Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,801 - 9,820 of 13,224 CVEs
CVE-2026-28072 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixFort pixfort Core pixfort-core allows Reflected XSS.This issue affects pixfort Core: from n/a through <= 3.2.22.

Vendor: PixFort
Product: pixfort Core
Published: Mar 05, 2026
Source: NVD
CVE-2026-28069 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Le Truffe letruffe allows PHP Local File Inclusion.This issue affects Le Truffe: from n/a through <= 1.1.7.

Vendor: ThemeREX
Product: Le Truffe
Published: Mar 05, 2026
Source: NVD
CVE-2026-28068 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Rhythmo rhythmo allows PHP Local File Inclusion.This issue affects Rhythmo: from n/a through <= 1.3.4.

Vendor: ThemeREX
Product: Rhythmo
Published: Mar 05, 2026
Source: NVD
CVE-2026-28067 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Bassein bassein allows PHP Local File Inclusion.This issue affects Bassein: from n/a through <= 1.0.15.

Vendor: ThemeREX
Product: Bassein
Published: Mar 05, 2026
Source: NVD
CVE-2026-28066 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Legrand legrand allows PHP Local File Inclusion.This issue affects Legrand: from n/a through <= 2.17.

Vendor: ThemeREX
Product: Legrand
Published: Mar 05, 2026
Source: NVD
CVE-2026-28065 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Eject eject allows PHP Local File Inclusion.This issue affects Eject: from n/a through <= 2.17.

Vendor: ThemeREX
Product: Eject
Published: Mar 05, 2026
Source: NVD
CVE-2026-28064 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Edge Decor edge-decor allows PHP Local File Inclusion.This issue affects Edge Decor: from n/a through <= 2.2.

Vendor: ThemeREX
Product: Edge Decor
Published: Mar 05, 2026
Source: NVD
CVE-2026-28063 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue affects Asia Garden: from n/a through <= 1.3.1.

Vendor: ThemeREX
Product: Asia Garden
Published: Mar 05, 2026
Source: NVD
CVE-2026-28062 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Happy Baby happy-baby allows PHP Local File Inclusion.This issue affects Happy Baby: from n/a through <= 1.2.12.

Vendor: ThemeREX
Product: Happy Baby
Published: Mar 05, 2026
Source: NVD
CVE-2026-28061 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tiger Claw tiger-claw allows PHP Local File Inclusion.This issue affects Tiger Claw: from n/a through <= 1.1.14.

Vendor: ThemeREX
Product: Tiger Claw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28060 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX S.King stephanie-king allows PHP Local File Inclusion.This issue affects S.King: from n/a through <= 1.5.3.

Vendor: ThemeREX
Product: S.King
Published: Mar 05, 2026
Source: NVD
CVE-2026-28059 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Dermatology Clinic dermatology-clinic allows PHP Local File Inclusion.This issue affects Dermatology Clinic: from n/a through <= 1.4.3.

Vendor: ThemeREX
Product: Dermatology Clinic
Published: Mar 05, 2026
Source: NVD
CVE-2026-28058 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Dixon dixon allows PHP Local File Inclusion.This issue affects Dixon: from n/a through <= 1.4.2.1.

Vendor: ThemeREX
Product: Dixon
Published: Mar 05, 2026
Source: NVD
CVE-2026-28057 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Mandala mandala allows PHP Local File Inclusion.This issue affects Mandala: from n/a through <= 2.8.

Vendor: ThemeREX
Product: Mandala
Published: Mar 05, 2026
Source: NVD
CVE-2026-28056 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX MCKinney's Politics mckinney-politics allows PHP Local File Inclusion.This issue affects MCKinney's Politics: from n/a through <= 1.2.8.

Vendor: ThemeREX
Product: MCKinney's Politics
Published: Mar 05, 2026
Source: NVD
CVE-2026-28055 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX M.Williamson williamson allows PHP Local File Inclusion.This issue affects M.Williamson: from n/a through <= 1.2.11.

Vendor: ThemeREX
Product: M.Williamson
Published: Mar 05, 2026
Source: NVD
CVE-2026-28054 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Legal Stone legal-stone allows PHP Local File Inclusion.This issue affects Legal Stone: from n/a through <= 1.2.11.

Vendor: ThemeREX
Product: Legal Stone
Published: Mar 05, 2026
Source: NVD
CVE-2026-28053 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Miller christine-miller allows PHP Local File Inclusion.This issue affects Miller: from n/a through <= 1.3.3.

Vendor: ThemeREX
Product: Miller
Published: Mar 05, 2026
Source: NVD
CVE-2026-28052 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Peter Mason petermason allows PHP Local File Inclusion.This issue affects Peter Mason: from n/a through <= 1.4.5.

Vendor: ThemeREX
Product: Peter Mason
Published: Mar 05, 2026
Source: NVD
CVE-2026-28051 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yacht Rental yacht-rental allows PHP Local File Inclusion.This issue affects Yacht Rental: from n/a through <= 2.6.

Vendor: ThemeREX
Product: Yacht Rental
Published: Mar 05, 2026
Source: NVD