Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
39,390 matching · page 335/788Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-66427(opens NVD record) | High | 7.6 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. | Jul 27, 2026 |
| CVE-2026-66050(opens NVD record) | High | 7.5 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login. | Jul 27, 2026 |
| CVE-2026-65568(opens NVD record) | Medium | 5.0 | Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | Jul 27, 2026 |
| CVE-2026-65567(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | Jul 27, 2026 |
| CVE-2026-65564(opens NVD record) | Medium | 5.3 | Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | Jul 27, 2026 |
| CVE-2026-65563(opens NVD record) | Medium | 5.9 | Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | Jul 27, 2026 |
| CVE-2026-65562(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | Jul 27, 2026 |
| CVE-2026-65561(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | Jul 27, 2026 |
| CVE-2026-65558(opens NVD record) | Medium | 5.4 | Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | Jul 27, 2026 |
| CVE-2026-65557(opens NVD record) | Medium | 5.9 | Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | Jul 27, 2026 |
| CVE-2026-65436(opens NVD record) | Medium | 6.8 | Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. | Jul 27, 2026 |
| CVE-2026-65435(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | Jul 27, 2026 |
| CVE-2026-65434(opens NVD record) | Medium | 6.5 | Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions. | Jul 27, 2026 |
| CVE-2026-65433(opens NVD record) | Medium | 6.5 | Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | Jul 27, 2026 |
| CVE-2026-59560(opens NVD record) | Medium | 6.5 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | Jul 27, 2026 |
| CVE-2026-59559(opens NVD record) | Medium | 6.5 | Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | Jul 27, 2026 |
| CVE-2026-59558(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | Jul 27, 2026 |
| CVE-2026-59557(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | Jul 27, 2026 |
| CVE-2026-59556(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | Jul 27, 2026 |
| CVE-2026-59553(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | Jul 27, 2026 |
| CVE-2026-59552(opens NVD record) | High | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | Jul 27, 2026 |
| CVE-2026-59551(opens NVD record) | High | 8.5 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Jul 27, 2026 |
| CVE-2026-59550(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | Jul 27, 2026 |
| CVE-2026-59549(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Jul 27, 2026 |
| CVE-2026-59548(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | Jul 27, 2026 |
| CVE-2026-59546(opens NVD record) | High | 7.4 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | Jul 27, 2026 |
| CVE-2026-59539(opens NVD record) | High | 7.5 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | Jul 27, 2026 |
| CVE-2026-59538(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | Jul 27, 2026 |
| CVE-2026-59537(opens NVD record) | High | 7.6 | Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | Jul 27, 2026 |
| CVE-2026-59536(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | Jul 27, 2026 |
| CVE-2026-59535(opens NVD record) | High | 7.3 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | Jul 27, 2026 |
| CVE-2026-59534(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. | Jul 27, 2026 |
| CVE-2026-59533(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | Jul 27, 2026 |
| CVE-2026-59532(opens NVD record) | High | 7.5 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | Jul 27, 2026 |
| CVE-2026-59531(opens NVD record) | High | 7.5 | Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | Jul 27, 2026 |
| CVE-2026-59530(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | Jul 27, 2026 |
| CVE-2026-59529(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | Jul 27, 2026 |
| CVE-2026-59528(opens NVD record) | High | 7.5 | Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | Jul 27, 2026 |
| CVE-2026-59527(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | Jul 27, 2026 |
| CVE-2026-10819(opens NVD record) | Medium | 6.5 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695 | Jul 27, 2026 |
| CVE-2026-10600(opens NVD record) | Medium | 4.3 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694 | Jul 27, 2026 |
| CVE-2025-59181(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users. | Jul 27, 2026 |
| CVE-2025-59180(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information. | Jul 27, 2026 |
| CVE-2025-59178(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system. | Jul 27, 2026 |
| CVE-2025-59177(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages. | Jul 27, 2026 |
| CVE-2025-59172(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root. | Jul 27, 2026 |
| CVE-2026-65879(opens NVD record) | Critical | 9.8 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | Jul 27, 2026 |
| CVE-2026-65878(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. | Jul 27, 2026 |
| CVE-2026-65877(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. | Jul 27, 2026 |
| CVE-2026-65876(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. | Jul 27, 2026 |