Total CVEs

149,278

Critical Severity

4,762

High Severity

17,011

Last 7 Days

3,271
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,281 - 9,300 of 45,683 CVEs
CVE-2026-56011 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

Vendor: chrisvrichardson
Product: MapPress Maps for WordPress
Published: Jun 26, 2026
Source: NVD
CVE-2026-56010 HIGH - 8.8

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

Vendor: Tyche Softwares.
Product: Abandoned Cart Pro for WooCommerce
Published: Jun 26, 2026
Source: NVD
CVE-2026-56008 HIGH - 8.8

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

Vendor: ThemeFusion
Product: Fusion Builder
Published: Jun 26, 2026
Source: NVD
CVE-2026-54847 HIGH - 7.5

Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.

Vendor: Design
Product: Stylish Cost Calculator
Published: Jun 26, 2026
Source: NVD
CVE-2026-54846 HIGH - 7.5

Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.

Vendor: akosglys
Product: Syncee Premium Dropshipping &amp; Wholesale
Published: Jun 26, 2026
Source: NVD
CVE-2026-54840 HIGH - 7.3

Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

Vendor: Tribulant Software
Product: Newsletters
Published: Jun 26, 2026
Source: NVD
CVE-2026-54839 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2.0.9 versions.

Vendor: kingaddons
Product: Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups
Published: Jun 26, 2026
Source: NVD
CVE-2026-54837 HIGH - 7.5

Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.

Vendor: Syed Balkhi
Product: Intranet &amp; Private Site &#8211; All-In-One Intranet
Published: Jun 26, 2026
Source: NVD
CVE-2026-54835 HIGH - 7.5

Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.

Vendor: Rustaurius
Product: Five Star Restaurant Menu
Published: Jun 26, 2026
Source: NVD
CVE-2026-54834 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

Vendor: fpuenteonline
Product: Object Cache 4 everyone
Published: Jun 26, 2026
Source: NVD
CVE-2026-54833 HIGH - 7.4

Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

Vendor: Dev Kabir
Product: Enable CORS
Published: Jun 26, 2026
Source: NVD
CVE-2026-54832 HIGH - 7.5

Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.

Vendor: Jegstudio
Product: Gutenverse Companion
Published: Jun 26, 2026
Source: NVD
CVE-2026-54831 CRITICAL - 9.3

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

Vendor: Paolo
Product: GeoDirectory
Published: Jun 26, 2026
Source: NVD
CVE-2026-54827 CRITICAL - 9.3

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

Vendor: contempoinc
Product: Real Estate 7
Published: Jun 26, 2026
Source: NVD
CVE-2026-54826 HIGH - 7.6

Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

Vendor: PSM Plugins
Product: SupportCandy
Published: Jun 26, 2026
Source: NVD
CVE-2026-54825 CRITICAL - 9.3

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

Vendor: wpDataTables
Product: wpDataTables
Published: Jun 26, 2026
Source: NVD
CVE-2026-54824 HIGH - 7.5

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

Vendor: Ads WPQuads
Product: Ads by WPQuads
Published: Jun 26, 2026
Source: NVD
CVE-2026-54820 CRITICAL - 9.3

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetBooking
Published: Jun 26, 2026
Source: NVD
CVE-2026-52701 MEDIUM - 6.5

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

Vendor: Themegrill
Product: User Registration
Published: Jun 26, 2026
Source: NVD
CVE-2026-4339 MEDIUM - 6.5

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with access to the MCP server in stdio mode to perform server-side request f...

Vendor: mattermost
Product: mattermost_server
Published: Jun 26, 2026
Source: NVD