Total CVEs

150,903

Critical Severity

5,032

High Severity

17,664

Last 7 Days

2,097
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,381 - 2,400 of 47,308 CVEs
CVE-2026-59522 MEDIUM - 6.5

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

Vendor: weDevs
Product: WP ERP
Published: Jul 23, 2026
Source: NVD
CVE-2026-59517 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

Vendor: hassantafreshi
Product: Easy Form Builder
Published: Jul 23, 2026
Source: NVD
CVE-2026-59514 CRITICAL - 9.3

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

Vendor: MightyNetworks vs BuddyBoss
Product: Buddyboss Platform
Published: Jul 23, 2026
Source: NVD
CVE-2026-59513 MEDIUM - 6.5

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

Vendor: masteriyo
Product: Masteriyo - LMS
Published: Jul 23, 2026
Source: NVD
CVE-2026-59512 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

Vendor: PI Web Solution
Product: Product Enquiry for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-57809 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.

Vendor: AffiliateWP
Product: AffiliateWP
Published: Jul 23, 2026
Source: NVD
CVE-2026-57808 MEDIUM - 6.5

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

Vendor: Saad Iqbal
Product: WP EasyPay
Published: Jul 23, 2026
Source: NVD
CVE-2026-57785 HIGH - 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

Vendor: ApusTheme
Product: ApusListing
Published: Jul 23, 2026
Source: NVD
CVE-2026-57784 CRITICAL - 9.6

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Vendor: Ninja Forms
Product: Ninja Forms File Uploads Extension
Published: Jul 23, 2026
Source: NVD
CVE-2026-57769 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

Vendor: ThemeGoods
Product: Grand Photography
Published: Jul 23, 2026
Source: NVD
CVE-2026-57767 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

Vendor: CodeCabin.io
Product: WP Google Maps Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-57735 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

Vendor: Soflyy
Product: Breakdance
Published: Jul 23, 2026
Source: NVD
CVE-2026-57717 MEDIUM - 6.5

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

Vendor: knitpay
Product: Knit Pay
Published: Jul 23, 2026
Source: NVD
CVE-2026-57716 MEDIUM - 5.3

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

Vendor: videowhisper
Product: Broadcast Live Video
Published: Jul 23, 2026
Source: NVD
CVE-2026-57704 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

Vendor: StoreApps
Product: Smart Manager
Published: Jul 23, 2026
Source: NVD
CVE-2026-57703 MEDIUM - 6.3

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

Vendor: sunshinephotocart
Product: Sunshine Photo Cart
Published: Jul 23, 2026
Source: NVD
CVE-2026-57701 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

Vendor: WebCodingPlace
Product: Real Estate Manager Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-57699 HIGH - 7.1

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

Vendor: bqworks
Product: Slider Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-57696 HIGH - 7.1

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

Vendor: videowhisper
Product: Picture Gallery
Published: Jul 23, 2026
Source: NVD
CVE-2026-57626 HIGH - 7.1

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.

Vendor: MailPoet
Product: MailPoet
Published: Jul 23, 2026
Source: NVD