Total CVEs

137,114

Critical Severity

3,291

High Severity

12,201

Last 7 Days

1,410
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 541 - 560 of 33,519 CVEs
CVE-2026-5079 HIGH - 7.5

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of dee...

Vendor: expressjs
Product: multer
Published: Jun 15, 2026
Source: NVD
CVE-2026-52704 CRITICAL - 10.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.

Vendor: Edgar Rojas
Product: WooCommerce PDF Invoice Builder
Published: Jun 15, 2026
Source: NVD
CVE-2026-49111 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

Vendor: ThemeGrill
Product: Masteriyo - LMS
Published: Jun 15, 2026
Source: NVD
CVE-2026-49064 HIGH - 7.5

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

Vendor: Stiofan
Product: GetPaid
Published: Jun 15, 2026
Source: NVD
CVE-2026-49062 HIGH - 8.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

Vendor: WP Engine
Product: Faust.js
Published: Jun 15, 2026
Source: NVD
CVE-2026-48969 MEDIUM - 6.5

Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.

Vendor: Really Simple Plugins B.V.
Product: Really Simple SSL
Published: Jun 15, 2026
Source: NVD
CVE-2025-64215 MEDIUM - 6.5

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.

Vendor: StylemixThemes
Product: MasterStudy LMS Pro
Published: Jun 15, 2026
Source: NVD
CVE-2019-25746 HIGH - 7.1

WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_inv...

Vendor: SlicedInvoices
Product: Sliced Invoices
Published: Jun 15, 2026
Source: NVD
CVE-2018-25437 HIGH - 7.5

WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management di...

Vendor: Cherryframework
Product: Cherry Framework Themes
Published: Jun 15, 2026
Source: NVD
CVE-2018-25436 CRITICAL - 9.8

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload ...

Vendor: Shipster
Product: Baggage Freight Shipping Australia
Published: Jun 15, 2026
Source: NVD
CVE-2016-20084 HIGH - 7.2

WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript i...

Vendor: dwbooster
Product: Booking Calendar Contact
Published: Jun 15, 2026
Source: NVD
CVE-2016-20083 MEDIUM - 5.3

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes o...

Vendor: henrikmelin
Product: More Fields
Published: Jun 15, 2026
Source: NVD
CVE-2016-20082 MEDIUM - 6.2

WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and ...

Vendor: abtest
Product: Abtest
Published: Jun 15, 2026
Source: NVD
CVE-2016-20081 HIGH - 7.5

WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access ...

Vendor: Husain
Product: HB Audio Gallery Lite
Published: Jun 15, 2026
Source: NVD
CVE-2016-20080 MEDIUM - 6.2

WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_ab...

Vendor: Brandfolder
Product: Brandfolder
Published: Jun 15, 2026
Source: NVD
CVE-2016-20079 MEDIUM - 6.2

WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway p...

Vendor: jamie
Product: Dharma Booking
Published: Jun 15, 2026
Source: NVD
CVE-2016-20078 MEDIUM - 6.2

WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.ph...

Vendor: Henrique Dias
Product: IMDb Profile Widget
Published: Jun 15, 2026
Source: NVD
CVE-2016-20077 MEDIUM - 6.2

WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in decode.php. Attackers can supply base64-encoded file paths in the 'id' parameter to the decode.php ...

Vendor: KaymeePhotography
Product: Photocart Link
Published: Jun 15, 2026
Source: NVD
CVE-2016-20076 HIGH - 7.5

WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation us...

Vendor: ChrisHurst
Product: Simple Backup
Published: Jun 15, 2026
Source: NVD
CVE-2016-20075 HIGH - 8.8

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Produ...

Vendor: Etoilewebdesign
Product: Ultimate Product Catalog
Published: Jun 15, 2026
Source: NVD