Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,711
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,001 - 8,020 of 13,016 CVEs
CVE-2026-32485 HIGH - 7.5

Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through <= 4.2.8.

Vendor: weDevs
Product: WP User Frontend
Published: Mar 25, 2026
Source: NVD
CVE-2026-32484 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.

Vendor: BoldGrid
Product: weForms
Published: Mar 25, 2026
Source: NVD
CVE-2026-32441 HIGH - 7.7

Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9.

Vendor: WebToffee
Product: Comments Import & Export
Published: Mar 25, 2026
Source: NVD
CVE-2026-31921 HIGH - 8.2

Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2.

Vendor: Devteam HaywoodTech
Product: Product Rearrange for WooCommerce
Published: Mar 25, 2026
Source: NVD
CVE-2026-31913 HIGH - 8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16.

Vendor: Whitebox-Studio
Product: Scape
Published: Mar 25, 2026
Source: NVD
CVE-2026-2995 HIGH - 7.7

GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.

Vendor: gitlab
Product: gitlab
Published: Mar 25, 2026
Source: NVD
CVE-2026-27088 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Darna Framework darna-framework allows Reflected XSS.This issue affects Darna Framework: from n/a through <= 2.9.

Vendor: G5Theme
Product: Darna Framework
Published: Mar 25, 2026
Source: NVD
CVE-2026-27087 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Wolverine Framework wolverine-framework allows Reflected XSS.This issue affects Wolverine Framework: from n/a through <= 1.9.

Vendor: G5Theme
Product: Wolverine Framework
Published: Mar 25, 2026
Source: NVD
CVE-2026-27081 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Rosebud rosebud allows PHP Local File Inclusion.This issue affects Rosebud: from n/a through <= 1.4.

Vendor: Mikado-Themes
Product: Rosebud
Published: Mar 25, 2026
Source: NVD
CVE-2026-27080 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Deston deston allows PHP Local File Inclusion.This issue affects Deston: from n/a through <= 1.0.

Vendor: Mikado-Themes
Product: Deston
Published: Mar 25, 2026
Source: NVD
CVE-2026-27079 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Amfissa amfissa allows PHP Local File Inclusion.This issue affects Amfissa: from n/a through <= 1.1.

Vendor: Mikado-Themes
Product: Amfissa
Published: Mar 25, 2026
Source: NVD
CVE-2026-27078 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Emaurri emaurri allows PHP Local File Inclusion.This issue affects Emaurri: from n/a through <= 1.0.1.

Vendor: Mikado-Themes
Product: Emaurri
Published: Mar 25, 2026
Source: NVD
CVE-2026-27077 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes MultiOffice multioffice allows PHP Local File Inclusion.This issue affects MultiOffice: from n/a through <= 1.2.

Vendor: Mikado-Themes
Product: MultiOffice
Published: Mar 25, 2026
Source: NVD
CVE-2026-27076 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes LuxeDrive luxedrive allows PHP Local File Inclusion.This issue affects LuxeDrive: from n/a through <= 1.0.

Vendor: Mikado-Themes
Product: LuxeDrive
Published: Mar 25, 2026
Source: NVD
CVE-2026-27075 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Belfort belfort allows PHP Local File Inclusion.This issue affects Belfort: from n/a through <= 1.0.

Vendor: Mikado-Themes
Product: Belfort
Published: Mar 25, 2026
Source: NVD
CVE-2026-27073 HIGH - 7.5

Use of Hard-coded Credentials vulnerability in Addi Addi &#8211; Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.This issue affects Addi &#8211; Cuotas que se adaptan a ti: from n/a through <= 2.0.4.

Vendor: Addi
Product: Addi &#8211; Cuotas que se adaptan a ti
Published: Mar 25, 2026
Source: NVD
CVE-2026-27054 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Soledad Data Migrator penci-data-migrator allows Reflected XSS.This issue affects Penci Soledad Data Migrator: from n/a through <= 1.3.1.

Vendor: PenciDesign
Product: Penci Soledad Data Migrator
Published: Mar 25, 2026
Source: NVD
CVE-2026-27048 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes The Aisle Core theaisle-core allows PHP Local File Inclusion.This issue affects The Aisle Core: from n/a through <= 2.0.5.

Vendor: Elated-Themes
Product: The Aisle Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-27047 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly Core curly-core allows PHP Local File Inclusion.This issue affects Curly Core: from n/a through <= 2.1.6.

Vendor: Mikado-Themes
Product: Curly Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-27045 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affects WooCommerce Infinite Scroll: from n/a through <= 1.6.2.

Vendor: sbthemes
Product: WooCommerce Infinite Scroll
Published: Mar 25, 2026
Source: NVD