Total CVEs

136,978

Critical Severity

3,261

High Severity

12,146

Last 7 Days

1,799
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 221 - 240 of 33,383 CVEs
CVE-2026-34898 HIGH - 7.5

Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.

Vendor: WP Swings
Product: Event Tickets Manager for WooCommerce
Published: Jun 15, 2026
Source: NVD
CVE-2026-34892 MEDIUM - 6.5

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

Vendor: Rank Math SEO
Product: Rank Math SEO
Published: Jun 15, 2026
Source: NVD
CVE-2026-34891 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.

Vendor: IDPay
Product: IDPay Payment Gateway for Woocommerce
Published: Jun 15, 2026
Source: NVD
CVE-2026-34886 HIGH - 7.5

Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.

Vendor: wp.insider
Product: Simple Membership
Published: Jun 15, 2026
Source: NVD
CVE-2026-27407 HIGH - 7.2

Editor Privilege Escalation in AI Engine <= 3.4.9 versions.

Vendor: Meow Apps
Product: AI Engine
Published: Jun 15, 2026
Source: NVD
CVE-2026-27333 HIGH - 8.1

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.

Vendor: VideoWhisper.com
Product: Paid Videochat Turnkey Site
Published: Jun 15, 2026
Source: NVD
CVE-2026-27089 HIGH - 7.5

Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.

Vendor: Magepeople inc.
Product: WpTravelly
Published: Jun 15, 2026
Source: NVD
CVE-2026-27053 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

Vendor: VideoWhisper.com
Product: Broadcast Live Video
Published: Jun 15, 2026
Source: NVD
CVE-2026-25440 MEDIUM - 5.3

Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.

Vendor: WPDeveloper
Product: Essential Addons for Elementor
Published: Jun 15, 2026
Source: NVD
CVE-2026-25425 HIGH - 7.5

Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.

Vendor: ThemeGrill
Product: User Registration
Published: Jun 15, 2026
Source: NVD
CVE-2026-24637 HIGH - 8.5

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

Vendor: Blubrry Podcasting
Product: PowerPress Podcasting
Published: Jun 15, 2026
Source: NVD
CVE-2026-23970 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.

Vendor: Themeisle
Product: Redirection for Contact Form 7
Published: Jun 15, 2026
Source: NVD
CVE-2025-69332 MEDIUM - 6.5

Subscriber Broken Access Control in Bookify <= 1.1.1 versions.

Vendor: myCred
Product: Bookify
Published: Jun 15, 2026
Source: NVD
CVE-2025-68872 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.

Vendor: Eli
Product: Eli&#039;s WordCents adSense Widget with Analytics
Published: Jun 15, 2026
Source: NVD
CVE-2025-68851 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.

Vendor: ArrayHQ
Product: Okay Toolkit
Published: Jun 15, 2026
Source: NVD
CVE-2025-68840 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.

Vendor: markbeljaars
Product: iRobots.txt SEO
Published: Jun 15, 2026
Source: NVD
CVE-2025-68049 MEDIUM - 6.3

Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.

Vendor: bunny.net
Product: bunny.net
Published: Jun 15, 2026
Source: NVD
CVE-2025-60175 MEDIUM - 4.4

Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.

Vendor: vynnus
Product: PopAd
Published: Jun 15, 2026
Source: NVD
CVE-2025-59133 HIGH - 7.5

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

Vendor: Projectopia
Product: Projectopia
Published: Jun 15, 2026
Source: NVD
CVE-2026-48988 MEDIUM - 5.3

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

Vendor: npm
Product: markdown-it
Published: Jun 15, 2026
Source: GitHub