Total CVEs

150,903

Critical Severity

5,032

High Severity

17,664

Last 7 Days

2,098
Quick preset (or use dates below)
Clear Filters
Showing 2,301 - 2,320 of 150,903 CVEs
CVE-2026-65489 MEDIUM - 5.3

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

Vendor: LA-Studio
Product: LA-Studio Element Kit for Elementor
Published: Jul 23, 2026
Source: NVD
CVE-2026-65488 HIGH - 7.1

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

Vendor: LA-Studio
Product: LA-Studio Element Kit for Elementor
Published: Jul 23, 2026
Source: NVD
CVE-2026-65487 MEDIUM - 5.3

Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.

Vendor: ThemeGoods
Product: Photography
Published: Jul 23, 2026
Source: NVD
CVE-2026-65486 MEDIUM - 5.3

Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.

Vendor: Bastien Ho
Product: Event post
Published: Jul 23, 2026
Source: NVD
CVE-2026-65485 MEDIUM - 5.3

Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.

Vendor: Daniel Iser
Product: Content Control
Published: Jul 23, 2026
Source: NVD
CVE-2026-65484 MEDIUM - 6.3

Contributor Broken Access Control in Style Kits <= 2.6.5 versions.

Vendor: AnalogWP
Product: Style Kits
Published: Jul 23, 2026
Source: NVD
CVE-2026-65483 MEDIUM - 5.9

Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.

Vendor: hashthemes
Product: HashThemes Demo Importer
Published: Jul 23, 2026
Source: NVD
CVE-2026-65482 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

Vendor: LA-Studio
Product: LA-Studio Element Kit for Elementor
Published: Jul 23, 2026
Source: NVD
CVE-2026-65481 HIGH - 7.5

Contributor Local File Inclusion in Vino <= 1.9 versions.

Vendor: Elated-Themes
Product: Vino
Published: Jul 23, 2026
Source: NVD
CVE-2026-65480 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.

Vendor: CodexThemes
Product: TheGem
Published: Jul 23, 2026
Source: NVD
CVE-2026-65479 MEDIUM - 5.4

Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.

Vendor: MVP Themes
Product: Reviewer
Published: Jul 23, 2026
Source: NVD
CVE-2026-65478 MEDIUM - 5.4

Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.

Vendor: CridioStudio
Product: ListingPro
Published: Jul 23, 2026
Source: NVD
CVE-2026-65477 HIGH - 7.5

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

Vendor: Select-Themes
Product: Tonda Core
Published: Jul 23, 2026
Source: NVD
CVE-2026-65476 MEDIUM - 5.3

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.

Vendor: uxper
Product: Civi
Published: Jul 23, 2026
Source: NVD
CVE-2026-65475 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.

Vendor: WP Chill
Product: Modula Image Gallery
Published: Jul 23, 2026
Source: NVD
CVE-2026-65474 MEDIUM - 5.3

Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

Vendor: WPManageNinja
Product: Ninja Tables
Published: Jul 23, 2026
Source: NVD
CVE-2026-65473 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.

Vendor: Nexcess
Product: Virtue/Ascend/Pinnacle Toolkit
Published: Jul 23, 2026
Source: NVD
CVE-2026-65472 MEDIUM - 5.3

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

Vendor: Kit
Product: Kit (formerly ConvertKit)
Published: Jul 23, 2026
Source: NVD
CVE-2026-65471 CRITICAL - 9.6

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

Vendor: Avada Studio
Product: Avada Core
Published: Jul 23, 2026
Source: NVD
CVE-2026-65470 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

Vendor: WPManageNinja
Product: Fluent Support
Published: Jul 23, 2026
Source: NVD