Total CVEs

150,903

Critical Severity

5,032

High Severity

17,664

Last 7 Days

2,098
Quick preset (or use dates below)
Clear Filters
Showing 2,281 - 2,300 of 150,903 CVEs
CVE-2026-65516 HIGH - 7.2

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

Vendor: Pepro Dev. Group
Product: PeproDev Ultimate Invoice
Published: Jul 23, 2026
Source: NVD
CVE-2026-65514 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

Vendor: codepeople
Product: Appointment Hour Booking
Published: Jul 23, 2026
Source: NVD
CVE-2026-65512 MEDIUM - 5.4

Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.

Vendor: Melapress
Product: WP Activity Log
Published: Jul 23, 2026
Source: NVD
CVE-2026-65511 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

Vendor: pixelacehq
Product: Manual - Documentation, Knowledge Base & Education WordPress Theme
Published: Jul 23, 2026
Source: NVD
CVE-2026-65510 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.

Vendor: Pepro Dev. Group
Product: PeproDev Ultimate Invoice
Published: Jul 23, 2026
Source: NVD
CVE-2026-65506 MEDIUM - 5.3

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

Vendor: sonaar
Product: MP3 Audio Player for Music, Radio & Podcast by Sonaar
Published: Jul 23, 2026
Source: NVD
CVE-2026-65505 MEDIUM - 5.3

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

Vendor: bdthemes
Product: Ultimate Store Kit Elementor Addons
Published: Jul 23, 2026
Source: NVD
CVE-2026-65503 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

Vendor: bdthemes
Product: Ultimate Store Kit Elementor Addons
Published: Jul 23, 2026
Source: NVD
CVE-2026-65501 MEDIUM - 5.3

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

Vendor: vendidero
Product: Shiptastic for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-65500 HIGH - 7.5

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

Vendor: pixelacehq
Product: Manual - Documentation, Knowledge Base & Education WordPress Theme
Published: Jul 23, 2026
Source: NVD
CVE-2026-65499 MEDIUM - 6.5

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

Vendor: Pepro Dev. Group
Product: PeproDev Ultimate Invoice
Published: Jul 23, 2026
Source: NVD
CVE-2026-65498 MEDIUM - 5.3

Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

Vendor: Complianz
Product: Complianz
Published: Jul 23, 2026
Source: NVD
CVE-2026-65497 HIGH - 7.2

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

Vendor: Complianz
Product: Complianz
Published: Jul 23, 2026
Source: NVD
CVE-2026-65496 MEDIUM - 4.4

Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.

Vendor: Complianz
Product: Complianz
Published: Jul 23, 2026
Source: NVD
CVE-2026-65495 HIGH - 7.5

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

Vendor: Dokan Multivendor Plugin
Product: Dokan Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-65494 HIGH - 7.1

Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.

Vendor: Dokan
Product: Dokan Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-65493 HIGH - 7.5

Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

Vendor: Dokan
Product: Dokan Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-65492 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.

Vendor: Dokan WordPress Plugin
Product: Dokan Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-65491 MEDIUM - 4.3

Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.

Vendor: Jonathan Daggerhart
Product: Query Wrangler
Published: Jul 23, 2026
Source: NVD
CVE-2026-65490 MEDIUM - 5.3

Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.

Vendor: mischiefmarmot
Product: Create by Mediavine
Published: Jul 23, 2026
Source: NVD