Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,800
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,061 - 9,080 of 13,211 CVEs
CVE-2026-32393 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly Theme Addons greenly-addons allows PHP Local File Inclusion.This issue affects Greenly Theme Addons: from n/a through < 8.2.

Vendor: Creatives_Planet
Product: Greenly Theme Addons
Published: Mar 13, 2026
Source: NVD
CVE-2026-32392 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly greenly allows PHP Local File Inclusion.This issue affects Greenly: from n/a through <= 8.1.

Vendor: Creatives_Planet
Product: Greenly
Published: Mar 13, 2026
Source: NVD
CVE-2026-32384 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpBookingly service-booking-manager allows PHP Local File Inclusion.This issue affects WpBookingly: from n/a through <= 1.2.9.

Vendor: magepeopleteam
Product: WpBookingly
Published: Mar 13, 2026
Source: NVD
CVE-2026-32369 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7.

Vendor: RadiusTheme
Product: Medilink-Core
Published: Mar 13, 2026
Source: NVD
CVE-2026-32368 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind SQL Injection.This issue affects Geo to Lat: from n/a through <= 1.0.19.

Vendor: delphiknight
Product: Geo to Lat
Published: Mar 13, 2026
Source: NVD
CVE-2026-32366 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categories allows Blind SQL Injection.This issue affects Collapsing Categories: from n/a through <= 3.0.9.

Vendor: robfelty
Product: Collapsing Categories
Published: Mar 13, 2026
Source: NVD
CVE-2026-32365 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Collapsing Archives: from n/a through <= 3.0.7.

Vendor: robfelty
Product: Collapsing Archives
Published: Mar 13, 2026
Source: NVD
CVE-2026-32364 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8.

Vendor: redqteam
Product: Turbo Manager
Published: Mar 13, 2026
Source: NVD
CVE-2026-32358 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind SQL Injection.This issue affects Booking Calendar: from n/a through <= 10.14.15.

Vendor: wpdevelop
Product: Booking Calendar
Published: Mar 13, 2026
Source: NVD
CVE-2026-32355 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.

Vendor: Crocoblock
Product: JetEngine
Published: Mar 13, 2026
Source: NVD
CVE-2026-32308 HIGH - 7.6

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explicitly allows interactive event bindings in Mermaid dia...

Vendor: OneUptime
Product: oneuptime
Published: Mar 13, 2026
Source: NVD
CVE-2026-31944 HIGH - 7.6

LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the flow, without verifying that the browser hitting the redirec...

Vendor: danny-avila
Product: LibreChat
Published: Mar 13, 2026
Source: NVD
CVE-2026-31922 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fox-lms allows Blind SQL Injection.This issue affects Fox LMS: from n/a through <= 1.0.6.3.

Vendor: Ays Pro
Product: Fox LMS
Published: Mar 13, 2026
Source: NVD
CVE-2026-31917 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.

Vendor: weDevs
Product: WP ERP
Published: Mar 13, 2026
Source: NVD
CVE-2026-31899 HIGH - 7.5

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.

Vendor: Kozea
Product: CairoSVG
Published: Mar 13, 2026
Source: NVD
CVE-2026-31814 HIGH - 7.5

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can cause arithmetic overflow in send-window accounting, which triggers a panic in the connection state machine. This is remotely reachable over a normal ne...

Vendor: libp2p
Product: rust-yamux
Published: Mar 13, 2026
Source: NVD
CVE-2026-2890 HIGH - 7.5

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent stat...

Published: Mar 13, 2026
Source: NVD
CVE-2026-2673 HIGH - 7.5

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred grou...

Published: Mar 13, 2026
Source: NVD
CVE-2026-29079 HIGH - 7.5

Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the q...

Vendor: lexbor
Product: lexbor
Published: Mar 13, 2026
Source: NVD
CVE-2026-29078 HIGH - 7.5

Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary size variable between iterations. The statement ctx->buffer_used -= size with a stale size = 3 causes an integer underflow that wraps to SIZE_MAX. Afterwards, memcpy is called wi...

Vendor: lexbor
Product: lexbor
Published: Mar 13, 2026
Source: NVD