Total CVEs

140,279

Critical Severity

3,710

High Severity

13,344

Last 7 Days

1,816
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 241 - 260 of 36,684 CVEs
CVE-2026-57314 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

Vendor: SureCart
Product: SureCart
Published: Jun 26, 2026
Source: NVD
CVE-2026-57313 MEDIUM - 6.5

Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

Vendor: SureCart
Product: SureCart
Published: Jun 26, 2026
Source: NVD
CVE-2026-57312 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

Vendor: wpeverest
Product: Everest Forms
Published: Jun 26, 2026
Source: NVD
CVE-2026-56773 HIGH - 8.8

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST...

Vendor: teableio
Product: teable
Published: Jun 26, 2026
Source: NVD
CVE-2026-56072 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

Vendor: Xtemos
Product: WoodMart
Published: Jun 26, 2026
Source: NVD
CVE-2026-56070 CRITICAL - 9.3

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

Vendor: ThemeHunk
Product: Advance Product Search
Published: Jun 26, 2026
Source: NVD
CVE-2026-56069 HIGH - 7.5

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

Vendor: Site Building with Toolset
Product: Toolset Forms
Published: Jun 26, 2026
Source: NVD
CVE-2026-56068 CRITICAL - 9.3

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetEngine
Published: Jun 26, 2026
Source: NVD
CVE-2026-56067 CRITICAL - 9.3

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetSmartFilters
Published: Jun 26, 2026
Source: NVD
CVE-2026-56066 MEDIUM - 5.8

Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.

Vendor: ShortPixel
Product: ShortPixel Adaptive Images
Published: Jun 26, 2026
Source: NVD
CVE-2026-56064 HIGH - 8.5

Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

Vendor: Themefic
Product: Tourfic
Published: Jun 26, 2026
Source: NVD
CVE-2026-56063 HIGH - 8.3

Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.

Vendor: bPlugins
Product: MailChimp Block
Published: Jun 26, 2026
Source: NVD
CVE-2026-56062 CRITICAL - 9.3

Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

Vendor: oooorgle
Product: Quotes llama
Published: Jun 26, 2026
Source: NVD
CVE-2026-56061 HIGH - 7.5

Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

Vendor: WP Swings
Product: Subscriptions for WooCommerce
Published: Jun 26, 2026
Source: NVD
CVE-2026-56060 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.

Vendor: tychesoftwares
Product: Print Invoice & Delivery Notes for WooCommerce
Published: Jun 26, 2026
Source: NVD
CVE-2026-56059 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

Vendor: PhysCode
Product: Travel Booking
Published: Jun 26, 2026
Source: NVD
CVE-2026-56058 CRITICAL - 9.9

Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

Vendor: ThemeCatcher
Product: Quform
Published: Jun 26, 2026
Source: NVD
CVE-2026-56057 CRITICAL - 9.8

Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

Vendor: Uncanny Owl
Product: Uncanny Automator Pro
Published: Jun 26, 2026
Source: NVD
CVE-2026-56055 HIGH - 8.8

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

Vendor: InspiryThemes
Product: RealHomes
Published: Jun 26, 2026
Source: NVD
CVE-2026-56048 MEDIUM - 6.5

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.

Vendor: tychesoftwares
Product: Payment Gateway Based Fees and Discounts for WooCommerce
Published: Jun 26, 2026
Source: NVD