Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,053
Quick preset (or use dates below)
Clear Filters
Showing 2,001 - 2,020 of 3,576 CVEs
CVE-2026-25413 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

Vendor: iqonicdesign
Product: WPBookit Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-25377 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.

Vendor: eyecix
Product: Addon Jobsearch Chat
Published: Mar 25, 2026
Source: NVD
CVE-2026-25366 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.

Vendor: Themeisle
Product: Woody ad snippets
Published: Mar 25, 2026
Source: NVD
CVE-2026-25345 CRITICAL - 9.9

Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.

Vendor: GalleryCreator
Product: SimpLy Gallery
Published: Mar 25, 2026
Source: NVD
CVE-2026-25340 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from n/a through < 4.8.4.

Vendor: NooTheme
Product: Jobmonster
Published: Mar 25, 2026
Source: NVD
CVE-2026-25035 CRITICAL - 9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2.

Vendor: Wasiliy Strecker / ContestGallery developer
Product: Contest Gallery
Published: Mar 25, 2026
Source: NVD
CVE-2026-25032 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

Vendor: park_of_ideas
Product: Ricky
Published: Mar 25, 2026
Source: NVD
CVE-2026-25031 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

Vendor: park_of_ideas
Product: Tasty Daily
Published: Mar 25, 2026
Source: NVD
CVE-2026-25030 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

Vendor: park_of_ideas
Product: Goldish
Published: Mar 25, 2026
Source: NVD
CVE-2026-25029 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

Vendor: park_of_ideas
Product: KIDZ
Published: Mar 25, 2026
Source: NVD
CVE-2026-24993 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Repor...

Vendor: WPFactory
Product: Advanced WooCommerce Product Sales Reporting
Published: Mar 25, 2026
Source: NVD
CVE-2026-24989 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.

Vendor: FantasticPlugins
Product: SUMO Affiliates Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-24971 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.

Vendor: Elated-Themes
Product: Search & Go
Published: Mar 25, 2026
Source: NVD
CVE-2026-24968 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.

Vendor: Xagio SEO
Product: Xagio SEO
Published: Mar 25, 2026
Source: NVD
CVE-2026-24378 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.

Vendor: Metagauss
Product: EventPrime
Published: Mar 25, 2026
Source: NVD
CVE-2026-22507 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.

Vendor: AncoraThemes
Product: Beelove
Published: Mar 25, 2026
Source: NVD
CVE-2026-22500 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2.

Vendor: axiomthemes
Product: m2 | Construction and Tools Store
Published: Mar 25, 2026
Source: NVD
CVE-2026-22484 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0.

Vendor: pebas
Product: Lisfinity Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-26833 CRITICAL - 9.8

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

Vendor: mmahrous
Product: thumbler
Published: Mar 25, 2026
Source: NVD
CVE-2026-26832 CRITICAL - 9.8

node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec(...

Published: Mar 25, 2026
Source: NVD