Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,659
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 361 - 380 of 36,814 CVEs
CVE-2026-57325 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

Vendor: Jellywp
Product: NanoMag
Published: Jun 26, 2026
Source: NVD
CVE-2026-57324 MEDIUM - 6.5

Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

Vendor: VillaTheme
Product: GIFT4U
Published: Jun 26, 2026
Source: NVD
CVE-2026-57323 MEDIUM - 5.8

Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.

Vendor: bPlugins
Product: Flash & HTML5 Video
Published: Jun 26, 2026
Source: NVD
CVE-2026-57322 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

Vendor: weDevs
Product: weMail
Published: Jun 26, 2026
Source: NVD
CVE-2026-57321 HIGH - 7.1

Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

Vendor: icc0rz
Product: H5P
Published: Jun 26, 2026
Source: NVD
CVE-2026-57319 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.

Vendor: RealMag777
Product: FOX
Published: Jun 26, 2026
Source: NVD
CVE-2026-57318 MEDIUM - 6.5

Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.

Vendor: Gemini Labs
Product: Site Reviews
Published: Jun 26, 2026
Source: NVD
CVE-2026-57317 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

Vendor: NSquared
Product: Simply Schedule Appointments
Published: Jun 26, 2026
Source: NVD
CVE-2026-57316 MEDIUM - 6.5

Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

Vendor: Roxnor
Product: GetGenie
Published: Jun 26, 2026
Source: NVD
CVE-2026-57315 HIGH - 8.5

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

Vendor: Creative Themes
Product: Blocksy Companion Pro
Published: Jun 26, 2026
Source: NVD
CVE-2026-57314 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

Vendor: SureCart
Product: SureCart
Published: Jun 26, 2026
Source: NVD
CVE-2026-57313 MEDIUM - 6.5

Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

Vendor: SureCart
Product: SureCart
Published: Jun 26, 2026
Source: NVD
CVE-2026-57312 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

Vendor: wpeverest
Product: Everest Forms
Published: Jun 26, 2026
Source: NVD
CVE-2026-56773 HIGH - 8.8

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST...

Vendor: teableio
Product: teable
Published: Jun 26, 2026
Source: NVD
CVE-2026-56072 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

Vendor: Xtemos
Product: WoodMart
Published: Jun 26, 2026
Source: NVD
CVE-2026-56070 CRITICAL - 9.3

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

Vendor: ThemeHunk
Product: Advance Product Search
Published: Jun 26, 2026
Source: NVD
CVE-2026-56069 HIGH - 7.5

Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

Vendor: Site Building with Toolset
Product: Toolset Forms
Published: Jun 26, 2026
Source: NVD
CVE-2026-56068 CRITICAL - 9.3

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetEngine
Published: Jun 26, 2026
Source: NVD
CVE-2026-56067 CRITICAL - 9.3

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetSmartFilters
Published: Jun 26, 2026
Source: NVD
CVE-2026-56066 MEDIUM - 5.8

Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.

Vendor: ShortPixel
Product: ShortPixel Adaptive Images
Published: Jun 26, 2026
Source: NVD