Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,761 - 6,780 of 12,776 CVEs
CVE-2026-5208 HIGH - 8.2

Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names

Published: Apr 08, 2026
Source: NVD
CVE-2026-3396 HIGH - 7.5

WCAPF โ€“ WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3243 HIGH - 8.8

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-39684 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicfood allows PHP Local File Inclusion.This issue affects OrganicFood: from n/a through <= 3.6.4.

Vendor: UnTheme
Product: OrganicFood
Published: Apr 08, 2026
Source: NVD
CVE-2026-39681 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows PHP Local File Inclusion.This issue affects Homeo: from n/a through <= 1.2.59.

Vendor: ApusTheme
Product: Homeo
Published: Apr 08, 2026
Source: NVD
CVE-2026-39679 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allows PHP Local File Inclusion.This issue affects Freeio: from n/a through <= 1.3.21.

Vendor: ApusTheme
Product: Freeio
Published: Apr 08, 2026
Source: NVD
CVE-2026-39677 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through <= 3.9.

Vendor: Creatives_Planet
Product: Emphires
Published: Apr 08, 2026
Source: NVD
CVE-2026-39671 HIGH - 7.1

Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross Site Request Forgery.This issue affects Extra Fees Plugin for WooCommerce: from n/a through <= 4.3.3.

Vendor: Dotstore
Product: Extra Fees Plugin for WooCommerce
Published: Apr 08, 2026
Source: NVD
CVE-2026-39623 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife allows PHP Local File Inclusion.This issue affects Biolife: from n/a through <= 3.2.3.

Vendor: kutethemes
Product: Biolife
Published: Apr 08, 2026
Source: NVD
CVE-2026-39621 HIGH - 8.8

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.

Vendor: spicethemes
Product: SpicePress
Published: Apr 08, 2026
Source: NVD
CVE-2026-39613 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Boutique kute-boutique allows PHP Local File Inclusion.This issue affects Boutique: from n/a through <= 2.3.3.

Vendor: kutethemes
Product: Boutique
Published: Apr 08, 2026
Source: NVD
CVE-2026-39611 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes KuteShop kuteshop allows PHP Local File Inclusion.This issue affects KuteShop: from n/a through <= 4.2.9.

Vendor: kutethemes
Product: KuteShop
Published: Apr 08, 2026
Source: NVD
CVE-2026-39544 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechco allows PHP Local File Inclusion.This issue affects LabtechCO: from n/a through <= 8.3.

Vendor: themeStek
Product: LabtechCO
Published: Apr 08, 2026
Source: NVD
CVE-2026-39538 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mikado-core allows PHP Local File Inclusion.This issue affects Mikado Core: from n/a through <= 1.6.

Vendor: Mikado-Themes
Product: Mikado Core
Published: Apr 08, 2026
Source: NVD
CVE-2026-39497 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5.

Vendor: RealMag777
Product: FOX
Published: Apr 08, 2026
Source: NVD
CVE-2026-39496 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL Injection.This issue affects YayMail: from n/a through <= 4.3.3.

Vendor: YayCommerce
Product: YayMail
Published: Apr 08, 2026
Source: NVD
CVE-2026-39495 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.

Vendor: NSquared
Product: Simply Schedule Appointments
Published: Apr 08, 2026
Source: NVD
CVE-2026-39487 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1.

Vendor: ameliabooking
Product: Amelia
Published: Apr 08, 2026
Source: NVD
CVE-2026-39479 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force OttoKit suretriggers allows Blind SQL Injection.This issue affects OttoKit: from n/a through <= 1.1.20.

Vendor: Brainstorm Force
Product: OttoKit
Published: Apr 08, 2026
Source: NVD
CVE-2026-39475 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.1.

Vendor: Syed Balkhi
Product: User Feedback
Published: Apr 08, 2026
Source: NVD