Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,704
Quick preset (or use dates below)
Clear Filters
Showing 6,981 - 7,000 of 13,935 CVEs
CVE-2026-39683 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chief Gnome Garden Gnome Package garden-gnome-package allows DOM-Based XSS.This issue affects Garden Gnome Package: from n/a through <= 2.4.1.

Vendor: Chief Gnome
Product: Garden Gnome Package
Published: Apr 08, 2026
Source: NVD
CVE-2026-39682 MEDIUM - 5.3

Missing Authorization vulnerability in Arjan Pronk linkPizza-Manager linkpizza-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects linkPizza-Manager: from n/a through <= 5.5.5.

Vendor: Arjan Pronk
Product: linkPizza-Manager
Published: Apr 08, 2026
Source: NVD
CVE-2026-39680 MEDIUM - 5.3

Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through <= 1.1.1.

Vendor: MWP Development
Product: Diet Calorie Calculator
Published: Apr 08, 2026
Source: NVD
CVE-2026-39678 MEDIUM - 5.3

Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.6.5.

Vendor: DOTonPAPER
Product: Pinpoint Booking System
Published: Apr 08, 2026
Source: NVD
CVE-2026-39676 MEDIUM - 5.3

Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52.

Vendor: Shahjada
Product: Download Manager
Published: Apr 08, 2026
Source: NVD
CVE-2026-39675 MEDIUM - 5.3

Missing Authorization vulnerability in webmuehle Court Reservation court-reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Court Reservation: from n/a through <= 1.10.11.

Vendor: webmuehle
Product: Court Reservation
Published: Apr 08, 2026
Source: NVD
CVE-2026-39674 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through <= 3.1.1.

Vendor: Manoj Kumar
Product: MK Google Directions
Published: Apr 08, 2026
Source: NVD
CVE-2026-39673 MEDIUM - 5.3

Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iZooto: from n/a through <= 3.7.20.

Vendor: shrikantkale
Product: iZooto
Published: Apr 08, 2026
Source: NVD
CVE-2026-39672 MEDIUM - 5.3

Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1.

Vendor: shiptime
Product: ShipTime: Discounted Shipping Rates
Published: Apr 08, 2026
Source: NVD
CVE-2026-39670 MEDIUM - 6.0

Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through <= 2.3.0.

Vendor: Brecht
Product: Visual Link Preview
Published: Apr 08, 2026
Source: NVD
CVE-2026-39669 MEDIUM - 5.3

Missing Authorization vulnerability in NitroPack NitroPack nitropack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NitroPack: from n/a through <= 1.19.3.

Vendor: NitroPack
Product: NitroPack
Published: Apr 08, 2026
Source: NVD
CVE-2026-39668 MEDIUM - 5.3

Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through <= 1.0.6.

Vendor: g5theme
Product: Book Previewer for Woocommerce
Published: Apr 08, 2026
Source: NVD
CVE-2026-39667 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-Based XSS.This issue affects Korea SNS: from n/a through <= 1.7.0.

Vendor: Jongmyoung Kim
Product: Korea SNS
Published: Apr 08, 2026
Source: NVD
CVE-2026-39666 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in telepathy Hello Bar Popup Builder hellobar allows DOM-Based XSS.This issue affects Hello Bar Popup Builder: from n/a through <= 1.5.1.

Vendor: telepathy
Product: Hello Bar Popup Builder
Published: Apr 08, 2026
Source: NVD
CVE-2026-39665 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac SEO Friendly Images seo-image allows DOM-Based XSS.This issue affects SEO Friendly Images: from n/a through <= 3.0.5.

Vendor: Vladimir Prelovac
Product: SEO Friendly Images
Published: Apr 08, 2026
Source: NVD
CVE-2026-39664 MEDIUM - 5.3

Missing Authorization vulnerability in leadrebel Leadrebel leadrebel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadrebel: from n/a through <= 1.0.2.

Vendor: leadrebel
Product: Leadrebel
Published: Apr 08, 2026
Source: NVD
CVE-2026-39663 MEDIUM - 5.3

Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.5.

Vendor: themetechmount
Product: TrueBooker
Published: Apr 08, 2026
Source: NVD
CVE-2026-39662 MEDIUM - 5.3

Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Price by Formula for WooCommerce: from n/a through <= 2.5.6.

Vendor: ProWCPlugins
Product: Product Price by Formula for WooCommerce
Published: Apr 08, 2026
Source: NVD
CVE-2026-39660 MEDIUM - 5.3

Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager: from n/a through <= 2.4.1.

Vendor: Automattic
Product: WP Job Manager
Published: Apr 08, 2026
Source: NVD
CVE-2026-39659 MEDIUM - 5.3

Missing Authorization vulnerability in Ultimate Member Ultimate Member ultimate-member allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Member: from n/a through <= 2.11.3.

Vendor: Ultimate Member
Product: Ultimate Member
Published: Apr 08, 2026
Source: NVD