Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,706
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,021 - 8,040 of 13,016 CVEs
CVE-2026-27040 HIGH - 8.8

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a through <= 14.0.31.

Vendor: AA-Team
Product: WZone
Published: Mar 25, 2026
Source: NVD
CVE-2026-27039 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This issue affects WZone: from n/a through <= 14.0.31.

Vendor: AA-Team
Product: WZone
Published: Mar 25, 2026
Source: NVD
CVE-2026-25464 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.3.

Vendor: TieLabs
Product: Jannah
Published: Mar 25, 2026
Source: NVD
CVE-2026-25461 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo Core listeo-core allows Reflected XSS.This issue affects Listeo Core: from n/a through <= 2.0.21.

Vendor: purethemes
Product: Listeo Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-25458 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Moments moments allows PHP Local File Inclusion.This issue affects Moments: from n/a through <= 2.2.

Vendor: Select-Themes
Product: Moments
Published: Mar 25, 2026
Source: NVD
CVE-2026-25457 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows PHP Local File Inclusion.This issue affects Mixtape: from n/a through <= 2.1.

Vendor: Select-Themes
Product: Mixtape
Published: Mar 25, 2026
Source: NVD
CVE-2026-25456 HIGH - 7.5

Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automated FedEx live/manual rates with shipping labels: from n/a through <= 5.1...

Vendor: Aarsiv Groups
Product: Automated FedEx live/manual rates with shipping labels
Published: Mar 25, 2026
Source: NVD
CVE-2026-25452 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDO Remoji remoji allows Stored XSS.This issue affects Remoji: from n/a through <= 2.2.

Vendor: WPDO
Product: Remoji
Published: Mar 25, 2026
Source: NVD
CVE-2026-25435 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Stored XSS.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.

Vendor: wpdevart
Product: Booking calendar, Appointment Booking System
Published: Mar 25, 2026
Source: NVD
CVE-2026-25414 HIGH - 8.8

Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

Vendor: iqonicdesign
Product: WPBookit Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-25406 HIGH - 8.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor LMS Pro: from n/a through <= 3.9.4.

Vendor: Themeum
Product: Tutor LMS Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-25401 HIGH - 7.5

Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.

Vendor: Arni Cinco
Product: WPCargo Track & Trace
Published: Mar 25, 2026
Source: NVD
CVE-2026-25400 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.

Vendor: thememount
Product: Apicona
Published: Mar 25, 2026
Source: NVD
CVE-2026-25397 HIGH - 7.5

Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4.

Vendor: Snowray Software
Product: File Uploader for WooCommerce
Published: Mar 25, 2026
Source: NVD
CVE-2026-25396 HIGH - 7.5

Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Commerce Coinbase For WooCommerce: from n/a through <= 1.6.6.

Vendor: CoderPress
Product: Commerce Coinbase For WooCommerce
Published: Mar 25, 2026
Source: NVD
CVE-2026-25383 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a through <= 3.6.16.

Vendor: Iqonic Design
Product: KiviCare
Published: Mar 25, 2026
Source: NVD
CVE-2026-25382 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes IdealAuto idealauto allows PHP Local File Inclusion.This issue affects IdealAuto: from n/a through < 3.8.6.

Vendor: jwsthemes
Product: IdealAuto
Published: Mar 25, 2026
Source: NVD
CVE-2026-25381 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP Local File Inclusion.This issue affects LoveDate: from n/a through < 3.8.6.

Vendor: jwsthemes
Product: LoveDate
Published: Mar 25, 2026
Source: NVD
CVE-2026-25380 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Feedy feedy allows PHP Local File Inclusion.This issue affects Feedy: from n/a through < 2.1.5.

Vendor: jwsthemes
Product: Feedy
Published: Mar 25, 2026
Source: NVD
CVE-2026-25379 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes StreamVid streamvid allows PHP Local File Inclusion.This issue affects StreamVid: from n/a through < 6.8.6.

Vendor: jwsthemes
Product: StreamVid
Published: Mar 25, 2026
Source: NVD