Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,753
Quick preset (or use dates below)
Clear Filters
Showing 2,401 - 2,420 of 3,596 CVEs
CVE-2026-24960 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.

Vendor: zozothemes
Product: Charety
Published: Mar 05, 2026
Source: NVD
CVE-2026-23802 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through <= 3.3.2.

Vendor: Jordy Meow
Product: AI Engine
Published: Mar 05, 2026
Source: NVD
CVE-2026-23767 CRITICAL - 9.8

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.

Vendor: Seiko Epson Corporation
Product: ESC/POS
Published: Mar 05, 2026
Source: NVD
CVE-2026-22501 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through <= 1.3.2.

Vendor: axiomthemes
Product: Mounthood
Published: Mar 05, 2026
Source: NVD
CVE-2026-22497 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7.2.

Vendor: AncoraThemes
Product: Jardi
Published: Mar 05, 2026
Source: NVD
CVE-2026-22475 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1.3.4.

Vendor: axiomthemes
Product: Estate
Published: Mar 05, 2026
Source: NVD
CVE-2026-22474 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through <= 1.5.

Vendor: ThemeREX
Product: Equestrian Centre
Published: Mar 05, 2026
Source: NVD
CVE-2026-22454 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5.

Vendor: ThemeREX
Product: Solaris
Published: Mar 05, 2026
Source: NVD
CVE-2026-22453 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through <= 2.3.

Vendor: ThemeREX
Product: Pets Club
Published: Mar 05, 2026
Source: NVD
CVE-2026-22451 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from n/a through <= 1.4.

Vendor: AncoraThemes
Product: Handyman
Published: Mar 05, 2026
Source: NVD
CVE-2026-22390 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Code Injection.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1.

Vendor: Builderall
Product: Builderall Builder for WordPress
Published: Mar 05, 2026
Source: NVD
CVE-2025-69338 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode Core riode-core allows Blind SQL Injection.This issue affects Riode Core: from n/a through <= 1.6.26.

Vendor: don-themes
Product: Riode Core
Published: Mar 05, 2026
Source: NVD
CVE-2025-68555 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/a through < 2.0.1.

Vendor: zozothemes
Product: Nutrie
Published: Mar 05, 2026
Source: NVD
CVE-2025-68554 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarch: from n/a through < 2.0.1.

Vendor: zozothemes
Product: Keenarch
Published: Mar 05, 2026
Source: NVD
CVE-2025-68553 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/a through < 2.0.1.

Vendor: zozothemes
Product: Lendiz
Published: Mar 05, 2026
Source: NVD
CVE-2025-54001 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <= 2.5.

Vendor: ThemeREX
Product: Classter
Published: Mar 05, 2026
Source: NVD
CVE-2024-57854 CRITICAL - 9.1

Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors. Data::Rand::Obscure uses Perl's built-in rand() function, which is not suita...

Vendor: DOUGDUDE
Product: Net::NSCA::Client
Published: Mar 05, 2026
Source: NVD
CVE-2026-3381 CRITICAL - 9.8

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zlib 1.3.2, which addresses findings fron the 7ASecurity audit of zlib. The includes fixs for CVE-2026-2...

Published: Mar 05, 2026
Source: NVD
CVE-2026-3257 CRITICAL - 9.8

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

Vendor: tokuhirom
Product: unqlite
Published: Mar 05, 2026
Source: NVD
CVE-2025-40931 CRITICAL - 9.1

Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will come fro...

Vendor: CHORNY
Product: Apache::Session::Generate::MD5
Published: Mar 05, 2026
Source: NVD