Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,121 - 3,140 of 3,470 CVEs
CVE-2025-67945 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite โ€“ WooCommerce integration woo-mailerlite allows SQL Injection.This issue affects MailerLite โ€“ WooCommerce integration: from n/a through <= 3.1.2.

Vendor: MailerLite
Product: MailerLite โ€“ WooCommerce integration
Published: Jan 22, 2026
Source: NVD
CVE-2025-67944 CRITICAL - 9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.

Vendor: Nelio Software
Product: Nelio AB Testing
Published: Jan 22, 2026
Source: NVD
CVE-2025-67617 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3.

Vendor: themeton
Product: Consult Aid
Published: Jan 22, 2026
Source: NVD
CVE-2025-64252 CRITICAL - 9.1

Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Request Forgery.This issue affects ANAC XML Viewer: from n/a through <= 1.8.2.

Vendor: Marco Milesi
Product: ANAC XML Viewer
Published: Jan 22, 2026
Source: NVD
CVE-2025-63017 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes WerkStatt Plugin werkstatt-plugin allows PHP Local File Inclusion.This issue affects WerkStatt Plugin: from n/a through <= 1.6.6.

Vendor: fuelthemes
Product: WerkStatt Plugin
Published: Jan 22, 2026
Source: NVD
CVE-2025-62754 CRITICAL - 9.1

Missing Authorization vulnerability in Kapil Paul Payment Gateway bKash for WC woo-payment-bkash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway bKash for WC: from n/a through <= 3.1.0.

Vendor: Kapil Paul
Product: Payment Gateway bKash for WC
Published: Jan 22, 2026
Source: NVD
CVE-2025-62741 CRITICAL - 9.1

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3.

Vendor: SmartDataSoft
Product: Pool Services
Published: Jan 22, 2026
Source: NVD
CVE-2025-62056 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1.

Vendor: blazethemes
Product: News Event
Published: Jan 22, 2026
Source: NVD
CVE-2025-62050 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.0.3.

Vendor: blazethemes
Product: Blogmatic
Published: Jan 22, 2026
Source: NVD
CVE-2025-54003 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Depot depot allows PHP Local File Inclusion.This issue affects Depot: from n/a through <= 1.16.

Vendor: Mikado-Themes
Product: Depot
Published: Jan 22, 2026
Source: NVD
CVE-2025-50004 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1.

Vendor: artbees
Product: JupiterX Core
Published: Jan 22, 2026
Source: NVD
CVE-2025-50003 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Amuli amuli allows PHP Local File Inclusion.This issue affects Amuli: from n/a through <= 2.3.0.

Vendor: axiomthemes
Product: Amuli
Published: Jan 22, 2026
Source: NVD
CVE-2025-50002 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects Energia: from n/a through <= 1.1.2.

Vendor: Farost
Product: Energia
Published: Jan 22, 2026
Source: NVD
CVE-2025-49994 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Athens athens allows PHP Local File Inclusion.This issue affects Athens: from n/a through <= 1.1.6.

Vendor: ovatheme
Product: Athens
Published: Jan 22, 2026
Source: NVD
CVE-2025-49055 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5.

Vendor: kamleshyadav
Product: WP Lead Capturing Pages
Published: Jan 22, 2026
Source: NVD
CVE-2025-49050 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5.

Vendor: kamleshyadav
Product: WP Lead Capturing Pages
Published: Jan 22, 2026
Source: NVD
CVE-2025-49049 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allows SQL Injection.This issue affects DZS Video Gallery: from n/a through <= 12.37.

Vendor: ZoomIt
Product: DZS Video Gallery
Published: Jan 22, 2026
Source: NVD
CVE-2025-47474 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ninetheme Anarkali anarkali allows PHP Local File Inclusion.This issue affects Anarkali: from n/a through <= 1.0.9.

Vendor: Ninetheme
Product: Anarkali
Published: Jan 22, 2026
Source: NVD
CVE-2025-69764 CRITICAL - 9.8

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.

Vendor: n/a
Product: n/a
Published: Jan 22, 2026
Source: NVD
CVE-2026-23760 CRITICAL - 9.8

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An una...

Vendor: SmarterTools
Product: SmarterMail
Published: Jan 22, 2026
Source: NVD