Total CVEs

149,967

Critical Severity

4,910

High Severity

17,396

Last 7 Days

1,778
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 541 - 560 of 46,372 CVEs
CVE-2026-66445 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

Vendor: 100plugins
Product: Open User Map
Published: Jul 27, 2026
Source: NVD
CVE-2026-66442 MEDIUM - 5.4

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

Vendor: YayCommerce
Product: YayPricing
Published: Jul 27, 2026
Source: NVD
CVE-2026-66438 MEDIUM - 5.3

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

Vendor: Tim Strifler
Product: Exclusive Addons Elementor
Published: Jul 27, 2026
Source: NVD
CVE-2026-66437 MEDIUM - 4.9

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

Vendor: Themeisle
Product: Feedzy
Published: Jul 27, 2026
Source: NVD
CVE-2026-66434 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

Vendor: Sayontan Sinha
Product: Photonic Gallery & Lightbox for Flickr, SmugMug & Others
Published: Jul 27, 2026
Source: NVD
CVE-2026-66433 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

Vendor: ShapedPlugin LLC
Product: Location Weather
Published: Jul 27, 2026
Source: NVD
CVE-2026-66428 MEDIUM - 4.3

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

Vendor: jgwhite33
Product: WP Google Review Slider
Published: Jul 27, 2026
Source: NVD
CVE-2026-66427 HIGH - 7.6

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.

Vendor: jgwhite33
Product: WP Google Review Slider
Published: Jul 27, 2026
Source: NVD
CVE-2026-66050 HIGH - 7.5

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attac...

Vendor: nitroshare
Product: nitroshare-desktop
Published: Jul 27, 2026
Source: NVD
CVE-2026-65568 MEDIUM - 5.0

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

Vendor: Visual Composer
Product: Visual Composer Website Builder
Published: Jul 27, 2026
Source: NVD
CVE-2026-65567 MEDIUM - 5.3

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

Vendor: Nexcess
Product: Event Tickets
Published: Jul 27, 2026
Source: NVD
CVE-2026-65564 MEDIUM - 5.3

Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

Vendor: chrisvrichardson
Product: MapPress Maps for WordPress
Published: Jul 27, 2026
Source: NVD
CVE-2026-65563 MEDIUM - 5.9

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

Vendor: Themeisle
Product: Orbit Fox by ThemeIsle
Published: Jul 27, 2026
Source: NVD
CVE-2026-65562 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

Vendor: WPDeveloper
Product: BetterDocs
Published: Jul 27, 2026
Source: NVD
CVE-2026-65561 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

Vendor: miniOrange
Product: WordPress Social Login and Register
Published: Jul 27, 2026
Source: NVD
CVE-2026-65558 MEDIUM - 5.4

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

Vendor: WPCenter
Product: AffiliateX
Published: Jul 27, 2026
Source: NVD
CVE-2026-65557 MEDIUM - 5.9

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

Vendor: Tychesoftwares
Product: Abandoned Cart Lite for WooCommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-65436 MEDIUM - 6.8

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

Vendor: Themeum
Product: Kirki
Published: Jul 27, 2026
Source: NVD
CVE-2026-65435 MEDIUM - 6.5

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

Vendor: Thrive Themes Coupon
Product: Thrive Leads Version
Published: Jul 27, 2026
Source: NVD
CVE-2026-65434 MEDIUM - 6.5

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

Vendor: yoomoney
Product: ЮKassa для WooCommerce
Published: Jul 27, 2026
Source: NVD