Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
Showing 1,981 - 2,000 of 3,576 CVEs
CVE-2026-32524 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This issue affects Photo Engine: from n/a through <= 6.4.9.

Vendor: Jordy Meow
Product: Photo Engine
Published: Mar 25, 2026
Source: NVD
CVE-2026-32523 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.

Vendor: denishua
Product: WPJAM Basic
Published: Mar 25, 2026
Source: NVD
CVE-2026-32520 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.

Vendor: Andrew Munro / AffiliateWP
Product: RewardsWP
Published: Mar 25, 2026
Source: NVD
CVE-2026-32519 CRITICAL - 9.0

Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.

Vendor: Bit Apps
Product: Bit SMTP
Published: Mar 25, 2026
Source: NVD
CVE-2026-32512 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.

Vendor: Edge-Themes
Product: Pelicula
Published: Mar 25, 2026
Source: NVD
CVE-2026-32502 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.

Vendor: Select-Themes
Product: Borgholm
Published: Mar 25, 2026
Source: NVD
CVE-2026-32499 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.

Vendor: QuantumCloud
Product: ChatBot
Published: Mar 25, 2026
Source: NVD
CVE-2026-32482 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24.

Vendor: deothemes
Product: Ona
Published: Mar 25, 2026
Source: NVD
CVE-2026-31920 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange for WooCommerce: from n/a through <=...

Vendor: Devteam HaywoodTech
Product: Product Rearrange for WooCommerce
Published: Mar 25, 2026
Source: NVD
CVE-2026-2414 CRITICAL - 9.8

Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 before 10.7.2.

Vendor: hypr
Product: hypr
Published: Mar 25, 2026
Source: NVD
CVE-2026-27095 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <= 5.6.0.

Vendor: magepeopleteam
Product: Bus Ticket Booking with Seat Reservation
Published: Mar 25, 2026
Source: NVD
CVE-2026-27084 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11.

Vendor: ThemeREX
Product: Buisson
Published: Mar 25, 2026
Source: NVD
CVE-2026-27083 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.

Vendor: ThemeREX
Product: Work & Travel Company
Published: Mar 25, 2026
Source: NVD
CVE-2026-27082 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.

Vendor: ThemeREX
Product: Love Story
Published: Mar 25, 2026
Source: NVD
CVE-2026-27071 CRITICAL - 9.1

Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 3.0.7.

Vendor: Arraytics
Product: WPCafe
Published: Mar 25, 2026
Source: NVD
CVE-2026-27051 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.

Vendor: uxper
Product: Golo
Published: Mar 25, 2026
Source: NVD
CVE-2026-27049 CRITICAL - 9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2.

Vendor: NooTheme
Product: Jobica Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-27044 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0.

Vendor: TotalSuite
Product: Total Poll Lite
Published: Mar 25, 2026
Source: NVD
CVE-2026-25447 CRITICAL - 9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through <= 2.3.9.

Vendor: Jonathan Daggerhart
Product: Widget Wrangler
Published: Mar 25, 2026
Source: NVD
CVE-2026-25429 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through <= 1.1.1.

Vendor: wpdive
Product: Nexa Blocks
Published: Mar 25, 2026
Source: NVD