NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3051 4.7 MEDIUM
Network
- - A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname lead… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-4550 2026-04-25 01:32 2026-03-22 Show GitHub Exploit DB Packet Storm
3052 4.7 MEDIUM
Network
- - Una vulnerabilidad ha sido encontrada en code-projects Simple Gym Management System hasta la versión 1.0. Esto afecta una parte desconocida del archivo /gym/func.php. Dicha manipulación del argumento… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-4550 2026-04-25 01:32 2026-03-22 Show GitHub Exploit DB Packet Storm
3053 4.3 MEDIUM
Network
- - A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in c… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4557 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3054 4.3 MEDIUM
Network
- - Una vulnerabilidad fue detectada en code-projects Exam Form Submission 1.0. Esto impacta una función desconocida del archivo /admin/update_s1.php. Realizar una manipulación del argumento sname result… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4557 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3055 7.5 HIGH
Network
- - The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up … CWE-89
SQL Injection
CVE-2026-2580 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3056 7.5 HIGH
Network
- - El plugin WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'orderby' en to… CWE-89
SQL Injection
CVE-2026-2580 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3057 7.3 HIGH
Network
- - A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation r… CWE-287
CWE-306
Improper Authentication
Missing Authentication for Critical Function
CVE-2026-4562 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3058 7.3 HIGH
Network
- - Se ha descubierto una falla de seguridad en MacCMS 2025.1000.4052. Esto afecta una parte desconocida del archivo application/api/controller/Timming.php del componente Timming API Endpoint. La manipul… CWE-287
CWE-306
Improper Authentication
Missing Authentication for Critical Function
CVE-2026-4562 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3059 4.3 MEDIUM
Network
- - A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detai… CWE-285
CWE-639
Improper Authorization
 Authorization Bypass Through User-Controlled Key
CVE-2026-4563 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3060 4.3 MEDIUM
Network
- - Se ha identificado una debilidad en MacCMS hasta 2025.1000.4052. Esta vulnerabilidad afecta a la función order_info del archivo application/index/controller/User.php del componente Member Order Detai… CWE-285
CWE-639
Improper Authorization
 Authorization Bypass Through User-Controlled Key
CVE-2026-4563 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3061 4.7 MEDIUM
Network
- - A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. This issue affects some unknown processing of the file /monitor/job/ of the component Quartz Job Handler. Such manipulat… CWE-74
CWE-94
Injection
Code Injection
CVE-2026-4564 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3062 6.5 MEDIUM
Network
- - The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authori… CWE-285
Improper Authorization
CVE-2025-10736 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3063 6.5 MEDIUM
Network
- - El plugin ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More para WordPress es vulnerable a acceso no autorizado a datos debido a controles … CWE-285
Improper Authorization
CVE-2025-10736 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3064 5.3 MEDIUM
Network
- - The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… CWE-285
Improper Authorization
CVE-2025-10731 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3065 4.7 MEDIUM
Network
- - Una vulnerabilidad de seguridad ha sido detectada en yangzongzhuan RuoYi hasta la versión 4.8.2. Este problema afecta a algún procesamiento desconocido del archivo /monitor/job/ del componente Gestor… CWE-74
CWE-94
Injection
Code Injection
CVE-2026-4564 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3066 7.3 HIGH
Network
- - The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and i… CWE-94
Code Injection
CVE-2025-10679 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3067 7.3 HIGH
Network
- - El plugin ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More para WordPress es vulnerable a llamadas a métodos arbitrarios en todas las vers… CWE-94
Code Injection
CVE-2025-10679 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3068 5.3 MEDIUM
Network
- - El plugin ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More para WordPress es vulnerable a la Exposición de Información Sensible en todas l… CWE-285
Improper Authorization
CVE-2025-10731 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3069 5.3 MEDIUM
Network
- - The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t… CWE-922
 Insecure Storage of Sensitive Information
CVE-2025-10734 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3070 5.3 MEDIUM
Network
- - El plugin ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More para WordPress es vulnerable a la Exposición de Información Sensible en todas l… CWE-922
 Insecure Storage of Sensitive Information
CVE-2025-10734 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3071 6.3 MEDIUM
Network
- - A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET P… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-4573 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3072 6.3 MEDIUM
Network
- - Se ha detectado una vulnerabilidad de seguridad en SourceCodester Simple E-learning System 1.0. Esto afecta una parte desconocida del archivo /includes/form_handlers/delete_post.php del componente Ge… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-4573 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3073 6.3 MEDIUM
Network
- - A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument fir… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-4574 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3074 6.3 MEDIUM
Network
- - Se detectó una vulnerabilidad en SourceCodester Simple E-learning System 1.0. Esta vulnerabilidad afecta a código desconocido del componente Gestor de Actualización de Perfil de Usuario. La manipulac… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-4574 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3075 2.4 LOW
Network
- - A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s2.php. This manipulation of the argument sname causes cross site… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4575 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3076 2.4 LOW
Network
- - Se ha encontrado una vulnerabilidad en code-projects Exam Form Submission 1.0. Este problema afecta a algún procesamiento desconocido del archivo /admin/update_s2.php. Esta manipulación del argumento… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4575 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3077 2.4 LOW
Network
- - A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /admin/update_s5.php. Such manipulation of the argument sname leads to cross site… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4576 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3078 2.4 LOW
Network
- - Una vulnerabilidad ha sido encontrada en code-projects Exam Form Submission 1.0. Afectada es una función desconocida del archivo /admin/update_s5.php. Tal manipulación del argumento sname lleva a cro… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4576 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3079 5.3 MEDIUM
Network
- - The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all version… CWE-200
Information Exposure
CVE-2025-13997 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3080 5.3 MEDIUM
Network
- - Los King Addons para Elementor – más de 4.000 secciones de Elementor listas, más de 650 plantillas, más de 70 widgets GRATUITOS para el plugin Elementor para WordPress es vulnerable a la divulgación … CWE-200
Information Exposure
CVE-2025-13997 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3081 6.4 MEDIUM
Network
- - The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnera… CWE-79
Cross-site Scripting
CVE-2025-6229 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3082 6.4 MEDIUM
Network
- - La extensión Sina para Elementor (Header Builder, Footer Builder, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin para WordPress es vu… CWE-79
Cross-site Scripting
CVE-2025-6229 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3083 2.4 LOW
Network
- - A vulnerability was found in code-projects Exam Form Submission 1.0. The affected element is an unknown function of the file /admin/update_s4.php. Performing a manipulation of the argument sname resu… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4577 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3084 2.4 LOW
Network
- - Se encontró una vulnerabilidad en code-projects Exam Form Submission 1.0. El elemento afectado es una función desconocida del archivo /admin/update_s4.PHP. La manipulación del argumento sname resulta… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4577 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3085 2.4 LOW
Network
- - A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_s3.php. Executing a manipulation of the argument sname … CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4578 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3086 2.4 LOW
Network
- - Se determinó una vulnerabilidad en code-projects Exam Form Submission 1.0. El elemento impactado es una función desconocida del archivo /admin/update_s3.PHP. La ejecución de una manipulación del argu… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4578 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3087 5.0 MEDIUM
Adjacent
- - A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation le… CWE-287
CWE-306
Improper Authentication
Missing Authentication for Critical Function
CVE-2026-4582 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3088 5.0 MEDIUM
Adjacent
- - Una vulnerabilidad de seguridad ha sido detectada en Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Afectada por esta vulnerabilidad es una funcionalidad desconocida del componente Bluetooth. Tal mani… CWE-287
CWE-306
Improper Authentication
Missing Authentication for Critical Function
CVE-2026-4582 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3089 5.0 MEDIUM
Adjacent
- - A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown functionality of the component Bluetooth Handler. Performing a manipulation result… CWE-287
CWE-294
Improper Authentication
Authentication Bypass by Capture-replay 
CVE-2026-4583 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3090 5.0 MEDIUM
Adjacent
- - Se detectó una vulnerabilidad en Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Afecta a alguna funcionalidad desconocida del componente Gestor de Bluetooth. Realizar una manipulación resulta en omisi… CWE-287
CWE-294
Improper Authentication
Authentication Bypass by Capture-replay 
CVE-2026-4583 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3091 3.1 LOW
Adjacent
- - A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmissi… CWE-310
CWE-319
Cryptographic Issues
Cleartext Transmission of Sensitive Information
CVE-2026-4584 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3092 3.1 LOW
Adjacent
- - Se ha encontrado una vulnerabilidad en Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Esto afecta a una parte desconocida del componente Gestor de Datos del Titular de la Tarjeta. La ejecución de una … CWE-310
CWE-319
Cryptographic Issues
Cleartext Transmission of Sensitive Information
CVE-2026-4584 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3093 9.8 CRITICAL
Network
- - A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-4585 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3094 3.7 LOW
Network
- - A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument cur… CWE-287
CWE-295
Improper Authentication
Improper Certificate Validation 
CVE-2026-4587 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3095 6.3 MEDIUM
Network
- - A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the componen… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-4589 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3096 9.8 CRITICAL
Network
- - Se ha encontrado una vulnerabilidad en la Plataforma de Gestión Integrada Tiandy Easy7 hasta la versión 7.17.0. Esta vulnerabilidad afecta a código desconocido del archivo /Easy7/apps/WebService/Impo… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-4585 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3097 6.3 MEDIUM
Network
- - A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-4586 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3098 6.3 MEDIUM
Network
- - Una vulnerabilidad fue encontrada en CodePhiliaX Chat2DB hasta 0.3.7. Esto afecta la función Upload del archivo chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/serve… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-4586 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3099 3.7 LOW
Network
- - Una vulnerabilidad fue encontrada en HybridAuth hasta la versión 3.12.2. Este problema afecta a algún procesamiento desconocido del archivo src/HttpClient/Curl.php del componente Gestor SSL. La manip… CWE-287
CWE-295
Improper Authentication
Improper Certificate Validation 
CVE-2026-4587 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm
3100 3.7 LOW
Network
- - A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-le… CWE-320
CWE-321
 Key Management Errors
 Use of Hard-coded Cryptographic Key
CVE-2026-4588 2026-04-25 01:32 2026-03-23 Show GitHub Exploit DB Packet Storm