Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
45,085 matching · page 250/902Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-65577(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | Aug 6, 2026 |
| CVE-2026-65576(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | Aug 6, 2026 |
| CVE-2026-65575(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | Aug 6, 2026 |
| CVE-2026-65574(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. | Aug 6, 2026 |
| CVE-2026-65573(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | Aug 6, 2026 |
| CVE-2026-65572(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | Aug 6, 2026 |
| CVE-2026-65571(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | Aug 6, 2026 |
| CVE-2026-65570(opens NVD record) | High | 8.1 | Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. | Aug 6, 2026 |
| CVE-2026-65569(opens NVD record) | High | 8.5 | Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. | Aug 6, 2026 |
| CVE-2026-65565(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | Aug 6, 2026 |
| CVE-2026-65560(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | Aug 6, 2026 |
| CVE-2026-65559(opens NVD record) | High | 7.2 | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | Aug 6, 2026 |
| CVE-2026-65556(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | Aug 6, 2026 |
| CVE-2026-65554(opens NVD record) | High | 7.1 | Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | Aug 6, 2026 |
| CVE-2026-65553(opens NVD record) | Critical | 10.0 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | Aug 6, 2026 |
| CVE-2026-65552(opens NVD record) | Critical | 9.8 | Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | Aug 6, 2026 |
| CVE-2026-65549(opens NVD record) | High | 7.2 | Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | Aug 6, 2026 |
| CVE-2026-65548(opens NVD record) | Critical | 9.9 | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | Aug 6, 2026 |
| CVE-2026-65547(opens NVD record) | High | 8.5 | Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | Aug 6, 2026 |
| CVE-2026-65546(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | Aug 6, 2026 |
| CVE-2026-65545(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | Aug 6, 2026 |
| CVE-2026-65544(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | Aug 6, 2026 |
| CVE-2026-65543(opens NVD record) | High | 7.5 | Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | Aug 6, 2026 |
| CVE-2026-65542(opens NVD record) | High | 8.8 | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | Aug 6, 2026 |
| CVE-2026-65541(opens NVD record) | High | 7.3 | Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | Aug 6, 2026 |
| CVE-2026-65523(opens NVD record) | High | 7.5 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | Aug 6, 2026 |
| CVE-2026-65520(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | Aug 6, 2026 |
| CVE-2026-65517(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | Aug 6, 2026 |
| CVE-2026-65515(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | Aug 6, 2026 |
| CVE-2026-65513(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | Aug 6, 2026 |
| CVE-2026-65509(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | Aug 6, 2026 |
| CVE-2026-65508(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | Aug 6, 2026 |
| CVE-2026-65507(opens NVD record) | Critical | 9.8 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | Aug 6, 2026 |
| CVE-2026-65504(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | Aug 6, 2026 |
| CVE-2026-65502(opens NVD record) | Medium | 5.3 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | Aug 6, 2026 |
| CVE-2026-61982(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | Aug 6, 2026 |
| CVE-2026-61964(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | Aug 6, 2026 |
| CVE-2026-61963(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | Aug 6, 2026 |
| CVE-2026-61961(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | Aug 6, 2026 |
| CVE-2026-61959(opens NVD record) | Medium | 6.5 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | Aug 6, 2026 |
| CVE-2026-54489(opens NVD record) | Critical | 9.1 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity. | Aug 6, 2026 |
| CVE-2026-53976(opens NVD record) | Critical | 9.1 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments. | Aug 6, 2026 |
| CVE-2026-53975(opens NVD record) | Critical | 9.8 | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response. | Aug 6, 2026 |
| CVE-2026-34502(opens NVD record) | High | 7.5 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. | Aug 6, 2026 |
| CVE-2026-34501(opens NVD record) | High | 7.5 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. | Aug 6, 2026 |
| CVE-2026-34191(opens NVD record) | Critical | 9.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 | Aug 6, 2026 |
| CVE-2026-32548(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | Aug 6, 2026 |
| CVE-2026-32469(opens NVD record) | Medium | 5.3 | Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. | Aug 6, 2026 |
| CVE-2026-32327(opens NVD record) | Critical | 9.1 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | Aug 6, 2026 |
| CVE-2026-28183(opens NVD record) | Unscored | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 6, 2026 |