Total CVEs

149,971

Critical Severity

4,911

High Severity

17,397

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
Showing 581 - 600 of 149,971 CVEs
CVE-2026-59536 HIGH - 7.5

Unauthenticated Broken Access Control in CoCart โ€“ Headless ecommerce <= 4.8.4 versions.

Vendor: CoCart Headless
Product: CoCart โ€“ Headless ecommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-59535 HIGH - 7.3

Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

Vendor: Thrive Themes Coupon
Product: Thrive Product Manager
Published: Jul 27, 2026
Source: NVD
CVE-2026-59534 HIGH - 7.5

Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

Vendor: Aurovrata Venet
Product: Post My CF7 Form
Published: Jul 27, 2026
Source: NVD
CVE-2026-59533 CRITICAL - 9.3

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

Vendor: Christoph Vielgrader
Product: Relevanssi Light
Published: Jul 27, 2026
Source: NVD
CVE-2026-59532 HIGH - 7.5

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

Vendor: magepeopleteam
Product: Booking and Rental Manager
Published: Jul 27, 2026
Source: NVD
CVE-2026-59531 HIGH - 7.5

Unauthenticated Unknown in Falcon โ€“ WordPress Optimizations & Tweaks <= 2.10.0 versions.

Vendor: Anh Tran
Product: Falcon โ€“ WordPress Optimizations & Tweaks
Published: Jul 27, 2026
Source: NVD
CVE-2026-59530 HIGH - 7.5

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

Vendor: Payment Plugins
Product: Stripe For WooCommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-59529 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

Vendor: motov.net
Product: Ebook Store
Published: Jul 27, 2026
Source: NVD
CVE-2026-59528 HIGH - 7.5

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

Vendor: shiptime
Product: ShipTime: Discounted Shipping Rates
Published: Jul 27, 2026
Source: NVD
CVE-2026-59527 CRITICAL - 9.3

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Vendor: RomanCode
Product: MapSVG
Published: Jul 27, 2026
Source: NVD
CVE-2026-10819 MEDIUM - 6.5

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded ...

Vendor: Mattermost
Product: Mattermost
Published: Jul 27, 2026
Source: NVD
CVE-2026-10600 MEDIUM - 4.3

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on...

Vendor: Mattermost
Product: Mattermost
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.

Vendor: Ericsson
Product: Ericsson Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

Vendor: Ericsson
Product: Packet Core Controller (PCC)
Published: Jul 27, 2026
Source: NVD
CVE-2026-65879 CRITICAL - 9.8

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD

Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

Vendor: joomshaper.com
Product: SP Page Builder extension for Joomla
Published: Jul 27, 2026
Source: NVD