Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
Showing 7,221 - 7,240 of 13,544 CVEs
CVE-2026-35525 HIGH - 7.5

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layouts roots before reading it. That check is path-based, not real...

Vendor: npm
Product: liquidjs
Published: Apr 08, 2026
Source: GitHub
CVE-2026-33229 HIGH - 9.8

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scr...

Vendor: maven
Product: org.xwiki.platform:xwiki-platform-oldcore
Published: Apr 08, 2026
Source: GitHub
CVE-2026-5795 HIGH - 7.4

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent reque...

Vendor: maven
Product: org.eclipse.jetty.ee10:jetty-ee10
Published: Apr 08, 2026
Source: NVD
CVE-2026-5301 HIGH - 7.6

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries

Published: Apr 08, 2026
Source: NVD
CVE-2026-28261 HIGH - 7.8

Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to...

Vendor: Dell
Product: Elastic Cloud Storage, ObjectScale
Published: Apr 08, 2026
Source: NVD
CVE-2026-5208 HIGH - 8.2

Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names

Published: Apr 08, 2026
Source: NVD
CVE-2026-3396 HIGH - 7.5

WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3243 HIGH - 8.8

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-39684 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicfood allows PHP Local File Inclusion.This issue affects OrganicFood: from n/a through <= 3.6.4.

Vendor: UnTheme
Product: OrganicFood
Published: Apr 08, 2026
Source: NVD
CVE-2026-39681 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows PHP Local File Inclusion.This issue affects Homeo: from n/a through <= 1.2.59.

Vendor: ApusTheme
Product: Homeo
Published: Apr 08, 2026
Source: NVD
CVE-2026-39679 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allows PHP Local File Inclusion.This issue affects Freeio: from n/a through <= 1.3.21.

Vendor: ApusTheme
Product: Freeio
Published: Apr 08, 2026
Source: NVD
CVE-2026-39677 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through <= 3.9.

Vendor: Creatives_Planet
Product: Emphires
Published: Apr 08, 2026
Source: NVD
CVE-2026-39671 HIGH - 7.1

Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross Site Request Forgery.This issue affects Extra Fees Plugin for WooCommerce: from n/a through <= 4.3.3.

Vendor: Dotstore
Product: Extra Fees Plugin for WooCommerce
Published: Apr 08, 2026
Source: NVD
CVE-2026-39623 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife allows PHP Local File Inclusion.This issue affects Biolife: from n/a through <= 3.2.3.

Vendor: kutethemes
Product: Biolife
Published: Apr 08, 2026
Source: NVD
CVE-2026-39621 HIGH - 8.8

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.

Vendor: spicethemes
Product: SpicePress
Published: Apr 08, 2026
Source: NVD
CVE-2026-39613 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Boutique kute-boutique allows PHP Local File Inclusion.This issue affects Boutique: from n/a through <= 2.3.3.

Vendor: kutethemes
Product: Boutique
Published: Apr 08, 2026
Source: NVD
CVE-2026-39611 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes KuteShop kuteshop allows PHP Local File Inclusion.This issue affects KuteShop: from n/a through <= 4.2.9.

Vendor: kutethemes
Product: KuteShop
Published: Apr 08, 2026
Source: NVD
CVE-2026-39544 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechco allows PHP Local File Inclusion.This issue affects LabtechCO: from n/a through <= 8.3.

Vendor: themeStek
Product: LabtechCO
Published: Apr 08, 2026
Source: NVD
CVE-2026-39538 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mikado-core allows PHP Local File Inclusion.This issue affects Mikado Core: from n/a through <= 1.6.

Vendor: Mikado-Themes
Product: Mikado Core
Published: Apr 08, 2026
Source: NVD
CVE-2026-39497 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5.

Vendor: RealMag777
Product: FOX
Published: Apr 08, 2026
Source: NVD