Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,681 - 10,700 of 13,241 CVEs
CVE-2026-22367 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Coworking coworking allows PHP Local File Inclusion.This issue affects Coworking: from n/a through <= 1.6.1.

Vendor: AncoraThemes
Product: Coworking
Published: Feb 20, 2026
Source: NVD
CVE-2026-22366 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Jude jude allows PHP Local File Inclusion.This issue affects Jude: from n/a through <= 1.3.0.

Vendor: axiomthemes
Product: Jude
Published: Feb 20, 2026
Source: NVD
CVE-2026-22364 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes SevenTrees seventrees allows PHP Local File Inclusion.This issue affects SevenTrees: from n/a through <=1.0.2.

Vendor: axiomthemes
Product: SevenTrees
Published: Feb 20, 2026
Source: NVD
CVE-2026-22363 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rhodos rhodos allows PHP Local File Inclusion.This issue affects Rhodos: from n/a through <= 1.3.3.

Vendor: axiomthemes
Product: Rhodos
Published: Feb 20, 2026
Source: NVD
CVE-2026-22362 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Photolia photolia allows PHP Local File Inclusion.This issue affects Photolia: from n/a through <= 1.0.3.

Vendor: axiomthemes
Product: Photolia
Published: Feb 20, 2026
Source: NVD
CVE-2026-22361 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes A-Mart a-mart allows PHP Local File Inclusion.This issue affects A-Mart: from n/a through <= 1.0.2.

Vendor: axiomthemes
Product: A-Mart
Published: Feb 20, 2026
Source: NVD
CVE-2026-22357 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through <= 0.9.0.

Vendor: Spencer Haws
Product: Link Whisper Free
Published: Feb 20, 2026
Source: NVD
CVE-2026-22356 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Automattic Jetpack CRM zero-bs-crm allows PHP Local File Inclusion.This issue affects Jetpack CRM: from n/a through <= 6.7.0.

Vendor: Automattic
Product: Jetpack CRM
Published: Feb 20, 2026
Source: NVD
CVE-2026-22354 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object Injection.This issue affects Woocommerce Category Banner Management: from n/a through <= 2.5.1.

Vendor: Dotstore
Product: Woocommerce Category Banner Management
Published: Feb 20, 2026
Source: NVD
CVE-2026-22352 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PersianScript Persian Woocommerce SMS persian-woocommerce-sms allows Reflected XSS.This issue affects Persian Woocommerce SMS: from n/a through <= 7.1.1.

Vendor: PersianScript
Product: Persian Woocommerce SMS
Published: Feb 20, 2026
Source: NVD
CVE-2026-22346 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow โ€“ Image slider, Gallery slideshow slider-responsive-slideshow allows Object Injection.This issue affects Slider Responsive Slideshow โ€“ Image slider, Gallery slideshow: from n/a through <= 1.5.4.

Vendor: A WP Life
Product: Slider Responsive Slideshow โ€“ Image slider, Gallery slideshow
Published: Feb 20, 2026
Source: NVD
CVE-2026-22345 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery โ€“ Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-gallery allows Object Injection.This issue affects Image Gallery โ€“ Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through <= 1....

Vendor: A WP Life
Product: Image Gallery โ€“ Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery
Published: Feb 20, 2026
Source: NVD
CVE-2026-22344 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes FiveStar fivestar allows PHP Local File Inclusion.This issue affects FiveStar: from n/a through <= 1.7.

Vendor: Mikado-Themes
Product: FiveStar
Published: Feb 20, 2026
Source: NVD
CVE-2026-20761 HIGH - 8.1

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.

Vendor: EnOcean Edge Inc
Product: SmartServer IoT
Published: Feb 20, 2026
Source: NVD
CVE-2025-69410 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Belletrist belletrist allows PHP Local File Inclusion.This issue affects Belletrist: from n/a through <= 1.2.

Vendor: Edge-Themes
Product: Belletrist
Published: Feb 20, 2026
Source: NVD
CVE-2025-69409 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coaching pj allows PHP Local File Inclusion.This issue affects PJ | Life & Business Coaching: from n/a through <= 3.0.0.

Vendor: axiomthemes
Product: PJ | Life & Business Coaching
Published: Feb 20, 2026
Source: NVD
CVE-2025-69408 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes HealthFirst healthfirst allows PHP Local File Inclusion.This issue affects HealthFirst: from n/a through <= 1.0.1.

Vendor: Mikado-Themes
Product: HealthFirst
Published: Feb 20, 2026
Source: NVD
CVE-2025-69407 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Inclusion.This issue affects Struktur: from n/a through <= 2.5.1.

Vendor: Select-Themes
Product: Struktur
Published: Feb 20, 2026
Source: NVD
CVE-2025-69406 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX FreightCo freightco allows PHP Local File Inclusion.This issue affects FreightCo: from n/a through <= 1.1.7.

Vendor: ThemeREX
Product: FreightCo
Published: Feb 20, 2026
Source: NVD
CVE-2025-69402 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX R&F rf allows PHP Local File Inclusion.This issue affects R&F: from n/a through <= 1.5.

Vendor: ThemeREX
Product: R&F
Published: Feb 20, 2026
Source: NVD