Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,810
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 241 - 260 of 36,720 CVEs
CVE-2026-57647 HIGH - 7.5

Contributor Local File Inclusion in Panorama Viewer โ€“ 360 Degree Image + Video Viewer <= 1.6.1 versions.

Vendor: bPlugins
Product: Panorama Viewer โ€“ 360 Degree Image + Video Viewer
Published: Jun 26, 2026
Source: NVD
CVE-2026-57646 MEDIUM - 5.4

Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.

Vendor: Majestic Support
Product: Majestic Support
Published: Jun 26, 2026
Source: NVD
CVE-2026-57645 HIGH - 8.1

newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

Vendor: Tribulant Software
Product: Newsletters
Published: Jun 26, 2026
Source: NVD
CVE-2026-57644 HIGH - 8.5

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

Vendor: jetmonsters
Product: Restaurant Menu by MotoPress
Published: Jun 26, 2026
Source: NVD
CVE-2026-57643 HIGH - 8.5

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

Vendor: AF themes
Product: WP Post Author
Published: Jun 26, 2026
Source: NVD
CVE-2026-57642 HIGH - 8.5

Contributor SQL Injection in Gallery <= 4.7.8 versions.

Vendor: bestwebsoft
Product: Gallery
Published: Jun 26, 2026
Source: NVD
CVE-2026-57641 MEDIUM - 6.5

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

Vendor: Contempoinc
Product: Real Estate 7
Published: Jun 26, 2026
Source: NVD
CVE-2026-57640 MEDIUM - 4.3

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.

Vendor: Stylemix
Product: MasterStudy LMS
Published: Jun 26, 2026
Source: NVD
CVE-2026-57638 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

Vendor: WPManageNinja LLC
Product: Fluent Booking
Published: Jun 26, 2026
Source: NVD
CVE-2026-57637 MEDIUM - 4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

Vendor: tychesoftwares
Product: Abandoned Cart Lite for WooCommerce
Published: Jun 26, 2026
Source: NVD
CVE-2026-57636 HIGH - 8.5

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

Vendor: Tomdever
Product: wpForo Forum
Published: Jun 26, 2026
Source: NVD
CVE-2026-57635 MEDIUM - 6.5

Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.

Vendor: FunnelKit
Product: FunnelKit Payment Gateway for Stripe WooCommerce
Published: Jun 26, 2026
Source: NVD
CVE-2026-57634 MEDIUM - 4.3

Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

Vendor: WP Folio Team
Product: PPWP
Published: Jun 26, 2026
Source: NVD
CVE-2026-57633 MEDIUM - 5.3

Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions.

Vendor: WCBoost
Product: WCBoost &#8211; Products Compare
Published: Jun 26, 2026
Source: NVD
CVE-2026-57632 MEDIUM - 5.4

Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

Vendor: Omnisend
Product: Email Marketing for WooCommerce by Omnisend
Published: Jun 26, 2026
Source: NVD
CVE-2026-57631 HIGH - 7.6

Administrator SQL Injection in Popup box <= 6.0.1 versions.

Vendor: Ays Pro
Product: Popup box
Published: Jun 26, 2026
Source: NVD
CVE-2026-57630 MEDIUM - 5.3

Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.

Vendor: Creative Themes
Product: Blocksy Companion Pro
Published: Jun 26, 2026
Source: NVD
CVE-2026-57629 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

Vendor: StatCounter
Product: StatCounter
Published: Jun 26, 2026
Source: NVD
CVE-2026-57628 HIGH - 7.6

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

Vendor: WP All Import
Product: WP All Import
Published: Jun 26, 2026
Source: NVD
CVE-2026-57627 MEDIUM - 4.9

Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

Vendor: Themeum
Product: Kirki
Published: Jun 26, 2026
Source: NVD