Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,981 - 2,000 of 3,443 CVEs
CVE-2026-32482 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24.

Vendor: deothemes
Product: Ona
Published: Mar 25, 2026
Source: NVD
CVE-2026-31920 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange for WooCommerce: from n/a through <=...

Vendor: Devteam HaywoodTech
Product: Product Rearrange for WooCommerce
Published: Mar 25, 2026
Source: NVD
CVE-2026-2414 CRITICAL - 9.8

Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 before 10.7.2.

Vendor: hypr
Product: hypr
Published: Mar 25, 2026
Source: NVD
CVE-2026-27095 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <= 5.6.0.

Vendor: magepeopleteam
Product: Bus Ticket Booking with Seat Reservation
Published: Mar 25, 2026
Source: NVD
CVE-2026-27084 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.

Vendor: ThemeREX
Product: Buisson
Published: Mar 25, 2026
Source: NVD
CVE-2026-27083 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.

Vendor: ThemeREX
Product: Work & Travel Company
Published: Mar 25, 2026
Source: NVD
CVE-2026-27082 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.

Vendor: ThemeREX
Product: Love Story
Published: Mar 25, 2026
Source: NVD
CVE-2026-27071 CRITICAL - 9.1

Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 3.0.7.

Vendor: Arraytics
Product: WPCafe
Published: Mar 25, 2026
Source: NVD
CVE-2026-27051 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.

Vendor: uxper
Product: Golo
Published: Mar 25, 2026
Source: NVD
CVE-2026-27049 CRITICAL - 9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2.

Vendor: NooTheme
Product: Jobica Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-27044 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0.

Vendor: TotalSuite
Product: Total Poll Lite
Published: Mar 25, 2026
Source: NVD
CVE-2026-25447 CRITICAL - 9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through <= 2.3.9.

Vendor: Jonathan Daggerhart
Product: Widget Wrangler
Published: Mar 25, 2026
Source: NVD
CVE-2026-25429 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.

Vendor: wpdive
Product: Nexa Blocks
Published: Mar 25, 2026
Source: NVD
CVE-2026-25413 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

Vendor: iqonicdesign
Product: WPBookit Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-25377 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.

Vendor: eyecix
Product: Addon Jobsearch Chat
Published: Mar 25, 2026
Source: NVD
CVE-2026-25366 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.

Vendor: Themeisle
Product: Woody ad snippets
Published: Mar 25, 2026
Source: NVD
CVE-2026-25345 CRITICAL - 9.9

Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.

Vendor: GalleryCreator
Product: SimpLy Gallery
Published: Mar 25, 2026
Source: NVD
CVE-2026-25340 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from n/a through < 4.8.4.

Vendor: NooTheme
Product: Jobmonster
Published: Mar 25, 2026
Source: NVD
CVE-2026-25035 CRITICAL - 9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2.

Vendor: Wasiliy Strecker / ContestGallery developer
Product: Contest Gallery
Published: Mar 25, 2026
Source: NVD
CVE-2026-25032 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

Vendor: park_of_ideas
Product: Ricky
Published: Mar 25, 2026
Source: NVD