar -EOPNOTSUPP por defecto en rsi_mac80211_config Esto activa un WARN_ON en ieee80211_hw_conf_init y no es el co… NVD-CWE-noinfo
CVE-2026-23373 2026-04-25 01:35 2026-03-25 Show GitHub Exploit DB Packet Storm
2275 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProgressionStudios Vayvo vayvo-progression allows Reflected XSS.This issue affects Vayvo: from n/… CWE-79
Cross-site Scripting
CVE-2026-25373 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2276 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ProgressionStudios Vayvo vayvo-progression permite XSS Reflejado. Este problema… CWE-79
Cross-site Scripting
CVE-2026-25373 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2277 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows Reflected XSS.This issue affects Addon Jo… CWE-79
Cross-site Scripting
CVE-2026-25376 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2278 7.1 HIGH
Network
- - Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en eyecix Addon Jobsearch Chat addon-jobsearch-chat permite XSS Reflejado. Este… CWE-79
Cross-site Scripting
CVE-2026-25376 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2279 9.3 CRITICAL
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jo… CWE-89
SQL Injection
CVE-2026-25377 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2280 9.3 CRITICAL
Network
- - Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') vulnerabilidad en eyecix Addon Jobsearch Chat addon-jobsearch-chat permite la inyección SQL. Este prob… CWE-89
SQL Injection
CVE-2026-25377 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2281 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes StreamVid streamvid allows PHP Local File Inclusion.This issue affec… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25379 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2282 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP, vulnerabilidad de 'inclusión remota de ficheros PHP', en jwsthemes StreamVid streamvid permite la incl… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25379 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2283 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Feedy feedy allows PHP Local File Inclusion.This issue affects Feedy… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25380 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2284 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('PHP inclusión remota de ficheros') vulnerabilidad en jwsthemes Feedy feedy permite PHP inclusión loca… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25380 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2285 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP Local File Inclusion.This issue affects… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25381 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2286 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP (vulnerabilidad de 'inclusión remota de ficheros PHP') en jwsthemes LoveDate lovedate permite la inclus… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25381 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2287 8.1 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes IdealAuto idealauto allows PHP Local File Inclusion.This issue affec… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25382 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2288 8.1 HIGH
Network
- - Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión remota de ficheros PHP') vulnerabilidad en jwsthemes IdealAuto idealauto permite la inclusi… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-25382 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2289 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects … CWE-79
Cross-site Scripting
CVE-2026-25383 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2290 7.1 HIGH
Network
- - Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Iqonic Design KiviCare kivicare-clinic-management-system permite XSS Reflejado.… CWE-79
Cross-site Scripting
CVE-2026-25383 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2291 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n… CWE-862
 Missing Authorization
CVE-2026-25390 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2292 6.5 MEDIUM
Network
- - Vulnerabilidad de autorización faltante en Saad Iqbal New User Approve new-user-approve permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema… CWE-862
 Missing Authorization
CVE-2026-25390 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2293 7.5 HIGH
Network
- - Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… CWE-862
 Missing Authorization
CVE-2026-25396 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2294 7.5 HIGH
Network
- - Vulnerabilidad por ausencia de autorización en CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce permite la explotación de niveles de seguridad de control de acceso confi… CWE-862
 Missing Authorization
CVE-2026-25396 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2295 7.5 HIGH
Network
- - Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from … CWE-35
 Path Traversal: '.../...//'
CVE-2026-25397 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2296 7.5 HIGH
Network
- - Salto de ruta: la vulnerabilidad '.../...//' en Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce permite el salto de ruta. Este problema afecta a File Uploader for WooComm… CWE-35
 Path Traversal: '.../...//'
CVE-2026-25397 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2297 6.5 MEDIUM
Network
- - Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… CWE-862
 Missing Authorization
CVE-2026-25398 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2298 6.5 MEDIUM
Network
- - Vulnerabilidad de autorización faltante en Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder permite la explotación de niveles de seguridad de control de acceso configurados incor… CWE-862
 Missing Authorization
CVE-2026-25398 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2299 8.8 HIGH
Network
- - Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25400 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm
2300 8.8 HIGH
Network
- - Vulnerabilidad de deserialización de datos no confiables en thememount Apicona apicona permite la inyección de objetos. Este problema afecta a Apicona: desde n/a hasta &lt;= 24.1.0. CWE-502
 Deserialization of Untrusted Data
CVE-2026-25400 2026-04-25 01:35 2026-03-26 Show GitHub Exploit DB Packet Storm