Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,981 - 10,000 of 13,238 CVEs
CVE-2026-22395 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Local File Inclusion.This issue affects Fiorello: from n/a through <= 1.0.

Vendor: Mikado-Themes
Product: Fiorello
Published: Mar 05, 2026
Source: NVD
CVE-2026-22394 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Evently evently allows PHP Local File Inclusion.This issue affects Evently: from n/a through <= 1.7.

Vendor: Mikado-Themes
Product: Evently
Published: Mar 05, 2026
Source: NVD
CVE-2026-22392 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Cortex cortex allows PHP Local File Inclusion.This issue affects Cortex: from n/a through <= 1.5.

Vendor: Mikado-Themes
Product: Cortex
Published: Mar 05, 2026
Source: NVD
CVE-2026-22389 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Cocco cocco allows PHP Local File Inclusion.This issue affects Cocco: from n/a through <= 1.5.1.

Vendor: Mikado-Themes
Product: Cocco
Published: Mar 05, 2026
Source: NVD
CVE-2026-22387 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Aviana aviana allows PHP Local File Inclusion.This issue affects Aviana: from n/a through <= 2.1.

Vendor: Mikado-Themes
Product: Aviana
Published: Mar 05, 2026
Source: NVD
CVE-2026-22385 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Wolmart wolmart allows PHP Local File Inclusion.This issue affects Wolmart: from n/a through <= 1.9.6.

Vendor: don-themes
Product: Wolmart
Published: Mar 05, 2026
Source: NVD
CVE-2025-69411 HIGH - 7.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-tester-plus allows Path Traversal.This issue affects ionCube tester plus: from n/a through <= 1.3.

Vendor: Robert Seyfriedsberger
Product: ionCube tester plus
Published: Mar 05, 2026
Source: NVD
CVE-2025-69340 HIGH - 7.5

Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3.

Vendor: BuddhaThemes
Product: WeDesignTech Ultimate Booking Addon
Published: Mar 05, 2026
Source: NVD
CVE-2025-69339 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Molla molla allows PHP Local File Inclusion.This issue affects Molla: from n/a through <= 1.5.16.

Vendor: don-themes
Product: Molla
Published: Mar 05, 2026
Source: NVD
CVE-2025-69090 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Remons remons allows PHP Local File Inclusion.This issue affects Remons: from n/a through <= 1.3.4.

Vendor: ovatheme
Product: Remons
Published: Mar 05, 2026
Source: NVD
CVE-2025-53335 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Berger berger allows PHP Local File Inclusion.This issue affects Berger: from n/a through <= 1.1.1.

Vendor: ThemeREX
Product: Berger
Published: Mar 05, 2026
Source: NVD
CVE-2026-2365 HIGH - 7.2

The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verifi...

Published: Mar 05, 2026
Source: NVD
CVE-2026-29127 HIGH - 7.8

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depend...

Vendor: International Datacasting Corporation
Product: SFX2100 Satellite Receiver
Published: Mar 05, 2026
Source: NVD
CVE-2026-26034 HIGH - 7.8

UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL.

Vendor: Dell Inc.
Product: UPS Multi-UPS Management Console (MUMC)
Published: Mar 05, 2026
Source: NVD
CVE-2026-29126 HIGH - 7.8

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and persistence) via modi...

Vendor: International Datacasting Corporation
Product: SFX2100 Satellite Receiver
Published: Mar 05, 2026
Source: NVD
CVE-2026-29124 HIGH - 7.8

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from th...

Vendor: International Datacasting Corporation
Product: SFX2100 Satellite Receiver
Published: Mar 05, 2026
Source: NVD
CVE-2026-29123 HIGH - 7.8

A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symlin...

Vendor: International Datacasting Corporation
Product: SFX2100 Satellite Receiver
Published: Mar 05, 2026
Source: NVD
CVE-2026-29093 HIGH - 8.1

WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sessions in that memcached instance. An attacker who c...

Vendor: composer
Product: wwbn/avideo
Published: Mar 05, 2026
Source: GitHub
CVE-2026-29121 HIGH - 7.8

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file r...

Vendor: International Datacasting Corporation
Product: SFX2100 Satellite Receiver
Published: Mar 05, 2026
Source: NVD
CVE-2026-29786 HIGH - 6.3

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. Thi...

Vendor: npm
Product: tar
Published: Mar 05, 2026
Source: GitHub