Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,746
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,701 - 2,720 of 3,469 CVEs
CVE-2026-22365 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Soleng soleng allows PHP Local File Inclusion.This issue affects Soleng: from n/a through <= 1.0.5.

Vendor: axiomthemes
Product: Soleng
Published: Feb 20, 2026
Source: NVD
CVE-2025-70831 CRITICAL - 9.8

A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly sanitize user-supplied input in the mediaId parameter before using it in a system shell command. This allows an unauthenticated attacker to inject arbitrary ...

Vendor: lkw199711
Product: smanga
Published: Feb 20, 2026
Source: NVD
CVE-2025-69405 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.6.

Vendor: ThemeREX
Product: Lorem Ipsum | Books & Media Store
Published: Feb 20, 2026
Source: NVD
CVE-2025-69404 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from n/a through <= 1.5.7.

Vendor: ThemeREX
Product: Extreme Store
Published: Feb 20, 2026
Source: NVD
CVE-2025-69403 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue affects Bravis Addons: from n/a through <= 1.1.9.

Vendor: Bravis-Themes
Product: Bravis Addons
Published: Feb 20, 2026
Source: NVD
CVE-2025-69382 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1.

Vendor: themesflat
Product: Themesflat Elementor
Published: Feb 20, 2026
Source: NVD
CVE-2025-69372 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a through <= 1.6.2.

Vendor: AncoraThemes
Product: SevenHills
Published: Feb 20, 2026
Source: NVD
CVE-2025-69371 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a through <= 1.6.1.

Vendor: AncoraThemes
Product: KindlyCare
Published: Feb 20, 2026
Source: NVD
CVE-2025-69370 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <= 2.5.5.

Vendor: ThemeGoods
Product: Capella
Published: Feb 20, 2026
Source: NVD
CVE-2025-69366 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerce Core emerce-core allows Blind SQL Injection.This issue affects Emerce Core: from n/a through <= 1.8.

Vendor: TeconceTheme
Product: Emerce Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69365 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan Core uroan-core allows Blind SQL Injection.This issue affects Uroan Core: from n/a through <= 1.4.4.

Vendor: TeconceTheme
Product: Uroan Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69337 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Wolmart Core wolmart-core allows Blind SQL Injection.This issue affects Wolmart Core: from n/a through <= 1.9.6.

Vendor: don-themes
Product: Wolmart Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69329 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < 1.4.1.

Vendor: Jthemes
Product: Prestige
Published: Feb 20, 2026
Source: NVD
CVE-2025-69310 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodly Core woodly-core allows Blind SQL Injection.This issue affects Woodly Core: from n/a through <= 1.4.

Vendor: TeconceTheme
Product: Woodly Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69309 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasplate Core saasplate-core allows Blind SQL Injection.This issue affects Saasplate Core: from n/a through <= 1.2.8.

Vendor: TeconceTheme
Product: Saasplate Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69308 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestbyte Core nestbyte-core allows Blind SQL Injection.This issue affects Nestbyte Core: from n/a through <= 1.2.

Vendor: TeconceTheme
Product: Nestbyte Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69307 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medinik Core medinik-core allows Blind SQL Injection.This issue affects Medinik Core: from n/a through <= 1.3.6.

Vendor: TeconceTheme
Product: Medinik Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69306 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Electio Core electio-core allows Blind SQL Injection.This issue affects Electio Core: from n/a through <= 1.4.

Vendor: TeconceTheme
Product: Electio Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69305 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete Core crete-core allows Blind SQL Injection.This issue affects Crete Core: from n/a through <= 1.4.3.

Vendor: TeconceTheme
Product: Crete Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-69304 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allmart allmart-core allows Blind SQL Injection.This issue affects Allmart: from n/a through <= 1.1.

Vendor: TeconceTheme
Product: Allmart
Published: Feb 20, 2026
Source: NVD