Total CVEs

140,279

Critical Severity

3,710

High Severity

13,344

Last 7 Days

1,816
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,141 - 8,160 of 13,041 CVEs
CVE-2026-22496 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hypnotherapy hypnotherapy allows PHP Local File Inclusion.This issue affects Hypnotherapy: from n/a through <= 1.2.10.

Vendor: AncoraThemes
Product: Hypnotherapy
Published: Mar 25, 2026
Source: NVD
CVE-2026-22495 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Greenville greenville allows PHP Local File Inclusion.This issue affects Greenville: from n/a through <= 1.3.2.

Vendor: AncoraThemes
Product: Greenville
Published: Mar 25, 2026
Source: NVD
CVE-2026-22494 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Good Homes good-homes allows PHP Local File Inclusion.This issue affects Good Homes: from n/a through <= 1.3.13.

Vendor: ThemeREX
Product: Good Homes
Published: Mar 25, 2026
Source: NVD
CVE-2026-22493 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gaspard gaspard allows PHP Local File Inclusion.This issue affects Gaspard: from n/a through <= 1.3.

Vendor: Elated-Themes
Product: Gaspard
Published: Mar 25, 2026
Source: NVD
CVE-2026-22491 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.35.

Vendor: wphocus
Product: My auctions allegro
Published: Mar 25, 2026
Source: NVD
CVE-2026-22480 HIGH - 7.2

Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.3.

Vendor: WebToffee
Product: Product Feed for WooCommerce
Published: Mar 25, 2026
Source: NVD
CVE-2026-22448 HIGH - 7.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal.This issue affects PitchPrint: from n/a through <= 11.1.2.

Vendor: flexcubed
Product: PitchPrint
Published: Mar 25, 2026
Source: NVD
CVE-2025-69358 HIGH - 7.5

Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.6.0.

Vendor: Metagauss
Product: EventPrime
Published: Mar 25, 2026
Source: NVD
CVE-2025-69347 HIGH - 8.5

Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSubscription: from n/a through <= 1.8.10.

Vendor: Convers Lab
Product: WPSubscription
Published: Mar 25, 2026
Source: NVD
CVE-2025-69096 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zorka allows Reflected XSS.This issue affects Zorka: from n/a through <= 1.5.7.

Vendor: G5Theme
Product: Zorka
Published: Mar 25, 2026
Source: NVD
CVE-2026-27889 HIGH - 7.5

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before authentication, and s...

Vendor: go
Product: github.com/nats-io/nats-server/v2
Published: Mar 25, 2026
Source: GitHub
CVE-2026-24750 HIGH - 7.6

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper Neutralization of Input During Web Page Generation as Stored XSS when modifying forms. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

Vendor: kiteworks
Product: Secure Data Forms
Published: Mar 25, 2026
Source: NVD
CVE-2026-20125 HIGH - 7.7

A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validatio...

Vendor: Cisco
Product: IOS, Cisco IOS XE Software
Published: Mar 25, 2026
Source: NVD
CVE-2026-20086 HIGH - 8.6

A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. ...

Vendor: Cisco
Product: Cisco IOS XE Software
Published: Mar 25, 2026
Source: NVD
CVE-2026-20084 HIGH - 8.6

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco C...

Vendor: Cisco
Product: Cisco IOS XE Software
Published: Mar 25, 2026
Source: NVD
CVE-2026-20012 HIGH - 8.6

A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a ...

Vendor: Cisco
Product: IOS, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco IOS XE Software, Cisco Secure Firewall Threat Defense (FTD) Software
Published: Mar 25, 2026
Source: NVD
CVE-2026-20004 HIGH - 7.4

A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device. This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vul...

Vendor: Cisco
Product: Cisco IOS XE Software
Published: Mar 25, 2026
Source: NVD
CVE-2026-1917 HIGH - 7.3

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.

Published: Mar 25, 2026
Source: NVD
CVE-2024-58341 HIGH - 8.2

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to...

Vendor: Opencart
Product: OpenCart Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-23514 HIGH - 8.8

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.

Vendor: kiteworks
Product: core
Published: Mar 25, 2026
Source: NVD